Skip to content

Security

We connect to your e-commerce tools with read-only access.

The tokens we hold can read data and nothing else, and we store no card numbers, so a breach at Velur cannot move money.

This page shows the exact access we ask for and what we do with the data we read.

0

Card numbers stored

0

Write scopes requested

EU

Where the database sits

What we ask each source for

ShopifyNoneRead
Ordersread_orders · read_all_ordersNone not requestedRead granted
Customersread_customersNone not requestedRead granted
ProductsNone grantedRead not requested
FulfilmentNone grantedRead not requested

We never ask for write access, so there is no Write column to show.

Stripe

Stripe access is a restricted key you create and can revoke. We refuse a secret key.

Recharge

Recharge access is a token you create and can revoke. We ask for read_subscriptions and store_info, and refuse a token that can write.

What we store

The shaped order and subscription records we need to compute a day: amounts, dates, currency, a pseudonymous customer reference. Then the daily figures we computed from them, each stamped with the version of the formula that produced it.

What we never store

No card number and no payment instrument. No customer name, email, phone or address: we keep only the customer id from an order and discard the rest before anything is stored, so we have none to hold.

How customers stay pseudonymous

At the boundary between raw and stage, each source customer id is replaced by a one-way hash with a salt unique to your workspace. What is stored is 16 characters of hex. The original id is not recoverable from it.

What leaves the database

Aggregates only, against a fixed allowlist: computed figures, deltas, calculation versions, units, dates, which rules fired, how fresh each source is, and an opaque workspace reference. The check runs before every brief and blocks it on failure.

Deletion

Shopify's privacy webhooks are implemented. A shop redaction request deletes every row for that workspace across raw, stage and mart. A customer redaction request deletes the customer row and clears their reference from every order. Disconnecting a source deletes the sealed token.

Export

You can export a segment's aggregates as CSV. A general export is not built yet.

Where the data sits

The database is a Supabase Postgres instance in the EU, region eu-west-3, Paris.

Sub-processors

Supabase for the database, in the EU. Vercel for hosting. Anthropic for the narrative, when it is enabled, receiving aggregates only. Resend for email delivery.

Certifications

We hold no SOC 2 and no ISO certification today.

Reporting a problem

Write to hello@velur.io and say what you found.