Privacy & Data Protection

Privacy Policy

Effective date: September 9, 2026Data Controller: Gabriel Canariniinfo@veyren.shop

This Privacy Policy explains how Veyren, together with related websites, storefronts, and Discord automation tools operated by Gabriel Canarini (collectively, the “Application” or the “Service”), collects, uses, protects, and discloses personal data. Gabriel Canarini is hereinafter referred to as the “Service Provider” or the “Data Controller”.

Data Controller Information

Gabriel Canarini acts as the Data Controller responsible for the processing of your personal data under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).

Data Controller:

Gabriel Canarini

Via Musolesi 1, Marzabotto, Italia

Email: info@veyren.shop

EU Representative:

Gabriel Canarini

Email: gabrielcanarini2@gmail.com

For any data protection inquiries, questions regarding our privacy practices, or to exercise your statutory GDPR rights, please contact the Data Controller at info@veyren.shop.

What Information Does the Application Obtain and Why?

We collect information that you directly provide when registering for an account, creating a workspace, connecting a Discord server, or completing a purchase through a Veyren storefront:

  • Account & Profile Data: Name, email address, password hashes (handled via secure cryptographic salting), and profile attributes.
  • Discord Account Identifiers: When you connect Discord via OAuth, we retrieve your Discord User ID, username, avatar, and server memberships solely to execute automated role assignment and synchronization.
  • Transactional Records: Order history, product identifiers, subscription tier status, fulfillment records, and timestamps.
Payment Card Information (PCI-DSS Level 1)

Veyren does NOT collect, process, or store sensitive credit or debit card numbers, CVVs, or full payment credentials on its servers. All payments are tokenized and processed directly by our authorized, certified payment partner (Stripe), conforming strictly to PCI-DSS Level 1 compliance.

Legal Basis for Processing Personal Data (GDPR Art. 6)

Where European data protection law applies, we process your personal data under the following lawful bases:

  • Contract Performance (Art. 6(1)(b)): Processing necessary to create your account, provide storefront checkouts, automate Discord role assignments, and deliver digital downloads.
  • Legitimate Interests (Art. 6(1)(f)): Maintaining platform infrastructure security, detecting fraud and unauthorized access, preventing abuse, and ensuring reliable system performance.
  • Legal Obligations (Art. 6(1)(c)): Retaining billing and financial transaction records to comply with statutory tax, accounting, and anti-fraud regulations.
  • Consent (Art. 6(1)(a)): Where you explicitly opt in to non-essential communications or optional feature integrations. Consent can be revoked at any time.

Third-Party Sub-Processors (GDPR Art. 28)

In order to provide our software services, we engage trusted third-party service providers (sub-processors) under formal Data Processing Agreements (DPAs):

Stripe Inc.

Payment processing, invoice management, tax calculation, and payout fulfillment.

Discord Inc.

OAuth authentication, member ID resolution, and Discord bot role automation.

Resend Inc.

Transactional email delivery (account verification, password resets, purchase receipts).

Cloud Hosting & Databases

Secure PostgreSQL database persistence, serverless application hosting, and encrypted file distribution.

Where personal data is transferred outside the European Economic Area (EEA), transfers are safeguarded by European Commission Adequacy Decisions or Standard Contractual Clauses (SCCs) in accordance with Chapter V of the GDPR.

Cookies and Technical Session Storage

The Application uses strictly necessary technical cookies and local storage keys (managed via our authentication system, Better Auth) to:

  • Maintain your authenticated login session across requests.
  • Protect against Cross-Site Request Forgery (CSRF) attacks.
  • Remember theme preferences (dark/light mode).

No Third-Party Advertising Trackers: We do not use cross-site tracking cookies, behavioral ad pixels, or third-party profiling tools. Under the EU ePrivacy Directive and GDPR, strictly necessary technical cookies do not require prior consent banners.

Automated Decision-Making and AI

The Application does not utilize Artificial Intelligence (AI) algorithms to profile users or make automated decisions producing legal or similarly significant effects. Role assignments on Discord are rule-based outcomes strictly triggered by your purchase or subscription status.

Data Retention Policy & Deletion

  • Active Account Data: Maintained for the duration of your active registration plus 12 months following account closure, unless required longer for legal compliance.
  • Financial Transaction Logs: Retained for the period mandated by Italian and EU statutory tax and accounting laws (up to 10 years).
  • Technical Server Logs: Retained for security and debugging for up to 90 days.

How to Request Account & Data Deletion

You can request the permanent deletion of your account and associated personal records at any time by contacting info@veyren.shop. Requests are processed within 30 days of identity verification, subject only to mandatory legal retention requirements.

Children's Privacy (16+)

The Application is not intended for or directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child under 16 has provided personal data without parental consent, please email info@veyren.shop so we can promptly remove the information.

Security Safeguards & Data Breach Notification

We employ industry-standard technical and organizational security measures (including TLS 1.3 encryption in transit, cryptographic password hashing, access control lists, and firewalls) to safeguard your data.

72-Hour Breach Notification (GDPR Art. 33 & 34)

In the event of a security incident resulting in a personal data breach likely to present a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware, and notify affected users without undue delay where required by applicable law.

Your GDPR Data Protection Rights

Under the General Data Protection Regulation (GDPR), you possess the following rights:

Right of Access:

Request confirmation and copies of your personal data.

Right to Rectification:

Request correction of inaccurate or incomplete personal data.

Right to Erasure:

Request deletion of your personal data (“right to be forgotten”).

Right to Restrict Processing:

Request restriction of how your personal data is processed.

Right to Data Portability:

Receive your data in a structured, commonly used machine-readable format.

Right to Object:

Object to processing based on legitimate interests or direct marketing.

You also have the right to lodge a complaint with your competent Data Protection Authority:

California Privacy Rights (CCPA / CPRA)

If you reside in California, you have the right to know what personal information is collected, request deletion, request correction, opt out of any sale or sharing of personal data (note: Veyren does not sell personal data), and receive non-discriminatory treatment for exercising your rights. Contact info@veyren.shop to exercise any CCPA rights.

Contact the Data Controller

For any questions regarding this Privacy Policy or your personal data, contact:

info@veyren.shop