Privacy Policy
1. Who we are
The controller of your personal data is VENUEBOOKER SOLUTIONS LTD (“VenueBooker”, “we”, “us”), a company registered in Northern Ireland with Company No. NI737741.
- Registered office: 1 Glebecoole Drive, Newtownabbey, Northern Ireland, BT36 6HZ
- Email: bookings@venuebooker.co
“VenueBooker” is a trading name of VENUEBOOKER SOLUTIONS LTD.
2. Scope of this policy
This policy covers personal data processed through:
- the website at venuebooker.co (the “Website”); and
- the mobile applications published by VENUEBOOKER SOLUTIONS LTD on the Apple App Store and Google Play, including the VenueBooker operator app (the “Apps”), once released.
Where venue operators use VenueBooker to manage their hirers’ bookings, the venue operator determines why that hirer data is collected and we process it to provide the service; the operator remains responsible for its own hirer relationships. This policy describes our processing in all cases.
3. Data we collect on the website
3.1 Email correspondence
If you email us (for example to join the early-access waitlist), we receive your email address, name if included, and the content of your message. We use this to reply, to manage the waitlist and to send you the updates you asked for.
3.2 Server logs
The Website is served by Cloudflare, which generates standard server logs (IP address, user agent, requested URL, timestamp) for security, abuse prevention and service delivery. We do not use these logs to identify individual visitors.
3.3 No analytics or advertising cookies
The Website sets no analytics cookies and no advertising cookies. The only cookies that may be set are strictly-necessary security cookies from Cloudflare — see our Cookie Policy.
4. Data we collect in our apps
The Apps are not yet released. This section describes the data the Apps will process at launch; we will update this policy before any material change.
4.1 Account information
Name, work email address, password (stored only as a cryptographic hash), venue name and your role at the venue. Used to create and secure your account and connect you to your venue’s workspace.
4.2 User content
Content you create in the service: spaces and calendars, booking records, hirer contact details you enter, function-sheet notes and attachments. Stored on our cloud infrastructure hosted by Cloudflare; your content remains yours and is processed only to provide the service.
4.3 Booking data
Booking dates and times, spaces booked, booking status, deposit and payment status, and communications about a booking. Used to operate the calendar, prevent double-bookings, generate function sheets and produce utilisation reports for your venue.
4.4 Device and technical data
Device model, operating system version, app version, language and time zone, and a device identifier necessary to deliver push notifications. Used for compatibility, security and service delivery.
4.5 Usage analytics
Aggregated, privacy-preserving usage metrics (for example which features are used and how often) to improve the product. These metrics contain no advertising identifiers and are not used to profile individuals.
4.6 Crash diagnostics
If the app crashes, we collect crash logs and diagnostic data (stack trace, device model, OS version, app state at crash) to find and fix defects.
4.7 App permissions
- Notifications — requested so we can alert you to new booking requests, changes and payment events. Optional; the app works without it. Revoke at any time in iOS Settings → Notifications or Android Settings → Apps → Notifications.
- Camera / photo library (only if you use attachment features) — requested only when you choose to attach a photo to a booking or function sheet. Optional and revocable in your device settings at any time.
The Apps request no other permissions. Each permission is asked for in context, with its purpose stated, and never at first launch as a blanket request.
4.8 What we do not do
We do NOT: sell your personal data; use advertising SDKs; track you across other companies’ apps or websites; or collect precise location data.
5. Purposes and lawful bases
| Purpose | Data used | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Answering enquiries and managing the early-access waitlist | Email correspondence | Legitimate interests (responding to people who contact us); consent for waitlist updates |
| Providing and securing the Website | Server logs, security cookies | Legitimate interests (running a secure website) |
| Creating and operating your account | Account information | Contract (performance of our terms with you) |
| Operating bookings, calendars, payments status and function sheets | User content, booking data | Contract |
| Sending push notifications you enable | Device data (push token) | Consent (via the notification permission), revocable at any time |
| Improving the product | Aggregated usage analytics | Legitimate interests (understanding how features are used, without profiling) |
| Fixing crashes and defects | Crash diagnostics | Legitimate interests (keeping the Apps working) |
| Meeting legal obligations (tax, accounting, disputes) | Invoices, essential records | Legal obligation |
6. Who we share data with
We share personal data only with service providers who process it on our instructions, and only as needed to run the service:
- Cloudflare, Inc. — website hosting, content delivery, security and cloud infrastructure.
- Apple Inc. — App Store distribution and iOS push notification delivery (once the iOS app is released).
- Google LLC — Google Play distribution and Android push notification delivery (once the Android app is released).
We commit to keeping this list current: before we add any new category of recipient (for example a payment processor at launch), we will update this policy. We do not share personal data with advertisers or data brokers, and we do not sell it. We may disclose data where the law requires (for example to a court or regulator), or as part of a corporate transaction, in which case this policy would continue to apply to it.
7. International transfers
We store data in the UK/EEA region where practicable. Where a provider processes data outside the UK (for example Cloudflare, Apple or Google infrastructure in the United States), we rely on one or more of: a UK adequacy decision for the destination country; the UK International Data Transfer Agreement (IDTA); or the UK Addendum to the EU Standard Contractual Clauses, together with any required supplementary measures.
8. How long we keep data
- Waitlist & enquiry emails: kept while you remain on the waitlist or your enquiry is open; deleted within 30 days of you asking to be removed, and in any event reviewed every 24 months.
- Account information: kept while your account is active; deleted within 30 days of account deletion (section 12).
- User content & booking data: kept while your account is active; deleted within 30 days of account deletion, subject to your venue’s export before closure.
- Push notification tokens: deleted when you disable notifications or delete the app/account.
- Aggregated usage analytics: contain no personal identifiers and are kept indefinitely in aggregate form.
- Crash diagnostics: deleted or anonymised within 12 months.
- Server logs: retained by Cloudflare for short rolling periods per its security practices; we do not retain separate copies.
- Invoices and records required by law: up to 6 years after the end of the relevant financial year (UK statutory requirement).
9. Your rights
Under UK GDPR you have the right to:
- Access — obtain a copy of your personal data;
- Rectification — correct inaccurate or incomplete data;
- Erasure — have your data deleted (“right to be forgotten”);
- Restriction — limit how we process your data;
- Data portability — receive your data in a structured, machine-readable format;
- Objection — object to processing based on legitimate interests, and to any direct marketing;
- Withdraw consent — at any time, where processing is based on consent, without affecting prior processing;
- Rights related to automated decision-making — we do not make solely automated decisions with legal or similarly significant effects; if that ever changed you would have the right to human review.
To exercise any right, email bookings@venuebooker.co. We may need to verify your identity. We respond within one month of receiving a valid request (extendable by two further months for complex requests, in which case we will tell you within the first month). Exercising your rights is free of charge.
10. Complaints to the ICO
If you are unhappy with how we handle your data, please contact us first — we take complaints seriously. You also have the right to complain to the UK supervisory authority:
- Information Commissioner’s Office (ICO) — ico.org.uk
- Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Telephone: 0303 123 1113
11. Children
The Website and Apps are business tools intended for adults and are not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact bookings@venuebooker.co and we will delete it promptly.
12. Account & data deletion
You can delete your VenueBooker account and associated personal data at any time:
12.1 In the app (once the Apps ship)
Go to Settings → Account → Delete account and confirm. Your account is deactivated immediately.
12.2 By email (available now)
Email bookings@venuebooker.co with the subject line “Account deletion request” from the address linked to your account or waitlist entry.
In both cases deletion completes within 30 days. We retain only the minimum data the law requires us to keep (for example invoices for tax purposes, retained up to 6 years) and a suppression record of your deletion request itself. Step-by-step instructions are also published on our Support page.
13. iOS App Tracking Transparency
The VenueBooker iOS app will not track you across apps or websites owned by other companies, and will not access the device advertising identifier (IDFA). Because no tracking occurs, the app does not need to show the App Tracking Transparency (ATT) permission prompt. If our practices ever changed in a way that constitutes “tracking” under Apple’s definition, we would ask for your consent through the ATT prompt first — consent-first, always.
14. Google Play Data Safety
The Data Safety section of the VenueBooker listing on Google Play will accurately reflect this policy: what data the Android app collects (sections 4.1–4.6), why, that data is encrypted in transit, that no data is sold or shared for advertising, and that users can request deletion (section 12). If this policy and a store listing ever disagree, this policy governs and we will correct the listing.
15. Security
We apply technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; passwords stored only as salted cryptographic hashes; access to production data restricted to authorised personnel on a need-to-know basis; separation of production and development environments; security headers and platform protections on the Website; and prompt application of security updates. No system is perfectly secure; if a breach affecting your data ever occurred, we would notify you and the ICO as required by law.
16. Changes to this policy
We may update this policy as the product develops — in particular before the Apps launch and before any new data recipient is added. The effective date at the top will change, and for material changes we will notify account holders and waitlist members by email before the change takes effect. Earlier versions are available on request.
17. Contact us
Questions about this policy or your data:
- Email: bookings@venuebooker.co (replies within one business day)
- Post: VENUEBOOKER SOLUTIONS LTD, 1 Glebecoole Drive, Newtownabbey, Northern Ireland, BT36 6HZ