Legal
Privacy Policy
Last updated: September 19, 2026
Effective date: September 19, 2026. This Privacy Policy explains how Vemzio ("we", "us") collects, uses, shares, and protects personal data when you use vemzio.com and related services. It is written to align with GDPR and CCPA principles, though the operator entity and lead supervisory authority depend on where Vemzio is incorporated (see §12).
1. Data We Collect
1.1 Account data
- Username and password. Passwords are hashed by our authentication provider (Supabase) and never stored or seen by Vemzio in plaintext. We currently create accounts with username + password only — we do not require your email (a synthetic internal address is derived for technical purposes; it cannot receive mail from you).
- Profile data you choose to publish: display name, bio, links (website, GitHub, X/Twitter), avatar, tags, and bio-page items.
1.2 Revenue verification data
- When you connect a merchant-of-record account (Stripe, Polar, Lemon Squeezy, Paddle, Creem, or other supported providers), we store encrypted API credentials or OAuth tokens (AES-256-GCM at rest) solely to sync your revenue metrics.
- We store the derived metrics: MRR, active subscriptions, churn, 30-day growth, customer count, business name/URL as reported by the provider, and sync timestamps/errors.
- We request read-only scopes. We cannot move money or modify your payment account. OAuth grants can be revoked by you at any time.
1.3 Transaction data
Escrow transactions store listing references, party usernames, amounts, platform fee, status milestones, delivery artifacts (domain auth codes, repository transfer states), and escrow chat messages.
1.4 Usage & technical data
- Server logs (IP address, user agent, requested URL, timestamp) for security and abuse prevention.
- Bio-page view counts (aggregate per page).
- Essential cookies only by default — see the Cookie Policy.
1.5 Data we do not collect
No advertising identifiers, no ad-tech pixels, no behavioral profiling, and no selling of personal data — ever.
2. Why We Process It (Legal Bases)
- Contract performance: operating your account, profiles, marketplace, escrow, and purchases.
- Legitimate interests: security, fraud and abuse prevention, service integrity, aggregate analytics that don't identify you.
- Consent: optional feature access you explicitly grant (e.g., connecting a revenue provider).
- Legal obligation: tax and accounting records for transactions.
3. Public By Design
Vemzio is a public network for builders. Data you publish — profiles, bios, listings, verified metrics badges, community posts, job posts — is publicly visible by design, including to logged-out visitors and search engines. Don't publish what you wouldn't want public. Public profiles are indexed by search engines unless you keep the content unpublished via your dashboard settings where available.
4. Sharing With Third Parties
- Supabase — authentication and database hosting (processors).
- Cloudflare — hosting/edge delivery and Workers runtime.
- Stripe / Lemon Squeezy / other MoR providers — escrow payments and digital delivery. They process payments under their own privacy terms; we share only what the transaction requires.
- Revenue providers you connect — we pull data from them; they see your OAuth authorization, not our systems' internals.
- We disclose to authorities only where legally compelled, with notice to you unless prohibited.
- We do not sell or rent personal data, and we do not share it for cross-context behavioral advertising.
5. International Transfers
Our processors operate globally (EU, US). Transfers rely on adequacy decisions or Standard Contractual Clauses implemented by the processor. You may request details of the current processor list via contact below.
6. Retention
- Account and profile data: for the life of the account; deleted within 30 days of verified account closure.
- Verification credentials: until you disconnect the provider or close the account; sync caches refreshed on schedule.
- Transaction records: up to 7 years where tax/accounting law requires, stored minimally.
- Server logs: 30–90 days.
7. Your Rights
Depending on your jurisdiction, you may have the right to: access your data; correct or delete it; object to or restrict certain processing; data portability (export); and to withdraw consent (e.g., disconnect a revenue provider) without affecting prior lawful processing. California residents: we do not "sell" or "share" personal information as defined by the CCPA/CPRA. To exercise rights, use your dashboard settings for self-service (profile edits, provider disconnection) or contact us. We respond within statutory windows.
8. Security
- TLS in transit; AES-256-GCM encryption at rest for revenue credentials; HMAC-signed session cookies (httpOnly, SameSite=Lax, Secure).
- Least-privilege, read-only API scopes for verification; no payment write access.
- Rate limiting and abuse detection on authentication endpoints.
- No system is perfectly secure: we notify affected users of qualifying breaches without undue delay.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect their data. If you believe a minor has an account, contact us for removal.
10. Automated Decisions
Signal Scores and verification badges are computed from provider metrics and activity. They are displayed as informational rankings — we do not use them for legally significant automated decisions about you.
11. Changes
We will post updates here with a revised "Last updated" date and announce material changes in the dashboard or via available contact channels.
12. Controller & Contact
[Operator to set: legal entity name, registered address, and contact email for privacy requests — e.g., privacy@vemzio.com. If GDPR applies, identify the lead supervisory authority accordingly.]
Questions about this document? Reach the Vemzio team through your dashboard. The English version of this document governs; translations are provided for convenience only.