velstash
Pricing Docs FAQ Try it free

Legal

Privacy Policy: Data Conservation and Retention

Last Updated: August 24, 2026

This Privacy Policy applies to the Service operated by the Provider (as identified in the Terms of Service), comprising the public website and dashboard at velstash.com and the cache infrastructure accessible via velstash.io. In compliance with the General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD), we hereby inform you about the retention periods for the three categories of data that coexist within our Service:

1. Transit Data and Temporary Storage (Cache Data)

1.a. Nature

This includes any information, records, or technical data that the Client (or the Client's applications) uploads to our Memcached infrastructure.

1.b. Retention Period

Cached contents ("values") are volatile and temporary, being automatically and irreversibly deleted upon hitting any of the following technical triggers:

  1. Expiration of the TTL (Time to Live) set freely by the Client.
  2. Server memory saturation (automated "eviction" processes).
  3. Immediately upon cancellation or termination of the service by the Client.
  4. Technical server restarts, updates, or maintenance windows.

1.b.i. Persistence of Cache Keys for Statistical Purposes

While the content ("values") stored in the cache remains strictly volatile and is never written to disk, the keys used to identify cached entries may be persisted to disk for the purpose of providing the Client with usage statistics through the dashboard (such as hit/miss rates, key access frequency, or other usage metrics). Per-key and per-prefix statistics are retained for a maximum of twelve (12) months, after which they are automatically deleted. The underlying key name is deleted as soon as no statistical record references it. This data is used exclusively to provide such statistics to the Client and is not used by the Provider for any other purpose.

The Client is solely responsible for the structure and content of the keys used by its applications. The Provider recommends that Clients avoid embedding personal data (such as email addresses, full names, or other directly identifying information) directly within cache key names, and instead use non-identifying references (such as internal IDs or hashes) where personal data would otherwise appear in a key.

1.c. Legal Role

Regarding this data, the Provider acts strictly as a "Data Processor", processing it solely on behalf and under the instructions of the Client (who acts as the Data Controller).

2. User Profile and Registration Data

2.a. Nature

Certain account and subscription-status metadata is provided to us by Dodo Payments, Inc. or its affiliates or successor entity (hereinafter "Dodo Payments") for the purpose of managing the Client's access to the service dashboard.

2.b. Retention Period

This data is not affected by cache expiration. It will be actively preserved as long as the Client keeps their account open on the platform, in order to provide access to the dashboard, manage subscriptions, and send authorized updates.

2.c. Legal Role

With respect to user profile and registration data that the Provider itself collects, stores, or generates directly (such as login credentials, dashboard activity, and account settings), the Provider acts as the Data Controller, determining the purposes and means of that processing.

With respect to this user profile and registration data, Dodo Payments acts as an independent Data Controller, and not as a processor on behalf of the Provider. This means Dodo Payments determines its own purposes and means for processing this data, in accordance with its own privacy policy, available at https://dodopayments.com/legal/privacy-policy.

2.d. Legal Restriction (Data Blocking)

Once a Client requests the permanent deletion of their account, their personal data will be removed or restricted (blocked). Blocked data is kept entirely separate from active databases and is preserved solely to comply with legal, tax, and accounting obligations under Spanish law (typically up to 4 or 5 years according to Spanish civil and tax limitation periods). After this period, it will be completely destroyed.

3. Payment Data

3.a. Nature

In order to process payments, the Client's billing and payment-related personal data (such as full name, email address, billing address, and payment method details) is collected and processed directly by payment processing partner, currently Dodo Payments, acting as Merchant of Record for all paid transactions on the Service.

3.b. Legal Role

With respect to this payment data, Dodo Payments acts as an independent Data Controller, and not as a processor on behalf of the Provider. This means Dodo Payments determines its own purposes and means for processing this data, in accordance with its own privacy policy, available at https://dodopayments.com/legal/privacy-policy.

The Provider does not receive or store full payment card details, which are handled exclusively by Dodo Payments.

3.c. International Transfer

Dodo Payments is based in the United States. Any transfer of personal data to Dodo Payments outside the European Economic Area (EEA) is carried out under appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission, as further described in Dodo Payments' own privacy policy.

3.d. Data Subject Rights

For any requests regarding the exercise of data protection rights (access, rectification, erasure, etc.) specifically in relation to billing and payment data processed by Dodo Payments, the Client should contact Dodo Payments directly, without prejudice to the Client's right to also contact the Provider or the relevant supervisory authority.

4. Infrastructure and European Compliance (Sub-Processors)

To ensure maximum security and strict GDPR compliance, all server infrastructure is contracted with premium providers who process and store information exclusively within the European Economic Area (EEA):

  • Hetzner Online GmbH: Servers located within the European Union (Germany/Finland).
  • OVH SAS: Server regions located strictly within the European Union (e.g., Gravelines/France).

With respect to infrastructure hosting, no international data transfers are made to third countries outside the EEA without an applicable adequacy decision or other appropriate safeguard. Payment data may be transferred to other jurisdictions outside the European Union as specified in section 3 of this document.

Additionally, we use the following providers outside EEA:

  • Proton AG: Servers located in Switzerland (a jurisdiction subject to a European Commission adequacy decision), used for transactional and account-related email delivery (including password resets, account notifications, and —where consented to— marketing communications).

5. Legal Basis and Data Subject Rights

5.a. Legal Basis for Processing

Where the Provider acts as Data Controller (as described in Sections 1.c and 2.c above), personal data is processed on the following legal bases, in accordance with Article 6 GDPR:

  • Performance of a contract (Art. 6.1.b): processing of account, dashboard, and cache-instance-configuration data necessary to provide the Service the Client has subscribed to.
  • Legitimate interest (Art. 6.1.f): processing necessary for the security, technical integrity, and fraud prevention of the Service, and to respond to support requests, provided such interest is not overridden by the Client's rights and freedoms.
  • Consent (Art. 6.1.a): processing of data for commercial communications and marketing purposes, as described in Section 9 of the Terms of Service, which the Client may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Compliance with a legal obligation (Art. 6.1.c): retention of blocked data for tax, accounting, and legal purposes as described in Section 2.d.

5.b. Data Subject Rights

With respect to personal data for which the Provider acts as Data Controller, the Client may exercise the following rights at any time, free of charge, by contacting the Provider at support@velstash.com:

  • Access: obtain confirmation of whether the Provider is processing your personal data, and access to that data.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of your data where it is no longer necessary for the purposes for which it was collected, subject to the retention obligations described in Section 2.d.
  • Portability: receive your data in a structured, commonly used, machine-readable format, where technically feasible.
  • Objection: object to processing carried out on the basis of legitimate interest, including for direct marketing purposes.
  • Restriction: request that processing of your data be limited in certain circumstances provided by law.

The Provider will respond to such requests within the timeframes established by applicable data protection law.

For rights relating to data controlled independently by Dodo Payments, please refer to Section 3.d.

5.c. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, the Client has the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), C/ Jorge Juan, 6, 28001 Madrid, or via www.aepd.es, if they consider that the processing of their personal data infringes applicable data protection law.

6. Cookies

The Service uses only one cookie, strictly necessary for its operation: a session identifier used to maintain the Client's authenticated session while using the dashboard. This cookie does not track the Client across other websites and is not used for advertising or analytics purposes. It is a session cookie, meaning it expires when the Client closes their browser (or, depending on the Client's browser settings, when their browsing session otherwise ends), rather than after a fixed period of time.

Because this cookie is strictly necessary for the Service to function, it does not require the Client's prior consent under applicable law (Article 22.2 of Law 34/2002, LSSI-CE). The Provider does not currently use any analytics, advertising, or non-essential cookies. If this changes in the future, the Provider will update this Policy accordingly and, where required, request the Client's consent before setting any new cookie.

© 2026 Velstash
Pricing Docs FAQ Terms of Service Privacy Policy DPA
Featured on LaunchBuff