Operator and scope
Attribution Relay is operated by Venture VD LLC, a Michigan domestic limited liability company (identification number 802557198), registered at 1963 16th Ave SW, Byron Center, MI 49315, United States. Contact support@venturevd.com for privacy, access, correction, export, or deletion requests.
The service is offered only to customers established in the United States or Canada. We do not market or sell it elsewhere. Customers control the lead data they collect; Venture VD processes it on their instructions under the Data Processing Addendum.
What we process and why
We process account identifiers, connected-form configuration, encrypted HubSpot OAuth credentials, form submissions, attribution context, and operational and security telemetry. Processing is limited to delivering supported third-party form submissions to the customer's HubSpot account, displaying delivery history, preventing abuse, supporting customers, and operating billing entitlements.
We do not sell lead data, use it for advertising, share it for targeted advertising, profile individuals, or use it to train models. Customers remain responsible for their form notices, lawful basis, and consent.
Retention and control
Raw submission payloads are retained for 90 days by default. Delivery metadata and audit history remain while the account is active. Customers may export JSON or CSV, request correction or deletion, and receive an export before uninstalling. Account data is scheduled for deletion 30 days after uninstall.
Sharing and subprocessors
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Fly.io | Application hosting and network | Account identifiers, submission content in transit, operational metadata | Chicago, United States |
| Fly Managed Postgres | Encrypted database, backups, recovery | Configuration, encrypted credentials, submissions, ledger data | Chicago, United States |
| Paddle.com Market Ltd | Merchant of record | Billing identity and subscription state, never lead payloads | Paddle infrastructure |
HubSpot is the customer-selected destination. Gravity Forms, Webflow, and Typeform are customer-selected sources. They are contracted directly by the customer. Error aggregation is not enabled at launch. Customers receive advance notice of material subprocessor changes and may object on reasonable data-protection grounds.
Security
The runtime database role cannot delete submissions or accounts; a separate restricted role performs retention deletion. Credentials use AES-256-GCM encryption at rest. Database connections require certificate-verified TLS. Vendor webhooks are signature-verified. Delivery attempts and audit events are append-only through database permissions, and production logs are structured and redacted.
Location and privacy rights
Data is processed in Fly.io's Chicago region in the United States. Canadian customers should understand that their data is processed outside Canada and may be subject to lawful access by United States authorities; we remain accountable under PIPEDA and require comparable contractual protection.
Depending on location, US state privacy laws and Canada's PIPEDA may provide rights to know, access, correct, delete, or port personal data. We do not sell or share personal data as defined by California law and will not discriminate for exercising a right. Leads should contact the customer controlling their form data first; we assist that customer. Requests may be appealed by replying, and individuals may complain to their state attorney general or Canada's Office of the Privacy Commissioner.
Changes
Material changes will be posted here with an updated date. Changes materially affecting customer data processing will also be sent to account administrators.