Sub-processors
Last updated: 1 August 2026
Velobook uses third-party services to operate the platform. This page lists each of them, what they process, and where they're located. It's the source of truth referenced from our Privacy Policy and from the Data Processing Addendum that forms part of every shop's contract with us.
They fall into two groups, and the difference matters for what a shop can object to. The first group is the processors Velobook chooses to run the platform. The second is integrations a shop connects itself, where the shop picks the vendor and holds the account. Most shops use few or none of the second group.
Processors Velobook uses
These are our choices, so they apply to every shop. We notify subscribed shops by email at least 30 days before adding a new one that handles their customer data, so the shop has time to object. To subscribe to those updates, or to object to a planned change, email privacy@velobook.app.
Supabase
Privacy policy ↗- Purpose
- Postgres database, file storage, authentication, edge functions.
- Data shared
- All booking data, shop configuration, customer accounts, uploaded photos and videos.
- Location
- Australia (Sydney, ap-southeast-2).
Resend
Privacy policy ↗- Purpose
- Transactional email (booking confirmations, reminders, reschedule and cancel notices, account verification).
- Data shared
- Recipient name, email address, and the body of the transactional message.
- Location
- United States.
Netlify
Privacy policy ↗- Purpose
- Hosting for the Velobook website and CDN.
- Data shared
- Standard web server request logs (IP, user agent, path, timestamp).
- Location
- United States with a global edge.
Stripe
Privacy policy ↗- Purpose
- Velobook subscription billing (charging shops). Stripe also processes customer payments for shops that have connected their own Stripe account, which is listed separately below.
- Data shared
- Shop billing contact, business name, and payment method. Stripe holds card numbers; we do not.
- Location
- United States (with global processing infrastructure).
Twilio
Privacy policy ↗- Purpose
- Optional SMS and WhatsApp messages when a shop has enabled them via Velobook's Twilio account. Both are transactional only (confirmations, reminders, ready-for-pickup). Not used unless the shop turns the channel on.
- Data shared
- Recipient phone number and the body of the SMS or WhatsApp message.
- Location
- United States with a global SMS network.
Google Analytics 4
Privacy policy ↗- Purpose
- Product analytics, loaded only after the user grants analytics consent. Advertising features and Google Signals are disabled.
- Data shared
- Pseudonymous client identifier, page URL, referrer, standard browser metadata.
- Location
- Global Google Cloud infrastructure.
Google (Maps and Places)
Privacy policy ↗- Purpose
- Address autocomplete on booking and delivery forms, and map display for mobile and delivery jobs. Loaded in your browser on the pages that use it.
- Data shared
- What you type into an address field while the suggestions are open, plus standard browser metadata. This can include a partial or complete street address.
- Location
- Global Google Cloud infrastructure.
Google (Gmail API)
Privacy policy ↗- Purpose
- Read-only access to Velobook's own support mailbox, so incoming mail can be triaged and answered. Read-only: this integration cannot send, draft or modify mail. It does not touch any shop's mailbox.
- Data shared
- The contents of email sent to Velobook's support address, including the sender's name and address.
- Location
- Global Google Cloud infrastructure.
Apple (Push Notification service)
Privacy policy ↗- Purpose
- Delivering push notifications to the Velobook staff app on iOS, for example a new booking alert. Only used for staff who have installed the app and allowed notifications.
- Data shared
- A device push token and the notification text, which can include a customer's first name and the service booked.
- Location
- Global Apple infrastructure.
Google (Firebase Cloud Messaging)
Privacy policy ↗- Purpose
- Delivering push notifications to the Velobook staff app on Android, for example a new booking alert. Only used for staff who have installed the app and allowed notifications.
- Data shared
- A device push token and the notification text, which can include a customer's first name and the service booked.
- Location
- Global Google Cloud infrastructure.
Tarot Routing
Privacy policy ↗- Purpose
- Route optimisation for shops running mobile or delivery jobs, working out the driving order for a day's stops.
- Data shared
- Stop coordinates (latitude and longitude) and time windows only. No name, address, contact details or booking details are sent.
- Location
- Global.
Anthropic (Claude API)
Privacy policy ↗- Purpose
- Optional shop-owner onboarding helper. When a new shop owner pastes their existing website URL or uploads a price list during signup, we send that content to Claude to pre-fill suggested services, workshops and rentals for them to confirm. Not used outside the onboarding wizard, and not used for customer-facing flows.
- Data shared
- The page text or uploaded file the shop owner provided. No customer personal data is sent. Anthropic does not train on API inputs.
- Location
- United States.
Integrations a shop connects
These are off by default and only carry data once a shop connects its own account (or, for Strava, once a customer connects theirs). Because the shop chooses the provider and agrees to that provider's terms directly, the 30-day notice above doesn't apply: a shop can add or disconnect any of them whenever it likes, from its own settings. Several of these providers are the shop's own processors rather than ours. We list them so customers can see where a booking's details can end up.
Stripe (Connect)
Privacy policy ↗- Purpose
- Where a shop has connected its own Stripe account to take customer payments. The shop is the merchant of record and funds settle to the shop.
- Data shared
- Paying customer's name, email, booking amount and payment method. Stripe holds card numbers; we do not.
- Location
- United States (with global processing infrastructure).
Square
Privacy policy ↗- Purpose
- Customer-payment rail, parallel to Stripe Connect. Where a shop has connected its own Square account, customers pay the shop through Square. The shop is the merchant of record and funds settle to the shop.
- Data shared
- Paying customer's name, email, booking amount and payment method. Square holds card numbers; we do not.
- Location
- United States with global processing infrastructure.
Shopify
Privacy policy ↗- Purpose
- Where a shop has connected Shopify. Depending on what the shop turns on, this covers workshop and booking checkout, order creation, and point-of-sale and inventory sync.
- Data shared
- Customer name, email, phone, booking reference, and the line items and amounts for the order or checkout.
- Location
- United States, Canada and global Shopify infrastructure.
Lightspeed (X-Series)
Privacy policy ↗- Purpose
- Point-of-sale integration where a shop runs Lightspeed X-Series. Velobook pushes the job's sale and its customer record into the shop's POS, and reads inventory back.
- Data shared
- Customer name, email address and phone number, plus the sale's line items and amounts.
- Location
- Global Lightspeed infrastructure.
Lightspeed (R-Series)
Privacy policy ↗- Purpose
- Point-of-sale integration where a shop runs Lightspeed R-Series (Retail). Same push as X-Series, against a different Lightspeed product.
- Data shared
- Customer name, email address and phone number, plus the sale's line items and amounts.
- Location
- Global Lightspeed infrastructure.
Ascend RMS
Privacy policy ↗- Purpose
- Point-of-sale integration where a shop runs Ascend. Velobook pushes the job's sale and its customer record into the shop's POS.
- Data shared
- Customer name, email address and phone number, plus the sale's line items and amounts.
- Location
- United States.
GoHighLevel (LeadConnector)
Privacy policy ↗- Purpose
- CRM integration where a shop has connected its own GoHighLevel sub-account. Booking customers are created or updated as contacts in the shop's CRM.
- Data shared
- Customer first name, last name, email address, phone number and booking tags.
- Location
- United States.
Google (Calendar)
Privacy policy ↗- Purpose
- Where a shop has connected a Google Calendar. Booking events are mirrored into the calendar.
- Data shared
- Booking time, customer name and service details.
- Location
- Global Google Cloud infrastructure.
Microsoft (Outlook Calendar)
Privacy policy ↗- Purpose
- Where a shop has connected an Outlook or Microsoft 365 calendar. Booking events are mirrored into the calendar.
- Data shared
- Booking time, customer name and service details.
- Location
- Global Microsoft infrastructure.
Strava
Privacy policy ↗- Purpose
- Where a customer connects their own Strava account, so their bikes and odometer readings can inform service intervals. Connected and revoked by the customer, not the shop.
- Data shared
- Read from Strava: the athlete's bike list, bike names and odometer readings. We send Strava no booking or customer data beyond the OAuth handshake.
- Location
- United States.
Why we pick what we pick
We pick processors for fit, security posture, and price. Each of the providers above offers a Data Processing Agreement and Standard Contractual Clauses (or an equivalent transfer mechanism) covering EEA, UK and Swiss data. We don't share personal data with a processor unless they've agreed to those terms.
Questions
Email privacy@velobook.app.