Effective 2026-08-21
Privacy Policy
Venuo ("we", "us") operates a space-booking platform for offices, sports venues and studios. This Privacy Policy explains how we collect, use and share personal data about you when you visit our website or use our services, in compliance with the EU General Data Protection Regulation (GDPR).
Data controller
Venuo is operated by Ewa Kucharska, a sole trader (jednoosobowa działalność gospodarcza) registered in Poland, who is the controller of personal data processed through our platform and this website. You can reach us at [email protected].
What data we collect
Account data
Name, email, password hash, role within a workspace, profile photo (optional), phone (optional), and authentication metadata (IP address of sign-ins, device, timestamps).
Booking data
Spaces you book, dates and times, booking notes, attendee information, and any special requirements you provide.
Technical data
Browser type and version, device identifiers, log data (request path, referrer, user-agent), error traces. We use this data to operate, secure and improve the service.
Waiting-list data
If you join our pre-launch waiting list, we store the email address you submit and the interface language at the time of submission. We process this on the basis of your consent (Art. 6(1)(a)), for the sole purpose of notifying you when Venuo becomes available. We do not use it for any other marketing and do not share it. You can be removed at any time — see "How long we keep data" below.
Cookies and analytics
This website sets no cookies until you choose "Accept all"
in the consent bar. Your choice itself is stored in your browser's local
storage (venuo-consent-v2) — that entry is strictly necessary
to remember your decision and contains nothing else.
If you accept analytics, the following tools run:
| Tool | Provider | Purpose | Storage duration |
|---|---|---|---|
| Google Analytics 4 | Google LLC | Traffic measurement — how visitors find and move through this site | Cookies _ga, _ga_* — up to 2 years; analytics data retained 14 months |
| Microsoft Clarity | Microsoft | Heatmaps and pseudonymous session replays showing how pages are used. Clarity receives page URLs and referrers, interaction events, and technical device and network data. Form inputs and other sensitive content are masked by default and masked content is not uploaded | Cookies may include _clck, _clsk, CLID, ANONCHK, MR, MUID, and SM. Recordings are retained for 30 days; click and heatmap data and labeled or favorited sessions for up to 9 months |
For Clarity data, Venuo and Microsoft act as independent controllers. Microsoft may use personal data as described in the Microsoft Clarity Terms and the Microsoft Privacy Statement, including to provide and improve its services and for profiling related to advertising. Venuo sends Clarity an explicit denial for advertising storage, does not show ads, and does not sell personal data.
If you choose "Necessary only", neither tool sets analytics cookies or builds a persistent profile from this site. Google Analytics then receives only aggregate, cookieless signals with no identifier that persists between pages; Microsoft Clarity does not load at all.
You can change your decision at any time via "Cookie settings" in the page footer. Withdrawing consent stops further cookie-based and persistent analytics collection from that moment.
The Venuo app (app.venuo.co) uses only strictly necessary cookies and local storage for authentication and session management — no analytics cookies, no advertising cookies.
Legal basis for processing
- Contract (Art. 6(1)(b)) — to provide the booking platform you signed up for.
- Legitimate interest (Art. 6(1)(f)) — to secure our service, prevent fraud and improve product quality.
- Consent (Art. 6(1)(a)) — for optional marketing communications and analytics cookies (see "Cookies and analytics").
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting and law-enforcement obligations.
How long we keep data
- Active accounts: for the lifetime of your account.
- Deleted accounts: profile data is removed within 30 days of your deletion request (grace period during which you may cancel). Booking records may be retained in anonymised form for legitimate interest (analytics) and legal obligations (invoicing).
- Audit logs: retained for 24 months for security-incident investigation.
- Invitations: pending invitations expire after 7 days; terminal-state records purged after 30 days.
- Waiting list: kept until launch and removed within 30 days of launch, or sooner on request via [email protected].
Your rights
Under GDPR you have the right to:
- Access (Art. 15) — obtain a copy of your personal data. In the app: Settings → Privacy → "Download my data".
- Rectification (Art. 16) — correct inaccurate data from your profile page.
- Erasure / "right to be forgotten" (Art. 17) — delete your account via Settings → Privacy → "Delete my account". Deletion is finalised 30 days after your request.
- Restriction (Art. 18) — email [email protected].
- Portability (Art. 20) — export your data in a machine-readable JSON format.
- Objection (Art. 21) — object to processing based on legitimate interest.
- Withdraw consent (Art. 7(3)) — as easily as you gave it: analytics cookies via "Cookie settings" in the footer; marketing email via the unsubscribe link in any message.
- Lodge a complaint — with your national supervisory authority (in Poland: UODO, uodo.gov.pl; in Ireland: Data Protection Commission, dataprotection.ie).
Who we share data with
We use the following service providers and analytics recipients. Except where described otherwise, service providers act as processors under Art. 28 GDPR data-processing agreements:
- Supabase — database, authentication and file storage; hosted in the EU (Ireland region).
- Cloudflare, Inc. — content delivery, hosting and DDoS protection.
- Resend, Inc. — transactional email delivery.
- Stripe, Inc. — payment processing (via Stripe Payments Europe, Ltd.). We never see or store your card number.
- Functional Software, Inc. (Sentry) — application error monitoring.
- Google LLC — website traffic analytics (Google Analytics 4), only after your consent.
- Microsoft — website usage analytics (Microsoft Clarity), only after your consent. Microsoft and Venuo act as independent controllers for Clarity data; see the Microsoft links in "Cookies and analytics" above.
A full, versioned provider and recipient list is available on request at [email protected].
International transfers
Your data is primarily stored in the EU (Supabase, eu-west-1). Some providers or recipients listed above are US companies, or transfer data to the US; transfers rely on the EU-US Data Privacy Framework (Commission adequacy decision (EU) 2023/1795 under Art. 45 GDPR) and, where applicable, Standard Contractual Clauses (Art. 46 GDPR) with supplementary safeguards.
Security
We use industry-standard measures: TLS in transit, encryption at rest, Row-Level Security for tenant isolation, password hashing (bcrypt), JWT with short expiry, and audit logging of security-sensitive changes.
Changes to this policy
We will notify you of material changes via email and in-app banner at least 30 days before they take effect. You may withdraw consent to the new version by deleting your account.
Contact
Questions? Email [email protected].