Last updated: February 10, 2026
Privacy Policy
Velvet Palace / Emporo Services ("we", "us", "our") is committed to protecting the privacy and personal data of our users. This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform at velvetpalace.club ("the Platform").
This policy is compliant with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the ePrivacy Directive 2002/58/EC, and other applicable European and international data protection legislation.
1. Data Controller
The data controller responsible for your personal data is Velvet Palace / Emporo Services. For any data protection inquiries, you may contact our Data Protection Officer at: privacy@velvetpalace.club
2. What Data We Collect
We collect the following categories of personal data:
- Account data: email address, username, display name, and avatar/profile images you upload;
- Authentication data: hashed passwords, OAuth tokens (if signing in via Discord or other providers);
- Payment data: PayPal.me username (we do not store credit card numbers, CVVs, or bank account details directly — payment processing is handled by third-party processors);
- Content data: images, text, and other content you upload to the Platform;
- Usage data: IP address, browser type, operating system, pages visited, timestamps, and referring URLs;
- Cookie data: as described in our Cookie Policy.
3. Legal Basis for Processing (Article 6 GDPR)
We process your personal data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): processing necessary to provide our services, manage your account, and process transactions;
- Legitimate interest (Art. 6(1)(f)): analytics, fraud prevention, platform security, and service improvement;
- Consent (Art. 6(1)(a)): marketing communications (where applicable) and non-essential cookies;
- Legal obligation (Art. 6(1)(c)): compliance with tax, accounting, and law enforcement requirements.
4. How We Use Your Data
Your personal data is used to:
- Create and manage your account;
- Display your public profile page to visitors;
- Process payments and payouts;
- Send transactional emails (e.g., account confirmation, password resets);
- Analyse usage patterns to improve the Platform;
- Detect and prevent fraud, abuse, and security threats;
- Comply with legal obligations.
5. Data Sharing and Third Parties
We do not sell your personal data to any third party. We may share data with:
- Supabase: database and authentication hosting (servers located in the EU);
- PayPal: payment processing (subject to PayPal's own privacy policy);
- Vercel: application hosting and CDN;
- Law enforcement: when required by a valid legal process or to protect the safety of our users.
6. International Data Transfers
Where data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, including EU Standard Contractual Clauses (SCCs) as approved by the European Commission under Decision 2021/914, or adequacy decisions under Article 45 GDPR.
7. Data Retention
We retain your personal data for as long as your account is active. Upon account deletion, we will erase your personal data within 30 days, except where retention is required by law (e.g., tax records, which may be retained for up to 7 years). Usage logs and anonymised analytics data may be retained indefinitely.
8. Your Rights Under GDPR
As a data subject, you have the right to:
- Access (Art. 15): request a copy of the personal data we hold about you;
- Rectification (Art. 16): request correction of inaccurate data;
- Erasure (Art. 17): request deletion of your data ("right to be forgotten");
- Restriction (Art. 18): request limitation of processing in certain circumstances;
- Data Portability (Art. 20): receive your data in a structured, commonly-used, machine-readable format;
- Objection (Art. 21): object to processing based on legitimate interest;
- Withdraw consent (Art. 7(3)): withdraw previously given consent at any time.
To exercise any of these rights, contact us at privacy@velvetpalace.club. We will respond within 30 days as required by GDPR.
You also have the right to lodge a complaint with a supervisory authority. If you are in the EU, you may contact the Data Protection Authority in your country of residence.
9. Security Measures
We implement appropriate technical and organisational measures to protect your personal data, including: encrypted data transmission (TLS/HTTPS), hashed password storage (bcrypt), role-based access controls, regular security audits, and secure hosting infrastructure.
10. Children's Privacy
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a user is under 18, their account will be terminated and all associated data deleted immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the Platform. We encourage you to review this page periodically.
12. Contact
For questions or concerns regarding this Privacy Policy or your personal data, contact us at: privacy@velvetpalace.club