nuvelo.
TermsCookiesGuide

Privacy policy

Last updated: 24 July 2026 · nuvelo and Nuvelo.net are trading names of Nuvelo Reservations Ltd (company no. 17350115), Monomark House, 27 Old Gloucester Street, London WC1N 3AX, United Kingdom

1. Introduction

This privacy policy sets out how nuvelo ("we", "us", "our") collects, uses, stores, shares and protects personal data, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection law.

nuvelo and Nuvelo.net are trading names of Nuvelo Reservations Ltd, a company registered in England and Wales under company number 17350115, with its registered office at Monomark House, 27 Old Gloucester Street, London WC1N 3AX, United Kingdom. We are registered with the UK Information Commissioner's Office (ICO) as a data controller under registration reference CSN8611072.

This policy applies to our website at nuvelo.net (and related subdomains such as booking-demo.nuvelo.net) and to the nuvelo booking service. It covers two groups: the venues who use nuvelo to take bookings, and the guests who book with those venues. By using our website or services you acknowledge that you have read and understood this policy.

2. Controller and processor

For your own account data as a venue, and for visitors to our own website, nuvelo is the data controller. For the guest data a venue collects through nuvelo (bookings, contact details, notes, visit history), the venue is the controller and nuvelo is the processor — we process that data on the venue's documented instructions to run the booking service. A separate Data Processing Agreement (UK GDPR Article 28) governs that relationship. Our contact details for data-protection matters are in Section 15.

3. What data we collect

WhoData
Venue accountsName, email, hashed password, two-factor authentication secret, venue settings, and subscription/billing status.
GuestsName, email, phone number, party size, booking date/time, any answers to a venue's booking questions (e.g. allergies, occasion), booking and visit history and — where a venue uses it — real spend recorded from its till and loyalty balances.
PaymentsCard payments are handled by Stripe or Square (whichever the venue uses); we never store full card numbers. For no-show protection we store a payment-method reference held at Stripe or Square, not the card itself.
TechnicalInternet protocol (IP) address (for rate-limiting and security) and a single functional cookie for the interactive demo (nuvelo_sandbox). See Section 10.

We do not deliberately collect special category data. Where a guest volunteers health-related information in a booking note (for example, an allergy or accessibility need), it is processed only to fulfil that booking, on the basis set out in Section 5.

4. How we collect your data

  • Directly from you — when a venue registers an account, configures its settings or contacts us, and when a guest makes, amends or cancels a booking.
  • Automatically — limited technical data (such as your IP address and the demo cookie) is collected as you interact with our website, for security and to make the service work.
  • From a venue — where a venue enters a booking on a guest's behalf, or records a guest's spend from its own till or point-of-sale system.

5. How we use your data, and our legal bases

We use personal data only where the law allows. Under Article 6 of the UK GDPR we rely on the following bases:

  • Contract — to provide the service: taking and managing bookings, deposits, payments and confirmations, and administering a venue's subscription and account.
  • Legitimate interests — for booking confirmations and reminders, security, fraud prevention, troubleshooting and improving the service, provided these interests are not overridden by your rights.
  • Consent — for a venue's marketing messages to its guests (or the soft opt-in), always with one-tap unsubscribe; and for any non-essential cookies, were we to introduce them.
  • Legal obligation — to meet our legal, accounting and tax obligations.

6. Who we share it with

We share personal data only with the sub-processors and third parties needed to run the service:

  • Stripe — card payment processing and subscription billing.
  • Square — card payment processing, for venues that take payments through their own Square account.
  • SumUp — card payment processing, for venues that take payments through their own SumUp account.
  • Twilio — sending SMS.
  • Microsoft (Microsoft 365) — sending transactional and marketing email.
  • DigitalOcean — cloud hosting for the live service (London, UK).
  • Cloudflare — content delivery, network security, and encrypted off-site database backups (Cloudflare R2).

We may also share data with our professional advisers (such as accountants or lawyers), and with regulators or authorities where the law requires it. If the business is ever sold or transferred, data may pass to the buyer under the same protections. We require every third party to respect the security of your data and to process it only on our instructions. We do not sell personal data. A current list of sub-processors is available on request.

7. International transfers

Our hosting and database backups are kept in the UK. Some providers (for example Stripe, Square and Twilio) may process data outside the UK/EEA. Where they do, transfers are protected by an appropriate safeguard — a UK adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

8. Data retention

We keep personal data only for as long as is reasonably necessary for the purposes we collected it, including to meet legal, accounting and dispute-resolution requirements. In practice:

  • Booking and account data is kept while a venue's account is active, and afterwards only as needed for legal, accounting and dispute-resolution purposes.
  • Erased records are anonymised on request, keeping only what a venue needs for its own accounting.
  • Operational logs are kept for a limited period and then deleted automatically — security and audit logs for up to 24 months, and message (email/SMS) logs for around 13 months.

Where we anonymise data so it can no longer be linked to you, we may keep that anonymised information without further notice.

9. Your rights

Under the UK GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), to object (Art. 21), not to be subject to solely automated decisions (Art. 22), and to withdraw consent at any time. nuvelo builds these in:

  • Guests — every booking confirmation links to a page where you can download the data held about you or request deletion (confirmed by email).
  • Venues — export or erase a guest from the guest book, and export or close your own account.

We do not use solely automated decision-making that produces legal or similarly significant effects. To exercise a right, use the in-app tools or contact us (Section 15). We respond within one month; there is no fee unless a request is clearly unfounded, repetitive or excessive.

10. Cookies

nuvelo uses a single functional cookie for the interactive demo (nuvelo_sandbox). Admin sign-in uses your browser's storage, not cookies. We do not use analytics or third-party advertising cookies. Full details are in our cookie policy.

11. Children's privacy

Our services are not directed at children. Soft-play and family bookings are made by adults on behalf of children; nuvelo does not create accounts for children or knowingly collect their data beyond the counts and age-bands a parent enters to book. If you believe a child has provided us with personal data, contact us (Section 15) and we will delete it.

12. Third-party links

Our website and emails may link to third-party sites (for example a venue's own website, or a payment provider's checkout). We do not control those sites and are not responsible for their privacy practices; we encourage you to read the privacy policy of every site you visit.

13. Data security

We take appropriate technical and organisational measures to protect personal data: passwords are hashed, venue payment keys are encrypted at rest (AES-256-GCM), optional two-factor authentication is available, all traffic is served over HTTPS, and data is backed up to encrypted off-site storage. We have procedures to handle any suspected personal data breach and will notify you and the Information Commissioner's Office where we are legally required to do so. No system is perfectly secure, but we work to protect your data.

14. Changes to this policy

We may update this policy from time to time by publishing a new version on our website. Material changes will be notified to venue account holders. Please check this page occasionally. This policy was last updated on the date shown at the top.

15. How to contact us

For any question about this policy, or to exercise your rights, contact us:

  • Email: [email protected]
  • Post: Nuvelo Reservations Ltd (nuvelo), Monomark House, 27 Old Gloucester Street, London WC1N 3AX, United Kingdom

16. Supervisory authority

You have the right to complain to the Information Commissioner's Office (ICO), the UK data-protection regulator, at ico.org.uk. We would appreciate the chance to address your concerns first, so please contact us before you approach the ICO. The ICO can be reached at: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 0303 123 1113.

nuvelo · home · terms · website terms · cookies · guide