Privacy and data handling
Privacy and data handling
Effective 23 September 2026.
Velarion Records is published by VELARIONAI LLC · Andrew Richardson, founder, at 5900 Balcones Dr Ste 100, Austin, TX 78731 (VELARIONAI LLC). This page says what this site collects when you use it or buy from it, what that information is used for, who else sees it, and how it is held. It applies to velarionrecords.com only.
Information we collect
What you give us at checkout. Buying anything here asks for one thing: an email address, where the document, the alerts or the file is delivered. The data license additionally asks for the name of the organization the license is granted to, because the license itself names the licensee; a purchase-order purchase asks for a billing address and an optional purchase-order number, because that is what an invoice is made out to. Nothing else is required and nothing else is asked for.
What you ask us to watch. A filing alert follows a record — a covered entity, a contract pharmacy, a hospital, a facility, a state, or a list of certifications you name. That identifier is stored with your subscription because the subscription cannot do its job without it, and so is the address the alerts are sent to.
What your browser tells the server. As on any web server, a request to this site carries an IP address, a user agent and the page asked for. We use these to serve the page and to count visits. A random session identifier is minted in your browser and kept in the browser’s own session storage for the length of the visit; it is not a cookie, it is not written to your disk, it expires when the tab does, and its only purpose is to join a visit to a checkout that visit begins. We set no advertising or tracking cookies, and this site carries no third-party advertising or analytics scripts.
Not collected. No card number ever reaches this site or this publisher. Payment is taken on Stripe’s own payment page, and the card details are typed there — we are given a charge and a receipt, and never the number behind it. There are no accounts here, so there is no password and no profile to hold.
How we use it
- To deliver the document, the file or the API key you bought, and the license that names its scope and term.
- To send the alerts you subscribed to, to the address you gave, and to act on the watch you set up.
- To take the payment and to raise the invoice, where you have asked for one.
- To answer you when you write to us.
- To count visits to the site in aggregate, so we know which pages are read — this tells us nothing about which single visitor read what.
- To keep the records a business is required to keep: an invoice, a receipt, and the license we granted. A license grant is kept for as long as the grant runs and a reasonable period after it, because it is a contract and both parties may need to show it.
None of it is used to build a profile of you, to advertise to you, or to train anything. No marketing email is sent: the only mail from this desk is the alerts you asked for, the delivery of what you bought, and a reply to something you sent.
How we share it
Personal information is never sold, and never shared for anyone else’s marketing. It is passed to the service providers that make this site work, and to no one else except where the law requires it:
- Stripe — payment processing. Stripe receives the amount, your email address and, on a card purchase, your card details, which are typed on Stripe’s page and never seen by us.
- Our email provider — transactional mail only: the delivery of a purchase, the alerts you subscribed to, and any reply from a person here.
- Our hosting and database providers — the site and the register it reads. They hold the records that serve this site; they do not use them for anything of their own.
Each of those providers sees only what it needs for its own function. Beyond them, we disclose nothing unless a valid legal process compels it, and we would say so on this page if the shape of that changed. If the publication were ever sold or transferred, subscriptions and the records behind them would go with it, and a buyer would be bound by this page as it stands now.
The records themselves are public. Nothing this desk publishes about a hospital, a covered entity or a facility is private information: every figure is a value a federal agency printed on a file it publishes to the world — the HRSA 340B covered-entity files, the Medicare cost reports, the CMS provider files — and each page names the file it came from. Where such a record carries a name, that name is in the agency’s own published file and not something this site added. Anyone may ask us to correct a figure; the route for that is Corrections, not this page.
Data security
Traffic to this site is encrypted in transit. The card data never enters Velarion’s systems at all, which is the single largest thing that could go wrong with it removed rather than guarded. What is held — an email address, the watch behind a subscription, the record of a license — is held in the database behind the site, reachable only with credentials held by this publisher, and every page on this site reads it without the ability to write to it.
No method of transmission or storage is perfectly secure and we will not claim otherwise. What we can say is what is true: nothing sensitive is stored because nothing sensitive is collected, and the one class of data that would be worth stealing from a storefront — a card number — is not here to steal.
Contact
Questions about any of this, or a request to see or delete the information held about you, go to hello@velarionrecords.com. This desk is small enough that a person answers. The publisher is VELARIONAI LLC, 5900 Balcones Dr Ste 100, Austin, TX 78731.
About this site · How these figures are defined · Corrections