Who is responsible for your data
The data controller is WEST SALE GROUP LLC (company number 43354484), 3A Kolberha St., Lviv 79013, Ukraine. We own the Velano trade mark and this website.
For anything related to your data, write to [email protected] — this is our single channel for such requests, and we answer all of them.
What we don't do
The quickest way to understand this site is to see what it does not have. It is not an online shop: you cannot buy or pay here, so we never see payment data at all.
- we take no payments and never see card numbers — you buy from our partners;
- there is no sign-up, no customer account and no passwords for shoppers;
- we set no cookies of our own for shoppers (the site's cookies are purely technical and only for shop owners signing in to the partner account);
- we do not build profiles and make no automated decisions about you;
- we do not sell, rent or trade your data;
- we do not collect your location — the map on "Where to buy" shows our partners, not you;
- we do not collect special categories of data (health, religion, political views and the like).
What data reaches us and why
Data reaches us only when you send something yourself — plus automatically: in technical logs, without which the site cannot run or defend itself, and in a visit counter that uses no cookies.
| When | What exactly | Why | Legal basis | How long |
|---|---|---|---|---|
| Newsletter sign-up | Email, site language, time, IP address, the text and version of your consent | To send news and offers; to prove consent was given | Your consent | Until you withdraw it |
| "Become a partner" application | Shop name, city, address, phone numbers, email, website, logo (if attached) | To process the application and contact you | Pre-contractual steps at your request | 3 years after last contact |
| Suggested correction to a shop listing | Your name and contact, the correction, IP address | To check and fix the map data | Our legitimate interest — accuracy of the map | 1 year |
| Partner account (for shop owners) | Email, name and phone of the contact person; the password — only as a cryptographic hash; if you sign in with Google — the email, name and account identifier that Google passes to us (we never see your Google password); time of last sign-in; a log of the changes you made to your shop's details | So that a shop owner can keep their own details on the map up to date, and we can see who changed what | Our contract with the partner and our legitimate interest — accuracy of the map | The account — while you use it or until you ask us to delete it; the change log — 1 year |
| Factory enquiry form (/factory) | Company, contact person, email, phone, WeChat, message, uploaded files | To process a B2B enquiry | Pre-contractual steps at your request | 2 years |
| Email, phone call or messenger | Whatever you write or say yourself | To reply to you | Your request | 3 years after last contact |
| Automatic error log | Page address, error text, browser, IP address | To spot a broken page before you do | Our legitimate interest — a working site | 30 days |
| Server and security logs | IP address, time, page address, browser | Protection against attacks and abuse, diagnostics | Our legitimate interest — security | 30 days |
| Cloudflare Web Analytics visit counter | Page address, the site you came from, country, device type, browser and operating system, page load speed. No cookies, no name or contact details | To know how many people visit the site and whether pages open quickly | Our legitimate interest — a working site | Up to 6 months |
We don't ask for more than we need: our forms contain no fields we couldn't reply without. If you send more than necessary, we delete the excess.
Who else sees this data
We pass data to nobody "for marketing". But the site physically runs on someone else's infrastructure, and these companies process data on our behalf:
| Who | What they do | Where |
|---|---|---|
| Hetzner Online GmbH | The server that runs the site and stores applications | Germany (EU) |
| Cloudflare, Inc. | Protection against attacks and site acceleration — sees visitor IP addresses; the cookie-free Web Analytics visit counter | Network with nodes in the EU and the US |
| Google LLC | Visit analytics, partner map, YouTube video player; sign-in to the partner account with Google — if the shop owner chose it | United States and other countries |
| Telegram | Instant notification to our team about a new enquiry | Outside the EU |
We may also disclose data where the law requires it — for example, on request from a court or law-enforcement body.
Transfers outside Ukraine
The site's server is in Germany — a European Economic Area state, which under Article 29(3) of the Ukrainian Personal Data Protection Act is deemed to provide an adequate level of protection. No separate consent from you is required for this.
Google and Telegram also operate outside the EU. That is exactly why Google Analytics on our site does not start until you press "Accept": without your consent, that data does not go there. Sign-in with Google in the partner account happens only when a shop owner presses the Google sign-in button themselves.
Cookies and analytics
Our site sets no cookies of its own for shoppers. We store only a few technical values in your browser (colour theme, comparison list, your analytics choice) — they never reach our server and do not identify you. The one exception is the partner account: the site gives a shop owner a technical session cookie, without which sign-in cannot work, and one more for a few minutes during sign-in with Google.
Google Analytics only starts after you consent. The full list is on the Cookies page. You can change your choice at any time via "Cookie settings" at the bottom of every page.
In addition, Cloudflare — the service whose network the site is served through — may add its own visit counter, Cloudflare Web Analytics, to the pages. It counts page views and measures how quickly pages load. The counter sets no cookies and stores nothing in your browser, and under Cloudflare's terms it does not recognise individual visitors or build profiles of them — which is why it runs regardless of your choice in the banner. If you object to this counting, common ad blockers stop it.
Partner data from public sources
On the "Where to buy" page we show shops that sell Velano. Some of those listings were not built from applications but from public sources: our supply contracts, the shops' own public pages and Google Maps. They may contain a name, address, phone number and website — and for sole traders that counts as personal data.
The basis is our legitimate interest in showing buyers where to buy, and the shops' own interest in receiving customers. We publish only what is already publicly available.
If you own a shop and want the listing corrected or removed from the map, write to [email protected]. We will remove or correct it without asking you for reasons.
Your rights
Article 8 of the Ukrainian Personal Data Protection Act — and, where it applies, the GDPR — gives you rights you can use at any time, free of charge:
- find out whether we hold data about you, what exactly and where we got it;
- get a copy of that data;
- correct inaccurate data;
- delete data or withdraw consent — for example, unsubscribe from the newsletter;
- object to processing where we rely on our legitimate interest;
- complain if you believe we got something wrong.
To use any of these rights, write to [email protected]. We review a request within 10 working days and fulfil it within 30 calendar days (Article 16(8) of the Act).
So that nobody else can obtain your data in your name, we reply to the same address the request came from, or cross-check it against your original application.
If our answer does not satisfy you, you may turn to the Ukrainian Parliament Commissioner for Human Rights or to a court. If you are in the European Union, you may also complain to the supervisory authority of your country.
How long we keep data
The periods are in the table above. When a period ends, the data is deleted automatically. Server backups are kept for up to 30 days, so deleted data may remain in them for a while before disappearing with the next rotation.
How we protect data
The site works only over an encrypted HTTPS connection. Applications are accessible to a handful of staff through individual accounts with different permission levels; passwords are stored as cryptographic hashes. Attack protection sits in front of the site, and the server accepts connections only through it. Backups are taken regularly.
No system is absolutely secure, so we do not promise perfect safety — but we do what is appropriate for a site of this size.
Children
This site is intended for adults — parents choosing products for their children. We deliberately do not collect children's data and offer no services to children.
Children may appear in our photos and videos. We use such material only with the consent of a parent or legal guardian. If you recognise your child in our material and did not give consent, write to us and we will remove it.
Changes to this policy
We update this page whenever the way we handle data changes — for instance when a new service is added. The update date is always shown at the top. If changes are significant, we will ask for your consent again.
This page is an informational document. If the language versions differ, the Ukrainian version prevails.


