Privacy Policy
1. Who we are
This policy explains how Velotit ("we" or "the service") handles the personal data of people who visit the site or use our reading services.
If you have any question about your data, write to hola@velotit.com.
2. What data we collect
We collect only what we strictly need to provide the service:
- ✦Account data: email, name (optional) and interface language.
- ✦Reading data: what you submit in each form (questions, birth dates, context, photos…) and the generated result.
- ✦Payment data: handled entirely by Stripe. We only store the customer ID and the charge ID — never your card details.
- ✦Usage data: pages visited, traffic source (Google, social networks, direct) and basic events (signup, purchase, etc.). Only if you accepted the cookie notice.
3. Why we use it
- ✦To create and maintain your account and process your readings.
- ✦To send reading results by email when applicable.
- ✦To charge for the service and issue receipts.
- ✦To answer questions and provide support.
- ✦To understand how the site is used and improve it — aggregated only, with consent.
- ✦To meet legal obligations (tax, accounting).
4. Legal basis for processing
- ✦Contract performance: to process your reading and deliver the service you purchased.
- ✦Consent: for usage analytics and any commercial communications you opt into.
- ✦Legal obligation: for invoicing and tax record-keeping.
5. Who we share your data with
We do not sell your data. We only share it with these processors, strictly so the service can run:
- ✦Stripe — payment processing.
- ✦Supabase — database hosting and authentication.
- ✦Resend (or equivalent) — transactional emails.
- ✦Vercel — site hosting.
- ✦Anthropic / OpenAI — AI processing for the reading. Your data is sent as part of the prompt and is not used to retrain the models.
6. How long we keep it
- ✦Account data: while the account is active. If you delete it, we erase it within 30 days unless we have a legal obligation to keep it.
- ✦Saved readings: while your account is active. You can delete them individually from your private area.
- ✦Billing data: the period required by Spanish tax law (currently up to 6 years).
- ✦Analytics data: up to 24 months, then aggregated or deleted.
7. Your rights
As the data subject you can, at any time:
- ✦Access the data we hold about you.
- ✦Ask us to correct or delete it.
- ✦Restrict or object to specific processing.
- ✦Request a portable copy.
- ✦Withdraw consent without affecting the legality of prior processing.
- ✦Lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Security
We apply reasonable technical and organisational measures: HTTPS in transit, role-based access in the database, separation between the application server and sensitive data, and periodic vendor reviews. No system is infallible: if you spot something, tell us and we act.
9. Changes to this policy
We may update this policy to reflect legal, technical or operational changes. If the changes are significant we'll notify you by email or with a prominent notice on the site before they take effect.
10. Contact
For anything related to your data: hola@velotit.com.