Privacy Policy
Last updated: 6 September 2026
This Privacy Policy explains how Velquro ("Velquro", "we", "us", "our") collects, uses, stores, and protects personal data in connection with the Velquro business management platform available at https://velquro.co.uk (the "Service"). It applies to visitors to our website, customers who register for an account, and individuals whose data our customers store within the Platform, such as their own customers and employees. By using the Service, you acknowledge that you have read and understood this Policy.
1. Introduction
This Privacy Policy explains how Velquro ("Velquro," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with our website and our web-based business management platform, which combines customer relationship management (CRM), project management, HR administration, and financial record-keeping tools within a single online dashboard (together, the "Service").
This Policy applies to: (a) visitors to our website; (b) individuals who purchase or register for a Velquro account ("Customers"); (c) individuals authorized by a Customer to use the Service under that Customer's account, such as employees or contractors ("Authorized Users"); and, where relevant, (d) individuals whose personal data a Customer enters into the Service as part of using its CRM, HR, or financial record-keeping tools, such as the Customer's own leads, clients, and employees ("End-Data Subjects").
This Policy should be read together with our Terms and Conditions, our Cookie Policy, and, where applicable, our Refund and Cancellation Policy, each of which forms part of the overall terms governing use of the Service.
We recommend reviewing this Policy periodically, since we may update it from time to time as described in Section 14 (Changes to This Policy) below.
2. Our Role: Controller and Processor
Because Velquro's Service is used by Customers to store and manage information about their own customers, leads, and employees, it's important to understand the different roles Velquro plays with respect to different categories of personal data.
(a) Velquro as data controller. In relation to the personal data of our website visitors, our Customers, and our Customers' Authorized Users — for example, account registration details, billing information, support communications, and website usage data — Velquro generally acts as the data controller (or equivalent term under applicable law), determining the purposes and means of processing that data as described in this Policy.
(b) Velquro as data processor (or service provider). In relation to the personal data that a Customer inputs into the Service about its own leads, customers, and employees — such as CRM contact records, HR employee records, and financial data relating to a Customer's own clients — Velquro generally acts as a data processor (or "service provider," under certain U.S. state privacy laws), processing that data on behalf of, and under the instructions of, the Customer, who acts as the data controller for that information. Where a separate data processing agreement is in place between Velquro and a Customer, the terms of that agreement govern Velquro's processing of such data, in addition to the general commitments described in this Policy.
(c) Customer responsibility for End-Data Subjects. As set out in our Terms and Conditions, Customers are responsible for ensuring they have an appropriate legal basis and any necessary consents to input personal data about their own leads, customers, and employees into the Service, and for responding to any requests such individuals may make regarding their personal data, except to the extent Velquro is required to assist as a processor under applicable law or a data processing agreement.
If you are an End-Data Subject whose personal data has been entered into the Service by a Customer (for example, because you are a client or employee of a business that uses Velquro), and you have questions or requests regarding that data, you should generally direct these to the relevant Customer in the first instance, since they control how that data is used. Velquro will support a Customer in responding to such requests where reasonably required, consistent with our role as a processor.
3. Personal Data We Collect
We collect several categories of personal data in connection with the Service, depending on how you interact with us.
(a) Account and registration data. When you register for a Velquro account, we collect information such as your name, business name, email address, phone number (where provided), and password (stored in encrypted or hashed form).
(b) Payment and billing data. When you purchase a Velquro package, payment card and billing details are collected and processed by Stripe, our third-party payment processor, on our behalf. Velquro does not directly store your full payment card number; we retain limited billing-related information such as transaction references, purchase dates, package selected, and billing address, as necessary to administer your account and process any refund requests under our Refund and Cancellation Policy.
(c) Customer Data entered into the Service. As a Customer uses the Service, they and their Authorized Users may input a wide range of information into the platform, including: CRM records relating to the Customer's own leads and clients (names, contact details, notes, sales pipeline status); project and task information (task descriptions, deadlines, team assignments); HR records relating to the Customer's own employees (contact details, leave records, onboarding documents, other employee documentation); and financial records (invoices, income and expense entries, payment status). We refer to this information collectively, together with any other data a Customer inputs into the Service, as "Customer Data," and it is handled as described in Section 2(b) above.
(d) Communications. When you contact our support team, respond to a survey, or otherwise communicate with us, we collect the content of those communications along with your contact details and any other information you choose to provide.
(e) Website usage and technical data. When you visit our website or use the Service, we (and, where applicable, our service providers) may automatically collect technical information such as your IP address, browser type and version, device information, pages viewed, and the date and time of your visit, generally through cookies and similar technologies as described in our Cookie Policy.
(f) Information from third parties. We may receive limited information from third parties, such as Stripe (confirming that a payment has been successfully processed) or other service providers we engage to help operate the Service.
4. How We Use Personal Data
We use personal data for the following general purposes:
(a) Providing and maintaining the Service, including creating and administering your account, enabling you to use the CRM, project management, HR administration, and financial record-keeping tools, and providing customer support;
(b) Processing transactions, including processing your one-off payment through Stripe, administering package upgrades, and handling refund requests in accordance with our Refund and Cancellation Policy; (c) Communicating with you, including sending account-related notifications (such as confirmation of purchase, security alerts, or updates to our policies), responding to support inquiries, and, where you have opted in, sending marketing communications about Velquro's products and updates;
(d) Improving the Service, including analyzing how our website and platform are used (where you have consented to analytics cookies, as described in our Cookie Policy), identifying and fixing technical issues, and informing decisions about new features or improvements;
(e) Maintaining security, including detecting and preventing fraud, unauthorized access, and other potentially harmful or unlawful activity affecting the Service or its users;
(f) Complying with legal obligations, including responding to lawful requests from public authorities, meeting record-keeping and reporting obligations, and enforcing our Terms and Conditions; and
(g) Processing Customer Data on behalf of Customers, strictly in accordance with the Customer's instructions and the purposes for which the Service is provided, as described in Section 2(b) above, and not for Velquro's own independent purposes (such as marketing to End-Data Subjects), except as may be separately agreed with the relevant Customer or required by law.
5. Legal Bases for Processing (EEA/UK)
Where the General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of personal data as a controller, we rely on the following legal bases, depending on the specific processing activity:
(a) Performance of a contract, where processing is necessary to provide the Service you have signed up for, including account administration, processing your purchase, and providing customer support;
(b) Legitimate interests, where processing is necessary for our legitimate interests in operating, securing, and improving our business and the Service, provided such interests are not overridden by your own rights and interests — for example, maintaining the security of our platform, understanding aggregate usage trends, or communicating with existing Customers about relevant product updates;
(c) Consent, where we rely on your specific consent, such as for certain non-essential cookies (as described in our Cookie Policy) or for optional marketing communications, which you may withdraw at any time; and
(d) Legal obligation, where processing is necessary for us to comply with an applicable legal or regulatory requirement, such as retaining certain transaction records.
Where Velquro acts as a processor on behalf of a Customer with respect to Customer Data, the Customer (as controller) is responsible for identifying an appropriate legal basis for its own processing of that data, including any personal data of its own leads, clients, or employees.
6. How We Share Personal Data
We do not sell personal data. We may share personal data in the following circumstances:
(a) Service providers. We engage third-party service providers to help us operate the Service, including hosting and infrastructure providers, our payment processor (Stripe), and, where applicable, analytics or customer support tool providers. These service providers are only permitted to process personal data on our behalf, for the purposes we specify, and are subject to contractual confidentiality and data protection obligations. (b) Within a Customer's account. Where you are an Authorized User of a Customer's account, or an End-Data Subject whose data has been entered into the Service by a Customer, your personal data may be visible to, and used by, that Customer and its other Authorized Users, consistent with the Customer's own use of the Service and its own policies, which are outside Velquro's control.
(c) Business transfers. If Velquro is involved in a merger, acquisition, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality protections and, where required, notice to affected individuals.
(d) Legal requirements. We may disclose personal data where required to do so by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect the rights, property, or safety of Velquro, our Customers, or others, including in connection with investigating fraud, security incidents, or violations of our Terms and Conditions.
(e) With your consent. We may share personal data for other purposes with your consent or at your direction.
We require our service providers and other recipients of personal data to implement appropriate safeguards consistent with this Policy and applicable law.
7. Payment Processing Through Stripe
As described elsewhere in our published terms, payments for Velquro packages are processed securely through Stripe, a third-party payment processor. When you make a purchase, the payment information you provide (such as your card details) is transmitted directly to Stripe and processed in accordance with Stripe's own privacy policy, which we encourage you to review.
Velquro receives limited information back from Stripe confirming that your payment has been successfully processed, along with transaction-related metadata (such as the amount charged, the package purchased, and a transaction reference), which we use to administer your account and process any refund requests. Velquro does not directly store your full card number, card verification code, or other sensitive payment credentials; these are handled exclusively within Stripe's secure payment infrastructure.
As set out in our Terms and Conditions and our other published policies, Velquro is a software provider only and does not hold or transmit funds on behalf of Customers or third parties. Our relationship with Stripe relates solely to processing your own one-off payment for access to the Service, and does not extend to any payments made by a Customer's own clients to that Customer, which occur entirely outside the Velquro platform.
8. International Data Transfers
Velquro and its service providers may process and store personal data in countries other than the country in which you or your business are located, including in jurisdictions that may have different data protection laws than your own. Where we transfer personal data internationally, we take steps intended to ensure that such transfers comply with applicable data protection law, which may include relying on recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful transfer mechanisms available under applicable law, depending on the jurisdictions involved. Where a Customer's own Customer Data (including data relating to the Customer's own clients or employees) is transferred internationally as part of Velquro's provision of the Service, we will implement such safeguards as are reasonably necessary and consistent with our obligations as a processor, and, where applicable, as set out in a separate data processing agreement with the Customer.
9. Data Retention
We retain personal data for as long as reasonably necessary to fulfil the purposes described in this Policy, including for as long as your account remains active, and thereafter for a period that allows us to comply with legal obligations (such as tax or accounting record-keeping requirements), resolve disputes, and enforce our agreements.
(a) Account and billing data. We generally retain account registration and billing-related data for as long as your account is active, and for a reasonable period thereafter to meet legal, accounting, and dispute-resolution requirements.
(b) Customer Data. Customer Data (including CRM, project, HR, and financial records entered by a Customer) is generally retained for as long as the Customer's account remains active. Following termination of an account (whether due to a refund under our Refund and Cancellation Policy or otherwise), we will retain Customer Data for a limited period to allow for data export, as described in our Terms and Conditions, after which such data will generally be deleted or anonymized, except where a longer retention period is required by applicable law or agreed with the Customer.
(c) Communications and support records. We generally retain records of support communications for a reasonable period to help us track and improve the quality of our support and to address any recurring or unresolved issues.
Where retention periods are not fixed by law or contract, we determine appropriate retention periods based on the amount, nature, and sensitivity of the personal data involved, the purposes for which it is processed, and applicable legal requirements.
When personal data is no longer needed for the purposes described in this Policy, we take reasonable steps to securely delete, destroy, or anonymize it, such that it can no longer be used to identify an individual, except where we are required or permitted by applicable law to retain it for a longer period (for example, financial or tax-related records that certain laws require businesses to retain for a set number of years).
10. Data Security
We implement technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction, appropriate to the nature and sensitivity of the data involved. These measures may include encryption of data in transit, access controls limiting who within Velquro can access personal data, and monitoring for suspicious or unauthorized activity.
While we take data security seriously and use industry-standard practices to protect personal data, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting personal data in a manner that requires notification under applicable law, we will notify affected individuals and/or relevant authorities as required by that law. Customers are responsible for maintaining the confidentiality of their own account credentials and for ensuring that their Authorized Users use the Service securely, consistent with the account security obligations described in our Terms and Conditions. We encourage Customers to use strong, unique passwords, to limit the number of Authorized Users granted access to sensitive HR or financial modules to those who genuinely need it, and to promptly remove access for any Authorized User who leaves the Customer's organization or no longer requires access to the Service.
Our security practices are reviewed and updated periodically to reflect changes in technology, industry standards, and the evolving threat landscape. Where we engage third-party service providers to help host or process personal data on our behalf (as described in Section 6), we take reasonable steps to assess that their security practices are appropriate to the sensitivity of the data involved before engaging them, and we impose contractual obligations requiring them to maintain adequate safeguards.
11. Your Privacy Rights
Depending on your location and applicable law, you may have certain rights in relation to your personal data, which may include the right to: (a) access the personal data we hold about you; (b) request correction of inaccurate or incomplete personal data; (c) request deletion of your personal data, subject to certain exceptions; (d) object to, or request restriction of, certain processing of your personal data; (e) request a copy of your personal data in a portable format; (f) withdraw consent, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal; and (g) lodge a complaint with a supervisory or data protection authority in your jurisdiction.
To exercise any of these rights in relation to data for which Velquro acts as controller (see Section 2(a)), please contact us using the details in Section 18 below. We will respond to verified requests within the timeframe required by applicable law.
If your personal data has been entered into the Service by a Customer as part of that Customer's use of the CRM, HR, or financial record-keeping tools (meaning Velquro is likely acting as a processor with respect to that data, as described in Section 2(b)), we encourage you to direct your request to the relevant Customer in the first instance, since they control how that data is used and are best placed to respond. Where required, Velquro will provide reasonable assistance to the Customer in responding to such requests.
Residents of certain U.S. states with comprehensive privacy laws (such as California) may have additional or differently framed rights under applicable state law, including rights relating to the sale or sharing of personal information (which, as noted in Section 6, we do not engage in) and rights to opt out of certain profiling activities. Where such rights apply, we will honor verified requests submitted through the contact channel described in Section 15.
To help protect your personal data, we may need to verify your identity before fulfilling a rights request, which may involve asking you to confirm certain account or purchase details, or, where relevant, submit the request through the email address associated with your account. We will not charge a fee to process a legitimate rights request, except where permitted by applicable law in the case of manifestly unfounded, excessive, or repetitive requests, in which case we may either charge a reasonable fee or decline to act on the request, and will explain our reasoning if we do so.
12. Automated Decision-Making and Profiling
Velquro does not currently use fully automated decision-making processes that produce legal or similarly significant effects concerning individuals without human involvement. Certain features within the Service — such as sales pipeline stages within the CRM module or financial reports generated from a Customer's own recorded data — involve organizing and presenting information a Customer has entered, but do not involve Velquro making automated decisions about individuals on the Customer's behalf. Where analytics cookies are used (subject to your consent, as described in our Cookie Policy) to understand aggregate usage of our website, this activity does not involve profiling of the kind that produces legal or similarly significant effects on any individual.
If this changes in the future — for example, if we introduce features that involve automated scoring or decision-making with a material effect on individuals — we will update this Policy accordingly and provide any additional information or rights required by applicable law, such as the right to request human review of a decision.
13. Marketing Communications
Where you have provided consent, or where otherwise permitted by applicable law, we may send you marketing communications about Velquro's products, features, and updates. You can opt out of receiving marketing communications from us at any time by following the unsubscribe instructions included in such communications, or by contacting us using the details in Section 18 below.
Please note that even if you opt out of marketing communications, we may still send you non-marketing, service-related communications, such as notices about changes to our policies, security alerts, or transactional messages relating to your account or a purchase, since these are necessary for us to operate the Service and are not considered marketing under applicable law.
14. Sensitive Data Entered Into the Service
Because Velquro's HR administration tools allow Customers to store employee records and related documentation, it is possible that some Customer Data entered into the Service could include categories of information treated as sensitive or "special category" data under certain data protection laws — for example, information that might reveal details relevant to health, where a Customer chooses to record leave reasons of that nature, or other similarly sensitive employee information a Customer elects to store as part of its own HR record-keeping.
Velquro does not request or require Customers to enter sensitive personal data into the Service, and we encourage Customers to carefully consider whether it is necessary and appropriate to record such information within the platform, and to ensure they have an appropriate legal basis and any necessary consents for doing so under applicable law, consistent with their role as data controller for such Customer Data as described in Section 2(b). Where a Customer does choose to record sensitive data of this kind, Velquro will handle it, as processor, subject to the same security and confidentiality commitments described in Section 10 (Data Security) that apply to Customer Data more generally, and in accordance with any separate data processing agreement in place with the Customer.
15. Cookies and Similar Technologies
We use cookies and similar tracking technologies on our website and within the Service, including strictly necessary cookies required for core functionality, as well as, where you have consented, functional and analytics cookies. Full details of the categories of cookies we use, their purposes, and how you can manage your preferences are set out in our separate Cookie Policy, which forms part of our overall privacy practices and should be read together with this Policy.
16. Children's Privacy
The Service is intended for use by businesses and individuals who meet the eligibility requirements described in our Terms and Conditions (generally, individuals who are at least eighteen years of age, or the age of legal majority in their jurisdiction), and is not directed at or intended for use by children. We do not knowingly collect personal data directly from children through the Service. If you believe a child has provided personal data to us in a manner inconsistent with this Policy, please contact us using the details in Section 18 so that we can investigate and take appropriate action, which may include deleting such data.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, the Service, or applicable law. Where we make a material change, we will update the "Last Updated" date at the top of this Policy and, where appropriate, provide additional notice, such as by email to registered Customers or a prominent notice on our website or within the Service.
We encourage you to review this Policy periodically. Your continued use of the Service after any updates to this Policy take effect constitutes your acknowledgment of the updated Policy, except where additional consent is separately required under applicable law, in which case we will seek that consent before the relevant change takes effect.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of personal data, please contact us through the contact details published on the Velquro website. We aim to respond to all privacy-related inquiries promptly and in accordance with applicable law.
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that provides for a supervisory authority or equivalent body responsible for data protection matters, you have the right to lodge a complaint with that authority if you believe our processing of your personal data does not comply with applicable law, in addition to contacting us directly.