1. Who we are
Velixa App Ltd ("Velixa", "we", "us") is the controller for the personal data we collect about you when you visit velixa.co.uk, create a customer account, or operate a Merchant account on the platform. Velixa App Ltd is registered in England & Wales, company number 17185369, with registered office at Office 1168, 60 Tottenham Court Road, Fitzrovia, London, United Kingdom, W1T 2EW. For booking data that a Merchant collects through Velixa, the Merchant is the controller and Velixa is the processor — see the Data protection page.
2. What we collect
- Customer accounts: name, email, phone, hashed password, per-Merchant marketing preferences, login and security events, and push-notification tokens for devices where you have granted notification permission.
- Bookings: service booked, date/time, staff member selected, price (including any staff-specific rate), payment status, cancellation history, and the Merchant you booked with.
- Loyalty, memberships and gift cards: loyalty-point balances and transaction history per Merchant, active membership details (plan, renewal date, status), and gift-card balances where you are the recipient.
- Merchant accounts: business name, address, staff members (name, email, phone, role, working hours, per-service pricing including staff-specific rates, profile photo where supplied), services, locations, subscription and billing details, and connected Stripe account ID (we do not see your Stripe credentials).
- Reviews and photos: any user-submitted content provided for moderation and public display.
- Technical: IP address, user-agent, session cookie, CSRF cookie, marketing-referral attribution cookie (see § 8), HMAC-signed visitor-tracking events, and audit logs of significant account actions.
3. Lawful bases (UK GDPR)
- Contract — delivering bookings, loyalty programmes, memberships, gift cards, account features, and the Merchant subscription.
- Legitimate interest — security, fraud prevention, debugging, attribution of bookings to marketing channels, and aggregated analytics about how the platform is used.
- Consent — marketing emails and SMS from Velixa and from Merchants you have opted in to; push notifications where you have granted permission on your device.
- Legal obligation — tax records, regulatory requests, fraud reporting.
4. How customer data is shared with Merchants
Your Velixa account is one global identity that works across the platform. When you book at a Merchant, only the data needed to fulfil that booking is shared with that Merchant: your name, email, phone, the booking, your loyalty balance with them, and the marketing preference you have set for them. Merchants cannot see your bookings at other Merchants, your marketing preferences for other Merchants, your loyalty balances at other Merchants, or your password. Customer-spend totals and loyalty balances shown to a Merchant are calculated only from their own transactions with you.
5. Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Stripe Payments UK Ltd | Card payments, subscription billing, membership recurring charges, gift-card payments | UK / EU |
| OpenAI, Inc. | Automated moderation of reviews and photos (AI-assisted screening) | USA (with UK GDPR safeguards) |
| Email delivery provider | Transactional and (opted-in) marketing email delivery | UK / EU |
| SMS delivery provider | Transactional SMS notifications (booking reminders, confirmations) and (opted-in) marketing SMS | UK / EU |
| Hosting provider | Application hosting and database | UK / EU |
An up-to-date sub-processor list is available on the Data protection page.
6. Marketing
We only send marketing emails or SMS messages where you have given explicit, recorded consent, and we maintain an audit log of every opt-in and opt-out event with timestamp, IP address and source. You can withdraw consent at any time from Marketing preferences or via the unsubscribe link in every marketing email. Transactional messages (booking confirmations, reminders, receipts, membership renewal notices, account security alerts) are sent under the lawful basis of contract performance and are not opt-out. Push notifications are sent only where you have granted permission on your device and can be turned off in your device settings at any time.
7. Payments
Card details are entered into Stripe’s hosted fields and never reach Velixa servers. Stripe is PCI-DSS Level 1 certified. This applies to all payment types on the platform: appointment charges, membership subscriptions, and gift-card purchases. See Stripe’s privacy policy.
8. Cookies & referral tracking
We use a small set of strictly-necessary first-party cookies (session, CSRF). We also set a short-lived marketing-referral cookie when you arrive via a tracked link, so the Merchant can attribute a booking to the marketing channel that brought you. This cookie does not track you across third-party websites and is not used for advertising. We do not use third-party advertising cookies. See the Cookie policy for full details.
9. Data retention
- Booking, membership and payment records: 6 years (UK tax law).
- Loyalty point transaction history: retained for the life of the loyalty programme relationship, then deleted or anonymised.
- Marketing-consent logs: 3 years after consent ends.
- Visitor-tracking and analytics events: 13 months, then aggregated.
- Application and security logs: 13 months.
- Customer accounts: kept until you delete them — at velixa.co.uk/account-deletion or by emailing [email protected]. Deletion removes personal identifiers and anonymises historic bookings to “Deleted customer”. Push-notification tokens and stored payment references are deleted immediately. See Account deletion for full detail.
- Merchant subscription records: life of subscription plus 6 years.
10. Your rights
You have the right to access, rectify, port, restrict, object to, and erase your personal data, and to withdraw consent at any time. To exercise any of these rights, email [email protected]. We will respond within one month. You may also complain to the UK Information Commissioner’s Office (ico.org.uk).
11. Security
All traffic is encrypted with TLS. Passwords are hashed with bcrypt. Sessions use HTTP-only, SameSite cookies and CSRF tokens. Multi-tenant data isolation is enforced by middleware on every request. Role-based access control restricts what each team member can see within a Merchant account. Access to production data is restricted to authorised personnel and is logged.
12. Contact
Privacy enquiries: [email protected]. Postal: Velixa App Ltd, Office 1168, 60 Tottenham Court Road, Fitzrovia, London, W1T 2EW.
Last updated: August 2026