Sub-processors
Last updated: 24 May 2026
Velobook uses a small set of third-party services to operate the platform. This page lists each of them, what they process, and where they're located. It's the source of truth referenced from our Privacy Policy and from the Data Processing Addendum that forms part of every shop's contract with us.
We notify subscribed shops by email at least 30 days before adding a new sub-processor that handles their customer data, so the shop has time to object. To subscribe to those updates, or to object to a planned change, email privacy@velobook.app.
Current sub-processors
Supabase
Privacy policy ↗- Purpose
- Postgres database, file storage, authentication, edge functions.
- Data shared
- All booking data, shop configuration, customer accounts, uploaded photos and videos.
- Location
- Australia (Sydney, ap-southeast-2).
Resend
Privacy policy ↗- Purpose
- Transactional email (booking confirmations, reminders, reschedule and cancel notices, account verification).
- Data shared
- Recipient name, email address, and the body of the transactional message.
- Location
- United States.
Stripe
Privacy policy ↗- Purpose
- Velobook subscription billing (charging shops).
- Data shared
- Shop billing contact, business name, and payment method. Stripe holds card numbers; we do not.
- Location
- United States (with global processing infrastructure).
Shopify
Privacy policy ↗- Purpose
- Optional integration where a shop has connected Shopify for workshop checkout. Not used unless the shop enables it.
- Data shared
- Attendee name, email, and a booking reference passed to a Shopify checkout link.
- Location
- United States, Canada and global Shopify infrastructure.
Google (Calendar)
Privacy policy ↗- Purpose
- Optional integration where a shop has connected a Google Calendar. Booking events are mirrored into the calendar.
- Data shared
- Booking time, customer name and service details.
- Location
- Global Google Cloud infrastructure.
Google Analytics 4
Privacy policy ↗- Purpose
- Product analytics, loaded only after the user grants analytics consent. Advertising features and Google Signals are disabled.
- Data shared
- Pseudonymous client identifier, page URL, referrer, standard browser metadata.
- Location
- Global Google Cloud infrastructure.
Netlify
Privacy policy ↗- Purpose
- Hosting for the Velobook website and CDN.
- Data shared
- Standard web server request logs (IP, user agent, path, timestamp).
- Location
- United States with a global edge.
Anthropic (Claude API)
Privacy policy ↗- Purpose
- Optional shop-owner onboarding helper. When a new shop owner pastes their existing website URL or uploads a price list during signup, we send that content to Claude to pre-fill suggested services, workshops and rentals for them to confirm. Not used outside the onboarding wizard, and not used for customer-facing flows.
- Data shared
- The page text or uploaded file the shop owner provided. No customer personal data is sent. Anthropic does not train on API inputs.
- Location
- United States.
Twilio
Privacy policy ↗- Purpose
- Optional SMS reminders when a shop has enabled SMS via Velobook's Twilio account. Not used unless the shop turns on SMS.
- Data shared
- Recipient phone number and the body of the SMS.
- Location
- United States with a global SMS network.
Why we pick what we pick
We pick processors for fit, security posture, and price. Each of the providers above offers a Data Processing Agreement and Standard Contractual Clauses (or an equivalent transfer mechanism) covering EEA, UK and Swiss data. We don't share personal data with a processor unless they've agreed to those terms.
Questions
Email privacy@velobook.app.