Privacy Policy
Last Updated: August 2026
This Privacy Policy describes how VEIGO (“we,” “us,” or “our”) collects, uses, discloses, and protects your personal data when you use our website at shopveigo.com and any related services (collectively, the “Services”). We are committed to complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the EU Digital Services Act (DSA).
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use our Services.
1. Data Controller
The data controller responsible for your personal data is VEIGO (ShopVeigo AI Technology). For any privacy-related inquiries, please contact us at support@shopveigo.com.
2. Information We Collect
We collect the following categories of information:
2.1 Account Information
When you register for an account, we collect your name, email address, and password (stored in hashed form). If you use third-party authentication (e.g., Google OAuth), we receive basic profile information from that provider.
2.2 Listing & Content Data
Information you provide when creating listings, including rental properties, job postings, gig services, and bid/tender submissions. This may include contact details, descriptions, images, and pricing information that you choose to publish.
2.3 Usage & Technical Data
We automatically collect information about your device and how you use our Services, including IP address, browser type, operating system, referring URLs, pages viewed, time spent, click data, and other standard web analytics data.
2.4 Cookie & Tracking Data
We use cookies and similar tracking technologies to collect information about your browsing activities. For detailed information, please refer to our Cookie Notice below or adjust your preferences via the “Cookie Settings” link in our footer.
2.5 Payment Information
Payment transactions are processed through third-party payment processors. We do not store your full credit card numbers or banking details on our servers. We may retain transaction records (amount, date, and reference numbers) for accounting purposes.
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process your personal data based on the following legal grounds:
- Contractual necessity: Processing required to perform our contract with you (e.g., providing account services, processing listings).
- Legitimate interests: Processing based on our legitimate business interests, such as improving our Services, preventing fraud, and ensuring network security, provided these interests are not overridden by your rights.
- Consent: Where you have given explicit consent for specific processing activities (e.g., marketing cookies), you may withdraw consent at any time.
- Legal obligation: Processing necessary to comply with applicable laws, regulations, or legal proceedings.
4. How We Use Your Information
- To provide, operate, and maintain our Services
- To process registrations, listings, and transactions
- To communicate with you regarding your account, support requests, or service updates
- To detect, prevent, and address fraud, abuse, and technical issues
- To analyze usage patterns and improve user experience
- To comply with legal obligations and enforce our Terms of Service
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Account data: Retained for the duration of your account plus 30 days after deletion request.
- Listing data: Retained while active; archived for up to 12 months after removal.
- Analytics data: Retained for up to 26 months.
- Transaction records: Retained for 7 years to comply with tax and accounting obligations.
- Communication records: Retained for up to 3 years after last contact.
After the applicable retention period, data is securely deleted or anonymized.
6. Third-Party Services
We engage the following categories of third-party service providers:
- Analytics: Google Analytics to analyze website usage patterns. Google may transfer and store data on servers outside the EEA. We have implemented Standard Contractual Clauses where required.
- Payment processors: Third-party payment services to handle financial transactions securely.
- Infrastructure: Cloud hosting and CDN providers for service delivery.
- Authentication: OAuth providers for secure sign-in.
Each third-party provider operates under their own privacy policy. We require all processors to implement appropriate technical and organizational security measures.
7. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including countries that may not have an adequacy decision from the European Commission. Where applicable, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for such transfers.
8. Your Rights
8.1 GDPR Rights (EEA Users)
If you are located in the EEA, you have the following rights:
- Right of access: Obtain a copy of your personal data we hold.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): Request deletion of your personal data under certain conditions.
- Right to restriction: Request that we limit the processing of your data.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent.
8.2 CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the CCPA:
- Right to know: Request disclosure of the categories and specific pieces of personal information collected, the sources, purposes, and third parties with whom it is shared.
- Right to delete: Request deletion of your personal information, subject to certain exceptions.
- Right to opt-out: We do not sell your personal information. If this changes, you will have the right to opt-out of such sales.
- Right to non-discrimination: You will not receive discriminatory treatment for exercising your CCPA rights.
To exercise any of these rights, please contact us at support@shopveigo.com. We will respond within 30 days (or 45 days for GDPR complex requests, with notice).
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS 1.3), encrypted storage, access controls, regular security assessments, and employee training. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
10. Children's Privacy
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately, and we will take steps to delete such data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via a prominent notice on our website at least 30 days before taking effect. Your continued use of the Services after the effective date constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have complaints regarding our data practices, please contact us: