Privacy Policy
How we protect and handle your data
Last updated: Effective October 5, 2026 · Last updated October 5, 2026
This document was last updated on Effective October 5, 2026 · Last updated October 5, 2026. If you have legal questions, contact hello@bookwithveya.com.
Who We Are
VEYA is operated by VEYA Hospitality Management Company Limited.
For the purposes of applicable data protection law, VEYA Hospitality Management Company Limited is the data controller responsible for determining how and why personal data is processed through VEYA, except where another organisation independently determines its own processing purposes.
This Privacy Policy explains how VEYA Hospitality Management Company Limited ("VEYA", "we", "us", or "our") collects, uses, stores, shares and protects personal data when individuals use the VEYA mobile application, website, venue and business tools, support services and related services.
Privacy contact: hello@bookwithveya.com.
Where VEYA relies on consent for a specific processing activity, that consent is requested separately where required and may be withdrawn subject to applicable law. This Privacy Policy is a transparency notice and does not itself constitute consent.
Who This Policy Applies To
This Privacy Policy applies to website visitors, app users, account holders, restaurant and venue guests, event attendees, ticket buyers, experience guests, venue and business contacts, venue staff using VEYA tools, business applicants, demo request applicants, and people contacting VEYA support.
Information We Collect
Account and identity information: name, email address, phone number, account identifier, profile information, authentication information, profile photograph where provided, and account preferences. Authentication is handled by VEYA's authentication infrastructure; VEYA does not intentionally store user passwords in plain text.
Reservation and booking information: venue, reservation date, reservation time, party size, guest name, guest email, guest phone, seating preferences, occasion, special requests, reservation status, cancellation information, deposit status, and booking history. You should avoid including unnecessary sensitive personal information in free-text special request fields. Where you voluntarily provide information relating to health, disability, accessibility, religion, allergies or dietary requirements, that information may be processed and shared with the relevant venue where necessary to address your request and where permitted by applicable law.
Ticket and event information: events viewed, tickets purchased, ticket type, quantity, order information, ticket identifiers and codes, event attendance and check-in status, and cancellation information.
Experience information: experience selected, booking date/time, party size, booking reference, payment status, and cancellation information.
Payment information: VEYA currently uses Paystack to process supported payments. VEYA does not intentionally store full payment card numbers or CVV security codes. VEYA may receive and store limited payment and transaction information including payment reference, payment status, authorization status, payment method or channel, card brand, last four digits where provided by the processor, transaction amount, currency, payment timestamps, refund status, chargeback or dispute information, and payment failure information.
Location information: approximate or precise location where you grant permission or where location functionality is used. Location may be used for nearby discovery, map features, location-aware recommendations, and showing relevant venues or events.
User content and communications: photographs, reviews, ratings, profile content, reports, support messages, feedback, communications submitted through VEYA, and venue or event content submitted by authorised business users.
Business and venue application information: information submitted through Join VEYA, business applications, business access requests, demo requests, and venue onboarding. This may include business name, contact name, role, work email, phone, WhatsApp, city, country, address, website, Instagram, business type, number of locations, current booking process, reservation volume, deposit use, business needs, and notes.
Device and technical information: IP address, device type, operating system, browser type, device identifiers where available, application version, technical logs, and security events.
Usage, analytics and diagnostic information: the VEYA mobile application may use product analytics and diagnostic tools to understand app interaction, feature usage, performance and crashes. Current mobile app service providers may include PostHog for product analytics and Sentry for error and performance monitoring. The current public VEYA website does not use PostHog, Sentry, advertising pixels or non-essential analytics SDKs unless and until such technologies are separately implemented.
Sources of Personal Data
VEYA may collect personal data directly from you when you create an account, make a reservation, purchase a ticket or experience, submit content, apply as a business, contact support, communicate with VEYA or otherwise use the service.
VEYA may receive information from participating venues, event organisers and experience providers where necessary to administer a booking, attendance, cancellation, dispute, refund, check-in or customer-service matter.
VEYA may receive limited information from service providers and third-party services used to operate the platform, including authentication providers, payment processors, communications providers, analytics and diagnostic providers, subject to the relevant service and your settings or permissions.
VEYA may also use information from public sources or information lawfully supplied by business partners where reasonably necessary for venue discovery, listing verification, fraud prevention, safety, compliance or business operations.
How We Use Personal Data
VEYA uses personal data for purposes including: creating and authenticating accounts; providing the VEYA service; processing reservations; automatically confirming eligible reservations; verifying deposit payments before confirming deposit-required reservations; processing ticket and experience transactions; issuing tickets; communicating booking information; sending transactional emails and notifications; providing customer support; providing venue tools; processing business applications and demo requests; preventing fraud and abuse; securing accounts and systems; investigating disputes; operating and improving VEYA; measuring mobile app feature performance; diagnosing crashes and technical problems; complying with legal, accounting and regulatory obligations; establishing, exercising or defending legal claims; and sending marketing communications where legally permitted and where required consent has been obtained.
Lawful Bases for Processing
VEYA relies on one or more lawful bases depending on the processing activity.
Contract or steps to enter a contract: including creating and managing an account, processing a reservation, processing a ticket or experience order, communicating transaction information, providing customer support connected with a booking, and processing a business application or request.
Legal obligation: including compliance with applicable law, financial recordkeeping, regulatory requests, lawful government or court requests, and applicable payment and dispute obligations.
Legitimate interests: VEYA may process information where necessary for legitimate operational interests and where those interests are not overridden by the rights and freedoms of the individual, including securing VEYA, preventing fraud and abuse, investigating misuse, resolving disputes, maintaining service reliability, improving the platform, understanding mobile app performance, and protecting VEYA, users and venue partners. VEYA does not use legitimate interest as a blanket basis for direct marketing or sensitive personal data.
Consent: including optional marketing communications, certain location permissions, certain sensitive personal information voluntarily provided for a specific guest request, and non-essential cookies or tracking technologies if introduced. Consent can be withdrawn, although withdrawal does not affect processing already lawfully carried out before withdrawal.
Transactional & Marketing Communications
VEYA may use contact information to send transactional and service communications that are reasonably necessary to provide the service, including reservation confirmations, ticket delivery, payment information, booking or event changes, security alerts, account notices and support messages.
Transactional communications may be delivered through supported channels such as email, SMS, WhatsApp or push notification where appropriate to the service requested and permitted by law.
Promotional or direct-marketing communications are treated separately from essential transactional communications. VEYA will obtain consent where required by applicable law and will provide an available method to withdraw consent, unsubscribe or adjust marketing preferences.
Withdrawing or declining marketing consent does not prevent VEYA from processing personal data or sending communications that are necessary to perform a requested transaction, provide the service, secure an account, respond to support or comply with law.
How Reservations Work and Data Sharing With Venues
For standard VEYA reservations, participating venues configure their availability, capacity and reservation settings. Where no deposit is required, an eligible reservation is automatically confirmed when the booking is successfully completed. Where a deposit is required, the reservation is confirmed only after the required payment has been successfully verified. There is no manual venue acceptance or rejection step for standard VEYA reservations.
When a reservation is confirmed, VEYA may share relevant guest and reservation information with the venue so the venue can fulfil and manage the reservation. This may include guest name, email address, telephone or WhatsApp number where provided, reservation date, reservation time, party size, seating preference, occasion, relevant special requests, and payment or deposit status.
For events and experiences, VEYA may similarly provide the relevant organiser or Provider with information reasonably necessary to fulfil the transaction, administer attendance or check-in, communicate operational changes, provide customer support, address safety issues, process permitted refunds or resolve disputes.
A venue, organiser or Provider that receives guest information may act as an independent data controller for processing it for its own lawful purposes. Receipt of guest contact information through VEYA does not by itself authorise that Provider to add the guest to an unrelated marketing list or send independent promotional communications. The Provider must establish its own lawful basis and obtain consent where required.
VEYA's Business Terms require participating Providers to use VEYA-supplied guest data appropriately, protect it and comply with applicable data protection requirements.
Service Providers and Third Parties
VEYA works with service providers to operate the platform, including:
Supabase: used for cloud database, authentication and backend infrastructure.
Paystack: used for supported payment processing and payment verification.
Resend: used for transactional email delivery.
Apple and Google: may be used where users choose supported sign-in services.
PostHog: may be used in the VEYA mobile application for product analytics.
Sentry: may be used in the VEYA mobile application for crash, error and performance diagnostics.
Venues and event organisers: receive information necessary to fulfil reservations, bookings, tickets or experiences.
Professional advisers: legal, accounting, audit or other professional advisers where necessary.
Public authorities: where disclosure is required or permitted by applicable law.
These providers may act as processors or independent controllers depending on the relevant processing activity and their own legal responsibilities. VEYA does not sell personal data to third parties.
Aggregated, De-identified & Statistical Data
VEYA may create aggregated, statistical or de-identified information from personal data for lawful purposes such as understanding service usage, measuring marketplace performance, improving products, planning operations and preparing business analysis.
Where information has been effectively anonymised so that it no longer identifies an individual under applicable law, it is not treated as personal data for the purposes of this Privacy Policy.
International and Cross-Border Data Processing
VEYA is based in Nigeria but uses technology and service providers whose infrastructure, personnel or processing operations may be located in other countries. Personal data may therefore be processed, accessed or stored outside Nigeria.
VEYA will take reasonable and appropriate steps required by applicable law when transferring personal data internationally, including using contractual, organisational or other recognised safeguards where required.
For further information about international processing and applicable safeguards, contact hello@bookwithveya.com.
Data Retention
VEYA retains personal data only for as long as reasonably necessary for the purposes for which it was collected, including providing services, maintaining transaction records, resolving disputes, preventing fraud and meeting legal, accounting or regulatory obligations.
Account information: retained while the account remains active and for a limited period after deletion where required for legitimate legal, security or recordkeeping purposes.
Reservation, ticket and experience records: retained for operational, customer support, dispute, fraud prevention, accounting and legal purposes.
Payment transaction records: retained as necessary for payment reconciliation, disputes, chargebacks, accounting and regulatory obligations.
Support communications: retained for as long as reasonably necessary to resolve the request and maintain appropriate support records.
Business applications: retained while the application is reviewed and for a reasonable period afterwards for business, audit and follow-up purposes.
VEYA periodically reviews retention needs and may anonymise or delete information that is no longer reasonably required.
Data Subject Rights
You have the right to access the personal data we hold about you, request correction or rectification of inaccurate data, request deletion or erasure, request restriction of processing, object to certain processing, request data portability where applicable, and withdraw consent where processing relies on consent.
You also have the right to complain to the Nigeria Data Protection Commission.
To exercise any of these rights, contact hello@bookwithveya.com with details of your request. VEYA may need to verify your identity before fulfilling certain requests. We aim to respond within the period required by applicable law.
Account Deletion
Users may delete their VEYA account through the VEYA mobile application. Users may also contact hello@bookwithveya.com for privacy or deletion assistance.
Deletion does not require VEYA to erase information that must or may lawfully be retained for payment records, fraud prevention, security, disputes, accounting, legal obligations, regulatory requirements, or legal claims.
Security
VEYA implements appropriate technical and organisational measures to protect personal data, including access controls, encryption where appropriate, security monitoring, and restricted administrative access.
No method of transmission over the internet is completely secure. While we implement strong security practices, we cannot guarantee absolute security.
Data Breaches
VEYA will assess personal data breaches and make regulatory or data subject notifications where required by applicable law.
Age & Children's Privacy
VEYA accounts are intended for individuals aged 18 or older. Individuals under 18 must not create or hold a VEYA account.
VEYA does not knowingly create accounts for or intentionally collect personal data through account registration from children. If VEYA becomes aware that an account has been created by a person under 18, VEYA may close the account and take appropriate steps concerning the associated data, subject to applicable legal retention requirements.
Some venues, events or experiences may impose higher minimum-age requirements. Account eligibility does not guarantee eligibility for a particular venue or event.
A parent or guardian who believes VEYA has collected personal data from a child in a manner not permitted by law should contact hello@bookwithveya.com.
Your Privacy Choices
You may review or update certain account information through available account controls. You may request additional correction or access by contacting VEYA.
You may opt out of promotional communications through an available unsubscribe, preference or opt-out mechanism or by contacting VEYA. You may continue to receive transactional or service communications necessary for bookings, tickets, payments, account security or support.
You can control device permissions such as location and notifications through your device settings. Disabling a permission may limit features that depend on it.
Where VEYA relies on consent, you may withdraw that consent at any time, subject to applicable law and without affecting processing lawfully carried out before withdrawal.
Third-Party Links and Services
VEYA may contain links to third-party websites, event pages, ticketing platforms, and external services. This Privacy Policy does not apply to third-party services, which have their own privacy policies and data practices. We encourage you to review their privacy policies before providing information.
Changes to This Policy
VEYA may update this Privacy Policy to reflect changes to the service, processing practices or applicable law. The current version will be published with an updated revision and effective date. Where required, VEYA will provide additional notice of material changes. The revised policy applies from the effective date stated in the published version or notice.
Complaints and Regulatory Rights
Individuals should contact VEYA first at hello@bookwithveya.com so that we can investigate and address privacy concerns. Individuals also have the right to lodge a complaint with the Nigeria Data Protection Commission where applicable. Contacting VEYA does not remove or limit the right to complain to the Commission.
For individuals protected by another applicable data protection regime, you may also have the right to complain to the relevant competent supervisory authority.
Contact
VEYA Hospitality Management Company Limited
Email: hello@bookwithveya.com
Website: https://bookwithveya.com