Privacy Policy
Last updated August 30, 2026
This Privacy Policy explains what information Velosiq ("Velosiq", "we", "us") collects, why we collect it, who we share it with, and the choices you have. It applies to our website and to the Velosiq application.
Velosiq is a business management platform. That means there are two different kinds of personal information in play, and it matters which is which:
- Account information — information about you, the person or business using Velosiq. We decide how this is used, so we are the controller of it, and this Policy governs it.
- Customer Data — information you enter about your own clients and contacts. You decide how that is used; we only process it to run the Service for you. Section 8 covers it, and your own privacy notice governs how you handle it.
1. Information we collect about you
You give us:
- Account details — your email address, name, and a password (which we store only as a bcrypt hash, never as readable text).
- Business profile — your business name, the name of your principal contact, your street address, and any avatar, header logo, or email header banner you upload.
- Support and correspondence — anything you send us by email, through the Help Center (including article feedback), or through the Send Feedback form in the app. Feedback you submit in the app is stored on your account and emailed to our support address so we can reply to you.
- Contact form messages — if you write to us through the contact form on our website, we keep your name, email address, the business name you give us (optional), what your message is about, your message itself, and which page you sent it from. You do not need an account to use it, so this may be the only information we hold about you. We store it and email it to our support address so we can reply, and we use it only to answer you — not to add you to a marketing list.
- Communication preferences — which categories of Velosiq email you have chosen to receive, and, if you unsubscribe, the date you did so.
We collect automatically:
- Authentication and session data — a signed token identifying your user, business, and role, held in your browser's local storage.
- Security and abuse-prevention data — IP addresses and request patterns used for rate limiting on sign-in, registration, and password reset, and to track failed login attempts against an account. When you request a password reset we also record the IP address the request came from, alongside a one-way hash of the reset link, until the link is used or expires.
- Activity log — a record of changes made in your account, so the account owner can see who did what. Each entry holds who acted, what they changed (including the previous and new values of the fields that moved), when, the IP address and browser user-agent the request came from, and successful and failed sign-in attempts. It also records actions your clients take on documents you send them — opening, accepting, or declining a proposal — including the name they sign with and the IP address they act from, which is what makes an acceptance verifiable. Owners and administrators of a business can read their own account's log; how long it is kept depends on the plan (see How long we keep it).
- Consent records — when you accept our Terms of Service and this Privacy Policy, we record the date and time, the version you accepted, and the IP address you accepted from. We do this so we can demonstrate that consent was given.
- Help Center usage — article view counts and helpful/not-helpful votes. Votes are deduplicated using a one-way hash of your IP address; we do not store the address itself for this purpose.
- Feedback context — when you submit in-app feedback, we also record which page you were on and your browser's user-agent string, so we can reproduce what you were describing.
We receive from others:
- Payment and subscription status from Stripe when you subscribe, change, or cancel a plan.
- Calendar data from Google, if you choose to connect Google Calendar.
2. What we do not collect
- We never see your full payment card number. Subscription payments run through Stripe's hosted Checkout and Customer Portal, and payments from your clients run through Stripe as well. Card details are entered on Stripe's pages, not ours.
- We do not sell personal information, and we do not share it with advertisers or data brokers.
- We do not use your Customer Data to train machine learning models.
- We do not use third-party advertising or cross-site tracking cookies, and we do not use cookies to build a profile of you across other websites. The analytics we do use on our public website are optional and off unless you turn them on.
3. Why we use it
| Purpose | What it covers |
|---|---|
| Providing the Service | Creating and running your account, storing your records, generating invoices and proposals, syncing your calendar |
| Billing | Managing subscriptions, processing payments, applying plan limits and entitlements |
| Security | Authenticating you, rate limiting, detecting and preventing abuse or unauthorized access |
| Communication | Service and account notices, invoices and proposals you ask us to send, invitation emails, replies to your support requests |
| Product and marketing email | Product updates, tips, improvement-program surveys, and occasional offers about Velosiq, sent to the address on your account — each category can be turned off at any time |
| Legal compliance | Meeting tax, accounting, and other legal obligations, and demonstrating that you accepted these agreements |
| Improving the Service | Understanding which help articles are useful and where the product falls short |
| Website analytics | Understanding how visitors find and use velosiq.net — only where you have given consent |
We rely on the necessity of performing our contract with you for most processing, on our legitimate interests in running and securing the Service for security and improvement, on our legitimate interest in telling our own customers about our products and asking for their feedback — which you can object to at any time by unsubscribing — on your consent where you connect an optional integration or allow analytics cookies on our website, and on legal obligation where the law requires us to retain records.
4. Service providers we share with
We share information with a small number of providers who help us run the Service, and only as much as each needs:
| Provider | What they receive | Why |
|---|---|---|
| Stripe | Your email, business name, and subscription details; payment information you enter on their pages | Subscription billing, and payment processing for invoices you send your clients |
| Calendar events you sync, and OAuth tokens we store to maintain the connection | Google Calendar sync, and address autocomplete, both optional | |
| Cloudflare | Your IP address and a captcha token when you sign in, register, or send us a message through the contact form | Turnstile bot protection |
| Google Analytics | Your IP address (shortened by Google before storage), device and browser details, and the pages you view on velosiq.net | Measuring how visitors find and use our public website — only if you consent. Not used inside the Velosiq app. |
| Microsoft Clarity | Your IP address, device and browser details, the pages you view on velosiq.net, and a recording of how you interact with them — clicks, scrolling, and mouse movement, with the text you type masked out | Heatmaps and session replay for our public website, so we can see where visitors get stuck — only if you consent. Not used inside the Velosiq app. |
| Our email provider | Recipient addresses and message contents | Sending invitations, invoices, proposals, reminders, and Velosiq product and marketing email |
| Hostinger | Everything hosted on our servers | Application and database hosting |
We may also disclose information if we are legally required to, if we need to enforce our Terms, or in connection with a merger, acquisition, or sale of assets — in which case we will give you notice before your information becomes subject to a different privacy policy.
5. Optional integrations
Google Calendar. If you connect it, we store an access token and a refresh token so we can keep your appointments in sync. You can disconnect at any time in the app, which removes those tokens, and you can also revoke access from your Google account settings. If you never connect it, we hold nothing from Google.
Stripe Connect. If you connect a Stripe account to collect payments from your clients, we store the account identifier and whether it is enabled for charges — not your Stripe credentials.
6. Files you upload
Some uploads are served publicly and some are not, and the difference is deliberate:
- Public — your business logos, the header banners and images you add to client email templates, and any images used in Help Center articles. Anyone with the URL can view them.
- Access-controlled — expense receipts, project files, and contract attachments. These require an authenticated request from your own account.
Please keep this in mind when choosing where to attach a document.
7. Cookies and browser storage
We group browser storage into two categories, and you control the second one.
Strictly necessary. These make the Service work and cannot be switched off. They include a signed token in your browser's local storage that keeps you signed in, the storage Cloudflare Turnstile needs to tell people from bots on our sign-in, registration, and contact forms, the storage Stripe sets on our billing and payment pages, and a cookie named velosiq_consent that records your choice below (kept for six months). We also store your theme preference, whether you have voted on a Help Center article, and whether you have already seen a one-time milestone message in the app, all in local storage on your own device.
Analytics — off unless you turn it on. On our public website at velosiq.net we use two tools, and both are disabled by default. We do not load either script at all until you consent.
- Google Analytics 4, to understand which pages and referrers bring people to Velosiq. We also tell Google that analytics storage is denied before any tag runs. If you consent, Google sets two cookies,
_gaand_ga_RL3VYBH02E, each lasting up to two years. - Microsoft Clarity, for heatmaps and session replay. This goes further than page counts: it records how you interact with a page — where you click, how far you scroll, how your pointer moves — and plays that back to us as an anonymous session recording, so we can see which parts of the page are confusing. Clarity masks the text you type, and we do not use its feature for attaching your identity to a recording. If you consent, Microsoft sets two cookies,
_clck(up to one year) and_clsk(one day), and stores related values in your browser's local storage.
Both are confined to velosiq.net. We do not use analytics inside the Velosiq app — signed-in pages set no analytics cookies at all, so nothing you do with your own clients' information is ever recorded this way.
We do not use advertising, retargeting, or cross-site tracking cookies, and we do not sell or share the information analytics produces.
Changing your mind. Select Cookie preferences in the footer of our website or the Help Center at any time. Turning analytics off stops further collection and deletes the _ga and _cl cookies already on your device, along with the analytics values in your local storage. You can also block or clear cookies in your browser settings; if you do, we will ask for your choice again.
8. Your clients' information
When you add clients, send invoices, log payments, or upload project files, you are processing personal information about other people. In that relationship you are the controller and Velosiq is your processor:
- We use Customer Data only to provide the Service to you, on your instructions.
- We do not contact your clients on our own behalf, and we do not market to them.
- Each business account is isolated; no other Velosiq customer can access your Customer Data.
- If one of your clients asks us about their information, we will refer them to you.
Email we send to your clients for you. Some features send email to your clients at your direction — invoices, proposals, appointment and payment reminders, and follow-up workflows you schedule. These are sent under your business name and reply to your address; we are only the delivery mechanism, and the content, timing, and decision to send are yours. They are not Velosiq marketing and they are not covered by the marketing preferences in Section 6, which apply to email we send you about your own account. Because your clients have no Velosiq account, these messages carry no Velosiq unsubscribe link — stopping them is done in your account, by switching the workflow off or removing the client.
Your booking page. If you turn on online booking, we host a public page under your business name where anyone with the link can enter their name, email address, and phone number to book a time with you. That information, and the IP address the booking came from, is Customer Data belonging to you: a client record is created in your account automatically, and we use it only to place the appointment and to send the confirmation on your behalf. Because the page is public and unlisted, anyone holding the link can see which times you are free — it shows open times only, never who your existing appointments are with. It is your responsibility to tell people how you use what they enter, and you can switch the page off at any time in your account settings.
You are responsible for telling your clients how you use their information, for having a lawful basis to do so, and for complying with the email marketing rules that apply where you and your clients are located when you use these features. Note that client portal, invoice, and proposal links are unlisted URLs viewable by anyone who has them, and that accepting a proposal records the signer's name, IP address, and timestamp.
9. Security
We hash passwords with bcrypt, authenticate every request with a signed token, and scope every database query to a single business account so data cannot cross between tenants. Sign-in, registration, password reset, and the contact form are rate limited per IP and protected by a captcha, and sign-in and password reset are additionally limited per account. Password reset links are stored only as a one-way hash, expire after an hour, and can be used once; changing a password invalidates every existing session and sends you an email notice. Access-controlled uploads are checked for ownership on every request. Traffic is served over HTTPS.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you without undue delay and as required by law.
10. How long we keep it
Messages you send through the contact form are kept as correspondence so we have a record of what was asked and answered; ask us at legal@velosiq.net and we will delete yours. Activity log entries are kept for a period set by your plan — 30 days on Free and Solo, 90 days on Business, and for as long as the account is open on Team — after which they are deleted automatically. We keep your account information and Customer Data for as long as your account is active. After you close your account, we delete or de-identify it within 90 days, except where we need to keep something longer to comply with tax or accounting rules, to resolve a dispute, or to enforce our agreements. Records of billing transactions and of your acceptance of our Terms are retained for as long as they may be legally relevant. Backups are purged on a rolling schedule.
11. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent for optional integrations and for analytics cookies. If you are in California, you also have the right not to be discriminated against for exercising these rights — and note that we do not sell or share personal information as those terms are defined under the CCPA.
To exercise any of these rights, email legal@velosiq.net. We will respond within the time your law allows, and may need to verify your identity first. Much of your information can also be viewed and corrected directly in the app.
You can stop our product and marketing email at any time from Settings → Notifications in the app, or with the unsubscribe link at the bottom of any such message — no account access required. Service and account messages, such as invoices, receipts, security alerts, and billing notices, are part of the Service and continue while your account is open.
If you are in the EEA or UK and believe we have not handled your information properly, you may complain to your local supervisory authority — though we would appreciate the chance to put it right first.
12. International transfers
Velosiq is operated from the United States and our servers are located there. If you use the Service from outside the US, your information will be transferred to and processed in the US, where privacy laws may differ from those in your country. Where required, we rely on standard contractual clauses or another approved transfer mechanism.
13. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it. Do not use Velosiq to store records about children under 13.
14. Changes to this Policy
We may update this Policy. When we make a material change, we will update the effective date at the top of this page and notify you in the app or by email before it takes effect. We keep a record of which version you accepted.
15. Contact
Privacy questions, or to exercise your rights: legal@velosiq.net
See also our Terms of Service.
This Policy has been prepared to describe how Velosiq actually handles information, but it is not legal advice and has not been reviewed by an attorney on your behalf. If you are relying on it commercially, have a lawyer licensed in your jurisdiction review it.