Security
We connect to your e-commerce tools with read-only access.
The tokens we hold can read data and nothing else, and we store no card numbers, so a breach at Velur cannot move money.
This page shows the exact access we ask for and what we do with the data we read.
0
Card numbers stored
0
Write scopes requested
EU
Where the database sits
What we ask each source for
| Shopify | None | Read |
|---|---|---|
| Ordersread_orders · read_all_orders | None not requested | Read granted |
| Customersread_customers | None not requested | Read granted |
| Products | None granted | Read not requested |
| Fulfilment | None granted | Read not requested |
We never ask for write access, so there is no Write column to show.
Stripe
Stripe access is a restricted key you create and can revoke. We refuse a secret key.
Recharge
Recharge access is a token you create and can revoke. We ask for read_subscriptions and store_info, and refuse a token that can write.
What we store
The shaped order and subscription records we need to compute a day: amounts, dates, currency, a pseudonymous customer reference. Then the daily figures we computed from them, each stamped with the version of the formula that produced it.
What we never store
No card number and no payment instrument. No customer name, email, phone or address: we keep only the customer id from an order and discard the rest before anything is stored, so we have none to hold.
How customers stay pseudonymous
At the boundary between raw and stage, each source customer id is replaced by a one-way hash with a salt unique to your workspace. What is stored is 16 characters of hex. The original id is not recoverable from it.
What leaves the database
Aggregates only, against a fixed allowlist: computed figures, deltas, calculation versions, units, dates, which rules fired, how fresh each source is, and an opaque workspace reference. The check runs before every brief and blocks it on failure.
Deletion
Shopify's privacy webhooks are implemented. A shop redaction request deletes every row for that workspace across raw, stage and mart. A customer redaction request deletes the customer row and clears their reference from every order. Disconnecting a source deletes the sealed token.
Export
You can export a segment's aggregates as CSV. A general export is not built yet.
Where the data sits
The database is a Supabase Postgres instance in the EU, region eu-west-3, Paris.
Sub-processors
Supabase for the database, in the EU. Vercel for hosting. Anthropic for the narrative, when it is enabled, receiving aggregates only. Resend for email delivery.
Certifications
We hold no SOC 2 and no ISO certification today.
Reporting a problem
Write to hello@velur.io and say what you found.