1. About this policy
This Cookie policy explains the cookies and similar technologies used on velixa.co.uk, on every Merchant booking page, on hosted Merchant websites, and inside the Velixa booking widget. It is published by Velixa App Ltd, company number 17185369.
2. What is a cookie?
A cookie is a small text file stored by your browser. We use them to keep you logged in, protect against cross-site request forgery (CSRF), attribute bookings to marketing channels, and remember basic UI preferences. We do not use third-party advertising cookies and we do not track you across other websites.
3. Cookies we use
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
| PHPSESSID | Maintains your sign-in session for customer, Merchant and admin areas. Multi-tenant isolation uses a separate session key per area. | Strictly necessary, first-party | Session |
| vx_csrf | Stores the CSRF token used to verify form submissions and prevent forged requests. | Strictly necessary, first-party | Session |
| vx_ref | Records the marketing referral source (e.g. UTM parameters from a link you clicked) so a Merchant can measure which channels drove a booking. Contains only the referral source string — no personal data. Set for the duration of a browsing session and not used for cross-site advertising. | Functional, first-party | Session |
4. Visitor analytics on Merchant sites
Where a Merchant has enabled visitor analytics on their hosted website or booking widget, an anonymous, HMAC-signed visitor identifier may be stored so the Merchant can measure page visits and booking conversions on their own site. This identifier contains no personal data and is not shared with other Merchants or used by Velixa for cross-site advertising. Merchants who use this feature are responsible for disclosing it in their own privacy notice and obtaining any consent required under PECR.
5. Third-party cookies
We do not set Google Analytics, Facebook Pixel, advertising or cross-site tracking cookies on velixa.co.uk. When you reach a payment step, Stripe’s hosted card fields and fraud-prevention tooling may set their own cookies in Stripe’s domain. Those are necessary for secure payment processing and fraud prevention — see Stripe’s cookie policy.
6. Local storage
The Merchant dashboard uses small amounts of browser localStorage to remember UI preferences (e.g. last-used calendar view, sidebar state, preferred location in multi-location accounts). This is stored only on your device and is not transmitted to our servers.
7. Your choices
You can clear or block cookies in your browser settings at any time. Blocking the session and CSRF cookies will sign you out and prevent the booking flow from working. The referral cookie can be blocked without affecting the booking experience — only attribution reporting is affected. If we ever add a new category of cookie that requires consent, we will provide an appropriate mechanism before setting it.
8. Changes
If we add a new cookie or category, this policy will be updated and the "Last updated" date revised. Where the change affects the user experience, we will announce it in your account or by email.
9. Contact
Questions about cookies: [email protected].
Last updated: August 2026