Privacy Policy
The service minimizes identifying data and separates private order access from public storefront analytics.
Updated
Data we collect
We may collect an optional email encrypted at rest, a one-way lookup hash, order status and timestamps, payment-provider identifiers, categorical payment events, security events, and the encrypted delivery payload.
We do not require a customer name for the standard order flow. We do not ask for an account password during checkout or support.
- Optional encrypted email.
- Payment-provider identifiers and order records.
- Security and delivery events needed to operate the service.
How data is used
Data is used to create and reconcile orders, reserve stock, provide the private link, deliver the account, support recovery, investigate payment issues, prevent abuse, keep accounting records, and handle replacement or refund requests.
An optional email is used only for private-link notifications and recovery. Delivery credentials are never placed in an ordinary email body.
Encryption and private access
Inventory and delivery content use AES-256-GCM encryption at rest. The browser-local access token is sent as a Bearer credential only when the private order is opened and is not placed in query strings, analytics events, or application logs.
Access to the private link depends on the customer protecting the link and browser token. Support cannot safely receive or store customer credentials.
Retention and deletion
Encrypted email and sensitive delivery data are retained for at most 30 days from automatic delivery, or deleted earlier by the customer through the private order page.
Deletion removes recoverable ciphertext and recipient data. Non-sensitive order, payment, audit, fraud-prevention, and dispute records may be retained as reasonably required for operations and legal obligations.
- Early payload deletion is irreversible.
- Deleted delivery data cannot support a later replacement claim.
- Contact support to request review of other retained personal data.
Processors, analytics, and rights
Payment providers, email delivery services, hosting providers, Telegram, and blockchain networks process relevant data under their own policies. Public-only analytics may use small categorical events on storefront, pricing, guide, and legal pages.
There are no analytics on private routes including checkout, orders, recovery, admin, and API paths. Users may ask to access, correct, delete, or restrict eligible personal data, subject to identity, security, accounting, fraud-prevention, and dispute-record requirements.
Contact and language
For questions, contact 001@v0c21dits.com or Telegram @va0019. Include the public order number when relevant, but never send passwords, private access tokens, wallet keys, or seed phrases.
v0credits is independent from v0 and Vercel. These documents do not claim an official relationship and do not provide a physical company address.