1. Introduction
Velocity ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our social media management application ("Service").
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies, please do not access the Service.
2. Information We Collect
2.1 Account Information
- Email address and password (encrypted)
- Full name and profile photo
- Account preferences and settings
2.2 Social Media Platform Data
When you connect your social media accounts, we collect:
- Instagram/Facebook (Meta): User ID, username, profile picture, access tokens, posting permissions, insights and analytics data, follower counts, and engagement metrics
- YouTube (Google): Channel ID, channel name, video analytics, subscriber counts, view statistics, and content management permissions
- LinkedIn: Member ID, profile information, company pages, and posting permissions
- TikTok: User ID, username, video statistics, and content publishing permissions
- X (Twitter): User ID, handle, tweet permissions, and engagement analytics
2.3 Content Data
- Media files (images, videos) you upload for posting
- Post captions, hashtags, and scheduling information
- Brand assets and creative materials
- AI-generated content created through our Service
2.4 Usage Data
- Log data (IP address, browser type, pages visited)
- Device information
- Feature usage patterns
3. How We Use Your Information
We use the collected information for:
- Service Delivery: To provide, maintain, and improve our social media management features
- Content Publishing: To schedule and publish content to your connected social media accounts on your behalf
- Analytics: To display performance metrics and insights from your connected platforms
- AI Features: To generate content suggestions, captions, and creative assets
- Communication: To send you service updates, security alerts, and support messages
- Improvement: To analyze usage patterns and enhance our Service
4. Platform-Specific Data Practices
4.1 Meta (Instagram & Facebook)
We access your Instagram and Facebook data through Meta's official APIs. This includes:
- Reading your basic profile information and account insights
- Publishing content (photos, videos, stories) on your behalf
- Accessing page insights and engagement metrics
- Managing comments and interactions when authorized
We comply with Meta's Platform Terms and Data Use Policy. You can revoke access at any time through Instagram/Facebook settings or within our app.
4.2 YouTube (Google)
Our use of YouTube data is governed by Google's API Services User Data Policy. We access:
- Channel information and statistics
- Video analytics and performance data
- Upload permissions for video publishing
You can revoke access at Google Security Settings.
4.3 LinkedIn
We access your LinkedIn profile through LinkedIn's Marketing API to:
- Post content to your personal profile or company pages
- Access engagement metrics and analytics
4.4 TikTok
Through TikTok's Content Posting API, we access:
- Basic user information and statistics
- Video publishing capabilities
- Performance analytics
4.5 X (Twitter)
We use X's API v2 to:
- Post tweets and media on your behalf
- Access engagement analytics
- Read your basic profile information
5. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption: All social media access tokens are encrypted at rest using AES-256 encryption
- Secure Transmission: All data is transmitted over HTTPS/TLS
- Access Control: Strict access controls limit data access to authorized personnel only
- Infrastructure: We use Supabase's secure cloud infrastructure with SOC 2 compliance
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share data only in these circumstances:
- Service Providers: With trusted third parties who assist in operating our Service (hosting, analytics)
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share information
7. Data Retention
We retain your data for as long as your account is active or as needed to provide services:
- Account Data: Retained until you delete your account
- Social Media Tokens: Retained until you disconnect the platform or tokens expire
- Analytics Data: Retained for up to 2 years for historical reporting
- Uploaded Media: Retained until you delete it or close your account
8. Your Rights and Choices
You have the following rights regarding your data:
8.1 Access and Portability
You can request a copy of your personal data at any time through your account settings.
8.2 Correction
You can update your account information directly within the Service.
8.3 Deletion
You can delete your account and all associated data through Settings. Upon deletion:
- All your personal information will be permanently deleted
- All connected social media accounts will be disconnected
- All uploaded media and scheduled posts will be removed
8.4 Platform Disconnection
You can disconnect any social media platform at any time, which will immediately revoke our access to that platform's data.
8.5 Meta (Facebook/Instagram) Data Deletion
If you connected via Facebook or Instagram, you can also request data deletion directly through Meta. We will process deletion requests within 30 days.
9. GDPR Compliance (EU Users)
For users in the European Economic Area (EEA), we comply with GDPR requirements:
- Legal Basis: We process data based on your consent and contractual necessity
- Data Transfers: Data may be transferred to the US where our servers are located, with appropriate safeguards
- DPO: You can contact our data protection team through the in-app support feature
- Supervisory Authority: You have the right to lodge a complaint with your local data protection authority
10. CCPA Compliance (California Users)
California residents have additional rights under CCPA:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell data)
- Right to non-discrimination for exercising your rights
11. Children's Privacy
Our Service is not intended for users under 13 years of age (or 16 in the EEA). We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.
12. Cookies and Tracking
We use essential cookies for authentication and session management. We do not use third-party tracking cookies for advertising purposes.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice in the Service. Your continued use after changes constitutes acceptance of the updated policy.
Third-Party Platform Policies
Your use of connected platforms is also governed by their respective privacy policies: