Privacy Policy
Last updated: 29 August 2026
This Privacy Policy explains how VelvetAuth (“we”, “us”, or “our”) collects, uses, and shares information when you use our website and authentication platform (the “Service”).
1. Who this applies to
- Account holders — developers and teams who register for VelvetAuth.
- End users — people who authenticate or activate licenses through apps that use VelvetAuth. In that case, the app owner is usually the primary controller of that data; we process it to provide the Service.
2. Information we collect
Account information: username, email address, password (stored hashed), plan level, and optional settings such as 2FA.
Billing information: payment status and subscription details. Card payments are processed by Stripe; we do not store full card numbers on our servers.
Application and license data: app configuration, license keys, variables, webhooks, logs, sessions, and related records you create.
End-user / client data (when your app uses our API): identifiers you send (for example usernames, emails, HWIDs, IPs, session tokens), depending on how you configure your integration.
Technical data: IP address, browser/device info, timestamps, and security logs used for abuse prevention and reliability.
Support data: messages you send through tickets or email.
3. How we use information
- Provide, operate, and secure the Service
- Authenticate users, enforce licenses, and run features you enable
- Process subscriptions and prevent fraud
- Send transactional email (verification, password reset, billing notices)
- Respond to support requests
- Monitor abuse, debug issues, and improve the platform
- Comply with law and enforce our Terms
We do not sell your personal information.
4. Legal bases (where applicable)
Depending on your location, we process data because: (a) it is needed to perform our contract with you; (b) we have a legitimate interest in running a secure service; (c) we have consent where required; or (d) we must comply with legal obligations.
5. Sharing
We may share information with:
- Service providers that help us run VelvetAuth (hosting, email delivery, payment processing such as Stripe), under obligations to protect the data.
- You / your team — data in your apps is available to account users and resellers you authorize.
- Authorities when required by law or to protect rights, safety, or security.
- Business transfers if we merge, sell, or reorganize, subject to appropriate protections.
If you connect optional services (for example a WireGuard VPS you control), data needed for that feature is sent to systems you configure.
6. International transfers
We may process data in Australia and other countries where our providers operate. Where required, we use appropriate safeguards for cross-border transfers.
7. Retention
We keep account and service data while your account is active and for a reasonable period afterward for backups, disputes, security, and legal requirements. You may request deletion of your account; some records (for example billing or security logs) may be retained where we must keep them.
8. Security
We use industry-standard measures such as hashed passwords, encrypted transport (HTTPS), access controls, and rate limiting. No method of transmission or storage is 100% secure. You are responsible for protecting your API secrets and for configuring your own applications safely.
9. Cookies and similar tech
We use cookies and similar technologies for sign-in sessions, security (including CSRF protection), and basic site functionality. These are primarily necessary for the Service to work rather than advertising.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to / restrict certain processing. Account holders can update many details in the dashboard. To make a privacy request, contact us using the details below. We may need to verify your identity first.
If you are an end user of a third-party app that uses VelvetAuth, contact that app’s owner first — they control much of the data about you.
11. Children
The Service is not directed to children under 16. If you believe we have collected information from a child inappropriately, contact us and we will take appropriate steps.
12. Changes
We may update this Privacy Policy from time to time. The “Last updated” date will change when we do. Continued use of the Service after an update means you acknowledge the revised policy.
13. Contact
Privacy questions or requests: open a support ticket from your VelvetAuth account, or email [email protected].