Privacy Policy
Last updated: 2 August 2026
This policy explains how Ghostscript Labs Ltd ("Veluma", "we", "us") collects, uses and protects personal information across everything we run — the Veluma business software and marketing site at velumabusiness.com, and the Veluma consumer marketplace at velumabook.com.
We take your privacy seriously and handle personal data in line with the UK GDPR and the Data Protection Act 2018.
1. Who we are
Ghostscript Labs Ltd (company number SC897850), registered office 3 Ogilvie Way, Livingston, West Lothian, EH54 8HL, is the data controller for the personal information described in this policy, except where we act as a processor for a business (see section 8).
We handle personal data in line with the UK GDPR and the Data Protection Act 2018. For any privacy question, or to exercise your rights, contact us at privacy@velumabusiness.com.
2. Who this policy is for
Veluma is used by two kinds of people: businesses (salons, stylists and other beauty and wellness professionals) who use our software to run bookings and get discovered, and customers who find and book those businesses through velumabook.com. This policy covers both.
3. Information we collect
Depending on how you use Veluma, we collect the following.
- From businesses: your name, email address, phone number, business name and details, the services and prices you offer, your staff and availability, your location, and billing information when you subscribe.
- From customers: your name, email address and phone number when you make a booking; your booking history; any notes or reference photos you add to a booking; reviews you leave; and, if you create an account, your sign-in email.
- From everyone, automatically: technical information such as your IP address, device and browser type, and pages visited, collected through essential cookies and standard server logs.
- Business clients' data: where a business uses Veluma to manage bookings for their own clients, that client information (names, contact details, appointment history) is provided to us by the business.
4. How and why we use your information
We use personal information to provide and operate the service — creating and managing accounts, taking and confirming bookings, sending booking confirmations, reminders and account emails, powering the marketplace and search, displaying reviews, and providing customer support.
We also use it to take payment for business subscriptions, to keep the service secure and prevent abuse, to improve Veluma, and to meet our legal obligations.
Our lawful bases under the UK GDPR are: performance of a contract (to provide the service you or a business have signed up for); our legitimate interests (to run, secure and improve Veluma, and to send service-related emails); your consent (where required, for example certain marketing); and compliance with a legal obligation.
5. AI features
Some Veluma features use artificial intelligence — for example generating website content, drafting messages, categorising services and answering marketplace searches. To provide these, relevant content you enter may be sent to our AI provider (OpenAI) to generate a response. We do not permit your content to be used to train their models. We don't use AI to make decisions that have legal or similarly significant effects on you.
6. Cookies
We use a small number of strictly necessary cookies — mainly to keep you signed in and keep the service secure. Because these are essential to providing a service you've asked for, they don't require consent. If we introduce analytics or marketing cookies in future, we'll ask for your consent first and update this policy.
7. Who we share information with
We do not sell your personal information. We share it only with trusted service providers who process it on our behalf, under contract and only as needed to run Veluma:
- Supabase — database, authentication and file hosting.
- Vercel — application hosting and infrastructure.
- Resend — sending transactional and account emails.
- OpenAI — powering AI features (as described in section 5).
- Stripe — processing subscription payments (once billing is live).
- OpenStreetMap / Nominatim — converting addresses to map locations for search.
- When a business lists on the marketplace, the business's public profile, services and reviews are shown to customers on velumabook.com.
8. When a business is the controller
When a business uses Veluma to manage bookings and information about their own clients, that business is the data controller for their client data and Veluma acts as their data processor — we process it only on their instructions to provide the service. If you're a customer of one of these businesses, that business's own privacy notice governs how they use your information, and you should contact them directly about it.
9. Where your information is stored
Some of our service providers are based outside the UK, including in the United States. Where personal information is transferred outside the UK, we rely on appropriate safeguards — such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — so it stays protected.
10. How long we keep it
We keep personal information for as long as your account is active and as long as we need it for the purposes in this policy, and then for a reasonable period afterwards to meet legal, accounting or dispute-resolution requirements. When it's no longer needed, we delete or anonymise it.
11. Your rights
Under the UK GDPR you have the right to:
- access the personal information we hold about you;
- have inaccurate information corrected;
- have your information erased in certain circumstances;
- restrict or object to certain processing;
- receive your information in a portable format;
- withdraw consent where we rely on it; and
- complain to the ICO (ico.org.uk) if you're unhappy with how we've handled your data — though we'd appreciate the chance to help first.
12. Keeping your information secure
We use appropriate technical and organisational measures to protect personal information — including encryption in transit, access controls, and reputable infrastructure providers. No system is completely secure, but we work hard to protect your data and to respond quickly if something goes wrong.
13. Children
Veluma isn't directed at children. Customer accounts are intended for people aged 16 or over, and business accounts for those aged 18 or over. If you believe a child has given us personal information, contact us and we'll remove it.
14. Changes to this policy
We may update this policy as Veluma grows or the law changes. If we make a material change, we'll take reasonable steps to let you know. The date at the top shows when it was last updated.
15. Contact us
For any privacy question or to exercise your rights, email us at privacy@velumabusiness.com or write to Ghostscript Labs Ltd, 3 Ogilvie Way, Livingston, West Lothian, EH54 8HL.