VEIL GROUP PTY LTD
Privacy policy
Last updated: 4 October 2026
This policy explains how Veil Group Pty Ltd handles information when you visit the WORO website or use the WORO service.
1. Information we handle
- Account information: your email address, account identifier, sign-in state, credit balance, and write-token labels and status.
- Exchange metadata: the account that created an exchange, its status, and creation, expiry, retrieval, and revocation times. This metadata does not contain the value or raw redeem token.
- Write tokens: WORO stores a cryptographic hash of each write token, not the raw token. A raw write token is shown only when you create it.
- Submitted data: the request body you send to WORO. WORO deletes the stored value on read; unredeemed data expires after 14 days. Do not send content that is illegal to transmit. Encrypt content before sending it if you do not want WORO to read it while processing your request.
- Payment information: Stripe processes your payment details. WORO receives payment and checkout references, the amount and currency, payment status, and the number of credits to grant. WORO does not receive your full card number or card security code.
- Service and security logs: request time, API request identifier, operation, outcome, duration, source IP address, and user agent. Logs do not include secret bodies, raw write tokens, or redeem tokens.
- Support messages: the name, reply email address, request type, subject, and message you submit. For submissions from a signed-in account, we also store the account identifier and account email. The message is stored in a private S3 object; the support notification email contains only its identifier and storage pointer, not the message.
2. How we use information
We use information to create and manage accounts, authenticate users, provide one-time data delivery, process payments and credit balances, respond to support requests, protect the service from abuse, investigate technical issues, and meet legal or accounting obligations.
The WORO website uses temporary browser session storage for sign-in and payment return flows. We do not currently use the website for advertising or analytics tracking.
3. Service providers and storage
WORO uses Amazon Web Services for account authentication, application hosting, storage, and logs. Support notification emails are sent through an SMTP relay provider, which processes email delivery metadata and the notification pointer. WORO's core AWS services are deployed in the Asia Pacific (Sydney) region. Stripe processes payments and may handle information in locations outside Australia under its own privacy terms.
Stored values are encrypted at rest using AWS server-side encryption. This protects stored objects at rest; it does not prevent WORO from reading unencrypted data while handling a request. Submitted content is not sent to Stripe for payment processing.
4. Retention and deletion
WORO deletes stored data on read; unredeemed data expires after 14 days. WORO uses a conditional claim so overlapping requests cannot both retrieve the same stored value. Exchange status metadata linked to your account is retained until 90 days after the value's expiry, then DynamoDB removes it under its TTL policy. A redeemed status records a WORO request; it does not identify the requester or confirm they received the response.
Audit logs are retained in an access-controlled S3 archive for up to seven years under the current configuration. These logs include source IP address and user agent. Support form submissions are stored in a private S3 prefix and automatically expire after one year. We retain account and payment records while needed to operate the service, resolve disputes, and meet applicable record-keeping obligations.
To request account closure or ask about access, correction, or deletion of personal information, contact support@veilgroup.au. Some information may need to be retained where required by law or for legitimate transaction and security records.
5. Security and your choices
We use access controls and encryption to protect information, but no internet service can guarantee absolute security. Keep write tokens and redeem tokens private. Do not include them in support requests.
You can choose to encrypt secret content before sending it. If you do, keep the decryption key separate from the redeem token.
6. Contact and updates
For privacy questions or complaints, contact Veil Group Pty Ltd at support@veilgroup.au. We may update this policy as WORO or our information handling changes. The date above shows when it was last updated.