Privacy Policy

Last updated: August 2026

This Privacy Policy is written for the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you are visiting from outside Australia, see the International visitors section — we extend equivalent rights to you regardless of where you live.

1. Who we are

Velosites is operated by VISHKRMA PTY LTD ATF VISHKRMA FAMILY TRUST, trading as Velosites (ABN 37 122 729 457, ACN 696 066 029) of Level 1, 331 High Street, Penrith NSW 2750, Australia ("Velosites", "we", "us"). We take your privacy seriously. This policy explains how we collect, hold, use and disclose your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

2. What personal information we collect

Account information

  • Business name and contact name
  • Email address and phone number
  • Country/region
  • Payment information (processed securely by our payment providers — we never store your card number or CVV)

Project information

To build and manage your website, we collect:

  • Business details and descriptions
  • Brand assets (logos, colours, fonts)
  • Social media links
  • Content and images you provide
  • Design preferences and requirements

Information collected automatically

  • IP address
  • Browser type and version
  • Device information
  • Usage data and analytics (subject to your cookie choices — see Cookies & analytics)

We collect personal information directly from you (through forms, your account, email and phone) and automatically when you use our website. We do not collect sensitive information (such as health or biometric data), and you can deal with us anonymously for general enquiries where practicable.

3. How we use your information

We use your personal information to:

  • Create and manage your account
  • Build, host and maintain your website
  • Process payments and subscriptions
  • Communicate about your projects and provide customer support
  • Send service updates and notifications
  • Improve our services
  • Comply with our legal obligations

Direct marketing

We may send you information about our services that we think will interest you. Every marketing email includes an unsubscribe link, and you can opt out at any time by using that link or contacting us — opting out never affects your service.

4. Who we share your information with

We do not sell your personal information. We disclose it only to:

  • Service providers who help us deliver the service: payment processors (Stripe), the operators of the data centres our servers sit in, our offsite backup provider (Backblaze), and — where mailboxes are not on the mail server we run ourselves — a third-party email provider
  • Professional advisers (accountants, lawyers) where required for the operation of the business
  • Government bodies and regulators where required or authorised by law
  • A purchaser or successor in connection with a merger, acquisition or sale of the business

Payment information is processed by Stripe Inc. Stripe's privacy policy is at stripe.com/au/privacy.

5. Overseas disclosure

It is more useful to tell you this leg by leg than to give you one sentence that is true of only part of it:

  • Hosting — Australia. The servers that run your site and hold its database are in Australia. That is the origin of record.
  • Backups — Canada, operated from the United States. Our offsite backups are stored with Backblaze in a Canadian region. Backblaze is a United States company and may be subject to US legal process. Backup data is encrypted before it leaves our infrastructure and we hold the key, so what the provider stores is ciphertext rather than readable content.
  • Public edge — global, for some sites. Many client sites are proxied through a global CDN, so TLS terminates and public pages cache at edge locations outside Australia. What sits at the edge is cached public content, not the database. Some sites, including this one, have no CDN leg at all.
  • One legacy client site — Singapore. One site we still host has not yet moved off an older overseas server. Nothing new is deployed there and it is being retired.
  • Payments — United States and elsewhere. Card and payment data is handled by Stripe under its own privacy policy.
  • Site analytics — Australia, and the United States if you consent. Our own website measurement is cookieless, runs on our own Australian server and is never sent overseas. Separately, Google Analytics loads only if you accept analytics cookies — if you do, that data is processed by Google outside Australia. Decline, and it does not load at all. See Cookies & analytics.

Where personal information does leave Australia, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles. If data residency matters to your business, ask us and we will answer for the specific leg you care about rather than in general terms.

6. 🍪 Cookies & analytics

Cookies are small text files stored on your device. We use:

  • Essential cookies — required for basic functionality (session management, security). Always enabled.
  • Analytics cookies — Google Analytics, where it is enabled. It loads through Google Tag Manager with Consent Mode set to denied by default, so it stays off unless you consent via the cookie banner.
  • Marketing cookies — advertising and retargeting cookies, set only if you expressly enable them in the cookie banner. We do not enable these by default.

Our own site measurement — no cookies

Separately from the cookies above, we run our own website measurement using Plausible Community Edition, self-hosted on our own Australian server and served from this domain. It runs on every page and is not behind the consent banner, because it sets no cookies, stores no identifier on your device, does not build a profile of you, and does not follow you across other websites. It records page views and aggregate signals such as referrer, approximate country, and browser and device type. That data stays on our infrastructure and is not shared with or sold to anyone. If you would rather not be counted at all, most browser tracking-protection settings and content blockers will stop it, and you can email us to ask.

You can change your cookie choices at any time by:

  • Clearing this site's stored data in your browser, which brings the consent banner back
  • Adjusting your browser cookie settings
  • Emailing privacy@velosites.com and asking us to change or delete them

7. Data security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including:

  • SSL/TLS encryption for data in transit
  • Secure password hashing
  • Isolated, containerised hosting per client
  • Access controls, uptime and certificate monitoring, and automated vulnerability scanning of every build before it is deployed

No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

8. Data retention

We retain personal information for as long as your account is active or as needed to provide services, comply with legal obligations (financial records are kept for a minimum of 7 years under Australian tax law), or resolve disputes. When personal information is no longer needed, we take reasonable steps to destroy or de-identify it. You may request deletion of your personal data by contacting privacy@velosites.com, subject to these retention requirements.

9. Access, correction & your choices

You may at any time:

  • Access the personal information we hold about you
  • Correct information that is inaccurate, out of date or incomplete
  • Delete your account and data (subject to the retention requirements above)
  • Export your data in a portable format
  • Opt out of marketing communications

To exercise any of these, contact privacy@velosites.com. We respond to requests within 30 days (or any shorter timeframe required by applicable law), and we will not charge you for making a request.

10. Complaints

If you believe we have mishandled your personal information, contact us first at privacy@velosites.com and we will investigate and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

11. 🌍 International visitors

We are an Australian business and primarily serve Australian and New Zealand customers. If you are located in the European Union, United Kingdom, California, Brazil or another jurisdiction with its own data-protection law, we extend you the same rights described in this policy — access, correction, deletion, portability, objection to marketing — regardless of where you live. In particular:

  • We do not sell personal information, and never have.
  • Cookie-based analytics and advertising are off by default and only run with your consent. Our own site measurement sets no cookies and does not identify you — see Cookies & analytics.
  • You may request a copy, correction or deletion of your data at any time via privacy@velosites.com.
  • You retain the right to lodge a complaint with your local data protection authority.

12. Children's privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this Privacy Policy periodically. We will notify you of significant changes via email or through the platform. The "Last updated" date indicates when the policy was last revised.

14. Contact us

For privacy-related questions, concerns, or to exercise your rights, contact:

Entity: VISHKRMA PTY LTD ATF VISHKRMA FAMILY TRUST, trading as Velosites — ABN 37 122 729 457 — ACN 696 066 029

Address: Level 1, 331 High Street, Penrith NSW 2750, Australia

Phone: 1300 487 842

Email: privacy@velosites.com