Privacy Policy
Last updated: August 6, 2026
This policy explains how personal data is collected and processed when you use the Velin website and when licenses are issued or activated. It reflects the current technical operation of the service.
1. Data controller
The data controller is:
Maxime LACOURPAILLE
Sole trader (micro-entrepreneur)
SIREN: 904 331 535
21 rue du bois
65380 Ossun
France
Contact: [email protected]
2. Data we process
Depending on how you use the site and app, we may process:
- Purchase data: email address provided during Stripe Checkout, Stripe session and payment identifiers, amount, currency, order status (paid / refunded), date, and where applicable a refund identifier.
- License data: license key, associated email, status (active / refunded), maximum activations (default 3), creation date, and license email send date.
-
Activation data: device identifier (
device_id) sent by the Velin app, activation date, and last license check date. - Security / anti-abuse data: IP address used temporarily to rate-limit certain API requests.
- Approximate location signals: country derived from the connection and browser language preferences, used only to suggest a suitable payment currency and locale. These signals are not stored as a user profile in our database.
Card payment details are collected and processed by Stripe on its checkout pages. They are not stored on Velin servers.
The site does not currently use third-party analytics or advertising tools (no Google Analytics, Meta Pixel, or similar cookies).
3. Purposes and legal bases
- Contract performance (purchase of a Velin license): creating the order, generating the key, sending the license email, activating and enforcing the device limit.
- Legal obligations: retaining records needed for accounting and transaction justification.
- Legitimate interest: securing the service (per-IP rate limiting), preventing abuse, handling refunds and invalidating related licenses.
- Pre-contractual / service delivery measures: adapting Stripe Checkout currency and language.
4. How data is used
- You start payment through Stripe Checkout from the website.
- After successful payment, an order is recorded, a license key is generated, and an email containing that key is sent to you.
-
The Velin app sends the key and a
device_idto our activation / status APIs to register or verify activation (maximum 3 devices per active license). - On a Stripe refund, the related order and license are marked refunded; activation is no longer allowed.
5. Recipients
Data may be shared with the following categories of recipients:
- Hosting and technical infrastructure — hosting the site, storing orders, licenses and activations, and securing the service (including temporary request limiting). The current host is identified in the legal notice / imprint.
- Payment provider (Stripe) — online payments, collection of email and payment methods, transaction confirmation and refunds.
- Email delivery provider — transactional delivery of the license-key email.
These providers act under their own terms and, as applicable, as processors or as independent controllers for payment processing. Transfers outside the European Economic Area may occur (including to the United States) under GDPR transfer mechanisms (standard contractual clauses, applicable transfer frameworks, etc.).
On request, we can provide the identity of the providers concerned.
6. Retention
- Orders and licenses: kept as long as needed to provide the license and meet applicable accounting / tax obligations (in practice, often for several years after the transaction).
-
Activations (
device_id): kept for the useful life of the license, to enforce the device limit and support status checks. - Anti-abuse technical data (IP): very short retention (on the order of one minute).
- Data held by our providers (payment, hosting, email): according to each provider’s retention policies.
7. Cookies and similar technologies
The Velin site itself does not set analytics or advertising cookies.
During payment, Stripe may set cookies or similar technologies on its domain as needed for secure Checkout. See Stripe’s privacy policy for details.
The host may process technical connection data as part of hosting and securing the site.
8. Security
Reasonable technical measures are in place, including:
- secrets and API keys available only on the server;
- verification of payment notification authenticity;
- per-IP rate limiting on sensitive APIs;
- encrypted communication (HTTPS).
No system is perfectly secure; absolute security cannot be guaranteed.
9. Your rights
Under the GDPR and applicable French data-protection law, you have rights of access, rectification, erasure, restriction, objection, and portability, where the legal conditions are met.
To exercise your rights, contact [email protected] and include the email used for purchase. Identity verification may be required.
Some data (e.g. transaction records) may be retained despite an erasure request when the law requires it.
You may also lodge a complaint with the French supervisory authority (CNIL) (www.cnil.fr).
10. Minors
Online payment is intended for persons with legal capacity to contract. If you are a minor, a purchase should be made by a parent or guardian, or with their consent, as required by applicable law.
11. Changes
This policy may be updated to reflect changes to the service or the law. The update date will appear at the top of this page.
12. Contact
Questions about this policy: [email protected]