Last updated: 24 July 2026 · nuvelo and Nuvelo.net are trading names of Nuvelo Reservations Ltd (company no. 17350115), Monomark House, 27 Old Gloucester Street, London WC1N 3AX, United Kingdom
This privacy policy sets out how nuvelo ("we", "us", "our") collects, uses, stores, shares and protects personal data, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable data protection law.
nuvelo and Nuvelo.net are trading names of Nuvelo Reservations Ltd, a company registered in England and Wales under company number 17350115, with its registered office at Monomark House, 27 Old Gloucester Street, London WC1N 3AX, United Kingdom. We are registered with the UK Information Commissioner's Office (ICO) as a data controller under registration reference CSN8611072.
This policy applies to our website at nuvelo.net (and related subdomains such as booking-demo.nuvelo.net) and to the nuvelo booking service. It covers two groups: the venues who use nuvelo to take bookings, and the guests who book with those venues. By using our website or services you acknowledge that you have read and understood this policy.
For your own account data as a venue, and for visitors to our own website, nuvelo is the data controller. For the guest data a venue collects through nuvelo (bookings, contact details, notes, visit history), the venue is the controller and nuvelo is the processor — we process that data on the venue's documented instructions to run the booking service. A separate Data Processing Agreement (UK GDPR Article 28) governs that relationship. Our contact details for data-protection matters are in Section 15.
| Who | Data |
|---|---|
| Venue accounts | Name, email, hashed password, two-factor authentication secret, venue settings, and subscription/billing status. |
| Guests | Name, email, phone number, party size, booking date/time, any answers to a venue's booking questions (e.g. allergies, occasion), booking and visit history and — where a venue uses it — real spend recorded from its till and loyalty balances. |
| Payments | Card payments are handled by Stripe or Square (whichever the venue uses); we never store full card numbers. For no-show protection we store a payment-method reference held at Stripe or Square, not the card itself. |
| Technical | Internet protocol (IP) address (for rate-limiting and security) and a single functional cookie for the interactive demo (nuvelo_sandbox). See Section 10. |
We do not deliberately collect special category data. Where a guest volunteers health-related information in a booking note (for example, an allergy or accessibility need), it is processed only to fulfil that booking, on the basis set out in Section 5.
We use personal data only where the law allows. Under Article 6 of the UK GDPR we rely on the following bases:
We share personal data only with the sub-processors and third parties needed to run the service:
We may also share data with our professional advisers (such as accountants or lawyers), and with regulators or authorities where the law requires it. If the business is ever sold or transferred, data may pass to the buyer under the same protections. We require every third party to respect the security of your data and to process it only on our instructions. We do not sell personal data. A current list of sub-processors is available on request.
Our hosting and database backups are kept in the UK. Some providers (for example Stripe, Square and Twilio) may process data outside the UK/EEA. Where they do, transfers are protected by an appropriate safeguard — a UK adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
We keep personal data only for as long as is reasonably necessary for the purposes we collected it, including to meet legal, accounting and dispute-resolution requirements. In practice:
Where we anonymise data so it can no longer be linked to you, we may keep that anonymised information without further notice.
Under the UK GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), to object (Art. 21), not to be subject to solely automated decisions (Art. 22), and to withdraw consent at any time. nuvelo builds these in:
We do not use solely automated decision-making that produces legal or similarly significant effects. To exercise a right, use the in-app tools or contact us (Section 15). We respond within one month; there is no fee unless a request is clearly unfounded, repetitive or excessive.
nuvelo uses a single functional cookie for the interactive demo (nuvelo_sandbox). Admin sign-in uses your browser's storage, not cookies. We do not use analytics or third-party advertising cookies. Full details are in our cookie policy.
Our services are not directed at children. Soft-play and family bookings are made by adults on behalf of children; nuvelo does not create accounts for children or knowingly collect their data beyond the counts and age-bands a parent enters to book. If you believe a child has provided us with personal data, contact us (Section 15) and we will delete it.
Our website and emails may link to third-party sites (for example a venue's own website, or a payment provider's checkout). We do not control those sites and are not responsible for their privacy practices; we encourage you to read the privacy policy of every site you visit.
We take appropriate technical and organisational measures to protect personal data: passwords are hashed, venue payment keys are encrypted at rest (AES-256-GCM), optional two-factor authentication is available, all traffic is served over HTTPS, and data is backed up to encrypted off-site storage. We have procedures to handle any suspected personal data breach and will notify you and the Information Commissioner's Office where we are legally required to do so. No system is perfectly secure, but we work to protect your data.
We may update this policy from time to time by publishing a new version on our website. Material changes will be notified to venue account holders. Please check this page occasionally. This policy was last updated on the date shown at the top.
For any question about this policy, or to exercise your rights, contact us:
You have the right to complain to the Information Commissioner's Office (ICO), the UK data-protection regulator, at ico.org.uk. We would appreciate the chance to address your concerns first, so please contact us before you approach the ICO. The ICO can be reached at: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF; telephone 0303 123 1113.