Privacy Policy
We collect the minimum needed to run a B2B data service: your account, your sessions, your messages. No tracking, no ads, no data sales.
Last updated: September 9, 2026
Who we are
Veinwork is a B2B data service operated from the Philippines. The data controller for personal data described in this policy is [PLACEHOLDER — legal entity name and registered address]. If you have any question about this policy or your data, contact [email protected].
What we collect
We collect very little, and only what the service needs:
- Account data — your name, business email address, and a hashed password (we never store passwords in plain text).
- Session data — server-side session records and the session cookie that keeps you signed in.
- Contact-form submissions — whatever you write to us, plus the email address you provide so we can reply.
- Security and diagnostic data — technical request information, rate-limit identifiers, and error reports used to protect and maintain the service.
We use no tracking or advertising cookies — the only cookies we set are the session cookies required for signing in. There is no third-party analytics script on this site.
Why we use it
We use this data for three purposes only:
- Providing the service — operating your account, the dashboard, and data exports (performance of our contract with you).
- Support — answering your messages and helping you use the product.
- Security — protecting accounts, rate limiting, and investigating abuse (our legitimate interest in keeping the service safe).
We do not sell personal data, and we do not use it for advertising.
Processors & subprocessors
The service uses the following providers for the purposes listed. Optional features use their provider only when enabled:
- Neon — Database hosting — stores account and application data.
- Render — Application hosting — the deployment platform for the website and dashboard.
- Vercel Blob — Private storage for large data exports, when enabled.
- Namecheap Private Email — Business and transactional email — inquiries, invitations, password resets, and notices.
- Sentry — Technical error diagnostics, when enabled.
- Wise — Payments — we invoice directly and receive bank transfers through Wise; we do not take card payments and never see card details.
International transfers
Our providers operate infrastructure in the United States and the European Union, and we operate from the Philippines — so personal data may be transferred outside the country where you live. Where data of EU/EEA or UK residents leaves those regions, transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an applicable adequacy decision.
Retention
We keep account data for as long as your account exists, and delete or anonymize it within a reasonable period after the account is closed. Session records expire and are removed automatically. Contact-form messages are kept only as long as needed to handle the conversation and any follow-up. We may retain limited records longer where the law requires it (for example, invoices and payment records kept for tax and accounting purposes).
Your rights
If you are in the EU/EEA or UK (and in many other places), you have the right to:
- Access the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data (“right to be forgotten”), subject to legal retention duties.
- Receive a portable copy of data you provided to us.
- Object to processing based on legitimate interest.
- Complain to a supervisory authority in your country if you believe we have mishandled your data.
To exercise any of these rights, email [email protected]. We respond within one month.
About the product data
Our web collection is limited to publicly available sources and focuses on product and non-personal business information, such as prices, availability, and aggregate ratings. We do not offer personal-profile harvesting or sensitive personal datasets. Public pages can still contain personal information; our collection policy requires excluding unnecessary identifiers and reviewing free text before delivery. Public visibility does not remove privacy obligations.
If you believe a delivered record contains personal information about you, contact [email protected] with the source URL and enough detail to locate the record. We will review the report and take appropriate action, including correction, restriction, or removal where required. See our Responsible data collection policy.
Changes to this policy
If we change this policy in a meaningful way — new data categories, new processors, new purposes — we will update this page and notify account holders by email or in the dashboard before the change takes effect. The date below always reflects the current version.