Privacy Policy

Last updated: 19 July 2026

This policy explains what we collect, why we collect it, and the choices you have. We collect the minimum needed to run the Service — we do not sell your data.

1. Data we collect

  • Account data: name, email address, and a securely hashed password (we never store the password itself).
  • Security data: encrypted two-factor secrets (if you enable 2FA), session tokens (hashed), IP address and browser type of sign-ins, and a security event log (e.g. failed logins).
  • Transaction data: wallet ledger entries, deposits and their payment references, orders and the public links you submit, support tickets.
  • Saved contacts: usernames/links you choose to save for reuse.
  • Developer data: API keys (stored only as hashes) and API request logs.

We do not collect payment card numbers — payments are made through external payment channels and matched by reference.

2. Why we use it

  • To operate your wallet, orders, refills and refunds.
  • To secure accounts (fraud prevention, rate limiting, anomaly detection).
  • To send transactional email: welcome messages, password-reset codes, and important account or service alerts. We do not send marketing email without consent.
  • To meet legal, tax and accounting obligations.

3. Cookies

We use essential cookies only — no advertising or cross-site tracking cookies:

  • vp_session — keeps you signed in (required).
  • vp_currency — remembers your price display currency.
  • vp_cookie_consent — remembers that you dismissed the cookie notice.

4. Sharing

  • Fulfilment providers: receive only the target link and quantity of an order — never your identity.
  • Email delivery: your email address is processed by our SMTP provider to deliver transactional messages.
  • Legal: we disclose data if validly required by law enforcement or courts.

We never sell or rent personal data.

5. Security and retention

Passwords are hashed with bcrypt; API keys and session tokens are stored only as SHA-256 hashes; 2FA secrets are encrypted at rest (AES-256-GCM); all traffic should be served over HTTPS in production. Financial ledger records are retained as long as required for accounting and dispute resolution; security logs are retained for a limited period; other data is kept while your account is active.

6. Your rights

You may request a copy of your personal data, correction of inaccurate data, or deletion of your account (subject to records we must keep by law) by opening a support ticket. If you are in a jurisdiction with statutory data-protection rights, we honour those rights as required.

7. Children and changes

The Service is not directed to anyone under 18 and we do not knowingly collect their data. We may update this policy; the “Last updated” date reflects the current version.