Privacy Policy
Last Updated: April 3, 2026
1. Introduction
Veyli (“we”, “us”, or “our”) operates the Veyli digital signage platform, players and dashboard at veyli.cloud (the “Service”). This Privacy Policy explains what data we collect, why we collect it, and how we protect it. By using the Service you agree to this policy.
2. Information We Collect
Account & Identity
- Email address (required for login and notifications)
- Name or display name (optional; sourced from your OAuth provider if used)
- OAuth provider identifier (Google or GitHub) when you sign in via OAuth
- Password hash (bcrypt) when you use email/password sign-in — your plain-text password is never stored
Screens & Players
- Screen name, location, timezone and group you assign
- Player model, operating system, player version, resolution and local IP address
- Heartbeat timestamps, online/offline status and health metrics (CPU, storage, temperature)
- Screenshots, only when you request one from the dashboard
Content & Proof of Play
- Media you upload (images, videos, documents, web links) and their metadata
- Playlists, layouts and schedules you create
- Playback logs: which item played on which screen, when and for how long
- We do not use your content for advertising or model training
Billing
- Subscription plan and status, sourced from Stripe
- Payment event history (succeeded/failed charges, amounts, dates) — card numbers are never stored by us
- Stripe customer ID and subscription ID
Audit & Security Logs
- Login events (success and failure), IP address, timestamp
- Content publishes, schedule changes, screen pairings, remote commands and member invite actions
- Retained in a rolling buffer of the last 2,000 events per workspace
3. Third-Party Services
We use the following third-party processors. Each has its own privacy policy.
- Stripe — payment processing. Stripe stores your payment method; we only receive a customer ID and payment status.
- Google OAuth 2.0 — optional sign-in. We receive your email and Google account ID; we do not access Drive, Gmail, or any other Google data.
- GitHub OAuth — optional sign-in. We receive your primary verified email and GitHub ID; we do not access your repositories.
- Resend — transactional email. Only your email address and invite details are transmitted.
4. How We Use Your Information
- Authenticate users and screens connecting to your workspace
- Deliver your scheduled content to the right screens at the right time
- Enforce plan limits (screen count, storage) based on your subscription
- Show fleet status and proof-of-play reports in your dashboard
- Send transactional emails (invites, payment receipts) — no marketing without consent
- Detect and prevent abuse, unauthorized access, and service disruptions
5. Data Retention
| Data Type | Free | Starter / Pro | Enterprise |
|---|---|---|---|
| Proof-of-play logs | 30 days | 13 months | Configurable |
| Billing event history | Indefinitely (legal requirement) | ||
| Account, screen & media data | Until account deletion | ||
| Audit logs | Last 2,000 events (rolling) | ||
6. Data Security
- All data is transmitted over TLS 1.2+, and media is served via short-lived signed URLs
- Passwords are hashed with bcrypt before storage
- Each player has its own revocable credential; unpairing a screen wipes its cached content
- Database access is restricted to internal infrastructure; no public database ports
- Staff access to customer content is restricted and logged
7. Information Sharing
We do not sell, rent, or trade your personal information. We may share data only in these circumstances:
- Service providers: Stripe, Resend, and cloud infrastructure providers under data processing agreements
- Legal obligation: If required by law, court order, or regulatory authority
- Business transfer: In connection with a merger or acquisition, with advance notice to users
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data (except data we are legally required to retain)
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
To exercise these rights, email us at [email protected]. We will respond within 30 days.
9. Cookies
The dashboard uses a single session cookie (set by NextAuth.js) to maintain your authenticated session. We do not use advertising cookies, cross-site tracking, or analytics cookies.
10. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the “Last Updated” date and, for material changes, notify you by email or a notice on the dashboard. Continued use of the Service after changes constitutes acceptance of the revised policy.
11. Contact
For privacy questions or data requests, contact us at [email protected].