Privacy Policy
How Velox collects, uses, and protects your personal data when you interact with our platform.
This Privacy Policy applies to all services provided through the Velox platform, including our web application, API endpoints, and any associated interfaces accessible at velox.fi and subdomains.
1. Introduction
Velox ("we," "our," or "us") is committed to protecting the privacy of individuals who use our platform ("you," "user"). This Privacy Policy explains what information we collect, how we use it, and the rights you have regarding your data. By accessing or using Velox, you acknowledge that you have read and understood this policy.
Velox is a non-custodial swap protocol operating on the TRON blockchain. We do not create user accounts, collect identification documents, or require personal registration to execute swaps. Our data collection is intentionally minimal and designed to respect user privacy while maintaining a secure and reliable platform.
2. Information We Collect
To operate the Velox platform, we may collect the following categories of information:
2.1 Wallet Addresses. When you connect your wallet and initiate a swap, we process your public TRON wallet address to execute the transaction. Wallet addresses are pseudonymous blockchain identifiers and do not, by themselves, reveal your identity.
2.2 Transaction Data. We record swap details including asset pair, amount, timestamp, transaction hash, and gas reserve utilization. This data is stored in hashed form and is used for settlement verification, performance monitoring, and platform analytics.
2.3 Technical Logs. Our servers automatically log standard technical information when you access the platform, including IP address, browser type, operating system, referring URL, and request timestamps. These logs are retained for a limited period for security monitoring and debugging.
2.4 Cookies & Local Storage. We use essential cookies and browser local storage to maintain session state, remember your UI preferences, and prevent fraudulent activity. We do not use tracking cookies for advertising or cross-site profiling.
2.5 Communication Data. If you contact us via email, support channels, or social media, we retain the content and metadata of those communications to respond to your inquiry and improve our support services.
3. How We Use Your Information
We use the information we collect exclusively for the following purposes:
- Platform Operation. To process swap transactions, allocate gas reserves, verify settlement on-chain, and deliver token outputs to your wallet.
- Security & Fraud Prevention. To monitor for malicious activity, prevent denial-of-service attacks, detect wallet-sweeping scripts, and protect the platform's infrastructure.
- Analytics & Improvement. To understand aggregate usage patterns, measure platform performance, identify bottlenecks, and guide product development decisions.
- Legal Compliance. To respond to valid legal process (subpoena, court order, regulatory inquiry) where we are required to do so under applicable law.
- Communication. To respond to your inquiries, provide technical support, and — only with your explicit consent — send service-related updates.
We do not sell, rent, or trade your information to third parties for marketing or advertising purposes. We do not use your data to build profiles for behavioral advertising.
4. Data Retention & Deletion
Our retention practices are calibrated to the purpose and legal obligations attached to each category of data:
4.1 Transaction Records. Swap settlement data is retained for a minimum of five (5) years from the date of the transaction to satisfy audit requirements and potential legal obligations. After this period, records are purged or permanently anonymized.
4.2 Technical Logs. Server access logs are retained for thirty (30) days, after which they are automatically deleted. Extended logs related to security incidents may be preserved longer for investigative purposes.
4.3 Communication Records. Support correspondence is retained for two (2) years following the resolution of your inquiry, after which it is deleted.
4.4 On-Chain Data. Blockchain transactions are immutable and publicly visible on TRON mainnet. Velox cannot delete or modify on-chain records. Once a transaction is confirmed on the TRON network, it is permanently recorded in the blockchain ledger.
5. Third-Party Service Providers
We engage a limited set of third-party service providers to deliver core platform functionality. Each provider is contractually bound to data processing terms that restrict use to the services we have engaged them for:
- Infrastructure & Hosting. Cloud service providers and content delivery networks that host our application, handle DNS resolution, and serve static assets. Logs may transit through their infrastructure.
- TRON Network Nodes. Our platform interacts with TRON full nodes (self-hosted and third-party) to query blockchain state, broadcast transactions, and confirm settlement. Wallet addresses and transaction payloads are transmitted to these nodes.
- Analytics. We use privacy-respecting, self-hosted analytics (no third-party scripts) to collect aggregate usage statistics. No personal identifiers are shared with external analytics vendors.
- Legal & Compliance. In the event of a legal obligation, we may share data with law enforcement, regulatory authorities, or court-appointed entities as required by applicable law.
6. Your Rights (GDPR & CCPA)
Depending on your jurisdiction, you may have the following rights regarding your personal data. Velox extends these rights to all users regardless of location:
Right of Access. You may request a copy of the personal data we hold about you. We will provide this in a structured, machine-readable format within thirty (30) days of verifying your request.
Right of Rectification. If you believe the data we hold is inaccurate or incomplete, you may request correction.
Right of Erasure. You may request deletion of your personal data, subject to our legal obligation to retain certain records (e.g., transaction data for regulatory compliance). On-chain data cannot be deleted.
Right to Restrict Processing. You may request that we limit how we process your data under certain circumstances.
Right to Data Portability. You may request your data in a portable format for transfer to another service provider.
Right to Object. You may object to processing of your data based on legitimate interests. Velox does not perform automated decision-making or profiling.
CCPA-Specific Rights. California residents have the right to know what personal information is collected, to opt out of the sale of personal information, and to non-discrimination for exercising privacy rights. Velox does not sell personal information.
To exercise any of these rights, contact us at privacy@velox.fi. We will respond within the timeframe required by applicable law. We may need to verify your identity before processing your request — for wallet-associated data, this may require you to sign a message with your connected wallet address.
7. Data Security
We implement industry-standard technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction:
- Encryption in transit (TLS 1.3) for all client-server communication and API traffic.
- Encryption at rest (AES-256) for stored transaction records and logs.
- Access controls limiting data access to authorized personnel with a legitimate operational need.
- Regular security audits and penetration testing of our infrastructure and smart contracts.
- Incident response procedures including breach notification to affected users and relevant authorities within 72 hours where required.
Despite these measures, no method of electronic storage or transmission over the internet is completely secure. You use the Velox platform at your own risk, and we cannot guarantee absolute security.
8. International Data Transfers
Velox operates on a globally distributed infrastructure. Your data may be processed and stored on servers located in jurisdictions outside your country of residence. By using the platform, you consent to the transfer of your data to servers in jurisdictions whose data protection laws may differ from those in your home country. We ensure that any international transfers comply with applicable data protection regulations, including the use of Standard Contractual Clauses (SCCs) where required under GDPR.
9. Contact & Data Requests
For questions about this Privacy Policy, to exercise your data rights, or to report a privacy concern:
Email: privacy@velox.fi
Response Time: We aim to acknowledge all privacy inquiries within three (3) business days and resolve them within thirty (30) calendar days.
Supervisory Authority: If you believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection supervisory authority.
10. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal obligations, or regulatory requirements. When we make material changes, we will post the updated policy on this page and update the "Last updated" date. We encourage you to review this policy periodically. Continued use of the platform after changes are posted constitutes your acceptance of the revised policy.