Who we are and who this applies to
Vebo is a platform that connects Buyers with Sellers who publish discounted products with a pickup window. We act as the data controller for account and profile data, and as a technical intermediary between you and Mercado Pago when charging a payment or connecting an account to receive payouts.
This policy applies to anyone who creates a Vebo account, whether with the Buyer or Seller role. The role is chosen once at sign-up and can't be changed from the app.
What data we collect
We ask for the minimum necessary for the account to work, and it varies by role.
For every account, Buyer or Seller
- Email: used as the account identifier and to verify it at sign-up.
- Password: if you sign up with email — we always store it hashed, never as plain text. If you sign in with Google we don't handle any password.
- Google account identifier: only if you choose to sign in with Google.
- First and last name: added to your profile after sign-up (auto-filled from your Google account when applicable).
- Account role: Buyer or Seller, fixed at sign-up.
If you're a Buyer
- Nickname (optional): if you set one, we show it instead of your full name throughout the app.
- Reservation and payment history: product, quantity, amount, currency, and status of every transaction you've made.
If you're a Seller
- Phone number: required, so buyers and the platform can reach you.
- Your store(s) details: business name, description, address, and Google Maps link for the pickup point.
- Connection to your Mercado Pago account: the user identifier Mercado Pago assigns you, and the access tokens that let us process charges on your behalf (see Sections 04 and 06 on how we protect them).
Technical data, always
- Registration verification code: a temporary code emailed to you at sign-up, valid for 10 minutes and up to 5 attempts by default, to confirm the inbox is yours. It's only requested to create the account, never to sign in afterward.
- Technical request logs: request identifier, HTTP method and path, and timestamp, for support and diagnostic purposes. Authentication headers are automatically excluded from these logs.
- Session token: stored in your browser's local storage to keep you signed in between visits (more detail in Section 10).
We don't request or store card numbers or other sensitive financial data: those are entered directly at Mercado Pago's checkout, outside Vebo's servers.
Who we share it with
We don't sell personal data, or use it for advertising. We only share it with the providers strictly necessary to run the account and the payment:
| Provider | What it receives | What for |
|---|---|---|
| Mercado PagoBuyer charge | Your email, and the order details (product, quantity, price, currency). | Process the order's payment and confirm its result to us. |
| Mercado PagoSeller payout account | Nothing from your Vebo profile: you authenticate directly with Mercado Pago using your own account. Vebo only gets back an account identifier and access credentials. | Let you receive payouts directly into your own Mercado Pago account. |
| Googlesign-in | Email, first and last name tied to your Google account. | Offer an alternative, password-free sign-in. |
| Outbound email provider | Your email and the registration verification code. | Deliver the code to confirm your account. |
Mercado Pago in detail
Mercado Pago shows up at two distinct moments in Vebo, and each one moves different data. We break them out separately here because it's the part that raises the most questions.
When you buy — we create a payment preference
When you start a checkout, our server creates a "payment preference" in Mercado Pago and sends it: your email, the product and quantity details, the price, an internal order reference, and the platform fee percentage that applies to that transaction. We don't send your first name, last name, or phone number at this step. You fill in the rest of your payment details (card, installments, etc.) directly in Mercado Pago's interface, outside Vebo.
When Mercado Pago confirms the result, it notifies us through a digitally signed notification (webhook); we validate that signature before marking the order as paid, so no one can fake a payment confirmation.
When you connect your account as a Seller
To let you get paid for your sales, we redirect you to Mercado Pago's official site, where you sign in with your own account and authorize the connection — Vebo never sees or handles your Mercado Pago username or password. Mercado Pago only returns to us an identifier for your account and a pair of technical credentials (access and refresh tokens) that we use to generate charges on your behalf. Those credentials are stored encrypted and never reach the browser (see Section 06).
If you disconnect your Mercado Pago account, your products stop being available for purchase until you reconnect it.
Why we process this data
- Delivering the service you asked for: creating your account, showing your profile, processing an order, or connecting your payouts as a Seller don't work without this data.
- Your consent: given when you sign up and accept this policy.
- Security and fraud prevention: for example, limiting verification-code attempts or validating payment webhook signatures.
- Legal and tax obligations: applicable to payment intermediation.
How we protect it
- Passwords are always stored hashed; never as plain text, and never recoverable by our team.
- Each Seller's Mercado Pago tokens are encrypted at rest (symmetric encryption with an initialization vector and per-operation integrity check) and are never exposed to the frontend or to other users.
- Mercado Pago webhooks are validated with a cryptographic signature before any data is modified; an invalid signature is rejected with no effect.
- The Seller account-connection flow uses a signed, short-lived, single-use state token, to prevent it from being reused or intercepted.
- Authentication headers are automatically excluded from our technical logs.
- All communication between your browser and our servers travels encrypted (HTTPS).
How long we keep it
| Data | Period |
|---|---|
| Account and profile (email, first name, last name, phone, nickname) | While your account is active; deleted or anonymized on a closure request, subject to the legal obligations detailed below. |
| Payment and transaction records | to be confirmed the period required by the tax and accounting regulations applicable in Argentina. |
| Registration verification code | Expires after 10 minutes or 5 failed attempts, whichever comes first; it's no longer valid after that. |
| Seller's Mercado Pago connection and tokens | While the connection is active. Once disconnected, we stop using them to generate new charges. |
| Technical request logs | to be confirmed rotation policy with the infrastructure team. |
Your rights over your data
As the owner of your data, and under Argentine Law No. 25,326 on Personal Data Protection, you can at any time:
- Access: the data we have about you.
- Rectify: or update it if it's outdated or incorrect — many fields, like first name, last name, phone, and nickname, you can edit yourself from your profile.
- Request its deletion: within the limits of our applicable legal or contractual obligations.
- Object: to a specific processing activity.
To exercise any of these rights, write to us through the contact channel in Section 13. The Agency for Access to Public Information (AAIP) is Argentina's oversight body and has the authority to handle complaints and claims.
Minors
Vebo isn't directed at anyone under 18, in particular because using the platform involves payment transactions. We don't knowingly collect data from minors; if we learn of an account created by a minor, we'll close it.
International transfers
Mercado Pago and Google may process and host data on servers located outside Argentina, under their own privacy policies. By choosing to pay with Mercado Pago or sign in with Google, that transfer is subject to those providers' terms, which we recommend you review.
Changes to this policy
If we make a material change to this policy, we'll notify you with reasonable advance notice by email or an in-app notice before it takes effect.
Contact
For questions about this policy, or to exercise your rights over your data, write to us at to fill in privacy email. Legal name, tax ID, and registered address of the data controller: to be defined
This site's waitlist
While Vebo is not operating, the site offers a waitlist for users and businesses. If you fill it in, we store your name, email, phone, province, city, postal code and area or neighborhood; if you join as a business, also the business name and business type. We also store the page language and the date of submission.
We use these details only to let you know when Vebo reaches your area. They are stored on Cloudflare infrastructure (D1 database), are not shared with third parties, and for now we do not query them or send you any notice. We keep them until Vebo operates in your area or until you ask us to delete them, whichever comes first. To ask, write to us through the contact channel in Section 13.
Last updated: August 28, 2026.
