00056-00006-00004 · Effective 2026-08-03Terms of Service
These Terms are a binding agreement between you and Vivbase LLC, a Wyoming limited liability company ("VelarumPay," "we," "us," or "our"). The Services are offered from the United States. By accessing velarumai.com or using the VelarumPay App, Platform API, Merchant Portal, SDKs, connectors, reference applications, or other official testnet services (the "Services"), you accept these Terms and the incorporated policies. If you do not agree, do not use the Services.
1. Eligibility and authority
You must be at least 18 and the age of legal majority where you live and able to contract. If you act for an organization, you represent that you can bind it. A person prohibited by sanctions, export controls, or other applicable law may not use the Services.
2. Official testnet Service
- The official environment supports only capabilities expressly labelled for Stellar testnet. Testnet tokens have no cash, fiat, or redeemable value and are not deposits, electronic money, or investments.
- The Services may create, deliver, display, and synchronize Payment Requests, Transaction Context, connection state, and testnet transaction status. Current App, API, and interface labels control actual availability.
- A schema, example, document, or roadmap is not a promise of availability. We may change, suspend, reset, or discontinue a testnet for security, maintenance, legal, or product reasons.
- VelarumPay currently charges no Service fee. A displayed testnet network fee has no real monetary value. Any future charge must be disclosed before it applies under separately published pricing terms.
3. Non-custodial boundary
- Recovery phrases, private keys, and signing material remain on your device. We do not request, receive, store, recover, or use them.
- Agents, merchants, apps, and connectors may request actions or read only expressly authorized information. A connection, token, or API key does not grant signing authority.
- You must review network, asset, amount, recipient, memo, fee, and context in the wallet and decide locally whether to sign. Support, display copy, and metadata do not override transaction facts.
- We generally cannot reverse, freeze, or recover an asset sent on the wrong network or mainnet, a lost key, a fraudulent approval, or a malicious third-party action.
4. Accounts and credentials
Provide accurate information and safeguard email access, device tokens, API keys, connector secrets, sessions, and credentials. Do not share, sell, or transfer an account. Revoke and rotate suspected credentials and notify security@velarumai.com.
5. Acceptable use
You must follow the Acceptable Use Policy below. We may reject requests, revoke connections, suspend accounts, preserve evidence, and respond to lawful demands. We cannot take control of your non-custodial wallet or a public blockchain.
6. Third parties and open networks
Mobile platforms, Firebase Cloud Messaging, Cloudflare, hosting and email infrastructure, Stellar testnet, Horizon, wallets, merchants, agents, and the internet are independent dependencies. Their terms may apply. Interoperability is not endorsement, and we do not control their content, consensus, availability, fees, addresses, contracts, or processing.
7. Ownership and license
We and our licensors retain the VelarumPay marks, brand assets, and non-open-source content. Public source code remains under Apache-2.0 or the identified repository license. We grant a limited, revocable, non-transferable, non-exclusive right to use the Services under these Terms. You retain your content and grant us only the license needed to provide, protect, and improve the Services.
8. Privacy
The Privacy Policy below applies. Never place recovery phrases, private keys, identity documents, real card data, or unnecessary sensitive data in requests, context, email, webhooks, or test records.
9. Suspension and termination
You may stop, revoke connections, and request account closure. We may suspend or end access for breach, security, law, dependency failure, or the end of a test program. Termination does not affect an independently controlled wallet or public-chain record. Ownership, disclaimers, limits, disputes, and indemnities survive.
10. Disclaimers
To the maximum extent permitted by law, the Services are provided “as is” and “as available.” We do not warrant uninterrupted, error-free, absolutely secure, universally compatible, or permanent operation. VelarumPay does not provide legal, tax, investment, accounting, custody, exchange, brokerage, or other regulated financial advice or services. A risk signal is not a safety guarantee.
11. Liability
To the maximum extent permitted by law, we are not liable for indirect, incidental, special, punitive, or consequential damages or loss of profits, goodwill, data, opportunity, or digital assets. Aggregate liability for the free testnet is limited to the greater of USD 100 or Service fees paid in the preceding 12 months. Limits do not cover liability law does not permit us to limit, including willful misconduct, gross negligence, personal injury, or non-waivable consumer rights.
12. Business indemnity
A business user will indemnify us and related personnel against reasonable losses from third-party claims caused by that user's unlawful use, breach, infringement, submitted data, or integration, only to the extent permitted by law and caused by that user. Consumers have no indemnity duty where prohibited.
13. Changes
We post revision dates here and provide reasonable advance notice through the website, App, Portal, or registered email for material changes. Urgent security, legal, or testnet fixes may apply immediately. Stop using the Services if you reject an update.
14. Electronic records and communications
By creating an account, clicking an acceptance control, or using the Services, you consent to receive these Terms, notices, disclosures, and records electronically. You confirm that you can access and retain them. You may withdraw consent by emailing legal@velarumai.com and discontinuing any feature that legally requires electronic delivery. Electronic records and signatures are governed by the federal E-SIGN Act, 15 U.S.C. § 7001, and the Wyoming Uniform Electronic Transactions Act, W.S. §§ 40-21-101–119, as applicable.
15. Law and disputes
Controlling United States federal law applies. Otherwise, Wyoming substantive law governs without its conflict-of-laws rules and without removing non-waivable consumer protection that applies where you live. The parties first attempt good-faith resolution for 30 days through legal@velarumai.com. Unresolved disputes go to a state or federal court with jurisdiction in Wyoming, with small-claims and interim injunctive relief available where permitted. A jury waiver applies only where law permits. Consumers may complain to a competent regulator.
16. General
These Terms and incorporated policies are the entire agreement for the Services. Invalidity of one provision does not invalidate the rest; non-enforcement is not waiver. You may not assign without written consent. We may assign in a merger, reorganization, or business transfer with required notice. Force majeure and open-network events outside reasonable control are not breach.
00056-00006-00005 · Effective 2026-08-03Privacy Policy
Vivbase LLC is a Wyoming limited liability company and the controller/business for account, security, reliability, legal, and direct-user processing described here. A business customer may be controller/business and Velarum its processor/service provider/contractor for configured Customer Personal Data under the DPA.
1. Data and purposes
| Website/network | IP, time, URL, user agent, language, errors, and security events to serve pages and TLS, rate-limit, debug, and prevent abuse. |
| Accounts/organizations | Email, verification, account, organization and member IDs, roles, and domains for Portal access, authorization, and support. |
| Devices/connections | Random device ID, token hashes, encrypted FCM token, scopes, revocation, and expiry for delivery, sync, push, and audit. |
| Testnet payment facts | Request ID, Stellar testnet address, asset, test amount, memo, status, tx hash, and fee for review, sync, deduplication, and dispute analysis. |
| Context/configuration | Merchant/agent identity, request explanation, evidence reference, agent/client public-key metadata, Recipient, webhook endpoint, and delivery logs for integration and request provenance. |
| Communications | Support, pilot, privacy, legal, and security emails and attachments to respond, investigate, and comply with law. |
We do not ask for or intentionally collect recovery phrases, private keys, signing material, full wallet backups, or real card data.
2. Sources
Data comes from you, your device, authorized organizations and members, connected merchants and agents, integrations, automatically generated security records, and public Stellar testnet. A merchant or agent supplying end-user data must have a legal basis, required notice, and minimization.
3. U.S. processing purposes and notice at collection
We collect and use the categories in Section 1 to provide requested features and perform our agreement; authenticate users; secure, debug, audit, and improve reliability; prevent fraud and abuse; provide support; establish or defend legal claims; comply with United States federal, Wyoming, and applicable state law; and obtain consent where law requires it. These are also our current notice-at-collection purposes. Refusing required account or device data makes that function unavailable but never requires a private key.
4. Sharing
- Authorized merchants, agents, applications, organization members, and webhook recipients receive what is needed for the relevant action.
- Infrastructure, email, push, and network providers are listed under Subprocessors.
- We may share for valid legal demands, security, abuse investigations, a corporate transaction, or at your direction.
- A submitted testnet transaction becomes visible to Stellar network participants, Horizon, explorers, and observers and cannot be deleted by us.
We do not sell personal data, share it for cross-context behavioral advertising, or use third-party advertising trackers.
5. Cookies
The website uses no advertising or analytics cookie. The Portal uses a necessary HttpOnly, Secure, SameSite session cookie and ephemeral CSRF proof. The App uses operating-system secure storage. See the Cookie Notice below.
6. Retention
- One-time verification, claim, and step-up tokens expire within minutes to 24 hours; only hashes or invalidation records remain server-side.
- Active account, organization, device, connection, and configuration records remain until closure, revocation, or test-environment reset, followed by deletion and backup rotation.
- Terminal requests and related context may be pruned on a short operational window; public-chain records remain public.
- Support/security correspondence, audit, and abuse evidence remain according to severity, dispute, and limitation periods. Legal holds restrict nonessential use.
Ask privacy@velarumai.com for the period applying to your data. We do not retain data indefinitely merely because it may be useful.
7. Location, security, and breach notice
Vivbase LLC is the U.S. controller. The current hosted deployment uses DigitalOcean, LLC in the syd1 region in Sydney, Australia, while other listed providers may use applicable global infrastructure. We use contracts, minimization, TLS, encryption/hash controls, least privilege, tenant isolation, audits, rate limits, credential rotation, and secret scanning. No system is absolutely secure. We investigate suspected breaches and provide notice without unreasonable delay when required by W.S. § 40-12-502 and other applicable United States state breach-notification laws.
8. U.S. privacy rights
Depending on your state and applicable exceptions, you may request access or knowledge, a portable copy, correction, deletion, and information about categories, purposes, sources, recipients, and retention; appeal certain denials; use an authorized agent where permitted; and receive service without unlawful discrimination. We do not sell personal data, share it for cross-context behavioral advertising, use it for targeted advertising, or conduct qualifying profiling, so those opt-outs are not presently necessary. For California residents, Sections 1–4 describe the categories collected, sources, purposes, and disclosures during the preceding 12 months.
Email privacy@velarumai.com with minimum identifying detail. We may verify identity and an agent's authority, but never require a recovery phrase or private key. We will explain any denial and available appeal or complaint route.
9. Children and automated decisions
The Services are for users at least 18. They are not directed to children under 13, and we do not knowingly collect their personal information. If we learn that we did so, we will delete it consistent with the Children's Online Privacy Protection Act (COPPA). Risk rules may warn or fail closed but do not make solely automated credit, employment, insurance, or similar decisions with legal or comparable significant effects.
10. U.S. references
FTC Act enforcement authority · Wyoming Title 40 · California CCPA · FTC COPPA guidance
00056-00006-00006 · Effective 2026-08-03Digital Asset and Testnet Risk Disclosure
This supplements the Terms and is not investment, legal, tax, or security advice.
Testnet and key risk
- Test XLM and other test assets have no monetary, redemption, or investment value. Do not buy, sell, pledge, or treat them as payment.
- Testnets may reset, fork, rate-limit, stop, or erase history. Test results do not establish mainnet safety or availability.
- Never send live mainnet assets to a test address, QR code, or example.
- Servers do not store or recover keys. Device loss, malware, screen capture, clipboard replacement, phishing, fake apps, cloud sync, weak locks, and unsafe backup can create irreversible harm.
Agent, chain, and public-data risk
- A merchant, connector, or AI agent may be wrong, compromised, prompt-injected, stale, or misleading. A connection is limited communication, not trust or signing authority.
- Consensus failure, reorg, congestion, node/Horizon outage, fee changes, upgrades, address or memo error, third-party failure, and push delay can cause failure or inconsistent state. REST and chain records are authoritative after push.
- Addresses, amounts, memos, times, and tx hashes may be public and permanently copied. Never put personal or confidential data in a memo.
- Allowlists, recipient verification, context, and risk signals only assist review. A green state is not a guarantee; chain facts control.
Legal and protection risk
United States legal classification depends on actual functions and value flow, not the words “non-custodial,” “software,” or “testnet.” Current test assets have no monetary value, and VelarumPay does not custody, exchange, accept, or transmit real value for a user; those facts do not create a blanket exemption. Mainnet, custody, exchange, acceptance or transmission of real value, or real settlement may trigger the Bank Secrecy Act and FinCEN rules, state money-transmitter licensing, securities or commodities rules, tax, and other regulation and must not launch without separate legal and licensing review. Test use remains subject to OFAC sanctions, export, privacy, consumer, cybersecurity, and criminal laws. The Service is not a bank account or insured deposit and has no FDIC, SIPC, redemption reserve, insurance, or loss fund. See FinCEN FIN-2019-G001.
Safe-use checkConfirm the official source and “Stellar testnet” label; review full recipient, amount, asset, memo, expiry, merchant, and agent; reject unexpected requests; never disclose a secret.
00056-00006-00007 · Effective 2026-08-03Acceptable Use Policy
Prohibited conduct
Do not use or assist use of the Services for fraud, theft, money laundering, terrorist financing, extortion, human exploitation, sanctions/export evasion, illegal gambling, unlawful drugs or weapons, impersonation, phishing, credential theft, rights violations, harassment, malware, unauthorized access, DDoS, credential stuffing, replay, forged webhooks/signatures/context/evidence, or circumvention of authentication, tenant isolation, scopes, revocation, rate limits, testnet gates, Recipient controls, or security warnings.
Do not request, upload, record, or transmit a recovery phrase, private key, signing material, plaintext API secret, or full wallet backup. Do not use the testnet for mainnet transfers or real-value settlement, market test assets as valuable, use agents to bypass review or hide facts, create unauthorized bulk accounts, resell access, scrape, spam, or deliberately impose infrastructure cost.
U.S. sanctions, export controls, and enforcement
The Services may not be used by or for a person, entity, wallet address, territory, end use, or transaction prohibited by United States sanctions, export controls, anti-money-laundering, counter-terrorist-financing, or other applicable law. Do not use a VPN, proxy, false identity, obfuscation, or intermediary to evade OFAC restrictions, the Export Administration Regulations, or a fact-dependent FinCEN obligation. We may investigate, reject, revoke, preserve evidence, suspend, terminate, or respond to authorities. Urgent security action may occur without advance notice. Appeal with facts and remediation to legal@velarumai.com.
OFAC virtual-currency sanctions guidance · BIS Export Administration Regulations · FinCEN FIN-2019-G001
00056-00006-00008 · Effective 2026-08-03Cookie and Similar Technologies Notice
Website
The website sets no advertising cookies, cross-site trackers, or analytics cookies and loads no third-party advertising scripts. Language uses URL paths. Pilot and support actions open your email app; website code does not submit or store the form contents.
Portal
The Portal uses vp_merchant_session (or a successor name) for a server-managed authenticated session. It is HttpOnly, Secure, and SameSite protected and paired with an ephemeral CSRF proof. Sessions last no more than 12 hours and expire after about 30 minutes of inactivity, with earlier sign-out or revocation. These controls are necessary; disabling them prevents sign-in.
App storage
The App may use Android Keystore, iOS Keychain/Secure Enclave, or equivalent secure storage for local credentials, encrypted wallet material, device ID, and preferences. These are not browser cookies, and servers do not store recovery phrases or private keys.
Before introducing nonessential analytics, advertising, fingerprinting, or cross-site technology, we will update this notice and provide any choice required by United States federal or applicable state law, including a legally recognized opt-out preference signal where required. No “accept all” banner is shown because the website uses no nonessential cookies and currently does not sell or share personal data.
Authorization and responsibilities
We grant a limited, revocable, non-transferable, non-exclusive testnet integration right. Do not market test credentials, addresses, assets, QR codes, screenshots, or status as real payment, mainnet support, regulatory approval, or commercial SLA. The pilot is free and has no SLA, service credit, compensation, or production commitment.
- Maintain accurate organization, member, agent, credential, Recipient, domain, and webhook records.
- Apply least scope, expiry, revocation, key rotation, rate limits, and human approval to agents and connectors.
- Use only synthetic, anonymized, or expressly authorized minimum test data—never real card data, identity documents, or wallet secrets.
- Provide your own end-user privacy notice, terms, support, and required consent, clearly identifying your independent role.
- Keep request facts accurate and display/metadata non-misleading; verify webhook signature, idempotency, replay protection, and tenant ownership.
Credentials, data, and exit
Store API keys, agent private credentials, webhook secrets, sessions, and connector secrets in a secret manager, not browser storage, client bundles, public repositories, logs, screenshots, or tickets. Revoke suspected exposure immediately. For configured Customer Personal Data, the Customer is generally controller/business and Velarum processor/service provider under the DPA. Customer controls webhook endpoints and must use HTTPS, validate signatures, and prevent SSRF/private redirects.
The testnet is reasonable efforts and may change. Customer may stop, revoke credentials, and request export/deletion of identifiable hosted configuration. No VelarumPay mark may imply partnership, certification, or endorsement without permission. Customer feedback may be used under a non-exclusive, perpetual, worldwide, royalty-free license excluding confidential information, marks, and personal data.
U.S. compliance allocation
Customer is solely responsible for determining whether its actual business model, value flow, marketing, data, and jurisdiction trigger United States federal or state obligations, including FinCEN/MSB registration, state money-transmitter licensing, OFAC and export controls, securities or commodities regulation, FTC and state unfair-or-deceptive-practices law, privacy, tax, consumer disclosures, or industry rules. VelarumPay's architecture and testnet label are product facts, not legal advice or a license. Customer must not expand to mainnet, custody, exchange, acceptance or transmission of real value, or real settlement without qualified U.S. counsel, required registrations or licenses, and separate written production approval from Vivbase LLC.
No production reliance: never use the official testnet for real funds, real goods/services settlement, financial books, or statutory records. A self-deployment requires an independent security, legal, operational, and license review and is not our hosted Service.
Instructions and details
Velarum processes Customer Personal Data only to provide, protect, support, and terminate the configured testnet and under the agreement, written instructions, and law. We do not sell or share it, use it for targeted or cross-context advertising, commercialize it outside the contract, or combine it with unrelated personal data except where applicable law permits. We apply the same level of privacy protection required of Customer, monitor compliance, and notify Customer if we can no longer meet an applicable obligation.
| Subject | Hosted API, Portal, connections, Payment Requests, Context, Recipients, webhooks, support, and security. |
|---|
| Duration | Contract/pilot plus deletion, backup rotation, dispute, and legal-retention periods. |
|---|
| People | Customer members, developers, test users, merchant contacts, agent/app-related people, and reporters. |
|---|
| Data | Email, roles, device/connection IDs, public testnet facts, request context, webhook and logs. Wallet secrets, real cards, and unnecessary sensitive/child data are prohibited. |
|---|
Security and subprocessors
Authorized personnel are bound by confidentiality and need-to-know access. Measures include TLS, token hashing, encrypted push/webhook secrets, least privilege, tenant isolation, session/CSRF controls, rate limits, audit, backup controls, secret scanning, vulnerability management, and incident response. Customer generally authorizes the published subprocessors and may object on documented protection grounds after notice.
Assistance, incidents, and deletion
We reasonably assist with rights requests, incident and risk assessments, regulatory consultation, and compliance evidence without disclosing another tenant, secrets, privileged material, or harmful security detail. We notify Customer without undue delay after confirming an incident involving Customer Personal Data, with known nature, scope, impact, mitigation, and updates. We investigate and cooperate with notices required by W.S. § 40-12-502 and other applicable United States state breach laws. Customer handles required notices unless law requires ours.
Customer may export available data before termination. We then delete or anonymize under the retention schedule unless law requires retention. Public-chain records, delivered webhooks, and third-party copies are outside our control.
U.S. state privacy terms, transfers, and audit
Applicable United States federal law and Wyoming law govern this DPA together with any state privacy provision legally covering the processing. Processing outside the United States uses contractual, security, and legally required transfer controls. EU Standard Contractual Clauses, a UK Addendum, or another foreign transfer instrument is not automatically incorporated and applies only if separately executed or expressly adopted in writing. We provide a reasonable annual questionnaire or evidence, with additional review after an incident or regulator request. Onsite audit requires notice, business hours, confidentiality, security, and no impact on others. Service liability limits apply except where privacy law prohibits limitation.
| Cloudflare, Inc. | Email Sending; edge deployments may use Workers and D1. Recipient email, templated security messages, minimum tenant/connection/request records, and network logs. U.S./global infrastructure; no Singapore regional resource selected. |
| Google LLC / Firebase | Android push using an encrypted-at-rest FCM token and opaque request/notification ID. No amount, recipient, memo, or secret in the push. REST remains authoritative. |
| Stellar Development Foundation and public testnet participants | Horizon and transaction status for public address, test amount, memo, tx hash, time, and network metadata on an open global network. |
| DigitalOcean, LLC | SYD1 Droplet hosting Caddy, website, API, Portal, private SQLite volumes, backups, and runtime logs in Sydney, Australia (syd1). DigitalOcean infrastructure and DPA-listed subprocessors may support the service. |
| ISRG / Let's Encrypt | Domain validation and public certificate-transparency records for TLS; no wallet or Payment Request content. |
Customer-selected webhook endpoints, merchants, agents, wallets, email providers, explorers, and integrations are generally independent recipients, not our subprocessors. We update this page and notify registered business Customers before a material addition where practicable. Vivbase LLC remains the U.S. operator and requires subprocessors to follow applicable United States state processor/service-provider restrictions. The current production testnet deployment is in DigitalOcean Sydney (syd1); migration requires review and notice where applicable. Safeguards include minimization, TLS, encrypted or hashed secrets, access control, contracts, retention limits, rights-request assistance, and incident notice.