Back to home

Privacy Policy

Last updated 16 August 2026

This explains what VenuesDock collects, why we collect it, who processes it on our behalf, and what you can ask us to do with it.

Who this covers

VenuesDock is booking software used by facility operators. Two groups of people appear in it: the staff who run a facility, and the renters who book its spaces. This policy covers both.

Where a facility uses VenuesDock to manage its own bookings, that facility decides what renter data it collects and how long it keeps it. VenuesDock processes that data on its behalf.

What we collect

We collect only what the product needs to function:

  • Account details — name, email address, hashed password, and the role and organization you belong to.
  • Facility configuration — venues, spaces, rates, availability, contract templates and document requirements you set up.
  • Booking records — renter name and email, the space and times booked, booking status, and messages exchanged about a booking.
  • Documents you upload — insurance certificates, waivers and similar files attached to a booking.
  • Payment records — amounts, status and Stripe identifiers. Card numbers are handled by Stripe and never reach our servers or database.
  • Phone numbers, where SMS booking reminders are enabled.
  • Technical data — error reports and aggregate usage analytics, described below.

Why we use it

To operate the service: to show availability, take and approve booking requests, generate and sign contracts, collect payments and deposits, send booking notifications and reminders, and produce the reports a facility needs to run.

To keep the service secure and working: to authenticate you, prevent abuse, diagnose faults and understand which features are used.

We do not sell personal data, and we do not use booking data to advertise to renters.

Who we share it with

We use a small number of processors, each for a specific purpose:

  • Stripe — payment processing, payouts and deposits, including Stripe Connect for facility payouts.
  • Resend — transactional email such as booking confirmations, contract links and password resets.
  • Cloudflare R2 — storage for documents and images you upload, and Cloudflare Turnstile to block automated abuse of public forms.
  • Neon — the managed PostgreSQL database holding your account and booking records.
  • Sentry — error reports used to diagnose faults.
  • Umami — privacy-focused, aggregate usage analytics.

How long we keep it

Account and facility records are kept for as long as the organization has an account with us. Booking, contract and payment records are kept while the facility needs them for its own operational, tax and dispute-resolution purposes.

Records that users delete in the product are deactivated rather than erased immediately, so that historical bookings and financial records stay intact and auditable. Contact us to request full erasure.

Your choices

You can view and correct most of your own information from the dashboard. You can request a copy of your data, correction of anything inaccurate, or deletion of your account by contacting us.

Renters should contact the facility they booked with in the first instance, since that facility controls its own booking records.

Security

Passwords are stored hashed, never in plain text. Traffic is encrypted in transit. Access to production data is limited to the people who need it to operate the service.

No system is perfectly secure. If you believe you have found a vulnerability, please report it to us rather than disclosing it publicly.

Changes and contact

If this policy changes materially we will update the date above and, where the change affects you, tell account holders by email.

Questions about this policy, or requests about your data, can be sent through our contact page.