Veltrum / Legal / Privacy

Privacy Policy

Effective: April 1, 2026 Last updated: April 26, 2026 Version: 1.2

01Introduction

Veltrum Technologies Pvt. Ltd. ("Veltrum", "we", "our", or "us") operates the Veltrum.io commerce orchestration platform — a software-as-a-service product that helps brands unify their commerce stack and deploy AI agents to run operational workflows. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have over it.

This policy applies to veltrum.io, our customer dashboard, our APIs, and any product, page or interaction that links to it. It does not apply to third-party services we integrate with — those are governed by their own privacy policies.

In short
We only collect what we need to run the product. We never sell your data. You can ask us to export or delete it at any time by emailing info@veltrum.io.

02Who we are

Veltrum Technologies Pvt. Ltd. is incorporated in India (CIN pending), with its registered office in Hyderabad, Telangana. For the purposes of EU/UK GDPR, we act as a data controller with respect to information collected through our marketing site and account onboarding, and as a data processor with respect to data processed inside our customers' Veltrum workspaces on their behalf.

03Data we collect

We collect information in three categories:

3.1 Information you give us

3.2 Information generated when you use Veltrum

3.3 Information from third parties

04How we use data

PurposeExamples
Provide the serviceRun agents, sync connectors, generate weekly reviews, render dashboards.
Improve the serviceAggregated, de-identified analytics; debugging; A/B tests of UI changes.
CommunicateOnboarding emails, product updates, security advisories, billing notices.
Sales & marketingReach out to prospects who applied to the waitlist; targeted advertising for lookalike audiences.
ComplianceAnti-abuse, anti-fraud, audit trails, responding to lawful requests.

We do not use customer workspace data to train foundation models, and we do not sell personal data to third parties.

Where GDPR applies, we rely on the following lawful bases:

06Sharing & disclosure

We share data only with the following categories of recipients, and only when needed:

07Sub-processors

An always-current list of our sub-processors is available from info@veltrum.io on request. Today they include:

VendorPurposeRegion
Amazon Web ServicesHosting, compute, storageap-south-1, us-east-1
CloudflareCDN, DDoS, WAFGlobal
Stripe / RazorpayPaymentsUS / IN
Anthropic, OpenAILLM inferenceUS
PostmarkTransactional emailUS
SentryError monitoringUS
PostHogProduct analyticsEU

08Retention

09Security

We aim to keep Veltrum to the standard of the most security-conscious teams that use it. Controls include:

If you suspect a vulnerability, please email info@veltrum.io. We aim to acknowledge reports within 24 hours.

10International transfers

Veltrum is operated from India and the United States. When personal data leaves your country of residence, we rely on Standard Contractual Clauses, the UK IDTA, and equivalent transfer mechanisms. A copy of the relevant clauses is available on request.

11Your rights

Depending on where you live, you may have the right to:

To exercise any of these, email info@veltrum.io. We aim to respond within 30 days.

12Cookies & tracking

We use first-party cookies for essential functions (auth, CSRF, session) and a small set of third-party analytics tools (PostHog, Google Analytics) to understand how the product is used. You can opt out via the cookie banner on first visit, or by adjusting your browser settings.

We do not run third-party advertising trackers inside the authenticated Veltrum dashboard.

13Children's privacy

Veltrum is a B2B product not directed at children. We do not knowingly collect data from anyone under 18. If you believe a minor has used our service, please contact us and we will delete the relevant information.

14Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated by email to active customers at least 30 days before they take effect. The version and "last updated" date at the top of this page will always reflect the current revision.

15Contact

For any privacy questions, requests, or concerns, contact our Data Protection team:

EU representative
For EEA & UK residents, we will appoint an Article 27 representative when our user base crosses the relevant thresholds. Until then, please write to info@veltrum.io.