Privacy Policy
Last updated: 9th July 2026 1. Who we are Vedron is a product and trading name of Blue Squirrel Pte Ltd , a company incorporated in Singapore (UEN 202306690Z ), with its registered address at Blk 328 Tampines St 32, 08-362, 520328, Singapore ("Vedron," "we," "us," or "our"). For any privacy-related question or request, you can contact us at info@vedron.io . If you are in the European Economic Area (EEA), our EU representative under Article 27 GDPR is Rinos Bikes GmbH, Goethestraße 11E, 15234, Frankfurt (Oder), Germany . 2. Scope of this policy This policy explains how we collect, use, and protect personal data when you: visit our website; sign up for, evaluate, or use VedronCMS or VedronERP; or interact with us as a prospective customer. It does not cover the privacy practices of the individual online stores our customers build using Vedron. Each of our customers ("Merchants") is responsible for their own privacy notice to their own shoppers. Where we handle shopper or business data on a Merchant's behalf, our responsibilities are set out in our Data Processing Agreement (DPA), not in this policy. 3. Our role: controller and processor Data protection law distinguishes between a controller (who decides why and how data is used) and a processor (who acts on the controller's instructions). In most of what we do, we act as a processor. Our Merchants control why and how their shoppers' and business data is collected and used, and we process it strictly on their documented instructions, as set out in our DPA. We act as a controller for: your account and billing information as a Merchant or prospective Merchant; data collected through our marketing website, including cookies; and our support and sales interactions with you. 4. Information we collect As a controller (information about you, our customer or prospective customer): Account information: name, email address, company name, and billing details. Website and usage data: including cookies and similar technologies (see Section 9 and our Cookie Policy ). Communications: support tickets, sales enquiries, and related correspondence. Beta evaluation data: where applicable, real business data you choose to provide during a product evaluation (see Section 4a). As a processor (information we handle on behalf of Merchants, relating to their shoppers and business operations): Order and customer data synced from connected sales channels, which currently include Allegro, Amazon, Bol, CDON, eBay, eMAG, Kaufland, mimovrste, PHH, Shopify, and TikTok Shop. Supplier, purchase order, and warehouse/fulfilment data. Accounting and financial data, including data transmitted to tax and accounting systems such as KSeF and e-Sprawozdania (Poland) and DATEV, easybill, and eRechnung/ZUGFeRD (Germany), as instructed by the Merchant. Payment-related data processed via Stripe and PayPal. We do not store raw payment card details. We regularly expand the platforms, marketplaces, and integrations we support, so the services and systems listed above may change over time and are provided as examples rather than a complete or fixed list. An up-to-date list of connected services and sub-processors is available at (link to be added) and forms part of our Data Processing Agreement. 4a. Beta program During our private beta, and only if you ask us to, we may load a representative sample of your actual business data so you can evaluate the product against your own numbers rather than a demo. Our role during the beta. During beta access, we act as both a controller and a processor , depending on the data in question — as a controller for your account and evaluation data, and as a processor for the business and shopper data you load or connect in order to test the product on your behalf. When beta access begins. Beta access takes effect once you begin actively using the product — for example, once your first marketplace or integration is connected, your first page is created in the CMS, or a domain is registered. What happens to your data. If you decide to stay with us, your beta arrangement transitions into a paid subscription and your data carries over into that plan. If you choose to withdraw from our system and services, we will delete your data within three months after the closure of your account is confirmed with Vedron (subject to any data we are required to retain by law). 5. Sub-processors We use the following sub-processors to provide our service: Sub-processor Purpose Stripe Payment processing PayPal Payment processing Cloudflare Content delivery, edge compute (Workers), and object storage (R2, for media and invoice PDFs) Hetzner Application and database hosting (Nuremberg, Germany) Connected sales channels (as enabled by you) Order and inventory synchronization KSeF / e-Sprawozdania Statutory tax reporting (Poland) DATEV / easybill Accounting and invoicing integration (Germany) An up-to-date list of sub-processors is available at (link to be added) and forms part of our Data Processing Agreement. 6. International data transfers We host your data within the European Union. Our application servers are located in Nuremberg, Germany (Hetzner). In some circumstances, personal data may nonetheless be processed by, or accessible from, outside the European Economic Area (EEA), and where this happens we put appropriate safeguards in place: Cloudflare (edge processing and storage). We use Cloudflare Workers to deliver our service and Cloudflare R2 to store certain files, including media and invoice PDFs that may contain personal data. Our R2 storage is located in the European Union. Cloudflare operates a global network and is headquartered in the United States, so some edge processing may occur outside the EEA; for any such transfer, we rely on the safeguards in Cloudflare's Data Processing Addendum, including the European Commission's Standard Contractual Clauses. Access from Singapore. Blue Squirrel Pte Ltd is based in Singapore, and our support and engineering staff may access data from there for administration and troubleshooting. Singapore does not currently benefit from a European Commission adequacy decision. For this transfer we rely on Standard Contractual Clauses approved by the European Commission, incorporated into our Data Processing Agreement with Merchants. 7. Data retention We keep personal data only for as long as necessary for the purposes described in this policy, or for as long as required by law. Because we operate across multiple countries, some data — particularly accounting and tax records — is subject to statutory retention periods that differ by jurisdiction. Where more than one period could apply, we retain the data for the longest applicable statutory period. We apply the following retention approach by category: Account and contract data — kept for the duration of your account, and for six years after account closure to handle post-termination obligations, legal claims, and disputes. Transaction, accounting, and tax data — retained for the longest statutory retention period applicable in the relevant market. These periods are set by national law and vary by country and document type; in the markets we currently serve they generally range up to ten years . Support communications — kept for up to one year after your query is resolved. Marketing data — kept until you withdraw consent or object, after which it is deleted or anonymised. When a retention period ends, we delete or anonymise the relevant data. 8. Your rights If you are in the EEA, under the General Data Protection Regulation you have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to rights concerning automated decision-making. If you are in Singapore, under the Personal Data Protection Act you have the right to access and correct your personal data and to withdraw consent. To exercise any of these rights, contact us at info@vedron.io . Where we act as a processor on a Merchant's behalf, we will forward your request to the relevant Merchant, unless we are required by law to respond to you directly. 9. Cookies We use cookies and similar technologies on our website. Strictly necessary cookies are set automatically; all other categories (functional, analytics, and marketing) are set only with your prior consent, which you can give or withdraw at any time via our cookie settings. Full details of the cookies we use are set out in our Cookie Policy . 10. Security We use a range of technical and organisational measures designed to protect personal data, including: Encryption in transit — traffic is protected using HTTPS/TLS. Encryption of sensitive credentials — connected service credentials (such as marketplace API keys) are encrypted at rest. Authenticated access — access is controlled using short-lived access tokens with separate refresh tokens. Role- and module-based access controls — users can access only the functions and data assigned to their role. Per-tenant data separation — each customer's data is separated at the database level. Rate limiting — to help protect the service against abuse. Regular backups — daily (2-2-7 backup system). We keep these measures under review and update them as needed. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. 11. Children's data Our services are directed at businesses, not children. We do not knowingly collect personal data from individuals below the applicable age of digital consent in their jurisdiction. 12. Changes to this policy We may update this policy from time to time. Where changes are material, we will notify you via email and/or an in-app notice before they take effect. 13. Contact us and complaints For any privacy question or to exercise your rights, contact us at info@vedron.io . If you are in the EEA, you also have the right to lodge a complaint with your local data protection supervisory authority. If you are in Singapore, you may contact the Personal Data Protection Commission (PDPC).
Privacy Policy
Last updated: 9th July 2026
1. Who we are
Vedron is a product and trading name of Blue Squirrel Pte Ltd, a company incorporated in Singapore (UEN 202306690Z), with its registered address at Blk 328 Tampines St 32, 08-362, 520328, Singapore ("Vedron," "we," "us," or "our").
For any privacy-related question or request, you can contact us at info@vedron.io.
If you are in the European Economic Area (EEA), our EU representative under Article 27 GDPR is Rinos Bikes GmbH, Goethestraße 11E, 15234, Frankfurt (Oder), Germany.
2. Scope of this policy
This policy explains how we collect, use, and protect personal data when you:
- visit our website;
- sign up for, evaluate, or use VedronCMS or VedronERP; or
- interact with us as a prospective customer.
It does not cover the privacy practices of the individual online stores our customers build using Vedron. Each of our customers ("Merchants") is responsible for their own privacy notice to their own shoppers. Where we handle shopper or business data on a Merchant's behalf, our responsibilities are set out in our Data Processing Agreement (DPA), not in this policy.
3. Our role: controller and processor
Data protection law distinguishes between a controller (who decides why and how data is used) and a processor (who acts on the controller's instructions).
In most of what we do, we act as a processor. Our Merchants control why and how their shoppers' and business data is collected and used, and we process it strictly on their documented instructions, as set out in our DPA.
We act as a controller for:
- your account and billing information as a Merchant or prospective Merchant;
- data collected through our marketing website, including cookies; and
- our support and sales interactions with you.
4. Information we collect
As a controller (information about you, our customer or prospective customer):
- Account information: name, email address, company name, and billing details.
- Website and usage data: including cookies and similar technologies (see Section 9 and our Cookie Policy).
- Communications: support tickets, sales enquiries, and related correspondence.
- Beta evaluation data: where applicable, real business data you choose to provide during a product evaluation (see Section 4a).
As a processor (information we handle on behalf of Merchants, relating to their shoppers and business operations):
- Order and customer data synced from connected sales channels, which currently include Allegro, Amazon, Bol, CDON, eBay, eMAG, Kaufland, mimovrste, PHH, Shopify, and TikTok Shop.
- Supplier, purchase order, and warehouse/fulfilment data.
- Accounting and financial data, including data transmitted to tax and accounting systems such as KSeF and e-Sprawozdania (Poland) and DATEV, easybill, and eRechnung/ZUGFeRD (Germany), as instructed by the Merchant.
- Payment-related data processed via Stripe and PayPal. We do not store raw payment card details.
We regularly expand the platforms, marketplaces, and integrations we support, so the services and systems listed above may change over time and are provided as examples rather than a complete or fixed list. An up-to-date list of connected services and sub-processors is available at (link to be added) and forms part of our Data Processing Agreement.
4a. Beta program
During our private beta, and only if you ask us to, we may load a representative sample of your actual business data so you can evaluate the product against your own numbers rather than a demo.
Our role during the beta. During beta access, we act as both a controller and a processor, depending on the data in question — as a controller for your account and evaluation data, and as a processor for the business and shopper data you load or connect in order to test the product on your behalf.
When beta access begins. Beta access takes effect once you begin actively using the product — for example, once your first marketplace or integration is connected, your first page is created in the CMS, or a domain is registered.
What happens to your data. If you decide to stay with us, your beta arrangement transitions into a paid subscription and your data carries over into that plan. If you choose to withdraw from our system and services, we will delete your data within three months after the closure of your account is confirmed with Vedron (subject to any data we are required to retain by law).
5. Sub-processors
We use the following sub-processors to provide our service:
| Sub-processor | Purpose |
|---|---|
| Stripe | Payment processing |
| PayPal | Payment processing |
| Cloudflare | Content delivery, edge compute (Workers), and object storage (R2, for media and invoice PDFs) |
| Hetzner | Application and database hosting (Nuremberg, Germany) |
| Connected sales channels (as enabled by you) | Order and inventory synchronization |
| KSeF / e-Sprawozdania | Statutory tax reporting (Poland) |
| DATEV / easybill | Accounting and invoicing integration (Germany) |
An up-to-date list of sub-processors is available at (link to be added) and forms part of our Data Processing Agreement.
6. International data transfers
We host your data within the European Union. Our application servers are located in Nuremberg, Germany (Hetzner). In some circumstances, personal data may nonetheless be processed by, or accessible from, outside the European Economic Area (EEA), and where this happens we put appropriate safeguards in place:
- Cloudflare (edge processing and storage). We use Cloudflare Workers to deliver our service and Cloudflare R2 to store certain files, including media and invoice PDFs that may contain personal data. Our R2 storage is located in the European Union. Cloudflare operates a global network and is headquartered in the United States, so some edge processing may occur outside the EEA; for any such transfer, we rely on the safeguards in Cloudflare's Data Processing Addendum, including the European Commission's Standard Contractual Clauses.
- Access from Singapore. Blue Squirrel Pte Ltd is based in Singapore, and our support and engineering staff may access data from there for administration and troubleshooting. Singapore does not currently benefit from a European Commission adequacy decision. For this transfer we rely on Standard Contractual Clauses approved by the European Commission, incorporated into our Data Processing Agreement with Merchants.
7. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, or for as long as required by law. Because we operate across multiple countries, some data — particularly accounting and tax records — is subject to statutory retention periods that differ by jurisdiction. Where more than one period could apply, we retain the data for the longest applicable statutory period.
We apply the following retention approach by category:
- Account and contract data — kept for the duration of your account, and for six years after account closure to handle post-termination obligations, legal claims, and disputes.
- Transaction, accounting, and tax data — retained for the longest statutory retention period applicable in the relevant market. These periods are set by national law and vary by country and document type; in the markets we currently serve they generally range up to ten years.
- Support communications — kept for up to one year after your query is resolved.
- Marketing data — kept until you withdraw consent or object, after which it is deleted or anonymised.
When a retention period ends, we delete or anonymise the relevant data.
8. Your rights
If you are in the EEA, under the General Data Protection Regulation you have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to rights concerning automated decision-making.
If you are in Singapore, under the Personal Data Protection Act you have the right to access and correct your personal data and to withdraw consent.
To exercise any of these rights, contact us at info@vedron.io. Where we act as a processor on a Merchant's behalf, we will forward your request to the relevant Merchant, unless we are required by law to respond to you directly.
9. Cookies
We use cookies and similar technologies on our website. Strictly necessary cookies are set automatically; all other categories (functional, analytics, and marketing) are set only with your prior consent, which you can give or withdraw at any time via our cookie settings.
Full details of the cookies we use are set out in our Cookie Policy.
10. Security
We use a range of technical and organisational measures designed to protect personal data, including:
- Encryption in transit — traffic is protected using HTTPS/TLS.
- Encryption of sensitive credentials — connected service credentials (such as marketplace API keys) are encrypted at rest.
- Authenticated access — access is controlled using short-lived access tokens with separate refresh tokens.
- Role- and module-based access controls — users can access only the functions and data assigned to their role.
- Per-tenant data separation — each customer's data is separated at the database level.
- Rate limiting — to help protect the service against abuse.
- Regular backups — daily (2-2-7 backup system).
We keep these measures under review and update them as needed. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children's data
Our services are directed at businesses, not children. We do not knowingly collect personal data from individuals below the applicable age of digital consent in their jurisdiction.
12. Changes to this policy
We may update this policy from time to time. Where changes are material, we will notify you via email and/or an in-app notice before they take effect.
13. Contact us and complaints
For any privacy question or to exercise your rights, contact us at info@vedron.io.
If you are in the EEA, you also have the right to lodge a complaint with your local data protection supervisory authority. If you are in Singapore, you may contact the Personal Data Protection Commission (PDPC).