Account Deletion Policy
This Deletion Policy explains how Velocity handles account deletion requests, what data is removed, what data may remain, and the retention periods applicable to retained information.
1. Right to Delete
You have the right to request the deletion of your Velocity account and associated personal data. You may submit a deletion request by contacting Velocity Support or using the account-deletion functionality provided in the application, where available.
Upon receiving a valid deletion request, Velocity will process the request in accordance with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable regulations.
2. What Happens When You Delete Your Account
When you request account deletion, Velocity will:
- Deactivate and remove your active account credentials and login access
- Delete personal identification data associated with your account
- Remove workspaces, projects, and related operational data
- Terminate active subscriptions and billing arrangements
- Revoke API keys, OAuth tokens, and other authentication credentials
- Remove your profile information from the Velocity application
- Process deletion of data stored in primary databases and active storage systems
Account deletion is permanent and irreversible for the data that Velocity is able to delete. You should carefully consider the consequences before submitting a deletion request.
3. Data That May Remain After Deletion
While Velocity will delete your personal data as part of the account deletion process, certain information may remain temporarily or may need to be retained for financial, security, fraud-prevention, auditing, or legal purposes. The following categories describe data that may remain:
Security Logs & Authentication Audit Trail — Retained for 120 Days
Security and authentication audit logs (including sign-in history, session lifecycle events, credential updates, IP addresses, browser/platform metadata, and approximate locations) are retained for 120 days before being automatically deleted by our scheduled background cleanup workers.
When you delete your account, security logs are preserved for the remainder of their 120-day retention window. This retention is strictly required to protect against account takeovers, enable forensic investigation of security breaches, and defend against fraud.
Detailed Ephemeral Session Telemetry — Purged in 24 Hours
Deep diagnostic network packets, transient webhook payloads, and ephemeral session telemetry traces are automatically and permanently purged within 24 hours.
Because transient network telemetry is deleted after 24 hours, users who observe unrecognized or suspicious activity must report the incident to Velocity Support within 24 hours of the event to enable detailed log investigation.
Operational Activity Logs — Up to 90 Days
Operational activity logs, container lifecycle events, and resource utilization records remain for up to 90 days before being automatically deleted by our scheduled activity log cleanup workers. These logs are strictly utilized for system integrity, debugging, and investigating potential infrastructure incidents.
Notification History — Up to 15 Days
Some notification records may remain in our systems for up to 15 additional days before permanent deletion. This includes transactional emails, security alerts, and other communications that were sent to or received on behalf of the deleted account.
Cached Data — Up to 7 Days
Due to caching, backups, replication, or asynchronous cleanup processes, a limited amount of data may temporarily remain in caches or secondary systems. We expect such cached copies to be removed within up to 7 days. This includes data stored in Upstash Redis caches, CDN edge caches, and any other distributed caching layers.
Public Repository Share Visitor IP Hashes
When you visit or interact with a public repository share link, an anonymized cryptographic SHA-256 hash of the visitor's IP address (combined with user-agent headers) is stored to prevent duplicate view count increments and maintain accurate analytics.
This visitor hash is persisted in the database and is only deleted when the repository owner permanently deletes the shared repository link. The repository owner can only view the aggregated numerical view count and can never access, export, or view the visitor IP hashes or raw IP addresses.
Telegram Information Associated with a Claimed Free Bonus
If you claimed a free bonus using a Telegram account, your Telegram user ID and Telegram username may be retained after account deletion. This information is retained to prevent repeated abuse of the one-time bonus and to maintain the integrity of our promotional system.
Arcjet Security Data
Velocity uses Arcjet for certain security and abuse-prevention functions. Depending on the Arcjet service and plan configuration, Arcjet may retain security-related records independently of Velocity's deletion process. Arcjet will retain data for no longer than 15 Days.
Arcjet's retention periods are governed by Arcjet's own privacy policy and service terms. For more information, please refer to Arcjet's published documentation.
Financial Records & Payment Security Raw IPs — Permanent
Financial transactions, wallet transactions, payment orders, and related accounting records—including raw IP addresses captured at the time of payment for Razorpay orders and bonus claims—are permanently stored in the database for payment security, anti-fraud compliance, chargeback defense, and statutory accounting obligations.
These payment security records and raw IP addresses are persisted permanently and will never be deleted, even following account deletion, in accordance with applicable tax regulations, anti-money laundering laws, and financial compliance mandates.
Composio Integration Logs & Telemetry
If you connected third-party toolkits or executed integration skills via Composio, connection metadata, execution telemetry, and service logs may persist on Composio's infrastructure according to Composio's own data retention and privacy policies. While Velocity initiates the deletion and disconnection of user integrations upon account deletion, third-party logs retained by Composio are subject to their independent governance, terms, and retention periods.
Usage, Analytics, and Infrastructure Metrics
Historical usage, billing, resource-consumption, analytics, and infrastructure metrics may be retained indefinitely or until they are removed as part of Velocity's applicable retention and system-lifecycle policies. These records may be retained in a form that is necessary to maintain historical billing, usage, operational, security, and financial records.
Such data is typically aggregated and anonymized where possible, and is used for service improvement, capacity planning, and operational analysis.
4. Legal Basis for Retaining Data
Velocity retains certain data after account deletion based on the following legal bases:
- Legal obligation — We are required by law to retain certain financial, tax, and accounting records for specified periods
- Legitimate interest — Retaining security logs and audit trails is necessary for fraud prevention, incident investigation, and system security
- Contractual obligation — Financial and billing records may be retained to fulfill contractual obligations and resolve disputes
- Regulatory compliance — Certain data must be retained to comply with financial regulations, anti-money laundering laws, and industry standards
- Protection of rights — Retaining security-related data helps protect Velocity and its users from fraud, abuse, and security threats
5. Third-Party Data Processors
Velocity works with various third-party service providers who may process and retain data independently. After account deletion, the following categories of third-party providers may retain information according to their own policies:
- Payment processors (e.g., Razorpay) — for financial transaction records and compliance
- Integration and tool orchestrators (e.g., Composio) — for third-party connector execution logs and analytics according to their respective privacy terms
- Security services (e.g., Arcjet) — for security logs and abuse-prevention data according to their plan-specific retention periods
- Email providers (e.g., Resend) — for transactional email records as required for delivery and compliance
- Database and infrastructure providers (e.g., NeonDB, Azure, Prisma, Aiven) — for backup and replication data subject to their retention policies
- Caching providers (e.g., Upstash Redis) — for cached data subject to cache expiration and cleanup cycles
- CDN and hosting providers (e.g., Vercel, Cloudflare) — for edge-cached content subject to cache invalidation timelines
- Webhook providers (e.g., Svix) — for event delivery logs according to their service terms
Velocity will make commercially reasonable efforts to notify third-party processors of deletion requests where required by law, but the actual deletion timelines may vary based on each provider's policies and technical capabilities.
6. Data Security and Safeguards
Data retained after account deletion is subject to the same security safeguards as data processed during active account usage. Velocity implements appropriate technical and organizational measures to protect retained data, including:
- Encryption of data at rest and in transit
- Access controls and role-based permissions
- Secrets management and credential protection
- Logging and monitoring of access to retained data
- Regular security audits and vulnerability assessments
- Secure deletion procedures when retention periods expire
7. Data Retention Schedule
The following table summarizes the retention periods for various categories of data after account deletion:
| Data Category | Retention Period | Purpose |
|---|---|---|
| Account Profile & Workspaces | Immediate | Permanent destruction or anonymization |
| Payment Records & Security Raw IPs | Permanent (Never Deleted) | Payment security, anti-fraud compliance, tax, and accounting mandates |
| Activity Logs & Audit History (with Raw IPs) | 90 Days | Security auditing and incident investigation; auto-deleted after 90 days |
| Shared Repository Visitor IP Hashes | Until Share Link Deletion | Duplicate view prevention; owners only see count, never IP hashes |
| Third-Party Integration Logs (Composio) | Governed by Provider Policy | External integration execution records and telemetry |
| Aggregated Performance Metrics | Indefinite (Anonymized) | Infrastructure capacity planning and service optimization |
8. User Rights & Exercising Your Data Requests
Depending on your jurisdiction, you may have statutory rights regarding your data, including:
- Right to erasure (the right to be forgotten)
- Right of access and export of your account data prior to deletion
- Right to rectification of inaccurate personal records
- Right to restriction of processing during verification of disputes
- Right to lodge a complaint with a supervisory authority
9. Contact and Grievance Officer
If you have any questions regarding this Deletion Policy or wish to exercise your rights, please reach out to our privacy officer:
Saksham Goel
New Delhi, India
Privacy Email: support@fairarena.raiseaticket.com
Support: support@fairarena.raiseaticket.com