Privacy Policy
Last updated 2026-08-19
Short version: we use account, purchase, support, site, and flash-delivery data to operate VeraScripts. We do not sell personal information. A Zen identity is used transiently during installation, but the flash ledger stores a shortened SHA-256 fingerprint rather than the raw serial.
Who operates VeraScripts
VeraScripts LLC, a Kentucky limited liability company, operates verascripts.com and is responsible for the information described in this policy. Privacy and business inquiries can be sent to support@verascripts.com.
What we collect
- Discord account data: Discord ID, username, display name, email, and avatar identifier supplied through Discord OAuth
- Purchase and licence data: Whop user, product, plan, membership, licence key, amount, currency, status, timestamps, refund or dispute state, billing name, payment-method type, card brand, last four digits, and country when Whop supplies them
- Website and advertising telemetry: account ID when signed in, IP address, path, request method and status, duration, browser user-agent, referrer, TikTok click and browser identifiers when present, and limited event metadata for page views, sign-in, checkout, purchases, claims, support, errors, and installation
- Flash records: account, product, version or payload hash, slot, time, status, firmware/protocol details, and a shortened SHA-256 fingerprint derived from the Zen identity
- Support data: messages and attachments you send through Discord, email, or a human ticket. The website Vera assistant stores answer-routing metadata such as question length, selected product/version, matched topics, citations, and escalation status; it does not put the raw website question in the site-event ledger
- Affiliate data: profile and Whop identity details, tracked links, attributed sales and commission snapshots, payout-onboarding status, and submitted promotional links or content
What we don’t collect
- Your full card number, CVV, bank password, or other raw payment credentials; Whop processes payment
- The raw Zen serial in the flash ledger. The raw device identity is used transiently to build the device-specific flash stream, then the server logs the shortened fingerprint described above
- Any data about your gameplay, K/D, ranking. The scripts run on the Zen, not on your console or PC, so we have no access to any of that
- Keystrokes, mouse movement, or session replays
How long we keep it
- Account and active licence records are kept while needed to provide access and support
- Routine website telemetry is subject to a rolling retention process; error, security, and operational records may be retained longer when needed to investigate an incident
- Purchase, refund, dispute, affiliate, flash-delivery, and support records may be retained as needed for accounting, evidence of delivery, fraud prevention, licence enforcement, and legal obligations, including after an account is closed
- The signed website session cookie expires 30 days after it is issued
- The first-party attribution cookie may remain for up to 400 days; affiliate and guest-checkout cookies remain for up to 30 days; browser-bound OAuth cookies remain for up to 10 minutes
Who sees your data
- VeraScripts staff and systems that need it to operate the store, installer, support, security, and affiliate program
- Whop for checkout, memberships, affiliate attribution, refunds/disputes, identity checks, and payouts
- Discord for sign-in, community roles, direct messages, and support tickets handled through Discord
- TikTok for advertising delivery and measurement through TikTok Pixel and Events API, and for read-only reporting from our own advertiser account through TikTok’s Business API
- Our hosting, network, font-asset, and AI service providers, limited to the data needed to deliver those services. When you communicate with Livvy, relevant message, account, purchase, and support context may be processed to draft and deliver support
Advertising measurement and reporting
We use TikTok Pixel and TikTok Events API to measure visits, checkout activity, and verified purchases connected with our advertising. When available, this may use TikTok’s _ttp browser identifier and the ttclid click identifier attached to an ad visit. Events sent to TikTok may include the page URL and referrer, IP address, browser user-agent, event and product details, purchase value and currency, and available SHA-256-hashed email, phone, or pseudonymous account identifiers. Browser and server events use matching event identifiers so TikTok can deduplicate the same action.
VeraScripts LLC also uses TikTok’s Business API for internal, read-only campaign reporting from the VeraScripts advertiser account. We use those reports to compare spend and delivery with first-party website activity and verified purchases. We do not manage third-party advertiser accounts through this integration and do not use it to create, edit, pause, or publish campaigns, audiences, or creative.
Your rights
To request access, correction, deletion, or a copy of your data, email support@verascripts.com with "Privacy" in the subject. We may verify your identity first. Deletion is subject to records we must or reasonably need to retain for transactions, security, disputes, licence enforcement, or law. Rights required by applicable privacy law remain available.
Cookies
VeraScripts uses these first-party cookies:
vs_s: a signed account session, Secure, HttpOnly, SameSite=Lax, for up to 30 daysvs_at: a random first-party attribution and journey identifier, HttpOnly and SameSite=Lax, for up to 400 daysvs_gc: a Secure, HttpOnly guest-checkout browser identifier for up to 30 daysvs_aff: the verified affiliate attribution code for up to 30 daysvs_oauth_discordandvs_oauth_whop: Secure, HttpOnly browser bindings used for up to 10 minutes to protect sign-in from cross-browser OAuth replayttclid: a Secure first-party copy of a valid TikTok ad click identifier for up to seven days
For advertising measurement, TikTok Pixel may also set or read TikTok identifiers including _ttp. TikTok controls the retention of identifiers it sets. Embedded Whop checkout, Discord sign-in, and externally served fonts or assets may make requests to those providers and may be governed by their own storage and privacy practices.
Changes
The “updated” date above identifies the current policy. If you disagree with a change, contact us to request an export or deletion subject to the limits described above.