VELORA WALLS · LEGAL
Privacy Policy
Effective date: September 8, 2026
Scope and contact
Velora Walls operates velorawalls.com, its canvas shop, Wall Studio and private business administration tools. This policy explains information used to provide these services. Send privacy questions, complaints and rights requests through our contact form. Social and advertising integrations are operated by authorized Velora Walls administrators for business accounts; shoppers do not need to connect a social account to buy artwork.
Information we collect
We receive account identifiers, name, email and authentication information; order details, delivery addresses, phone numbers, purchased items and payment status; uploaded artwork and room photographs; studio selections; and support messages. Hosting and security services process technical information such as IP addresses, request times, browser information and security events. Uploaded files may contain embedded metadata: remove location or other sensitive metadata before uploading. We do not ask for social-platform passwords or receive full payment-card numbers through our custom storefront.
Why we use information
We use this information to authenticate accounts, save collections and rooms, operate the bag and checkout, prepare and fulfill orders, respond to support requests, protect the service and meet legal obligations. Business administrators use connected account data to check connections, manage approved content and review their own business performance. Where applicable, our legal grounds are performing your contract, complying with law, consent for optional activities and legitimate interests in operating and securing the service. You can decline optional features and withdraw consent without affecting earlier lawful processing.
Private artwork, rooms and phone uploads
Artwork and saved rooms are linked to your signed-in account and can be removed using their delete controls. Signing out does not delete them. They are not automatically placed in the public catalog or used in social posts. Uploading grants us permission to process the file for the requested preview, storage, security checks and, when ordered, printing. Phone upload links contain a temporary upload capability and expire after ten minutes; anyone with the link may use it while valid, so do not share it. Shared studio layouts use preset backgrounds rather than your private room photograph.
Shopify, Printify and fulfillment
Shopify provides customer authentication, product and order services, checkout and payment processing. Printify and the selected print provider receive the artwork and product specifications needed to prepare personalized products and the delivery information needed to fulfill orders. Carriers receive delivery information. Removing an original upload does not cancel an order or automatically remove production copies or legally required transaction records. Contact us about those copies. See Shopify privacy and Printify privacy.
Pinterest, Facebook, Instagram and TikTok
When an administrator authorizes an integration, we process its access credentials, account identifiers and permitted profile details to identify the business account. Depending on granted permissions and enabled features, we send selected images, videos, captions and links, and receive board or content identifiers, publication results and performance information. Facebook and Instagram can use separate authorizations. Sandbox and production access are distinct. Connection checks do not publish content; separately labeled write tests can create test resources. Published content is subject to the selected platform and audience settings. We do not sell platform data, use it for unrelated advertising audiences or train AI models with it. Read the applicable Pinterest, Meta and TikTok privacy policies.
Google services and YouTube API Services
We use YouTube API Services. Authorized features access channel identity, channel statistics and branding, and upload or update content selected by an administrator. Google integrations can also read authorized GA4 reports, Search Console site information, Merchant Center account information and Google Ads account details. We store account configuration and encrypted authorization credentials, and may retain diagnostics and business reports. Access is limited to the enabled features and permissions granted. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements where applicable. See the Google Privacy Policy. You can revoke access in Google account connections and request deletion of our stored information through our contact form.
AI features
Optional styling and administrator content tools use OpenAI. When you request room styling, your prompt and selected room image may be processed by that service. Administrator generation uses supplied brand material and public catalog content. Private original artwork is not automatically submitted to styling, and connected-platform reports are not included in the strategy agent’s prompts. We do not train our own models on your uploads or connected-account data. Provider processing and retention follow the service agreement; an AI request is not a promise of zero retention. You can use the manual studio without AI. See OpenAI privacy.
Cookies, device storage and advertising
First-party cookies maintain the bag, account login, administrator access and secure authorization flows. Browser storage remembers studio choices and recently shown products. The bag cookie can last up to 30 days; clearing browser storage may reset preferences but does not delete server records. Saving a Google Analytics measurement ID or advertising pixel ID in the admin does not itself activate a storefront tracking tag. The current storefront application does not embed advertising pixels. The Shopify Inbox help widget also loads from Shopify; it can process device information and messages you send, using its own storage and privacy controls. Shopify checkout and third-party destinations may use their own cookies and privacy controls. Any later activation of optional tracking requires appropriate notices and consent controls where required; this policy alone is not consent to such tracking.
Sharing, security and international processing
Access is limited to authorized personnel and service providers needed for hosting, storage, security scanning, authentication, payment, fulfillment and the optional services described here. Cloudflare hosts and protects application services; additional processing services support file checks and production preparation. We may disclose information when legally required or necessary to address fraud, abuse or security incidents. We use HTTPS, access controls and encrypted integration credentials; no security measure is absolute. Providers may process information outside your country, including in the United States. Applicable contractual and legal safeguards must govern restricted international transfers.
Retention and deletion
Saved artwork and rooms remain until you delete them or request account removal. We keep account and authorization records while needed to provide the connected service, and retain order and support records as needed for fulfillment, disputes, fraud prevention and applicable legal requirements. Token expiry or signing out does not itself erase stored records. Requests are reviewed to identify related copies, connected services and any lawful retention exception; we explain exceptions rather than promising that every copy disappears instantly. Published platform content must also be removed on that platform. See our data deletion instructions.
Your choices and rights
Depending on your location and applicable law, you may request access, a copy, correction, deletion, restriction or portability of your information, object to processing, withdraw consent, or complain to your local privacy authority. Use our contact form, identify the relevant account and describe your request. We may verify ownership using information reasonably needed for that purpose; do not send passwords, API tokens or payment-card details. We respond within applicable legal deadlines. We do not sell personal information or use connected API data for cross-context behavioral advertising. Authorized agents may contact us with evidence of authority where applicable.
Children and changes
The service is not directed to children under 13. Do not create an account or provide personal information if you are under 13. Contact us if a child has provided information so we can investigate and remove it as appropriate. Purchases and administrator integrations require an adult authorized to enter the relevant agreement. We update the effective date when this policy changes and provide additional notice or request consent for material changes where required.