Privacy Policy

Last updated: September 1, 2026

This document is a general-purpose Privacy Policy describing how Veyit actually handles data today. It has not been reviewed by a lawyer. Depending on where your Merchants and Customers are located, you may have additional obligations (for example under GDPR or similar regional frameworks) — have this reviewed by qualified legal counsel before treating it as your complete compliance posture.

1. Who this applies to

This Policy describes how Veyit collects and uses personal data when a Merchant operates a Store on the platform, and when a Customer interacts with a Merchant's Telegram bot.

2. What we collect

FromDataWhy
Merchant Name, email, organization details, team member roles Account creation and access control, via our identity provider
Merchant Telegram bot token, connected payment method details Operating the Store's bot and matching incoming payments; tokens are stored encrypted and never displayed back in full
Customer Telegram user ID, display name, language preference Identifying who placed an Order and replying in their language
Customer Order, product, and payment-confirmation records Fulfilling and recording the transaction
Anyone Standard request logs (IP address, timestamps, error data) Security, abuse prevention, and debugging

We do not collect payment card numbers. Payment verification is done by matching a provider transfer (for example, an exchange or on-chain transfer) against an Order, not by processing card details directly.

3. How data is isolated

Each Merchant's data is scoped to that Merchant at the database level — a Merchant cannot read or write another Merchant's Stores, Orders, or Customers, and this is enforced independently of the application code that serves requests.

4. Who we share data with

We use a small number of infrastructure and identity providers to operate the Service:

We do not sell personal data, and we do not share it with advertisers.

5. Retention

We retain Order, payment, and audit records for as long as the associated Store remains active and for a reasonable period afterward to satisfy accounting, dispute, and legal obligations. A Merchant closing a Store does not immediately erase historical transaction records that a Customer, tax authority, or dispute process may still need.

6. Your rights

Depending on where you are located, you may have the right to request access to, correction of, or deletion of your personal data. To make a request, contact us at the address below. We will respond within a reasonable time and may need to verify your identity first.

7. Digital goods and stock files

Digital stock content a Merchant uploads for delivery to Customers is stored privately and is never exposed in logs, previews, or administrative interfaces in plaintext. It is decrypted only at the moment of delivery to the Customer who purchased it.

8. Security

We use encryption in transit and at rest for sensitive fields, tenant isolation enforced at the database layer, and audit logging of sensitive actions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Children

The Service is not directed at children, and we do not knowingly collect personal data from anyone below the age of consent applicable in their jurisdiction.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.

11. Contact

Questions about this Policy, or requests regarding your data, can be sent to support@veyit.com.