Legal

Privacy Policy

Last updated: August 27, 2026

1. Overview

VELORA Booking OS (“VELORA”, “we”, “us”, “our”) is a booking and business operations platform for service businesses. This Privacy Policy explains how we collect, use, store and protect information when you use our website, applications and services.

2. Information we collect from business owners and operators

  • Name, email address and phone number.
  • Business name, category, currency, timezone and location details.
  • Staff, service, pricing, availability and booking configuration.
  • Customer and booking records created through your account.
  • Payment account information used to receive payouts.
  • Communications with our support team.

3. Information we collect from customers and clients

When a client books through a VELORA-powered storefront, we collect the information the business requests to fulfil the appointment. This typically includes:

  • Name and contact details (email and/or phone number).
  • Selected service, staff member, date and time.
  • Payment information processed by Paystack (we do not store full card details).
  • Notes or preferences the client chooses to provide.

4. Account and authentication information

We use Supabase Auth to manage authentication. When you sign up or sign in with email and password or through Google OAuth, Supabase processes your authentication credentials and issues a secure session token. We store your user ID, email address and role information needed to operate your account.

5. Business, staff, service, location and booking data

The operational data you enter into VELORA — including staff profiles, services, locations, availability rules, bookings, cancellations and client records — is stored in our backend database. This data is isolated by tenant and protected by row-level security so that each business can access only its own data.

6. Payment-related information

Deposits, booking payments and subscription charges are processed through Paystack. Paystack collects and stores the payment information required to complete transactions. We receive and store transaction references, amounts, currencies, statuses and timestamps so we can reconcile bookings and payouts. We do not store full payment card numbers on VELORA systems.

7. Uploaded business and storefront media

You may upload images, logos and other media to customise your storefront. These files are stored in secure object storage and may be served publicly through your storefront link if you choose to display them. You retain ownership of the media you upload and are responsible for ensuring you have the right to use it.

8. Cookies and essential session technologies

VELORA uses cookies and similar technologies to keep you signed in, maintain your session state, remember your preferences and protect the platform against abuse. These are essential for the service to function and cannot be disabled without breaking core features. We do not use third-party advertising or tracking cookies.

9. How we use information

  • To provide, operate and improve the VELORA platform.
  • To authenticate users and enforce access controls.
  • To process bookings, payments and payouts.
  • To send booking confirmations, reminders and service-related notices.
  • To respond to support requests and resolve technical issues.
  • To enforce our Terms of Service and prevent fraud or abuse.

10. How information is stored and protected

Data is stored in encrypted databases and object storage hosted by our infrastructure providers. We use industry-standard encryption in transit (TLS) and at rest. Access is restricted by authentication, role-based permissions and tenant isolation enforced at the database layer. We review access logs and apply security patches on an ongoing basis.

11. Data retention

We retain your account and business data for as long as your account is active or as needed to provide the service. If you delete your account, we will remove or anonymise your data within a reasonable period, except where retention is required by law or necessary for legitimate business purposes such as fraud prevention, audit or billing records.

12. Third-party service providers

We rely on carefully selected providers to operate VELORA:

  • Supabase — authentication, database and storage infrastructure.
  • Paystack — payment processing for deposits, bookings and subscriptions.
  • Email and communications providers — for transactional messages such as confirmations and password resets.

These providers process data only on our behalf and under contractual obligations that require appropriate security and confidentiality measures.

13. Business and customer data separation

Each business account is a separate tenant. Customer data entered through your storefront is associated with your tenant and is not shared with other businesses, except where a customer explicitly consents or where required by law. VELORA staff may access data only when necessary to provide support or maintain the platform, and only under strict internal controls.

14. Your rights and data requests

Depending on your location, you may have the right to access, correct, export or delete your personal data. Business owners can manage most data directly within the VELORA dashboard. For other requests, contact us using the details below and we will respond within a reasonable timeframe.

15. Account deletion

You may request deletion of your VELORA account at any time. Deleting your account will remove access to the dashboard and begin the process of removing or anonymising associated business and customer data, subject to any legal or billing retention requirements.

16. Security practices

  • Encrypted connections for all data in transit.
  • Encrypted storage for data at rest.
  • Tenant isolation through row-level security policies.
  • Multi-factor authentication for platform administration.
  • Regular dependency reviews and security monitoring.

17. Changes to this policy

We may update this Privacy Policy as the service evolves. When we make material changes, we will revise the “Last updated” date and may notify you through the platform or by email. Continued use of VELORA after changes constitutes acceptance of the updated policy.

18. Contact us

For privacy questions, data requests or concerns about this policy, please contact us:

VELORA LABS

Email: privacy@velbooking.com

(Mailing address and phone number to be added by the operating business.)

This policy should be reviewed by qualified legal counsel before publication. It is provided as a starting point and may need adjustments for your jurisdiction.