Data security

Last updated: 1 September 2026

Veloseller processes data about stock levels and stock movements and, where marketplaces are connected, the data required to access their APIs. This page describes the principal technical and organisational measures applied to protect that data.

The legal grounds for processing, the purposes, the retention periods and other legal information are set out in the Privacy policy.

Where the data is stored

Veloseller data is stored on servers located in the Russian Federation. The primary data store is PostgreSQL running on self-hosted Supabase infrastructure. The database is under Veloseller’s control and is not passed to third-party analytics platforms. The list of third-party service providers used to operate the service, including hosting, email and payment processing, is set out in the Privacy policy.

Encryption and protection of credentials

Connections to Veloseller use the secure HTTPS protocol. HSTS is applied to enforce the use of a secure connection. Marketplace API keys and access tokens are stored encrypted using AES-256-GCM. The encryption key is held separately from the database, in a protected server environment. Obtaining a copy of the database does not by itself make it possible to decrypt the stored access keys.

User passwords are not stored in plain text. They are stored as irreversible cryptographic hashes.

Veloseller staff do not ask users for their passwords by email, in messengers or through any other channel.

Access control

Access to data is separated using the PostgreSQL Row Level Security (RLS) mechanism. Access policies limit data retrieval to the scope of the relevant user and cabinet. Access control is therefore enforced not only at the interface and application level, but directly at the database level. Where access is granted to a team member, their scope is limited to the cabinet they were invited to and the role assigned to them. Data isolation rules are subject to automated checks as part of the development and release process.

Backups

Veloseller creates daily backups of the database and of report files. The most recent 14 backups are retained. Backup creation is monitored automatically. If a scheduled backup does not appear, the system raises a notification to those responsible for running the service. Backups exist to restore data and service availability in the event of a technical failure or incident.

Staff access

Access to production infrastructure and data is limited to staff who require it to operate and support Veloseller. User data may be accessed for the purposes of diagnosing technical problems, handling user enquiries, resolving incidents and maintaining the security of the service.

Veloseller does not sell user data and does not use information about customers’ assortment, sales or stock in the interests of other sellers. Data is disclosed to third parties only in the cases and for the purposes provided for by the Privacy policy.

Payment

Veloseller does not receive or store users’ bank card details. Payment processing is carried out by the Robokassa payment service. Veloseller stores only the data required to identify the payment, to record it and to provide the corresponding plan.

Managing your data

A user may export their data or delete their account using Veloseller’s own tools. When an account is deleted, the data associated with it is deleted, including information about warehouses, products and operation history, in accordance with the conditions and periods established by the Privacy policy.

Reporting a security problem

If you have found a potential vulnerability or another problem relating to the security of Veloseller, report it to info@veloseller.ru.

We review reports of potential vulnerabilities and take the measures necessary to verify and remediate them.