Skip to main content

Sub-processors

Last updated: 24 May 2026

Velobook uses a small set of third-party services to operate the platform. This page lists each of them, what they process, and where they're located. It's the source of truth referenced from our Privacy Policy and from the Data Processing Addendum that forms part of every shop's contract with us.

We notify subscribed shops by email at least 30 days before adding a new sub-processor that handles their customer data, so the shop has time to object. To subscribe to those updates, or to object to a planned change, email privacy@velobook.app.

Current sub-processors

  • Purpose
    Postgres database, file storage, authentication, edge functions.
    Data shared
    All booking data, shop configuration, customer accounts, uploaded photos and videos.
    Location
    Australia (Sydney, ap-southeast-2).
  • Purpose
    Transactional email (booking confirmations, reminders, reschedule and cancel notices, account verification).
    Data shared
    Recipient name, email address, and the body of the transactional message.
    Location
    United States.
  • Purpose
    Velobook subscription billing (charging shops).
    Data shared
    Shop billing contact, business name, and payment method. Stripe holds card numbers; we do not.
    Location
    United States (with global processing infrastructure).
  • Purpose
    Optional integration where a shop has connected Shopify for workshop checkout. Not used unless the shop enables it.
    Data shared
    Attendee name, email, and a booking reference passed to a Shopify checkout link.
    Location
    United States, Canada and global Shopify infrastructure.
  • Google (Calendar)

    Privacy policy ↗
    Purpose
    Optional integration where a shop has connected a Google Calendar. Booking events are mirrored into the calendar.
    Data shared
    Booking time, customer name and service details.
    Location
    Global Google Cloud infrastructure.
  • Google Analytics 4

    Privacy policy ↗
    Purpose
    Product analytics, loaded only after the user grants analytics consent. Advertising features and Google Signals are disabled.
    Data shared
    Pseudonymous client identifier, page URL, referrer, standard browser metadata.
    Location
    Global Google Cloud infrastructure.
  • Purpose
    Hosting for the Velobook website and CDN.
    Data shared
    Standard web server request logs (IP, user agent, path, timestamp).
    Location
    United States with a global edge.
  • Anthropic (Claude API)

    Privacy policy ↗
    Purpose
    Optional shop-owner onboarding helper. When a new shop owner pastes their existing website URL or uploads a price list during signup, we send that content to Claude to pre-fill suggested services, workshops and rentals for them to confirm. Not used outside the onboarding wizard, and not used for customer-facing flows.
    Data shared
    The page text or uploaded file the shop owner provided. No customer personal data is sent. Anthropic does not train on API inputs.
    Location
    United States.
  • Purpose
    Optional SMS reminders when a shop has enabled SMS via Velobook's Twilio account. Not used unless the shop turns on SMS.
    Data shared
    Recipient phone number and the body of the SMS.
    Location
    United States with a global SMS network.

Why we pick what we pick

We pick processors for fit, security posture, and price. Each of the providers above offers a Data Processing Agreement and Standard Contractual Clauses (or an equivalent transfer mechanism) covering EEA, UK and Swiss data. We don't share personal data with a processor unless they've agreed to those terms.

Questions

Email privacy@velobook.app.

Cookies & storage

velobook uses essential browser storage to keep you signed in, remember which shop you are working in, and route custom domains. With your permission, we also use Google Analytics to understand how people use velobook. Advertising trackers are always off. Choose what is okay with you.

Read our privacy policy.