Skip to content
Veylo
Terms Privacy Your data
Open Veylo

Privacy Policy

Last updated: 6 June 2026  ·  Effective: 6 June 2026

This Privacy Policy ("Policy") explains how Veylo ("Service", "we", "us", "our"), operated at veylo.tearfulsoft.space, collects, uses, stores, shares, and protects your personal data when you access or use our platform. It also explains your rights under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), the Florida Digital Bill of Rights (FDBR), and other applicable US federal and state privacy laws.

We are committed to handling your personal data responsibly and transparently. Please read this Policy carefully. If you do not agree with our practices, please do not use the Service.

Summary for quick reading: We collect only what we need to run the Service, your Discord and Roblox account info, API credentials (encrypted), payment verification data, and session information. We do not sell your personal data. We do not use advertising cookies or trackers. We store data on servers in the EU/UK. You have rights to access, correct, delete, and port your data.

Table of Contents

  1. Data Controller Identity
  2. Scope and Applicability
  3. Personal Data We Collect
  4. Lawful Bases for Processing (GDPR/UK GDPR)
  5. How We Use Your Data
  6. Cookies and Local Storage
  7. Data Sharing and Disclosure
  8. International Data Transfers
  9. Data Retention
  10. Data Security
  11. Your Rights
  12. Children's Privacy
  13. California Residents (CCPA/CPRA)
  14. Do Not Sell or Share My Personal Information
  15. Florida Residents (FDBR)
  16. Other US State Privacy Rights
  17. Automated Decision-Making and Profiling
  18. Changes to This Policy
  19. Contact and Complaints

1. Data Controller Identity

For the purposes of the GDPR, UK GDPR, and other applicable data protection laws, the data controller for personal data collected through the Service is the Operator of Veylo. Contact details are provided in Section 19.

Where we process personal data relating to third parties on your instructions (for example, Roblox group member information processed when you execute ranking commands), we act as a data processor acting on your instructions, and you are the data controller for such third-party personal data. You are responsible for ensuring you have a lawful basis and any required consents to instruct us to process such data on your behalf.

We have not appointed a formal Data Protection Officer (DPO), as we are not required to do so under applicable law. Data protection enquiries should be directed to the contact address in Section 19.

2. Scope and Applicability

This Policy applies to:

  • All users of the Service, wherever located;
  • Personal data collected directly by us through the Service's website and API;
  • Personal data received from third-party platforms (Discord, Roblox, Ko-fi) in connection with your use of the Service.

This Policy does not apply to:

  • The privacy practices of Discord, Roblox, Ko-fi, or any other third-party service, each third party's practices are governed by their own privacy policies;
  • Personal data processed solely by other users through their own Roblox groups or Discord servers using the Service, such users are independent data controllers.

3. Personal Data We Collect

We collect only the minimum personal data necessary to provide and improve the Service. The categories of personal data we collect, and the sources from which we collect them, are set out below.

3.1 Data You Provide Directly

Category Specific Data Elements How Collected
Roblox API Credentials Open Cloud API keys (encrypted at rest with AES-256-GCM before storage) Entered manually in the dashboard
Payment Verification Data Ko-fi transaction ID entered manually to activate a licence Entered manually in the dashboard
Support Communications Any personal data you include in messages sent to us for support Voluntarily submitted via Discord or email

3.2 Data Collected via Third-Party Authentication

Category Specific Data Elements Source
Discord Account Data Discord user ID, username (including discriminator where applicable), display name, avatar hash, email address Discord OAuth2 API (collected when you sign in)
Roblox Account Data Roblox user ID, Roblox username Roblox OAuth2 API (collected when you link your Roblox account)

3.3 Data Collected Automatically

Category Specific Data Elements Source / Method
Session Data Encrypted session identifier, login timestamps Automatically created on authentication; stored in a signed cookie
IP Address Your IP address at the time of login (stored for security and fraud prevention purposes; visible to administrators only) Automatically collected on each authenticated request
Command and Operation Logs Bot command name, timestamp, target Roblox user ID and username, command outcome (success/failure), latency, error message where applicable, Discord guild ID and channel ID Generated automatically when bot commands are executed
Staff Chat Messages Message content, Discord user ID and username, Roblox username (if linked), avatar hash, timestamp Generated when you send a message in the built-in staff chat feature

3.4 Data Received from Ko-fi

Category Specific Data Elements Source
Ko-fi Webhook Data Transaction ID, payment amount and currency, supporter name, supporter email address (as provided by Ko-fi), payment type, Ko-fi transaction timestamp Ko-fi webhook delivered to our server upon payment

3.5 Data We Do Not Collect

We do not collect:

  • Payment card numbers, bank account details, or any payment instrument information (these are handled exclusively by Ko-fi or Roblox);
  • Government-issued identification numbers;
  • Biometric data;
  • Precise geolocation data;
  • Health or medical information;
  • Racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or sexual orientation;
  • Any data from individuals below the applicable minimum age threshold.

4. Lawful Bases for Processing (GDPR / UK GDPR)

For users in the European Union and United Kingdom, every processing activity requires a lawful basis under Article 6 of the GDPR / UK GDPR. The following table sets out our lawful bases:

Processing Activity Lawful Basis (GDPR Art. 6) Detail
Authentication and account management Performance of contract (Art. 6(1)(b)) Necessary to provide you access to the Service you have contracted for
Storing and using Roblox API credentials to execute commands Performance of contract (Art. 6(1)(b)) Core to the Service's operation; you cannot use the Service without this processing
Licence verification and payment processing Performance of contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) Required to activate and maintain your licence; also required to comply with financial record-keeping obligations
Maintaining operation logs Legitimate interests (Art. 6(1)(f)) Our legitimate interest in providing users with a record of commands executed; users' legitimate interest in auditing group activity
IP address logging for security Legitimate interests (Art. 6(1)(f)) Our legitimate interest in detecting and preventing fraud and unauthorised access
Staff chat messages Performance of contract (Art. 6(1)(b)); Consent (Art. 6(1)(a)) The staff chat feature is opt-in; by using it you consent to your messages being stored and visible to other licensed users
Compliance with legal obligations Legal obligation (Art. 6(1)(c)) Where we are required to retain data by applicable law
Service improvement and bug fixing Legitimate interests (Art. 6(1)(f)) Our legitimate interest in improving the reliability and quality of the Service

Where we rely on legitimate interests as a lawful basis, we have assessed that our interests do not override your rights and interests. You may object to processing based on legitimate interests as described in Section 11.

5. How We Use Your Personal Data

We use the personal data we collect for the following purposes, and no others:

5.1 Service Delivery

  • Authenticate you and maintain your login session;
  • Verify your licence status and unlock appropriate Service features;
  • Execute group management operations on Roblox on your behalf using the credentials you have provided;
  • Display command logs, group statistics, and other information in the dashboard;
  • Send bot commands and responses through your Discord server;
  • Process in-game licence purchases via the Roblox developer product integration.

5.2 Payment and Fraud Prevention

  • Verify Ko-fi transaction data received via webhook to activate licences;
  • Prevent duplicate licence activations using the same transaction ID;
  • Detect and investigate fraudulent or abusive activity.

5.3 Security and Integrity

  • Log IP addresses to detect unauthorised access attempts;
  • Monitor for misuse of the Service or violations of our Terms of Service;
  • Protect against spam, abuse, and automated attacks.

5.4 Legal Compliance

  • Comply with applicable laws, regulations, court orders, and lawful requests from competent authorities;
  • Establish, exercise, or defend legal claims.

5.5 What We Do Not Do

  • We do not sell, rent, or trade your personal data to third parties;
  • We do not use your personal data for targeted advertising or behavioural profiling;
  • We do not share your personal data with data brokers;
  • We do not use automated profiling to make decisions that produce legal or similarly significant effects on you;
  • We do not use your personal data for any purpose incompatible with the purposes described in this Policy.

6. Cookies and Local Storage

6.1 Cookies We Use

We use a minimal number of cookies, strictly necessary to operate the Service:

Cookie Name Purpose Duration Type
connect.sid Session management, identifies your authenticated session after login. This cookie is HTTP-only (not accessible to JavaScript) and Secure (HTTPS only). 7 days (sliding expiry on activity) Strictly necessary

6.2 Local Storage

The dashboard uses browser local storage to store your theme preference (light/dark mode) under the key veylo-theme. This is stored locally on your device and is not transmitted to our servers. It contains no personal data.

6.3 What We Do Not Use

We do not use:

  • Advertising or marketing cookies;
  • Analytics or tracking cookies (e.g., Google Analytics);
  • Third-party tracking pixels;
  • Fingerprinting technologies.

6.4 Cookie Consent

Because we only use strictly necessary cookies that are essential to the operation of the Service, we do not display a cookie consent banner as a matter of legal requirement. However, by using the Service, you acknowledge the use of the session cookie described above. You may disable cookies in your browser settings, but doing so will prevent you from logging in to the Service.

6.5 Third-Party Cookies

Google Fonts, which we use to load typography, may set cookies in accordance with Google's privacy practices. You can review Google's Privacy Policy for details. To avoid Google Fonts cookies entirely, you may block requests to fonts.googleapis.com via your browser or a content blocker.

7. Data Sharing and Disclosure

7.1 We Do Not Sell Your Data

We do not sell, rent, lease, or trade your personal data to any third party for monetary consideration or other value, consistent with the definitions of "selling" and "sharing" under the CCPA/CPRA and equivalent laws.

7.2 Authorised Disclosures

We may share your personal data in the following limited circumstances:

7.2.1 Service Operation

  • Discord: We interact with Discord's APIs to authenticate you and deliver bot commands to your Discord server. Your Discord user ID, server IDs, and channel interactions are transmitted to Discord as necessary to operate the bot. Refer to Discord's Privacy Policy.
  • Roblox: We transmit your Roblox Open Cloud API credentials and command parameters to Roblox's Open Cloud API endpoints to execute the operations you request. Refer to Roblox's Privacy Policy.
  • Ko-fi: We receive transaction data from Ko-fi via webhook. We do not transmit data to Ko-fi except as part of normal HTTPS webhook receipt. Refer to Ko-fi's Privacy Policy.
  • Cloudflare: Our web application is delivered through Cloudflare's network infrastructure, including Cloudflare Tunnel. Cloudflare may process your IP address and request metadata as part of routing and DDoS protection. Refer to Cloudflare's Privacy Policy.

7.2.2 Legal and Regulatory Disclosure

We may disclose your personal data to courts, law enforcement agencies, regulatory authorities, or other third parties where we are legally required to do so or where disclosure is necessary to:

  • Comply with a court order, subpoena, legal process, or governmental request;
  • Protect the rights, property, or safety of us, our users, or the public;
  • Detect, prevent, or address fraud, security, or technical issues;
  • Enforce our Terms of Service or other agreements.

Where permitted by law, we will notify you of any such disclosure request.

7.2.3 Business Transfers

In the event of a merger, acquisition, sale of assets, or other corporate transaction, your personal data may be transferred to the successor entity. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy, and you will have the opportunity to delete your data if you do not consent to the transfer.

7.3 Aggregated and De-identified Data

We may use and share aggregated or de-identified data that cannot reasonably be used to identify you for any purpose, including analytics, research, and service improvement. Such data is not personal data under applicable law.

8. International Data Transfers

8.1 Location of Data Storage

Your personal data is stored on servers located within the United Kingdom / European Economic Area (UK/EEA). We do not currently transfer your personal data outside the UK/EEA for storage purposes.

8.2 Transfers via Third-Party Services

Some of the third-party services we use, including Discord (operated from the US), Roblox (operated from the US), and Ko-fi (operated from the UK/EU), may process your personal data in countries outside your home jurisdiction, including the United States. These transfers occur because:

  • Discord is incorporated in the United States and operates servers globally;
  • Roblox is incorporated in the United States and operates servers globally.

When your data is transferred to these third parties, those transfers are subject to the safeguards described in those third parties' own privacy policies and, where required, standard contractual clauses (SCCs) or equivalent transfer mechanisms approved under GDPR Chapter V and UK GDPR.

8.3 Safeguards

Where transfers of personal data from the UK or EEA to third countries occur, we rely on one or more of the following transfer mechanisms:

  • European Commission adequacy decisions;
  • Standard contractual clauses (SCCs) approved by the European Commission;
  • UK International Data Transfer Agreements (IDTAs) or UK Addendum to EU SCCs;
  • The derogations in Article 49 GDPR where applicable (e.g., transfers necessary for the performance of a contract).

You may request details of the specific transfer mechanisms we rely on by contacting us at the address in Section 19.

9. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to comply with legal obligations and resolve disputes. The following table sets out our retention periods:

Data Category Retention Period Reason
Discord and Roblox account data (user ID, username, avatar, email) Duration of active account, plus 30 days after deletion request Required to provide the Service; 30-day window for account recovery
Encrypted Roblox API credentials Until you delete them from the dashboard, or 30 days after account deletion Required to execute commands on your behalf
Session cookie data 7 days of inactivity (sliding expiry) Strictly necessary for login sessions
Command and operation logs Up to 12 months from the date of the command, unless you request earlier deletion Legitimate interest in providing analytics; users' interest in auditing group operations
Ko-fi transaction records 7 years from the date of transaction Legal obligation to retain financial records; prevention of duplicate licence activation
IP address logs 90 days Security and fraud prevention; rolling window sufficient for incident investigation
Staff chat messages Until deleted by the author or an administrator, or upon account deletion Feature functionality; messages visible to other licensed users during retention period
Support communications 3 years from the date of the last communication Legitimate interest in maintaining records of support interactions for dispute resolution

At the end of the applicable retention period, personal data is securely deleted or anonymised. Where legal obligations require us to retain data beyond the periods stated above, we will retain only the minimum data necessary for compliance purposes.

10. Data Security

10.1 Technical and Organisational Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:

  • Encryption at rest: Roblox API keys and other sensitive credentials are encrypted using AES-256-GCM symmetric encryption before being written to our database. Encryption keys are stored separately from encrypted data.
  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher, enforced through our Cloudflare Tunnel integration.
  • Session security: Session cookies are HTTP-only (inaccessible to client-side JavaScript) and Secure (transmitted only over HTTPS). Sessions are cryptographically signed using a private secret key.
  • Access controls: Access to production server infrastructure and the database is restricted to authorised operators only, protected by SSH key authentication.
  • Input validation: All user-supplied inputs are validated and sanitised to prevent injection attacks.
  • Dependency management: We regularly review and update software dependencies to address known security vulnerabilities.

10.2 Limitations

No system of security is completely impenetrable. Despite our best efforts, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and, where required by applicable law (including GDPR Article 33 and 34), the relevant supervisory authority within the legally required timeframe.

10.3 Your Role in Security

You are responsible for maintaining the security of your Discord account credentials, which are the primary means of authenticating to the Service. You should use a strong, unique password for your Discord account and enable two-factor authentication. We will never ask you for your Discord password.

11. Your Rights

11.1 Rights Under GDPR and UK GDPR

If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights under the GDPR and UK GDPR:

📋
Right of Access (Art. 15 GDPR) You have the right to request a copy of all personal data we hold about you and information about how we process it.
✏️
Right to Rectification (Art. 16 GDPR) You have the right to request correction of inaccurate or incomplete personal data we hold about you.
ðŸ-‘️
Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR) You have the right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you withdraw consent (where consent is the lawful basis), or where we have no other lawful basis for processing. This right is subject to our legal obligation to retain certain records.
⏸️
Right to Restriction of Processing (Art. 18 GDPR) You have the right to request that we restrict processing of your personal data in certain circumstances, for example where you contest the accuracy of the data or where you have objected to processing.
📦
Right to Data Portability (Art. 20 GDPR) Where processing is based on your consent or the performance of a contract, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
🚫
Right to Object (Art. 21 GDPR) You have the right to object to processing of your personal data where the lawful basis is legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds which override your interests, rights, and freedoms, or where processing is necessary for legal claims.
🤖
Rights in Relation to Automated Decision-Making (Art. 22 GDPR) You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not currently use such automated decision-making.
↩️
Right to Withdraw Consent (Art. 7(3) GDPR) Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.

To exercise any of these rights, please contact us at the address in Section 19. We will respond within one calendar month of receiving your request, as required by Article 12 GDPR. We may extend this period by a further two months where requests are complex or numerous, in which case we will notify you within one month of receiving the request. We will not charge a fee for your first request in any 12-month period; however, we may charge a reasonable fee for manifestly unfounded or excessive repeat requests.

We may require you to verify your identity before processing your request. We will not use information provided in a rights request for any purpose other than processing that request.

11.2 Right to Lodge a Complaint with a Supervisory Authority

If you believe we have violated your data protection rights, you have the right to lodge a complaint with the relevant supervisory authority:

  • EU users: The data protection authority of your EU member state of habitual residence, place of work, or the place of the alleged infringement. A full list of EU supervisory authorities is available at edpb.europa.eu.
  • UK users: The Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Website: ico.org.uk. Helpline: 0303 123 1113.

We encourage you to contact us first so that we can try to resolve your concern before you contact a supervisory authority.

12. Children's Privacy

12.1 Age Restrictions

The Service is not directed to, and we do not knowingly collect personal data from, individuals below the following minimum ages:

  • 13 years, for users in the United States, consistent with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506;
  • 16 years, for users in the European Union and EEA, consistent with Article 8 of the GDPR (unless a lower age is permitted by the law of the applicable EU member state, with a minimum of 13);
  • 13 years, for users in the United Kingdom, consistent with the UK GDPR and the Children's Code (Age Appropriate Design Code);
  • The applicable minimum age under local law, for users in all other jurisdictions.

12.2 COPPA Compliance

In accordance with COPPA, we do not knowingly collect, use, or disclose personal information from children under 13 in the United States without verifiable parental consent. If you are a parent or guardian and believe your child under 13 has provided personal data to the Service without your consent, please contact us immediately at the address in Section 19. We will delete such data promptly upon verification.

12.3 Account Detection and Deletion

If we become aware that a user account was created by a person below the applicable minimum age, we will immediately take steps to suspend and delete the account and all associated personal data. We rely on Discord's and Roblox's own age verification mechanisms in addition to our own eligibility requirements.

13. California Residents, CCPA / CPRA Disclosures

13.1 Applicability

This Section applies to residents of the State of California and supplements the rest of this Policy. It is provided pursuant to the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA), Cal. Civ. Code § 1798.100 et seq.

13.2 Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:

CCPA Category Examples Collected Collected?
A, Identifiers Discord user ID, Roblox user ID, username, email address, IP address Yes
B, Personal information categories (Cal. Civ. Code § 1798.80(e)) Name (username), email address Yes (username/email only)
C, Protected classification characteristics Age (indirectly, via eligibility checks) No (not actively collected)
D, Commercial information Transaction ID, payment amount Yes (Ko-fi transaction data)
E, Biometric information N/A No
F, Internet/network activity IP address, session data, command logs Yes
G, Geolocation data N/A (IP addresses are not used to derive precise location) No (not precise)
H, Sensory data N/A No
I, Professional/employment-related information N/A No
J, Non-public education information N/A No
K, Inferences drawn from personal information N/A No
L, Sensitive personal information (CPRA) Account login credentials (Roblox API keys, encrypted) Yes (API keys only, encrypted)

13.3 Sources of Personal Information

We collect personal information from the following sources: directly from you; Discord's OAuth2 API; Roblox's OAuth2 API; Ko-fi's webhook system; and automatically through your use of the Service.

13.4 Business or Commercial Purpose for Collection

We collect personal information for the business and commercial purposes described in Section 5 of this Policy.

13.5 Sale and Sharing of Personal Information

We do not sell personal information, nor do we share personal information with third parties for cross-context behavioural advertising purposes, as those terms are defined under the CCPA/CPRA. See Section 14.

13.6 Your California Privacy Rights

Subject to certain exceptions, California residents have the following rights under the CCPA/CPRA:

  • Right to Know: You have the right to request that we disclose the categories of personal information we have collected about you, the sources, the business purpose for collection, the categories of third parties with whom we share it, and the specific pieces of personal information collected about you.
  • Right to Delete: You have the right to request deletion of personal information we have collected about you, subject to certain exceptions.
  • Right to Correct: You have the right to request correction of inaccurate personal information we maintain about you.
  • Right to Opt-Out of Sale or Sharing: You have the right to opt out of the sale of your personal information or the sharing of your personal information for cross-context behavioural advertising. We do not sell or share personal information, so this right is not currently applicable, but we will honour any opt-out request.
  • Right to Limit Use of Sensitive Personal Information: You have the right to direct us to limit our use of sensitive personal information (including your encrypted API credentials) to that which is necessary to perform the Service. We do not use sensitive personal information beyond what is necessary to provide the Service.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you goods or services, charge different prices, provide a different quality of service, or suggest any such differentiation because you exercised a privacy right.

To exercise your California privacy rights, please contact us using the information in Section 19. We will verify your identity before processing your request. We will respond to verifiable consumer requests within 45 days. If we need more time (up to 90 days total), we will notify you within the initial 45-day period.

13.7 Authorised Agents

California residents may designate an authorised agent to submit requests on their behalf. We will require the authorised agent to provide written authorisation from you, and we may still require you to verify your own identity directly with us for security purposes.

13.8 Financial Incentives

We do not offer financial incentives or price differences in exchange for the collection, retention, or sale of personal information.

14. Do Not Sell or Share My Personal Information

We do not sell your personal information. We do not share your personal information with third parties for cross-context behavioural advertising. Accordingly, there is no opt-out mechanism required. However, if you wish to make a formal opt-out request, or if you believe we may have sold or shared your data in error, please contact us at the address in Section 19.

We also honour Global Privacy Control (GPC) signals where technically feasible. If your browser or extension sends a GPC opt-out signal, we will treat it as a request to opt out of the sale and sharing of your personal information.

15. Florida Residents, Florida Digital Bill of Rights

The Florida Digital Bill of Rights (FDBR), Fla. Stat. § 501.701 et seq., became effective 1 July 2024. The FDBR applies to controllers that: (a) conduct business in Florida or provide products or services targeted to Florida residents; (b) annually process personal data of 100,000 or more Florida consumers, or of 25,000 or more Florida consumers and derive more than 50% of global gross revenue from the sale of personal data. We do not believe we currently meet these thresholds.

Nonetheless, as a matter of good practice, we extend the following rights to Florida residents, consistent with the FDBR's principles: the right to access personal data we hold, the right to correct inaccurate data, the right to delete personal data, the right to data portability, and the right to opt out of targeted advertising, profiling, and the sale of personal data. We do not engage in targeted advertising, profiling, or the sale of personal data.

Florida residents may exercise these rights by contacting us at the address in Section 19.

16. Other US State Privacy Rights

Several US states have enacted comprehensive consumer privacy laws. The following state laws may apply to residents of those states, subject to their applicable thresholds and definitions:

  • Virginia: Consumer Data Protection Act (CDPA)
  • Colorado: Colorado Privacy Act (CPA)
  • Connecticut: Personal Data Privacy and Online Monitoring Act (CTDPA)
  • Utah: Utah Consumer Privacy Act (UCPA)
  • Texas: Texas Data Privacy and Security Act (TDPSA)
  • Montana, Oregon, Delaware, New Hampshire, New Jersey, Nebraska, Indiana, Iowa, Tennessee, Kentucky, Maryland, Minnesota: Various state privacy laws enacted as of the date of this Policy

To the extent these laws apply to our processing of your personal data, we extend the following rights: the right to access, correct, delete, and port your personal data; the right to opt out of targeted advertising, the sale of personal data, and profiling; and the right to appeal our decisions regarding your privacy requests. We do not engage in targeted advertising, sale of personal data, or automated profiling.

To exercise any applicable state privacy rights, contact us at the address in Section 19. We will respond within the timeframe required by applicable law.

17. Automated Decision-Making and Profiling

We do not use your personal data for automated decision-making that produces legal effects or similarly significant effects on you, and we do not build profiles of individual users for commercial, advertising, or other such purposes. The only automated processes we use are:

  • Automatic session expiry after 7 days of inactivity;
  • Automatic licence activation upon verified payment (based on algorithmic verification of transaction data received from Ko-fi or Roblox);
  • Automatic blocking of requests that fail server-side validation checks (e.g., missing authentication tokens).

None of these automated processes produce decisions with legal or similarly significant consequences for you. All decisions regarding account suspension, termination, or licence revocation are made by human reviewers.

18. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in applicable law, our data processing practices, or the Service. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page;
  • Where practicable and required by law, notify you by email (to the address associated with your Discord account) or through a prominent notice on the dashboard;
  • For material changes that require your consent under applicable law, obtain your consent before such changes take effect.

Your continued use of the Service after any updated Policy takes effect constitutes your acceptance of the updated Policy. If you do not agree with a material change, you may request deletion of your account before the change takes effect.

We encourage you to review this Policy periodically. The version of the Policy in effect at the time any data was collected governs our processing of that data.

19. Contact and Complaints

19.1 Exercising Your Rights

To exercise any of your privacy rights or make a formal data rights request, use one of the following methods:

  • Online form (recommended): veylo.tearfulsoft.space/data-rights, a dedicated form for all data rights requests, available to everyone including non-logged-in users. You can select your request type (access, erasure, portability, correction, restriction, objection) and describe your request. We respond within 30 days.
  • Dashboard (fastest, logged-in users): Visit the My Data & Privacy page in your dashboard to download your data instantly or submit a formal request that is tracked in real time.
  • Email / Discord: As listed on the Veylo Ko-fi page. Please include "Privacy Request" in the subject.

We will take reasonable steps to verify your identity before processing your request. Please include sufficient information to identify your account (e.g., your Discord username or Roblox username). We will not use information provided in a rights request for any purpose other than processing that request.

19.2 Response Timeframes

  • GDPR / UK GDPR requests: We will acknowledge your request within 72 hours and respond substantively within 30 days (extendable by a further 60 days for complex requests).
  • CCPA/CPRA requests: We will respond within 45 days (extendable to 90 days with notice).
  • Other requests: We aim to respond within 30 days.

19.3 Complaints

If you believe we have not handled your personal data in accordance with applicable law, we encourage you to contact us first so we can attempt to resolve the matter. If you remain unsatisfied, you have the right to lodge a complaint with the relevant supervisory authority as described in Section 11.2.

19.4 Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and, where required by Article 33 of the GDPR or equivalent provisions of applicable law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Our notification will include information about the nature of the breach, the categories of personal data affected, and the steps we are taking to address it.

© 2026 Veylo. Not affiliated with Roblox Corporation or Discord Inc. TermsPrivacyYour data