01Who we are
Corelink Solutions FZE, incorporated in the Ajman Free Zone, United Arab Emirates (“we,” “us,” “our”). For EU/UK users, we act as the data controller for personal data processed in connection with Veloxa.
Contact: privacy@veloxa.app
02What we collect
Free tier (no account)
• Speed test results (download, upload, ping, jitter, loss) — stored only on your device.
• Local network metadata: device IP addresses, MAC address prefixes (vendor lookup only), device types — stored only on your device.
• App version, OS version, device model — used for crash reporting only, not linked to any identifier.
• Anonymous crash logs via Sentry — no personal data, no network data included.
Paid plans (account required)
• Everything above, plus:
• Email address (for authentication and billing notifications).
• Name (optional — used for in-app greeting).
• Speed test history synced to our servers (encrypted, AES-256).
• Device profiles (OS version, device model, Veloxa app version) linked to your account.
• Subscription status (plan, expiry date) from Apple or Google IAP.
• Country code derived from IP at login time (for regional pricing; we don't store your IP).
When you contact support
• Name, email, and the contents of your message.
• Diagnostic logs you choose to attach (these may include app version, OS, and anonymized speed test results).
03How we use it
04What we don't do
• We do not read, intercept, or log your internet traffic (websites visited, files downloaded, messages sent).
• We do not sell your personal data to anyone, ever.
• We do not serve ads inside Veloxa.
• We do not track your location beyond country-level for regional pricing.
• We do not build advertising profiles about you.
• We do not share your data with your ISP.
05Data sharing
We share data with a small number of sub-processors to operate the service:
• Sentry — anonymous crash reporting. No personal data.
• Resend — transactional email delivery (billing receipts, trial reminders). They receive your email address for delivery only.
• Cloudflare R2 — file storage for data exports. Encrypted at rest.
• Neon / Railway — managed Postgres database hosting. All data encrypted at rest.
• Apple / Google — process subscription payments and provide IAP receipts. We never see your payment details.
All sub-processors are contractually bound to process data only as instructed by us and to maintain appropriate security standards.
06Advertising ID (IDFA / GAID)
We do not use your Advertising ID for advertising purposes. On iOS, we request App Tracking Transparency (ATT) consent only if you enable a feature that requires it (e.g., regional benchmarking). You can deny this request with no loss of core functionality.
On Android, we do not request the Advertising ID at all.
07Data retention
• Free tier device data: never sent to us; stays until you uninstall the app.
• Pro account data: retained while your account is active + 30 days after deletion.
• Support emails: 2 years from last contact.
• Anonymized analytics (aggregated speed benchmarks): indefinitely.
When you delete your account, we initiate deletion within 7 days and complete it within 30 days, except where we're legally required to retain billing records (typically 5–7 years for tax purposes).
08Your rights
Depending on where you live, you have the right to:
• Access — request a copy of the personal data we hold about you.
• Rectification — correct inaccurate data.
• Deletion — ask us to delete your account and associated data.
• Export — download all your data in JSON format from within the app.
• Opt-out — unsubscribe from marketing emails at any time (link in every email).
• Objection — object to processing based on legitimate interest.
To exercise any of these rights, email privacy@veloxa.app. We respond within 30 days.
09Children
Veloxa is not directed at children under 13. We do not knowingly collect personal data from children. If we discover that we have inadvertently collected data from a child, we will delete it promptly. Contact us at privacy@veloxa.app if you believe this has occurred.
10Security
• Passwords hashed with Argon2id (no plaintext storage).
• All data in transit encrypted with TLS 1.3.
• Speed history encrypted at rest with AES-256.
• Session tokens stored as SHA-256 hashes server-side.
• 2FA (TOTP) available for all accounts; mandatory for admin roles.
• No payment data stored — all payments processed by Apple/Google/Stripe.
If you discover a security vulnerability, please email security@veloxa.app. We respond within 48 hours.
11UAE PDPL, GDPR, and CCPA
We comply with the UAE Personal Data Protection Law (PDPL Federal Decree-Law No. 45 of 2021), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
For EU/EEA residents: the legal basis for processing personal data is contract performance (subscription), consent (marketing), and legitimate interest (crash analytics, fraud prevention).
For California residents: we do not sell personal data. You have the right to know, delete, and opt-out. To exercise CCPA rights, email privacy@veloxa.app.
12Changes to this policy
We'll notify you of material changes via email (if you have an account) and by updating this page with a new effective date. Continued use after the effective date means you accept the changes.
Privacy questions?
Our data protection contact is available for any privacy-related questions or requests.