Vero privacy policy
This policy explains what data Vero collects, how we use it, who we share it with, how we protect it, and how you can delete it. It covers the Vero application at dashboard.vc-solutions.net and the data businesses connect to it. The VC Solutions website and agency services have their own privacy policy.
- Who we are
- What Vero does
- Data we collect
- Google user data
- How we use data
- Who we share it with
- AI answers
- Security
- Retention and deletion
- Your choices
- Children
- Changes
- Contact
1. Who we are
Vero is built and operated by VC Solutions ("VC Solutions", "we", "us"), a location-level marketing company in Tampa Bay, Florida. You can reach us at info@vc-solutions.net.
For data a business connects to Vero, such as its sales and advertising reporting, we act on behalf of that business. For account and usage data we collect to run Vero, we decide how it is used.
2. What Vero does
Vero is a reporting tool for businesses with more than one location. A business creates a workspace, connects its point-of-sale system and its ad accounts, and assigns each ad account to the location it advertises. Vero then shows sales and advertising spend by location and week and answers questions about them.
3. Data we collect
Account data
Your name, email address, organization membership and role. Sign-in is handled by our authentication provider, Clerk.
Workspace setup
Your business name, its locations (names and addresses), and the answers you give during setup, such as which advertising channels you use.
Point-of-sale data
When an administrator connects Square, Vero imports the business's location list and, for each location and day, net sales and the number of orders. Vero does not import individual customers, card details or item-level receipts from Square.
Meta advertising data
When an administrator connects Meta, Vero imports the selected ad accounts' identifiers, names, currency and time zone, campaign names and status, and daily spend, impressions and clicks. Meta-specific deletion steps are on our Meta data page.
Google Ads data
Described in full in section 4.
Other connected systems
If an administrator connects another supported system, such as ServiceTitan, Vero imports the reporting totals it needs for the same comparison of sales and advertising.
Questions and answers
The questions you ask Vero and the answers it returns.
Technical data
Server logs with IP address, browser type, pages requested and errors, and the cookies needed to keep you signed in. Vero does not use advertising cookies or third-party trackers.
4. Google user data
This section describes how Vero handles data it receives from Google APIs. It applies when an administrator clicks Connect Google Ads in Vero and signs in with Google.
What we request
| Permission | Why Vero needs it |
|---|---|
openid and email | To record which Google login is connected, so the administrator can see it on the Connections page and switch to another login if needed. |
https://www.googleapis.com/auth/adwords | To read Google Ads account and campaign reporting. Google offers no read-only permission for Google Ads, so this is the narrowest permission that allows reporting reads. |
What we access and store
- Your Google account email address and Google account ID.
- An OAuth refresh token, stored encrypted, which lets Vero keep importing without asking you to sign in each time.
- The Google Ads accounts your login can access, including client accounts under a manager account: account ID, name, status, currency, time zone, the manager account used to reach it, and whether it is a test account.
- For each campaign in an account the administrator selects: campaign ID, name, status and channel type (for example Search or Performance Max).
- Daily cost, impressions, clicks, conversions and conversion value for each of those campaigns, for up to about 13 months back and then each new day.
- Technical details of each import: the API version, Google's request IDs and the time of the read.
Vero does not access ad creative, keywords, search terms, audience lists, billing information or the personal data of the people who see or click your ads.
How we use it
We use Google user data only to provide Vero's reporting to the business that connected it:
- to list the accounts the administrator can choose to import and let them assign each one to a location
- to show the business its own Google Ads spend and delivery next to its sales, by location and week
- to answer questions about that business's results, as described in section 7
- to show import status and errors, and to fix problems the business reports to us
Vero only reads from Google Ads. It never creates, edits, pauses or deletes campaigns, ads, budgets or any other Google Ads setting.
What we do not do
- We do not sell Google user data.
- We do not use it for advertising, including ad targeting, retargeting or building profiles of people.
- We do not use it to decide anyone's creditworthiness or for lending.
- We do not show one business's Google Ads data to another business, or combine it across businesses.
- We do not use it to develop, improve or train generalized AI or machine-learning models.
- Our staff do not read it unless the business asks us for help with a specific problem, it is needed to investigate abuse or a security issue, or the law requires it.
Who receives it
Only the service providers listed in section 6, which process it for us to run Vero. We transfer Google user data to others only if the law requires it, or as part of a merger, acquisition or sale of assets, in which case we will notify affected businesses first.
Limited Use
Vero's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deleting Google data
- Disconnect. On the Connections page, an administrator can disconnect Google Ads. Vero deletes the stored token and revokes its access at Google, unless the same Google login is still connected to another active Vero workspace. Imports stop.
- Delete Google Ads data. On the same page, an administrator can delete all imported Google Ads data. This disconnects Google Ads and removes every imported account, campaign, daily and weekly figure and location assignment for that workspace.
- Revoke from Google. You can remove Vero's access at any time at myaccount.google.com/permissions. Vero then stops importing.
- Ask us. Email info@vc-solutions.net and we will delete the data within 30 days.
5. How we use data
- To provide Vero: import connected data, show reports, answer questions and keep imports up to date.
- To control access: each workspace's data is visible only to its members, and members restricted to some locations see only those locations.
- To support you when you contact us.
- To keep Vero secure and working: monitor errors, prevent abuse and fix problems.
- To meet legal obligations.
We do not sell data, and we do not use connected business data for our own marketing.
6. Who we share it with
We use these service providers to run Vero. Each processes data only to provide its service to us.
| Provider | What it does for Vero |
|---|---|
| Vercel | Hosts the Vero application |
| Supabase | Database that stores workspace and imported data |
| Clerk | Sign-in and organization membership |
| Trigger.dev | Runs the background jobs that import Google Ads reporting |
| Anthropic, OpenRouter | AI models that write Vero's answers (see section 7) |
Within a business, Vero shows data to the members that business's administrators invite, according to their roles. VC Solutions staff can access a workspace to support the business, under the limits above. We may disclose data if the law requires it or to protect the rights and safety of our users or others.
7. AI answers
Vero's written answers come from an AI language model. To answer a question, Vero sends the model the question and the workspace's figures needed to answer it, such as weekly sales and advertising spend by location. The model provider processes this to return the answer. We do not use your data, including Google user data, to train AI models, and we do not send the model your access tokens or account passwords.
8. Security
- All traffic to Vero uses HTTPS.
- Access and refresh tokens for connected accounts are encrypted with AES-256-GCM before they are stored. Google tokens use their own encryption key.
- Imported data sits in tables that only Vero's servers can read. Browsers never query the database directly.
- Only organization administrators can connect or disconnect accounts or delete imported data.
No system is perfectly secure. If we learn of a breach that affects your data, we will notify you as the law requires.
9. Retention and deletion
- Account data stays while your account exists.
- Connection tokens are deleted when an administrator disconnects the account.
- Imported reporting stays until an administrator deletes it, the workspace is deleted, or we process a deletion request. After a disconnect it stays in place but no longer updates.
- Deleting a workspace deletes its connections and imported data.
- Server logs are kept for up to 30 days. Database backups expire on our provider's schedule, so deleted data can remain in an encrypted backup for a short time before it is overwritten.
10. Your choices
You can ask us to tell you what data we hold about you, correct it, export it, or delete it. Email info@vc-solutions.net. We answer within 30 days. If the data belongs to a business workspace, we may ask that business's administrator to confirm the request. Depending on where you live, you may also have the right to complain to a data protection authority.
11. Children
Vero is a tool for businesses and is not meant for anyone under 18. We do not knowingly collect data from children.
12. Changes
If we change this policy, we will update the date at the top. If a change affects how we use data you have already given us, we will tell workspace administrators by email or in Vero before it takes effect.
13. Contact
VC Solutions
Tampa Bay, Florida
info@vc-solutions.net