Privacy Policy
Last updated: 19 September 2026
This policy explains how Velo Software, trading as Velosoft (“Velosoft”, “we”), collects, uses, shares and protects personal data through velosoft.in, the Velo mobile app, and payments made to us. It is published in compliance with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
1. Who we are (data fiduciary)
Velo Software (trading as Velosoft)Edaganasalai, Elampillai, Salem District, Tamil Nadu 637502, India
Email: [email protected] · Phone: +91 99626 60236
2. What we collect
- Enquiries and quotes: name, phone/WhatsApp number, business type, optional email and project brief submitted through our forms, phone, WhatsApp or email.
- Client and account data: business name, billing address, contact persons, login credentials (hashed), GSTIN if you provide one, and the business data you enter into Velo (products, orders, customers, invoices). You are responsible for having the right to enter your customers’ data into Velo; for that data we act on your instructions as a data processor.
- Payment data: when you pay us, we receive from Cashfree Payments the payment status, amount, date, payment method type (e.g. UPI, card, EMI), masked card/UPI identifiers, transaction and mandate reference IDs and your name, email and phone. We never receive or store full card numbers, CVV, card expiry, UPI PINs, net-banking passwords or OTPs.
- Recurring-payment (mandate) data: for Velo auto-pay we store the mandate ID, plan, maximum amount, frequency, status and next-debit date provided by Cashfree.
- Technical data: our hosting provider logs IP addresses and request metadata for security. The Velo app collects device type, OS version and crash diagnostics. We do not run advertising trackers on velosoft.in.
3. Why we use it and our legal basis
- To respond to your enquiry and prepare a proposal (your consent and the request you initiated).
- To deliver, bill, support and improve our services and the Velo app (performance of our contract with you).
- To process payments, refunds, EMI orders and recurring debits, and to prevent fraud and chargebacks (contract and legal obligation).
- To issue invoices and keep accounts and tax records as required (legal obligation). Velosoft is currently unregistered under GST; invoices are issued without GST until registration.
- To send service messages such as payment receipts, pre-debit notifications, renewal reminders and security alerts (contract). Marketing messages are sent only with your consent and you can opt out at any time.
4. Payments processed by Cashfree
All online payments to Velosoft are processed by Cashfree Payments India Private Limited, a payment aggregator authorised by the Reserve Bank of India and PCI DSS compliant. When you pay through a Cashfree payment link, payment page or in-app checkout:
- Your payment credentials are entered on Cashfree’s secure pages or SDK and transmitted directly to Cashfree, the card networks and your bank. Card data is tokenised in line with RBI tokenisation rules; Velosoft does not store it.
- Cashfree collects the information necessary to complete the payment, comply with RBI/KYC/AML rules and detect fraud, under its own privacy policy.
- For recurring payments (UPI Autopay, e-NACH/e-mandate, card standing instructions) your mandate is registered with Cashfree, your bank and NPCI. You will receive a pre-debit notification at least 24 hours before each charge, and you may pause or cancel the mandate at any time in the Velo app, your UPI app or your bank’s portal.
- For EMI and pay-later (including ZestMoney / DMI Finance, HDFC Bank, ICICI Bank, IDFC FIRST Bank, CASHe and other Cashfree EMI partners), the lender you choose will collect the identity, contact and credit information it needs to assess eligibility and provide the loan, under the lender’s own privacy policy. Velosoft receives only the approval status, lender name and order value, never your credit report or KYC documents.
5. Who we share data with
- Payment and finance: Cashfree Payments, its partner banks, card networks, NPCI and, where you choose EMI, the lender.
- Infrastructure: our hosting, cloud, email and form-handling providers, who process data only on our instructions under contract.
- Communication: email, SMS and WhatsApp Business service providers used to send service messages you requested.
- Maps: interactive maps load from Google only when you click “Load interactive map”, at which point Google’s privacy policy applies.
- Legal: regulators, courts, banks or law enforcement where required by law, for example RBI or GST record requests or chargeback investigations.
We never sell or rent personal data. Data is stored on servers located in India wherever practical; where a provider stores data outside India, we ensure contractual safeguards as permitted under the DPDP Act.
6. Cookies
velosoft.in uses no advertising or analytics cookies. Cashfree’s payment pages and the Velo app use strictly necessary cookies or tokens to keep your payment session secure and prevent fraud.
7. How long we keep it
- Enquiry data: up to 24 months after our last contact.
- Client, contract and Velo account data: for the duration of the relationship and 30 days after cancellation for export, after which business data is deleted or anonymised.
- Invoices, payment records and mandate records: 8 years, as required by Indian tax, company and RBI record-keeping rules.
- Dispute and chargeback records: until the dispute is closed plus the applicable limitation period.
8. Your rights
Under the DPDP Act you may access a summary of your personal data, correct or update it, request erasure where we no longer need it, nominate a person to exercise your rights, and withdraw consent at any time (which does not affect processing already done or processing we must carry out by law). Email [email protected] or call +91 99626 60236 from your registered contact; we respond within 7 working days. If you are unsatisfied, you may complain to the Data Protection Board of India.
9. Data storage & security
This section is our data-storage and security policy. velosoft.in and the Velo app are served over HTTPS only. Personal and payment data is stored on servers located in India wherever practical. Payment credentials are handled exclusively by Cashfree Payments under PCI DSS; Velosoft does not store full card numbers, CVV, UPI PINs or net-banking passwords. Velo business data is stored encrypted at rest with role-based access. Access to personal data is limited to staff who need it to deliver the service. We retain payment and tax records for 8 years as required by Indian law. We notify affected users and the Data Protection Board of any personal-data breach as required by law. Where a processor stores data outside India, we use contractual safeguards permitted under the DPDP Act.
10. Children
Our services are for businesses and adults aged 18 and above. We do not knowingly collect personal data of children.
11. Changes
We will post changes on this page with a new “Last updated” date and email Velo subscribers about material changes. Related policies: Terms & Conditions · Refund & Cancellation Policy · Service Delivery Policy.