1.Introduction and scope
This policy applies to the Velora Business platform, its dashboards, and the booking pages created through it. It describes how data is collected, used, kept and shared, and when we act as the party responsible for it rather than processing it on a subscribing company's behalf.
It does not apply to external sites or systems a subscribing company may link to from outside the platform, nor to the relationship between a company and its customers beyond their use of the platform.
2.What Velora Business is, and what it is for
Velora Business is software delivered as a service. Service businesses use it to manage bookings, appointments, teams, branches, services and prices, and to receive bookings from their own customers through a booking page of their own.
The purpose is operational: organising a subscribing company's day-to-day work. We do not sell data, and we do not use a company's customer data for advertising.
3.Who this policy covers
Four groups are covered, each with a different relationship to the data:
- The subscribing company: the entity that opens an account on the platform and subscribes to a plan.
- The account owner and team members: the people the company grants access to its dashboard.
- The company's customers: those who book its services through the booking page or through its team.
- Visitors to the public site: people browsing Velora's marketing pages without creating an account.
4.Data processing roles
Our role changes with the category of data, and that distinction is the basis for the rest of this policy.
This description is provisional and open to review; its contractual detail will be set out in a separate data processing agreement with subscribing companies.
- Platform account, operations and security data: we act as the controlling party, because we determine the purposes and means of processing — company account details, sign-in records, security records, and subscription data.
- A company's customer and booking data: we process it as a processor on that company's behalf and on its instructions, and the company remains the controlling party in its relationship with its customers.
- We do not use one company's customer data for our own purposes, and we do not share it with another company on the platform.
5.Categories of data we process
We collect what the platform needs in order to work, and no more. These are the categories as actually implemented:
- Company account and owner: company name, legal name where provided, short identifier, owner email, account status and onboarding stage.
- Team members and permissions: the email used for the invitation, display name, role, membership status, and the pages each role may open.
- Branches and services: branch name, address, phone, email, coordinates and city; services with their categories, prices, durations, opening hours and availability.
- Customers and bookings: customer name and mobile number, booking details, time and status, booking notes, the service city, and for at-home services the service address and its coordinates.
- Subscriptions and billing: the chosen plan, billing interval, seat count, applied price, and subscription events. No payment card data is stored on the platform, and it has no payment gateway integration.
- Communications and notifications: the log of operational WhatsApp messages tied to bookings and verification codes, and browser push subscriptions where enabled.
- Session, device and security: sign-in sessions and the display name on them, records of sensitive administrative changes, and the technical logs needed to operate the service and diagnose faults.
6.How we use the data
We use data for these purposes only:
- Operating the platform and enabling a company to manage its bookings, teams and branches.
- Creating accounts, verifying identity and managing permissions.
- Confirming bookings and sending the operational alerts and reminders that go with them.
- Managing the subscription, the plan and usage limits.
- Technical support and responding to reports and enquiries.
- Protecting the platform, detecting misuse and investigating security incidents.
- Improving the platform's performance and reliability using aggregated operational data.
- Meeting regulatory and contractual obligations.
7.The legal or contractual basis for processing
Our processing rests on performance of the contract with the subscribing company, on the legitimate interest in operating and securing the platform, on compliance with the applicable regulatory requirements in the Kingdom of Saudi Arabia, and on consent wherever consent is the appropriate basis.
For a company's customer data, the subscribing company is responsible for having a lawful basis to collect that data and to share it with us for processing on its behalf.
9.International transfers
Depending on the technical infrastructure in use, some data may be processed or stored by service providers outside the Kingdom. Where that happens, the cross-border transfer requirements of the relevant Saudi regulations and the controls issued by the competent authority are applied.
10.Retention and deletion
We keep data for as long as is necessary to provide the service and to meet regulatory and contractual obligations, after which it is deleted or de-identified.
When a company's subscription ends it may request an export or deletion of its data within a reasonable period, subject to anything that must be retained by law. Per-category retention periods will be set out in the data processing agreement.
Backups may persist for a limited period for disaster recovery, under the same protections.
11.Security and access controls
We apply technical and organisational controls, including:
- Isolating each company's data from every other at the database level, so one company's account cannot reach another's data.
- Role-specific permissions, so a team member sees only what their work requires.
- Hashed passwords, never stored in a readable form.
- Encrypted connections to the platform in transit.
- An append-only record of sensitive administrative changes to the platform team.
- Separating internal operational privileges from browser sessions, so a user session is never granted administrative rights directly.
12.Data subject rights
Under the Personal Data Protection Law of the Kingdom of Saudi Arabia, a data subject has the right to be informed that their data is being processed, to access it, to obtain it in a readable form, to request its correction or update, and to request its destruction once it is no longer needed.
If you are a customer of a company that uses the platform, address your request to that company first, as the party controlling your data; we will support it in carrying the request out.
If you are an account owner or a team member, you can contact us directly using the address at the end of this policy.
13.Marketing communications
The messages the platform sends today are operational by nature: a booking confirmation, an appointment reminder, a verification code, or an alert about the account. They are part of the service and cannot be switched off while the platform is in use.
If we send marketing messages in future, they will be sent with prior consent and every message will carry a clear way to stop them.
15.Children's data and sensitive data
The platform is aimed at companies and their teams, not at children, and we do not knowingly collect data from them.
The platform does not ask for sensitive data such as health, religious or detailed financial information. If a subscribing company enters such data into free-text fields like booking notes, it is responsible for the lawfulness of doing so and for informing its customers.
16.Changes to this policy
We may update this policy whenever the platform's functionality or the regulatory requirements change. The date of the last update is shown at the top of the page.
Where a change is material and affects how data is processed, we will seek to notify subscribing companies by an appropriate means before it takes effect.
17.Contact us
For any privacy question or request, or to exercise your rights, contact us at the address below and we will work to respond within a reasonable period.
Email: privacy@luvelle.sa
Velora Business
Privacy Policy
This policy explains how data is handled inside Velora Business, the platform companies use to run bookings, teams and branches. It separates the data we manage to operate the platform from the data we process on a company's behalf about its own customers.
Last updated