Privacy policy
Last updated: 20 July 2026
Velobook is a booking platform for repair and workshop trades. Independent shops (bike shops, watch repairers, instrument techs, cobblers and similar) sign up to run their bookings through Velobook, and their customers book services through a page hosted by us. This policy explains what personal information we handle, why we handle it, who we share it with, and the choices you have.
Velobook is operated from Australia, and offered to shops and customers in Australia, New Zealand, the United States, the United Kingdom and the European Economic Area. We aim to handle your information in line with each of these regimes: the Privacy Act 1988 (Cth) and Australian Privacy Principles, the New Zealand Privacy Act 2020, the UK GDPR and Data Protection Act 2018, the EU General Data Protection Regulation, and the California Consumer Privacy Act and related US state privacy laws. Where a particular regime gives you a stronger right than this policy describes, that right still applies.
Questions, requests, or complaints, email privacy@velobook.app (or alex@velobook.app). You can also submit a structured rights request via our privacy request form.
Who this policy applies to
Velobook handles two distinct kinds of personal information, and our role is different in each case. Under the GDPR/UK GDPR these correspond to controller and processor roles; under the CCPA they correspond to business and service provider.
- Shop owners and staff. When a shop signs up to use Velobook, we collect the information needed to run that account and to bill the business. Velobook is the controller (business) for that information.
- Customers booking a service. When you book through a shop running on Velobook, the shop is the controller of your booking. Velobook stores and processes that booking on the shop's behalf as a processor (service provider) so they can take, run, and follow up on the appointment. Our processor obligations are set out in our Data Processing Addendum, which forms part of every shop's contract with us.
- Customers with a Velobook account. If you choose to sign up for a Velobook account (so you can see your bookings across multiple shops in one place), we also hold a small profile record directly, and Velobook is the controller of that record.
Which privacy laws apply to you
Different rules apply depending on where you live and how you interact with Velobook. The most common cases:
- Australia: Australian Privacy Principles under the Privacy Act 1988 (Cth).
- New Zealand: Information Privacy Principles under the Privacy Act 2020.
- EEA: the EU General Data Protection Regulation (Regulation 2016/679).
- United Kingdom: the UK GDPR and the Data Protection Act 2018.
- United States, California: the California Consumer Privacy Act as amended by the CPRA. See the California-specific disclosures below.
- Other US states with comprehensive privacy laws (currently including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Minnesota, Maryland and Rhode Island). The rights described below, to access, correct, delete, port and opt out of targeted advertising, apply to residents of these states regardless of which one passed the law.
What we collect from shop owners
When a shop signs up, we collect:
- The owner's name and email address (used for sign in).
- A password, stored as a salted hash by our auth provider.
- Shop details: trading name, slug, timezone, branding (logo, colours, copy), service catalogue, opening hours.
- Optional integration credentials the shop chooses to connect (for example, a Google Calendar account or a Shopify checkout). These are stored only to make the connected feature work.
- Billing details for the shop's Velobook subscription. Payment card data is handled by Stripe and never stored on our servers.
- If the shop owner uses the optional onboarding scan to pre-fill their catalogue, the URL they paste or the file they upload is sent to our AI sub-processor (see sub-processors) for that one request. We don't store the uploaded file or the fetched page after the response comes back; we keep only the source reference (the URL or the file name) and the extracted catalogue suggestions, both of which the owner confirms or edits before anything is saved.
What we collect from booking customers
When you book a service through a shop on Velobook, the shop asks for:
- Your first and last name (and the names of any other attendees for a workshop).
- Your email address and phone number.
- Your postcode, if the shop has opted to ask for it.
- A description of the item and the work you want done.
- Any notes, photos, or video you choose to send with the booking.
We also collect a small amount of technical information automatically whenever you interact with a booking page:
- Your IP address, used to apply abuse and rate limits. (Our bot challenge is a self-hosted proof-of-work that runs in your browser, so it shares nothing with a third party.)
- Standard request metadata your browser sends (user agent, referer, request timestamps).
- A login session cookie or local-storage token, only if you sign in to a Velobook customer account or a shop signs in to their admin area.
We use Google Analytics 4 across Velobook, including on shop booking pages, to measure traffic and understand how the product is used. In the EEA, the UK and California, Google Analytics is only loaded after you grant analytics consent in the cookie banner shown on your first visit. We also honour the Global Privacy Control (GPC) browser signal where supported: if your browser sends GPC, we treat it as opting out of analytics and the targeted-advertising sale/share category for the duration of your visit. You can change your choice at any time via the link in the footer. Advertising features (Google Signals, ad personalisation, and ad storage) are disabled in all cases, and we do not use bookings to build marketing profiles.
Cross-shop history (optional)
If you sign up for a Velobook customer account, your past bookings made under the same email are automatically linked to that account so you can see them in one place. By default, that history is visible only to you. You can choose to share your history with shops you book at by toggling that setting in your account. When sharing is on, a shop you visit can see prior bookings you've made at other Velobook shops, so they have useful context for the job. You can turn sharing off at any time.
Text messages (SMS)
When you give a phone number while booking, you agree that the shop and Velobook, its booking platform, may text you about that booking. These messages are strictly transactional, for example booking confirmations, reminders, and a note when your bike or service is ready. We do not send marketing or promotional text messages, and providing a mobile number is optional at shops that allow it.
You can opt out of texts at any time by replying STOP, and reply HELP for help. Message and data rates may apply, and message frequency varies with your bookings. Your mobile number and SMS consent are never sold, and are never shared with third parties for their own marketing.
Why we collect it (purposes and lawful basis)
Under the GDPR and UK GDPR we must identify a lawful basis for each purpose. The table below covers all the personal information we handle.
- Operating bookings (accepting, scheduling, managing and following up on a booking). Lawful basis: performance of the contract between the shop and the customer (Art. 6(1)(b) GDPR), to which Velobook is a processor acting on the shop's instructions.
- Account management for shops (sign-up, authentication, billing, support). Lawful basis: performance of our contract with the shop (Art. 6(1)(b)) and compliance with tax and record-keeping laws (Art. 6(1)(c)).
- Customer accounts on Velobook (cross-shop history, magic-link sign-in). Lawful basis: performance of our contract with you (Art. 6(1)(b)).
- Abuse prevention and security (rate limits, a self-hosted proof-of-work bot challenge, audit logs, account-takeover detection). Lawful basis: our legitimate interest in keeping the platform secure (Art. 6(1)(f)), balanced against your interests.
- Product analytics (Google Analytics 4 with advertising features off). Lawful basis: consent (Art. 6(1)(a) and ePrivacy Directive). Only loaded after you accept analytics in the cookie banner, and disabled if you send a Global Privacy Control signal.
- Improving Velobook (aggregate usage, error logs). Lawful basis: legitimate interest (Art. 6(1)(f)) for server-side error logs; consent for browser analytics.
- Compliance and dispute resolution (responding to data-subject requests, regulator queries, legal claims). Lawful basis: legal obligation (Art. 6(1)(c)) and legitimate interest in establishing or defending claims (Art. 6(1)(f)).
We do not make decisions about you using automated processing that produces legal or similarly significant effects (Art. 22 GDPR / CPRA automated-decision rules), and we do not use your information to train AI or machine-learning models.
Where it's stored
Booking data, shop configuration, and customer account records are stored in a Postgres database hosted by Supabase. Photos and videos attached to a booking are stored in Supabase Storage. Supabase operates the database in cloud infrastructure (currently the Sydney ap-southeast-2 region) under their published terms and security practices.
Who else handles your data (sub-processors)
We share the minimum data needed with third-party processors to make Velobook work. We keep one source of truth rather than a second copy here that can drift out of date: the current list, what each processor handles, and where it's located are published at velobook.app/subprocessors. Most of them are optional integrations, so which ones apply to you depends on what the shop you booked with has switched on.
We notify subscribed shops by email at least 30 days before adding a new sub-processor that handles their customer data, so the shop has time to object. If you want to be on that list, email privacy@velobook.app.
We do not sell your personal information, we do not share it for cross-context behavioural advertising (as those terms are defined in the CCPA/CPRA), and we do not share it with anyone else for marketing.
International data transfers
Some of the processors listed at velobook.app/subprocessors operate outside your country. Most are headquartered in the United States or run on global infrastructure, and each entry on that page states where that processor is located. Our primary database (Supabase) is in Sydney. Where we transfer personal data across borders, the protections below apply:
- EEA and UK to outside the EEA/UK: we rely on the European Commission's Standard Contractual Clauses (Module Two, controller to processor; or Module Three, processor to processor where applicable) and, for UK transfers, the UK International Data Transfer Addendum to the EU SCCs. Where a recipient is certified under an active EU or UK adequacy mechanism (for example, the EU-US Data Privacy Framework as available to a particular processor), we may also rely on that adequacy decision.
- Australia and New Zealand: overseas disclosures comply with Australian Privacy Principle 8 and Information Privacy Principle 12 of the NZ Privacy Act respectively. We take reasonable steps to ensure overseas recipients handle your information consistently with the relevant privacy principles.
- Transfer impact: we have assessed the laws of the destination countries (primarily the United States) and consider the SCC protections plus the technical and organisational measures described under “Security” below to be sufficient. A summary of our transfer-impact assessment is available on request at privacy@velobook.app.
How long we keep it
We retain personal information for the shortest period consistent with the purpose for which it was collected. Specifically:
- Booking records: kept by the shop for as long as they need them to operate their business. For bookings tied to a payment, the Australian Taxation Office requires records to be kept for at least 5 years from the date of the transaction; equivalent obligations apply in other jurisdictions (HMRC: 6 years; IRS: typically 3 years).
- Photos and videos attached to a booking: kept while the booking is active and may be swept from storage after the booking is completed.
- Shop subscription records: kept while the subscription is active, then for a short wind-down window (typically 30 days), then deleted except where required by law (for example, invoices retained for the tax-record period above).
- Customer Velobook accounts: kept until you ask us to delete them. Deletion of the account does not automatically delete bookings the shops still hold, because those records belong to the shops as separate controllers.
- Rate-limit and abuse logs (IP + request type): kept for 24 hours and then automatically deleted.
- Server logs (errors, audit trail): kept for 30 days, then deleted.
- Analytics events: retained by Google for the default GA4 period (currently 14 months) under our Google Analytics configuration.
- Record of an erasure: when your details are erased at a shop, we keep a one-way fingerprint (a salted hash) of the email address and phone number that were erased. We do not keep the address or the number, and the fingerprint cannot be turned back into them. It exists for one reason: if that shop later uploads a customer list that still contains you, we recognise the fingerprint and skip you, rather than recreating the details you asked us to delete. The fingerprint is specific to that one shop, so it cannot be used to recognise you anywhere else, and we keep it for as long as the erasure stands.
Your rights
Wherever you live, you can ask us to:
- Access the personal information we hold about you and receive a copy.
- Correct anything that's wrong or out of date.
- Delete your information, subject to records we're legally required to keep. After an erasure we keep a one-way fingerprint of the erased email and phone, never the details themselves, so that a later customer-list upload cannot bring you back. See How long we keep it.
- Receive a copy of your data in a portable format (typically JSON or CSV).
- Opt out of analytics via the cookie banner or your browser's Global Privacy Control signal.
Additional rights for EEA / UK residents
- Restrict processing of your information while a query is being resolved (Art. 18 GDPR).
- Object to processing based on legitimate interest, including any profiling (Art. 21 GDPR). We do not use profiling that produces legal or similarly significant effects.
- Withdraw consent at any time where we process information on the basis of consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Lodge a complaint with your local data protection authority. For UK residents that's the Information Commissioner's Office (ico.org.uk); for the EEA, your country's authority listed on the EDPB site.
Additional rights for California residents (CCPA/CPRA)
In the last 12 months we have collected the following categories of personal information from California consumers, from the sources, for the purposes, and disclosed to the recipients described in this policy:
- Identifiers (name, email, phone, IP address), collected from you when you book or sign up.
- Customer record information (postcode, item description, job notes).
- Commercial information (booking history, billing records for shops).
- Internet activity information (page interactions, GA4 events if you consented).
- Geolocation data, coarse only (derived from IP).
- Audio, electronic, visual or similar information (photos and videos you attach to a booking).
- Inferences are not drawn from this data for profiling purposes.
We do not sell or share (as those terms are defined under the CCPA/CPRA) personal information, and we do not knowingly collect or sell the personal information of minors under 16. You have the right to:
- Know what personal information we have collected.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of sale or sharing (we do neither, but you may still submit a request).
- Limit use of sensitive personal information (we do not use sensitive personal information for any purpose that would trigger this right).
- Be free from retaliation for exercising any of these rights.
We honour authorised-agent requests on the same terms as direct requests, provided the agent supplies signed written permission. Our response time is 45 days, extendable once by a further 45 days where reasonably necessary, and we will confirm receipt within 10 business days.
Additional rights for other US state residents
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Tennessee, Indiana, Iowa, Delaware, New Hampshire, New Jersey, Minnesota, Maryland and Rhode Island have access, correction, deletion, portability and opt-out rights substantially similar to those described above. Where your state law gives you a right to appeal a refusal to act on a request, we will provide an appeal mechanism free of charge when responding to your request.
How to make a request
Submit a structured request via velobook.app/privacy-requests, or email privacy@velobook.app from the address on file. We'll acknowledge your request promptly and respond within the timeframe required by your privacy law (30 days under GDPR/UK GDPR, 45 days under CCPA/CPRA and most US state laws, with possible extensions where allowed). We won't charge a fee for the first request, and won't discriminate against you for making one. If your booking sits with a specific shop and you're asking us to act on the shop's behalf as processor, we may need to coordinate with that shop to fulfil the request, and will tell you if that's the case.
We may need to verify your identity before acting on a request, for example by confirming control of the email address on file. We will only ask for the minimum information needed to verify you.
Cookies and similar technologies
Velobook uses essential browser storage to keep you signed in, remember which shop you're working in, and route custom domains. With your permission (collected via the cookie banner on first visit) we also load Google Analytics 4 to measure product usage. Advertising trackers are not in use anywhere on the site. You can change your choice at any time via the link in the footer.
If your browser sends a Global Privacy Control (GPC) signal, we treat it as a refusal of analytics for that visit, and as an opt-out of any future “sale” or “share” category we might add. Today we do neither, so GPC mostly acts as an analytics opt-out on your behalf.
Security
We take reasonable steps to protect your information: all traffic to Velobook uses HTTPS, data is protected by row-level security in the database with tenant isolation, all writes flow through server-side functions that validate input, and rate limits apply to public endpoints. Database backups are encrypted at rest and access to production data is restricted to authorised personnel.
No system is ever fully secure. If you believe you've found a security issue, email us at privacy@velobook.app and we'll look into it. We aim to acknowledge reports within two business days.
Data breach notification
If we become aware of a personal data breach that's likely to cause serious harm or pose a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required by GDPR or UK GDPR, and notify the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme where applicable, and the Office of the Privacy Commissioner (NZ) under the NZ Privacy Act 2020. We will notify affected individuals without undue delay where the law requires it or where doing so is appropriate in the circumstances. Where we're acting as a processor for a shop, we will notify the shop without undue delay so they can meet their own notification obligations.
Children
Velobook isn't aimed at children, and we don't knowingly collect personal information from anyone under 16 in the EEA / UK, or under 13 in the United States. Children may legitimately appear as workshop attendees when a parent books them in. In that case the parent is the account holder and is responsible for the booking. If you believe a child has provided us with personal information directly, email privacy@velobook.app and we'll delete it.
EU and UK representatives
Velobook is established in Australia. If we have an obligation to appoint a representative in the EU under Article 27 GDPR, or in the UK under Article 27 UK GDPR, those representatives will be listed here. Until then, EEA and UK individuals may contact us directly at privacy@velobook.app for any privacy matter. We will appoint a representative when the volume or nature of EEA/UK processing requires it.
Complaints
If you're unhappy with how we've handled your information, contact us first and we'll try to fix it. You can also lodge a complaint with your local supervisory authority:
- Australia: Office of the Australian Information Commissioner, oaic.gov.au.
- New Zealand: Office of the Privacy Commissioner, privacy.org.nz.
- United Kingdom: Information Commissioner's Office, ico.org.uk.
- EEA: your national supervisory authority listed on the European Data Protection Board site.
- California: the California Privacy Protection Agency, cppa.ca.gov or the California Attorney General.
- Other US states: your state attorney general's consumer protection office.
Changes to this policy
We'll update the date at the top of this page whenever the policy changes. Material changes will be flagged on booking pages and in the shop admin area, and we'll email subscribed shops at least 30 days in advance of changes that affect how we process their customer data.
Contact
Alexander John Watts (ABN 72 732 848 534), the registered holder of the business name "Velobook"
Privacy matters: privacy@velobook.app
General: alex@velobook.app