Privacy policy
We name every advertising click identifier we receive and tell you how to turn its storage off.
Velaxmora runs a small skincare and home-care catalogue at velaxmora.com, and this page sets out what we collect when you send an inquiry, chat with us, or arrive here from a paid Google, Microsoft or Meta ad, and what happens to that information afterward.
This policy took effect on 24 September 2026.
The date this page decides is when the version you are reading became the one that governs your visit.
Every version of this policy carries the date it took effect. The version now in force took effect on 24 September 2026 and applies to every inquiry, chat message and page view at velaxmora.com from that date. If you read this page on paper or in a saved copy, check velaxmora.com/privacy.html for the current version before relying on it.
Velaxmora, in Austin, Texas, is who this policy is written by.
This section identifies the business responsible for the site and the data it collects.
Velaxmora, trading at velaxmora.com, operates this catalogue site and is the controller of the personal data described below. Our postal address is 61 Market Street, Office 12, Austin, Texas 91496, United States. We can be reached at office@velaxmora.com or +1 (894) 555-9475 for any question about this policy or about a specific piece of data we hold.
Velaxmora is a catalogue business, not a clinic. We describe products so a household can decide whether to inquire; we do not collect health records, and we ask that you not send us any in a message.
Five categories of data pass through this site, and none of them is a payment card.
This is the full list of what the inquiry form, the chat widget, the server and the advertising links can each collect.
Inquiry form data. When you send a product inquiry through tejod52.php, we receive your name, phone number, email address, delivery address, the kind of inquiry you selected, your message, the specification you asked about (for instance, which jar or set), and your consent tick. Two hidden fields on that form, named company and website, are honeypots meant to catch automated spam; they are never shown to you and never carry your data.
Chat data. The support widget, through jeze703.php, keeps the text of your conversation with us and a token stored in your browser's local storage so the conversation can continue if you come back. If you give a name, phone or email when starting a chat, that is stored with the transcript.
Technical and log data. Our server automatically records your IP address, your browser's user-agent string, the page that referred you here, and the exact moment a form was rendered and the moment it was submitted. This happens for every visit, whether or not you send us anything.
Cookie and storage identifiers. Your consent choice is written to your browser under the key site_consent_v2. No other cookie or local storage value on this site persists a choice you have made; see our cookie policy for the full list of what each one does.
Advertising click identifiers. If you arrive by clicking a paid ad, the link you followed can carry a click identifier in its address — gclid from Google Ads, msclkid from Microsoft Advertising, or fbclid from Meta Ads. Where storage is allowed, that identifier is used to tell the advertising platform that a click led to a visit.
Each category of data does one job, and we do not repurpose it beyond that job.
This is what we actually do with the information listed above.
Inquiry form data is used to answer your question about a cream, oil, cleanser or set, to discuss a possible order, and to reach you if we need a detail to do either. Chat data is used to hold the conversation and to let you pick it back up later on the same device. Technical and log data is used to keep the site secure, to diagnose faults, and to understand roughly how the site is used in aggregate. Cookie and storage identifiers are used only to remember the consent choice you made. Advertising click identifiers are used to measure whether a paid ad led to a visit and, where you have allowed it, to help Google, Microsoft or Meta measure and refine that advertising.
Every purpose above rests on a specific legal basis, not a blanket one.
For visitors covered by the GDPR, this table states the basis for each use in plain terms.
| Data | Purpose | Basis |
|---|---|---|
| Inquiry form | Answering your question, discussing an order | Contract — taking steps toward an order you asked us to consider |
| Chat transcript | Holding and continuing a conversation | Consent, given when you tick the box and start the chat |
| Log and technical data | Security, fault-finding, aggregate usage | Legitimate interest in keeping the site working and safe |
| Consent storage key | Remembering your storage choice | Legitimate interest in not asking you twice |
| Advertising click identifiers | Ad measurement and personalisation | Consent, given through Consent Mode v2 when you allow storage |
Google Ads, Microsoft Advertising and Meta Ads currently send paid traffic to this site.
This section names the advertising platforms running today and the identifier each one attaches to a click.
Velaxmora runs paid campaigns through Google Ads, Microsoft Advertising and Meta Ads to bring visitors to this catalogue. Each platform can attach its own click identifier to the link you followed to get here: gclid from Google Ads, msclkid from Microsoft Advertising, and fbclid from Meta Ads. These identifiers let the platform that sent you here match your visit back to the ad you clicked, so it can report which ads are working.
None of these platforms has reviewed or approved velaxmora.com; running ads through them is not the same as their endorsement of this site or its products.
Consent Mode v2 keeps four advertising signals denied until you say otherwise.
This is exactly what changes on the page when you allow or decline storage.
This site runs Google's Consent Mode v2. Before you make a choice, and at any time you decline, four signals are held denied: ad_storage, ad_user_data, ad_personalization and analytics_storage. Denied means no advertising cookie is set, no advertising identifier is stored, and no analytics storage is written for that visit.
When you allow storage through the banner at the bottom of the page, those four signals are set to granted and stay that way for the period stated in our cookie policy, unless you change your choice. If you decline, or later withdraw a choice you made, all four signals are set back to denied immediately.
Four kinds of third party receive some of this data, each for a stated reason.
Here is who gets what, named one by one rather than as a general category.
Google Ireland Ltd / Google LLC operates Google Ads, which attaches gclid to a click and receives the Consent Mode v2 signals described above.
Microsoft Ireland Operations Ltd operates Microsoft Advertising, which attaches msclkid to a click. Microsoft's own handling of that data is described in the Microsoft privacy statement at privacy.microsoft.com.
Meta Platforms Ireland Ltd operates Meta Ads, which attaches fbclid to a click where a Velaxmora campaign is running there.
Our hosting provider serves this site and stores the enquiry database on our behalf, and our mail provider carries the notification email from a submitted form through to our inbox. Both act only on our instructions and do not use the data for their own purposes.
Some of this data leaves the country it was collected in, under a recognised safeguard.
This explains what makes a cross-border transfer lawful when one of our processors is outside your country.
Velaxmora is based in the United States, and our hosting and mail providers process data there. Google, Microsoft and Meta each operate in multiple countries, including the United States and Ireland. Where data collected from a visitor in the European Economic Area or the United Kingdom is transferred to the United States, that transfer relies on the standard contractual clauses adopted by the relevant platform or provider, or another safeguard recognised under the GDPR, and we expect any processor we use to maintain one.
Nothing here is kept indefinitely; each category has a stated limit.
These are the real periods we hold each kind of data before it is deleted.
- Inquiries and their email copies: 36 months from the last message.
- Chat transcripts: 18 months from the last message.
- Server and access logs: 60 days.
- The record of a consent choice: 12 months, after which we ask again.
Access to inquiry and chat records is limited to the people who answer them.
This is what protects the data once it reaches us.
Form and chat data travels to our server over an encrypted connection. It is stored behind access controls that limit it to the small team who read and reply to inquiries, and the honeypot fields on the inquiry form exist specifically to filter automated submissions before a person ever sees them. We do not store payment card numbers anywhere on this site, because no payment is taken here.
Visitors covered by the GDPR hold seven specific rights over this data.
If you reach this site from Europe, this is what the GDPR gives you and how each right works here.
Under the GDPR, if you are in the European Economic Area or the United Kingdom, you have the right to: access the personal data we hold about you; have inaccurate data corrected; have it erased where there is no reason for us to keep it; restrict how we use it while a dispute is resolved; receive a copy in a portable format; object to processing based on legitimate interest; and withdraw consent at any time for anything based on consent, including the advertising signals described above. Withdrawing consent does not affect anything we did before you withdrew it.
California and other US states give you a separate, parallel set of rights.
This is what US state privacy law, including the CCPA, entitles a resident to ask of us.
If you are a resident of California, the CCPA, as amended by the CPRA, gives you the right to know what personal information we have collected about you, to request its deletion, to correct it, and to opt out of the sale or sharing of personal information. Velaxmora does not sell personal information for money. We do allow advertising identifiers to be shared with Google Ads, Microsoft Advertising and Meta Ads when you allow storage, which some state laws treat as a form of sharing, and you can opt out of that sharing by declining or withdrawing consent in the banner on this site or through the Global Privacy Control described below. Residents of other US states with comparable privacy laws have equivalent rights, which we honour on the same basis.
A Global Privacy Control signal from your browser is treated as an opt-out automatically.
This is what happens if your browser or an extension sends that signal, without you having to ask again.
This site honours the Global Privacy Control signal. If your browser sends the Sec-GPC header, we treat it as a request to opt out of the sharing described above and hold the Consent Mode v2 signals denied for that visit, without showing you the banner again to ask.
This site is not built for children, and we do not knowingly collect their data.
This states plainly who this catalogue is not addressed to.
Velaxmora's catalogue and its inquiry form are addressed to adults making decisions about home skincare. We do not knowingly collect personal data from anyone under 16, and if we learn that a chat or inquiry has come from a child, we delete it.
You can complain to a regulator, not just to us, if you think we've got this wrong.
This is where to take a complaint we haven't resolved to your satisfaction.
If you are unhappy with how we have handled your data, we would rather hear from you first at office@velaxmora.com. You are also entitled to complain to your state Attorney General, and, if you are in California, to the California Privacy Protection Agency. If you are in the European Economic Area or the United Kingdom, you may complain to your local data protection authority, which has the power to investigate under the GDPR.
Any request about your data reaches a person within fourteen days.
This is how to exercise the rights listed above and what to expect once you do.
To access, correct, delete, or ask about any data we hold on you, write to office@velaxmora.com or post to Velaxmora, 61 Market Street, Office 12, Austin, Texas 91496, United States. You can also use our data request page, which routes the same request through a short form. We answer within 14 days of receiving a request we can verify is yours.
A change to this policy is dated and posted here, not announced quietly elsewhere.
This is how you will know if something above has changed since your last visit.
If we change what we collect, why, or who receives it, we update this page and change the effective date at the top. We do not remove the previous date without replacing it, so the version in force is always the one currently published at velaxmora.com/privacy.html.
A real person reads office@velaxmora.com, not a queue.
This is the direct route to us for anything in this policy.
Velaxmora, 61 Market Street, Office 12, Austin, Texas 91496, United States
See also our cookie policy and our terms of service, and read our accessibility statement if you have trouble reading any of this.
This policy covers velaxmora.com only. It does not cover any third-party site you reach by following a link from here, including the advertising platforms named above.