Privacy policy

What we collect, and what we do not.

Written to be read once and understood, not to be survived. If a line here is unclear, that is a fault in the line — tell us and we will fix it.

Last updated 8 September 2026

Who this is about

VeloCapture is a product of Velozent Technologies. This policy covers the web application at app.velocapture.com, the VeloCapture mobile app for Android and iOS, the VeloCapture browser extension, and this marketing site.

Two different relationships run through the product, and the difference matters. For your own account information we are the controller. For the business data you put into the product — your leads, your opportunities, your proposals, your contacts — your organisation is the controller and we are the processor acting on your instructions.

What we collect, and why

Account information — your name, work email address, and the password you set (stored only as a one-way hash, never in a form we can read). Used to sign you in and to tell your colleagues who did what.

Profile information you choose to add — job title, phone number and an email signature. These are optional, and they exist because the product writes outreach emails in your name; an empty signature simply means a plainer email.

Your organisation's business data — the organisations, contacts, opportunities, proposals, notes and messages you and your colleagues create or import. This is the product doing its job.

Security and audit records — sign-in times, the IP address a change was made from, and an immutable record of who changed what. Kept because an audit trail nobody can edit is the point of an audit trail.

Billing information — handled by Stripe. Card numbers never reach our servers; we hold a customer reference, your plan and your invoice history.

Support messages — what you write to us when you ask for help, along with your account and the screen you were on.

In the mobile app, specifically

The app collects less than the website, and this is the complete list.

  • Your email address and password, sent once when you sign in. The resulting session token is stored in the device keychain (Android Keystore / iOS Keychain), not in ordinary app storage.
  • Your profile fields, if you edit them in the app — name, job title, phone, signature.
  • A push notification token and the platform name ("android" or "ios"), if you allow notifications. Declining is supported and the rest of the app works normally; the in-app bell is the fallback.
  • Whatever you type into the app as business data — a note, a message to a colleague, a support request, a question to the assistant.

The app contains no advertising SDK, no analytics SDK and no third-party tracker. It does not collect a device identifier for advertising, and it does not build a profile of you across other apps or websites.

It asks for no device permissions other than notifications. It does not access your location, camera, microphone, photos, files or your phone's contacts. Where the product says "contacts", it means business contacts inside your organisation's own account — never the address book on your phone.

Nothing in the app is sold, and nothing is shared with a data broker.

Data about other people

The product surfaces business-contact information — a contracting officer named on a public government solicitation, an executive named in a public regulatory filing, a work email address inferred from an organisation's published pattern. This is business-context data drawn from public records and from your own account, not personal data about consumers.

Your organisation decides who to contact and remains the controller of that decision. The product enforces the rules that go with it: every outreach email carries the legally required footer and an unsubscribe link, unsubscribe and suppression lists are honoured across the whole account, and bounces stop further sending.

If you are a person who appears in this data and you would like it corrected or removed, write to us and we will route the request to the account that holds it and act on it ourselves where we can.

Who else processes your data

We use a small number of sub-processors, each for one job:

  • Microsoft Azure — hosting for the application and database, in the United States.
  • Anthropic — the AI features, unless your organisation brings its own API key, in which case no prompt from your account is sent under ours. Prompts are not used to train models under the terms we operate on.
  • Microsoft 365 or SendGrid — transactional email (sign-in links, notifications) that you do not send from your own mailbox.
  • Stripe — billing and payments.
  • Sentry — error monitoring on the web application. It records that an error happened and where in the code; it does not receive message bodies.
  • Expo — delivery of push notifications to your device. The notification title and body pass through the relay in order to be delivered.

We do not sell your data, we do not share it for advertising, and we never send your account's data to a contact-data vendor.

How long we keep it

Your organisation's business data is kept for as long as the account is open. Retention is configurable per tenant in Settings → Data retention.

Audit records are kept for the life of the account by design — an audit log you can prune is not an audit log.

When an account is closed we delete its data on request, and otherwise within 90 days. Backups roll off on their own schedule within the same region.

A push notification token is deleted when you sign out of that device, and dead tokens are pruned automatically.

Your choices

You can see and edit your own profile in the app or on the web, and change your password at any time.

You can turn any notification channel on or off, per type, in Settings → Notifications.

You can ask us for an export of your organisation's data, or for it to be deleted, and we will do it. Depending on where you live you may also have a statutory right to access, correct, port or erase your personal data, and to object to processing — write to us and we will honour it without making you cite the statute.

Two-factor sign-in is available on both the web and the app, and an administrator can require it for a whole organisation.

Security

Tenant isolation is enforced by the database itself, not only by application code. Credentials, provider API keys and two-factor secrets are encrypted before storage and are never returned to a browser or an app. Sessions are short-lived and revocable.

The detail, including what we do not yet have — there is no SOC 2 report — is on the trust page rather than summarised away here.

Children

This is a business product. It is not directed at children, we do not knowingly collect data from anyone under 16, and there is no consumer-facing surface where a child would plausibly sign up.

Changes, and how to reach a person

If this policy changes in a way that affects you, we will say so in the product rather than quietly reposting the page. The date at the top is the last change.

Questions, requests, or a correction to something on this page: hello@velocapture.com. A person answers, within one business day.

See also trust & security for how these commitments are actually enforced, or contact us.