Privacy Policy

How Veap handles your data: no accounts, no ads, no tracking cookies. What we collect, who processes it, how long we keep it, and how to reach us about it.

Last updated September 19, 2026

Who we are

Veap is an open-source modular application framework and plugin registry operated by the Veap Core Team. This policy covers https://veap.pl, the plugin registry, documentation, and sponsorship features linked from it.

The short version

You do not need an account to browse the documentation or install plugins. We do not run third-party advertising, we do not use invasive tracking cookies, and we do not sell or share your data with anyone for marketing purposes.

The only personal data we process is what sponsors provide in order to be listed, and whatever you choose to send us directly via email or GitHub.

What we collect

  • Anonymous usage analytics: aggregated page views, referrer, country, browser and device type, collected through Databuddy. The data is privacy-preserving and not used to identify individuals.
  • Sponsorship billing details: name, company, billing address, email address and tax identifiers, collected and stored securely by our payment processor, not by us. We receive only your name/company, email, tier and subscription status.
  • Sponsor brand assets: the logo, company name and destination link you provide for showcase placement.
  • Direct communications: information you include when contacting us by email or social channels.
  • Public repository activity: issues, discussions, and pull requests opened on GitHub are public by design and governed by GitHub Terms of Service.

What we do not collect

We do not run cross-site tracking, behavioral profiling, or advertising scripts. We never see or store your payment card details.

Installing a plugin or template via bun, npm, or the Veap CLI fetches public packages directly. Nothing about your local application, proprietary source code, or internal machine environment is transmitted to us.

Your theme preferences (dark/light mode) are stored locally in your browser and are never transmitted to our servers.

Payments

Payments are processed by Dodo Payments (https://dodopayments.com), acting as the merchant of record. Dodo Payments collects payment details directly, calculates applicable taxes, and issues invoices. Their handling of your data is governed by their privacy policy at https://dodopayments.com/legal/privacy-policy.

Service providers

We rely on a minimal set of trusted infrastructure providers to operate the platform:

  • Dodo Payments: payment processing, subscription management and invoicing.
  • Databuddy: privacy-friendly, aggregated website analytics.
  • GitHub: hosts our open-source codebase, plugin repositories, issue tracker, and public release stars.
  • Hosting provider: serves the website with short-lived security access logs.

How we use your information

We use contact and billing details to deliver sponsorships, issue receipts, and communicate technical updates. We use aggregated usage metrics to understand which plugins developers use most and guide framework development. We never engage in automated decision-making or profiling.

Where your data is processed

We operate primarily from the European Union (Poland), and our service providers process data in the EU and the United States under standard contractual clauses and appropriate GDPR safeguards.

How long we keep it

Invoices and accounting records are retained as required by tax regulations, typically up to 7 years. Email support threads are retained while useful for resolution and then pruned. Aggregated analytics contain no personal identifiers and are stored indefinitely.

Your rights

Under GDPR and applicable data protection regulations, you have the right to request access to, rectification of, or deletion of your personal data. Contact us at contact@veap.pl and we will respond within 2 business days, and in any event within 30 days.

If you are located in the European Union or UK and believe your rights have not been respected, you have the right to lodge a complaint with your local supervisory authority.

Security

All traffic is encrypted in transit via modern HTTPS/TLS. Payment credentials are handled exclusively on PCI-DSS certified infrastructure.

Children

The site and framework are intended for developers and professionals. We do not knowingly collect personal data from anyone under 16.

Changes to this policy

We may update this privacy policy from time to time. The date at the top indicates when it was last revised. Substantial updates affecting active sponsors will be communicated via email.

Contact

For inquiries regarding privacy or your personal data: contact@veap.pl.

veap
Preparing0%