Privacy Policy
Last updated: September 17, 2026 · Takes effect: September 21, 2026
This is the policy as it will read from 21 September 2026. Until then, the version dated 14 March 2026 remains in force. What changes: the retention section now says the same thing as the Terms of Service and the Data Processing Agreement, we name Google as a third-party service in both of the places it does work for us, analytics is switched off entirely for visitors in the European Economic Area and the United Kingdom and runs without a banner everywhere else, and we say where in the world the people who support the platform are.
Overview
Veldun (“we,” “us,” “our”) provides a membership management platform for small organizations. This policy explains what data we collect, how we use it, and your rights regarding that data.
What we collect
Account information. When you sign up, we collect your name, email address, and organization name. If you invite members, we store their names and email addresses as provided by your organization.
Usage data. We collect standard analytics: pages visited, features used, browser type, and device information. This helps us understand how the product is used and where to improve it. For visitors in the European Economic Area and the United Kingdom we collect none of it - see Cookies below.
Payment information. Dues payments are processed by Stripe. We do not store credit card numbers or bank account details. Stripe handles all payment data under their own privacy policy.
Content you create. Events, emails, member records, and documents you create within Veldun are stored on our servers to provide the service.
How we use your data
We use your data to:
- Provide and maintain the Veldun platform
- Process membership dues and event payments via Stripe
- Send transactional emails (confirmations, reminders, receipts)
- Power AI features (event creation, newsletter assembly, renewal alerts)
- Improve the product based on aggregate usage patterns
- Respond to support requests
We do not sell your data. We do not use your data for advertising. We do not share member lists with third parties. And we do not use your data to train AI models - not ours, and not our providers', who are contractually barred from training on what we send them.
Third-party services
Veldun uses the following third-party services to operate:
- Amazon Web Services (AWS) - hosting, database, file storage, and background job processing
- Stripe - payment processing for membership dues and event fees
- Resend - transactional and campaign email delivery
- Anthropic (Claude API) - AI features including event creation, newsletter assembly, and renewal intelligence. Content sent to Claude is processed according to Anthropic's data usage policy and is not used to train their models.
- Sentry - error monitoring and performance tracking
- Cloudflare - DNS and static website hosting for organization public sites
- Google - two separate things. Google Analytics measures how the Veldun application is used - the marketing site, the dashboard, and the Veldun pages where members join, pay dues, register for events and donate. It does not run on your organization's own website, which carries no analytics of any kind. It is switched off for visitors in the European Economic Area and the United Kingdom, and runs for everyone else (see Cookies below). Separately, when an administrator asks the platform to generate a cover image for an event or a newsletter, we send Google's Vertex AI the organization name and the title and description of the item being illustrated, so it has something to work from. That request goes to a United States regional endpoint, so the image is generated in the United States.
Data retention
We retain your data for as long as your account is active. If you cancel your account, we keep your organization's data for 30 days - so you can still request an export - and then delete it permanently. Backups roll off within a further 30 days.
Payment records processed through Stripe are retained according to Stripe's data retention policies and applicable financial regulations.
Your rights
You have the right to:
- Export your data. Download your member list, event history, and email records at any time from your dashboard.
- Delete your data. Request complete deletion of your organization's data by emailing us.
- Correct your data. Update your account information and member records directly in the platform.
- Restrict processing. Request that we limit how we use your data.
If you are located in the European Economic Area, you have additional rights under the GDPR. Contact us to exercise any of these rights.
Security
Data is encrypted in transit (TLS) and at rest (AES-256). Database access uses IAM authentication. All file uploads use signed URLs with expiration. We follow AWS security best practices for infrastructure management.
Where your data lives, and who can reach it
Your data is stored and processed in the United States, on Amazon Web Services in the US-East region. That does not change.
Veldun is a small team, and the people who operate and support the platform work from outside the United States - currently the United Arab Emirates and India. They reach your data by logging in remotely to that same US environment, under named accounts with role-based, need-to-know access, and every access is logged. We do not copy or cache your data onto devices outside the United States, and we do not use a support provider outside the United States without telling the organization first.
We say this plainly because it is the sort of thing an organization's counsel asks about, and the honest answer is better than a vague one.
Cookies
Essential cookies. These keep you signed in and remember which organization you are looking at. They are set because the product does not work without them.
Analytics cookies, outside the EEA and the UK. Google Analytics records which pages are visited and which features get used, which is how we decide what to build next; we also set a first-party cookie recording how you first arrived (a search engine, a link, a campaign) so a signup can be attributed to it. There is no banner, because there is no question: these are set unless you are in one of the places below.
Nothing stored, inside the EEA and the UK. For visitors in the European Economic Area and the United Kingdom, both of those are switched off before anything loads. Neither cookie is set and nothing is stored on your device.
We would rather be exact than flattering about what is left. The Google tag still loads, so your browser still reaches Google and Google still receives a record that a page was viewed, including the IP address it came from. What it does not get is anything kept on your device, or any identifier that would let it recognize you on a later visit or join that view to anything else.
If you would rather not be measured anywhere, your browser's own controls - blocking third-party cookies, or any tracker-blocking extension - stop it, and nothing about the site stops working.
We do not use advertising cookies, and we do not let anyone use what we collect to target you elsewhere.
Changes to this policy
We may update this policy as our practices evolve. We will notify account administrators by email of any material changes before they take effect.
Contact
For privacy questions or data requests, email privacy@veldun.com. We respond to every inquiry within one business day.