Privacy Policy
Last updated: July 25, 2026
This Privacy Policy describes how Velora Calendars (“we”, “us”, or “our”) collects, uses, and shares information when you use our website and online appointment scheduling service (the “Service”).
1. Who we are
Velora Calendars provides multi-tenant booking software for businesses such as salons, clinics, tutors, and gyms. Business owners create accounts; their customers book appointments via a public booking link. Contact: support@veloraai.site.
2. Information we collect
- Business account data: business name, owner email, password (stored as a one-way hash), timezone, working hours, services, message templates, and plan information.
- Booking data: customer name, phone number (required for WhatsApp), optional email, appointment date/time, service selected, and related status fields.
- Technical data: IP address for rate limiting public booking requests, cookies for authenticated sessions, and standard server logs.
- Google account data (optional): if a business owner connects Google Calendar, we store an encrypted OAuth refresh token and calendar identifiers needed to sync availability and events.
3. How we use information
- To provide booking pages, dashboards, and availability logic.
- To send WhatsApp and (when email is provided) email confirmations, reminders, and cancellation notices.
- To sync with Google Calendar when the owner has connected it: read free/busy times and create or delete booking-related events.
- To secure accounts, prevent abuse, and improve the Service.
4. Google Calendar / Google API data
Connecting Google Calendar is optional. When connected, Velora Calendars uses Google OAuth to access Calendar free/busy information and to create or delete events that correspond to bookings on our platform. We use Google user data only to provide and improve these scheduling features for the connecting business owner.
We do not sell Google user data, use it for advertising, or share it with unrelated third parties. Owners may disconnect Google Calendar at any time from Settings, which revokes access and removes stored refresh tokens from our systems where technically feasible.
Velora Calendars's use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Sharing with service providers
We use trusted processors to operate the Service, including hosting/database providers, Twilio (WhatsApp messaging), Gmail (transactional email, when configured), and Google (Calendar API, when connected). These providers process data only as needed to deliver their services to us.
6. How we protect sensitive data
We take technical and organizational measures to protect personal data and Google user data against unauthorized access, loss, misuse, or disclosure. These include:
- Encryption in transit: the Service is served over HTTPS/TLS so data exchanged between your browser and our servers is encrypted.
- Encryption at rest for Google tokens: Google OAuth refresh tokens are encrypted before storage in our database and decrypted only server-side when making Calendar API calls.
- Password hashing: business account passwords are stored using one-way hashing (not reversible plaintext).
- Access controls: authenticated sessions use secure httpOnly cookies. Dashboard and Google integration actions require an authenticated business owner (or authorized staff) session. Google Calendar data is used only for the connecting business and is not exposed to other tenants.
- Least privilege: we request only the Google Calendar scopes needed for scheduling (
calendar.eventsandcalendar.freebusy). We do not request access to Gmail, Drive, Contacts, or other Google products. - Infrastructure controls: application data is hosted with reputable cloud providers that apply industry- standard physical and network security controls.
- Revocation & deletion: disconnecting Google Calendar from Settings revokes API access and removes stored refresh tokens where technically feasible. Account deletion requests are handled via support@veloraai.site.
No method of transmission or storage is 100% secure. If you believe your account or Google connection has been compromised, disconnect Google Calendar immediately and contact us.
7. Cookies
We use an httpOnly authentication cookie for business owner sessions. We do not use third-party advertising cookies.
8. Data retention
We retain account and booking data while the account is active and as needed to provide the Service, resolve disputes, and meet legal obligations. You may request deletion of your business account by contacting us.
9. Your choices
- Update business profile and settings in the dashboard.
- Disconnect Google Calendar at any time.
- Contact us to access, correct, or delete account data.
10. Contact
Privacy questions: support@veloraai.site
Also see our Terms of Service.