LEGAL

Privacy Policy

Last updated Monday 28 September

This policy explains what personal data VELURA holds about companions, clients and visitors, why, who else handles it, how long it is kept, and the rights you have over it under the EU General Data Protection Regulation (GDPR).

1. Visitors

You can browse VELURA without an account. We do not use analytics, advertising or tracking tools, and we do not build profiles of visitors. Like any website, the servers that deliver the site briefly process your IP address and technical request data to send you the page and protect the service.

2. Clients who request a booking

When you request a booking we collect:

  • your name, email address and phone number, and any message you choose to write;
  • the companion, service, date and time you chose, and the language you were reading the site in, so our emails reach you in it;
  • whether you asked for emails about your booking and for a review link, and how you would like the companion to contact you;
  • the messages you and the companion exchange in the booking's conversation, and when each of you last read it;
  • your IP address and email address in a separate log used only to limit how many requests can be sent, which is deleted after 30 days.

Your name, email, phone and message are shared with the companion you asked, so they can answer and arrange the appointment with you. They are not shown publicly or to anyone else.

The conversation about a booking is private between you and the companion. Nobody at VELURA reads it unless one of you reports it; a report lets our moderators read that conversation in order to deal with it.

If you leave a review, its rating, text and the tags you chose are published on the companion's profile under your initial or first name, as you choose.

We do not ask for, and ask you not to include, information about your health, sex life or sexual orientation.

3. Companions

When you create an account and a profile we collect:

  • your email address and password (stored only in hashed form), or your Google account's email and name if you sign in with Google;
  • your profile: display name, age, country, city, languages, description, photos, WhatsApp number if you give one, services, prices, availability, time zone and preferred language;
  • your settings, such as which emails you want to receive;
  • your messages with clients in booking conversations, and with VELURA in your support conversation;
  • the bookings and reviews connected to your profile, and our record of reviewing and moderating your profile.

Your published profile is public by design. Your email address, and the notes we keep about reviewing your profile, are never shown on it.

4. Why we use it, and on what basis

  • To run the platform — publish profiles, pass booking requests, send the emails that belong to a booking, publish reviews: necessary to perform our contract with you (Art. 6(1)(b) GDPR), or to take steps you asked for before one.
  • To keep VELURA safe — limit request rates, review profiles before publication, act on reports, prevent fraud and abuse: our legitimate interest in a safe, lawful platform (Art. 6(1)(f)).
  • To send you a review link after an appointment: your consent, given with the tick-box on the booking form, which you can withdraw by simply not using the link.
  • To meet our legal obligations, such as answering lawful requests from authorities and keeping accounting records: Art. 6(1)(c).

We do not sell personal data, use it for advertising, or make decisions about you by automated means alone.

5. Who else handles it

We use a small number of service providers who process data on our behalf, under contract and only on our instructions:

  • Supabase — database, sign-in and photo storage, hosted in [SUPABASE DATA REGION].
  • Vercel — hosting and delivery of the website.
  • Resend — sending our emails.
  • Google — only if you choose to sign in with Google.
  • Stripe — payment for companion subscriptions and paid options, once those are offered. We never see or store card details.

Some of these providers are based in, or may access data from, the United States. Where data leaves the European Economic Area, the transfer is covered by the EU–US Data Privacy Framework or by the European Commission's standard contractual clauses.

If a companion lists a WhatsApp number, contact through WhatsApp happens between the client and the companion on that service, under its own terms and privacy policy.

6. How long we keep it

  • Request-rate log (email and IP address): 30 days.
  • Review links: they expire after 30 days, and only a one-way fingerprint of the link is ever stored.
  • Booking records: kept as a record for both the client and the companion while the companion's account exists. A client can ask us to erase or anonymise their details at any time, unless we need them to establish or defend a legal claim.
  • Booking conversations: closed 7 days after the appointment, or when a request is declined, cancelled or expires, and deleted 30 days after closing. A reported conversation is kept until the report has been dealt with.
  • Your conversation with VELURA: while your account exists; deleting the account deletes it.
  • Companion accounts: until you delete the account. Deleting it from Settings removes your photos and erases your name, contact details, description and profile address at once, and declines any request still waiting. Bookings other people were part of are kept without your details, because they are their records too. Your sign-in record (your email address) remains until you ask us to remove it.
  • Accounting records for paid features: as long as tax law requires.

7. Your rights

You have the right to access your data, to have it corrected or erased, to restrict or object to its use, and to receive it in a portable format. Companions can download everything we hold about them from Settings and delete their account there. Anyone else can write to appvelura@gmail.com; we answer within one month.

Where we rely on your consent, you can withdraw it at any time without affecting what was done before.

You can also complain to a data protection authority — in Portugal, the Comissão Nacional de Proteção de Dados (www.cnpd.pt) — or to the authority where you live.

8. Cookies

VELURA sets only cookies that are strictly necessary for the site to work. They need no consent, which is why you do not see a cookie banner. We use no analytics, advertising or third-party tracking cookies; if that ever changes, we will ask for your consent first.

  • NEXT_LOCALE — remembers the language you chose. Kept for one year.
  • sb-…-auth-token — keeps a companion or administrator signed in. Set only when you sign in, and removed when you sign out.
  • sb-…-auth-token-code-verifier — protects the Google sign-in against interception. Set only while you are signing in with Google, for a few minutes.

If you sign in with Google, Google sets its own cookies on its own website under its own policy.

9. Security

Data travels over encrypted connections. Access to it is limited by database rules so that each account can reach only its own records, and the few operations that need wider access run on our servers, never in your browser. Passwords are stored only in hashed form. No system is perfectly secure; if a breach puts your rights at risk, we will tell you and the authority as the law requires.

10. Changes to this policy

We will update this policy when what we do with data changes. The date at the top shows the current version, and we tell companions by email about any significant change.