Privacy Policy
Effective date: August 7, 2026
Last Updated: June 11, 2026
Applies to: VEGA by VEL mobile application, myvel.com, user accounts, bookings, and related physical services
Privacy at a glance#
VEL uses information to create accounts, reserve and access physical Facilities, process transactions through independent payment providers, support users, keep locations secure, and improve reliability. VEL does not sell personal information or share it for cross-context behavioral advertising. Optional permissions and AI features require separate, contextual choices.
Topic | VEL position |
|---|---|
Physical-service payments | VEL does not receive or store full card numbers or security codes. An independent payment provider processes them. |
Precise location | Used only with device permission and only for a requested function such as nearby search or arrival verification. A manual alternative is provided. |
Voice and AI | Optional. No voiceprint or biometric identification. Personal data is not sent to a third-party AI provider without a clear disclosure and required permission. |
Advertising | No sale of personal information and no cross-context behavioral advertising. No advertising SDK should be enabled under this policy. |
Your control | Account settings, permission controls, marketing opt-outs, privacy requests, and in-app account deletion. |
1. Scope and who is responsible#
This Privacy Policy explains how Space 3, Inc., a Delaware corporation doing business as VEL (VEL, we, us, or our), collects, uses, discloses, retains, and protects personal information when you use the VEGA by VEL mobile application (App), visit myvel.com (Site), communicate with us, make or manage a Booking or Membership, or enter and use a VEL physical location, pod, workspace, or related service (Facility).
VEL is responsible for the practices described here unless a checkout, in-app, or on-site notice identifies another organization as the controller or business responsible for a particular Facility or service. A landlord, employer, hotel, airport, Venue Partner, payment provider, or monitoring operator may separately process information under its own privacy notice. Before purchase or entry, VEL will make the applicable Facility roles and material notices reasonably accessible.
Contact: Space 3, Inc. d/b/a VEL, 1417 Sadler Road, Suite 412, Fernandina Beach, Florida 32034, United States; support@myvel.com.
2. Information we collect#
2.1 Account and contact information
We collect information you provide when creating or updating an Account, such as name, email address, mobile number, password or authentication reference, organization or employer, preferred location, communication settings, and age confirmation. If you use an eligible third-party sign-in method, we receive the profile information you authorize that provider to share.
2.2 Booking, Membership, and transaction information
We collect Booking location, Facility or service type, date and time, duration, capacity, Guests where permitted, check-in and check-out status, Membership, credits, prices, taxes, discounts, receipts, refunds, disputes, and related customer-service history. If you invite a Guest, we may receive the Guest's name and contact details from you and send that Guest the required registration, Terms, Privacy Policy, monitoring notice, and location rules. We generate identifiers needed to confirm and administer the transaction.
2.3 Payment information
VEL does not hold full card details Your full payment card number, security code, and payment-account credentials are provided directly to the independent payment processor or wallet provider shown at checkout. VEL-controlled systems do not collect, process, or store those full credentials.
The provider may return limited payment metadata to VEL, such as a token or customer reference, transaction identifier and status, card brand and last four digits, billing country or postal code, fraud signal, and refund or chargeback information. We use this metadata to confirm payment, issue receipts or refunds, prevent fraud, and keep financial records.
2.4 Location and device permissions
If you grant permission, the App may collect approximate or precise device location while the App is in use to show nearby Facilities, display directions, verify arrival, or enable a location-dependent access feature. We do not collect background location under this policy. You may search for or select a location manually if you decline location permission.
Depending on features you choose, the App may request camera access to scan a code, microphone access for voice assistance, Bluetooth or local-network access to interact with authorized Facility equipment, and notification permission for Booking, access, or service alerts. We request a permission at the time it is needed, explain the purpose, and provide a reasonable alternative where feasible.
If the App offers Face ID, Touch ID, or an equivalent device-authentication option, the operating system performs the biometric comparison locally. VEL does not receive or store the fingerprint, face, iris, or other biometric template and receives only an authentication result.
2.5 Facility access, operational, and safety information
When you enter or use a Facility, we may collect access credential events, entry and exit times, door or lock events, Booking-to-Facility association, occupancy status, device commands, environmental settings, equipment status, incident reports, support actions, and security logs. These records help deliver the booked service, troubleshoot equipment, prevent unauthorized access, investigate incidents, and protect users and property.
Some Facilities or buildings may use security cameras or other safety monitoring. Where VEL controls the monitoring, we provide appropriate in-app or on-site notice identifying the operator, purpose, ordinary retention, and contact. Audio recording is disabled unless separately approved and prominently disclosed. Access to footage is restricted to authorized safety, security, legal, and support personnel. A Venue Partner may operate building-wide monitoring under its own notice. We do not use ordinary Facility sensor data to infer health conditions or create biometric profiles.
2.6 Voice and AI-assisted features
If you choose an AI-assisted or voice feature, we collect the text you submit, the requested action, output, and technical information needed to provide and secure the feature. If you activate voice input, microphone audio is transmitted for real-time transcription and response generation.
VEL does not use voice input for biometric identification and does not create a voiceprint. Under this Policy, neither VEL nor a processor acting for VEL may retain raw microphone audio after the requested response is completed, unless a separate, explicit notice and choice says otherwise. Operational transcripts are retained for no more than 30 days unless a longer period is reasonably required to investigate abuse, a safety incident, or a legal claim.
Before personal information or your input is sent to a third-party AI or transcription provider, the App will name each recipient, describe the data and purpose, and request any explicit permission required by app-store policy or law. Do not include sensitive information that is unnecessary for your request. Neither VEL nor a provider acting for VEL uses AI content to train or improve a general-purpose model, product, or service for other customers without a separate, specific opt-in. You can withdraw future AI transfer permission in Settings > Privacy > AI Data Sharing without losing ordinary Booking, access, or manual controls.
2.7 App, website, cookie, and diagnostic information
We automatically receive IP address, device and browser type, operating system, app version, language, time zone, pages and screens viewed, taps or interactions, session timestamps, referring URL, cookie or similar identifier, crash logs, performance data, and security events. We use this information for authentication, core functionality, analytics, debugging, fraud prevention, and service improvement.
2.8 Communications and information from others
We collect messages, support tickets, call or chat notes, survey responses, feedback, and files you choose to provide. We may receive eligibility, account, Booking, or billing-allocation information from an employer, enterprise customer, Venue Partner, referral partner, or another user who is authorized to include you in a Booking.
2.9 Legal, consent, and preference records
We keep records of Terms and Privacy Policy versions, account and Guest acceptance, recurring-billing consent, permission and cookie choices, marketing preferences, AI-transfer choices and withdrawal, arbitration opt-outs, notices shown, timestamps, locale, application version, and related evidence needed to honor choices, demonstrate compliance, and resolve disputes.
3. Sensitive information#
Depending on your choices and applicable law, precise geolocation, Account credentials, voice content, access-control records, and certain payment metadata may be treated as sensitive. We use sensitive information only as reasonably necessary to provide a feature you request, secure Accounts and Facilities, prevent fraud, comply with law, or protect health and safety. We do not sell it, use it for targeted advertising, use voice for biometric identification, or use Facility data to diagnose a medical condition.
VEL does not collect government identification, biometric identifiers, health records, or physiological measurements through the App under this policy. If a future feature requires any of these categories, VEL will provide a separate, prominent notice, obtain required consent, update store disclosures, and complete a legal and security review before launch.
4. Sources of information#
- Directly from you, including Account, Booking, support, survey, and permission choices.
- Automatically from the App, Site, device, cookies, access systems, and Facility equipment.
- From payment, authentication, communications, mapping, analytics, AI, smart-access, cloud, and security providers.
- From your employer, enterprise sponsor, Venue Partner, Guest organizer, referral source, or other authorized party.
- From public authorities or sources when necessary for legal compliance, fraud prevention, or safety.
5. How we use information#
- Create, authenticate, administer, secure, and delete Accounts.
- Display availability; confirm, modify, fulfill, and support Bookings and Memberships.
- Issue and validate access credentials and operate authorized Facility controls.
- Process payments through providers; issue receipts, credits, and refunds; maintain tax and accounting records.
- Send transactional messages, access alerts, security notices, and service updates.
- Provide optional location, voice, AI, notification, camera, Bluetooth, or local-network features you choose.
- Monitor availability, occupancy, safety, equipment health, misuse, fraud, and security.
- Analyze and improve reliability, design, accessibility, customer support, and physical-service performance, using aggregated or de-identified information where appropriate and subject to the AI-content limits in Section 2.6.
- Personalize location, service, and setting preferences without using data for cross-context behavioral advertising.
- Comply with law, enforce agreements, resolve disputes, and protect users, VEL, Venue Partners, and the public.
- Send marketing only where permitted and subject to your choices.
6. When we disclose information#
We disclose personal information only for the purposes described here:
- Service providers. Cloud hosting, authentication, payment, fraud prevention, mapping, communications, analytics, crash reporting, support, AI, smart-access, equipment, and security providers process information for VEL under contractual and security requirements.
- Venue Partners and on-site operators. We share the minimum Booking, access, incident, and operational information needed to host, secure, maintain, or support the Facility.
- Enterprise sponsors and administrators. Where an organization funds or administers your access, we share only the eligibility, spend, Booking, usage, and compliance fields reasonably needed to operate that program. Before enterprise use, we explain what the administrator can see. We do not share private support, AI content, or a sensitive wellness-service detail unless necessary, authorized, and clearly disclosed.
- At your direction. We disclose information when you ask us to share it, invite a Guest, connect a third-party service, or otherwise authorize the disclosure.
- Legal, safety, and rights protection. We may disclose information to comply with law or legal process; respond to a lawful request; investigate fraud or a security or safety incident; enforce our Terms; or protect rights, property, health, or safety.
- Corporate transaction. Information may be disclosed to advisers and a buyer, investor, lender, or successor in connection with diligence, financing, merger, reorganization, sale, or transfer, subject to appropriate confidentiality and applicable law.
VEL does not sell personal information for money and does not share personal information for cross-context behavioral advertising. We do not permit providers to use VEL personal information for their own advertising. If this practice changes, we will update this Policy and provide any legally required opt-out before the change.
7. Payments and app-store treatment#
Charges made through the App pay for Physical Services or physical goods consumed at VEL locations outside the App. The App does not use Apple In-App Purchase or Google Play Billing for these transactions. Apple, Google, and their app stores are not the sellers or providers of the Physical Services.
Apple Pay and Google Pay may act as wallets, and an independent processor may handle the transaction. Their privacy practices apply to information they independently control. VEL's statement that it does not receive full card credentials does not mean the payment provider collects no information.
8. Cookies and similar technologies#
The Site and App may use cookies, local storage, software development kits, pixels, and similar technologies. Strictly necessary technologies support security, authentication, preferences, checkout, and core functions. Analytics technologies help us understand performance and improve the service. Advertising or cross-site tracking technologies are not used under this Policy.
Where law requires, non-essential analytics will remain off until you choose Accept, and you may change your choice through Privacy Choices or cookie settings. Browser controls may also block cookies, but blocking necessary technologies can prevent login or checkout. Where applicable, we honor a recognized Global Privacy Control signal as a request to opt out of sale or sharing, even though VEL does not currently engage in those practices.
Some browsers send a Do Not Track signal. Because there is no uniform technical standard for that signal and VEL does not use cross-context behavioral advertising under this Policy, the services do not otherwise change behavior in response to Do Not Track. We do respond to legally recognized opt-out preference signals, including Global Privacy Control, where required.
9. Legal bases for EEA, UK, and similar jurisdictions#
Where a law requires a legal basis, VEL relies on: performance of a contract to create an Account and fulfill Bookings or Memberships; legitimate interests to secure and improve services, prevent fraud, and administer operations where those interests are not overridden by your rights; consent for optional permissions, AI disclosure, non-essential cookies, and marketing where required; and legal obligation or vital interests for compliance and urgent safety.
You may withdraw consent at any time through Settings, device controls, cookie controls, or by contacting us. Withdrawal does not affect processing already lawfully completed and may prevent an optional feature from working.
10. Data retention#
We keep information only as long as reasonably necessary for the purpose described, including transaction, safety, fraud, dispute, accounting, and legal obligations. The schedule below applies unless a longer period is required by law or an active dispute, or a shorter period is required by a valid deletion request:
Information | Default retention |
|---|---|
Account and profile | While active; deleted or de-identified within 90 days after verified deletion, except retained records below. |
Saved payment token or customer reference | While you choose to keep it or an active Membership needs it; removed within 30 days after removal, Membership cancellation, or Account deletion unless needed for a pending transaction, dispute, or legal duty. |
Booking, Membership, receipts, tax and payment metadata | Seven years after the transaction or longer if required for tax, accounting, chargeback, or legal claims. |
Location and access events | Nearby-search coordinates are not retained as precise history. A derived arrival-verification result may be kept up to 30 days; entry, check-in, lock, equipment, and security events up to 24 months; the booked Facility remains in the transaction record for seven years. |
Raw voice input | Not retained by VEL or its processors after completion of the requested response under this Policy. |
AI or voice transcript | Up to 30 days; longer only for a documented safety, abuse, dispute, or legal investigation. |
Legal acceptance and consent evidence | For the Account relationship and ordinarily seven years after the last transaction or event relying on the record; longer for an active dispute or legal duty. |
App analytics and diagnostics | Up to 24 months, then deleted or de-identified. |
Support and incident records | Three years after resolution; longer for safety, insurance, chargeback, or legal needs. |
Marketing preferences | Until opt-out, plus a suppression record needed to honor the opt-out. |
Security camera footage controlled by VEL | Ordinarily 30 days, unless retained for a documented incident or legal requirement; on-site notice may state a different lawful period. |
Backups are deleted on a rolling schedule and may remain for a limited time after deletion from active systems. When retained information is no longer needed, we delete, aggregate, or de-identify it. We do not attempt to re-identify properly de-identified data.
11. Security#
VEL uses administrative, technical, and physical safeguards designed for the nature of the information, including access controls, encryption in transit, protected credentials and tokens, logging, vendor review, least-privilege access, secure development and testing, and incident-response procedures. No system is completely secure, and we cannot guarantee absolute security.
Protect your device and credentials and report suspected unauthorized access to support@myvel.com. Do not send full payment card details, passwords, government identification, or unnecessary sensitive information through support or AI chat.
12. Your choices and rights#
- Account. Review and update profile and communication settings in the App.
- Device permissions. Change location, microphone, camera, Bluetooth, local-network, and notification choices in device settings. A manual alternative is provided where feasible.
- Marketing. Use unsubscribe links, reply STOP where supported, or change Settings. Transactional messages may continue.
- Cookies. Use Privacy Choices or cookie settings where available.
- Access, correction, portability, deletion, and restriction. Submit a request using the in-app privacy controls, the form at myvel.com/privacy-choices, or email support.
- Objection or consent withdrawal. Object to certain processing or withdraw consent where applicable.
- Appeal. If applicable law provides an appeal from a denied privacy request, reply to the decision with Appeal in the subject line.
To exercise a right, use myvel.com/privacy-choices, email support@myvel.com, or use the Account and Privacy controls in the App. We may verify your identity using information already associated with the Account. An authorized agent may submit a request where law permits, subject to proof of authority. We will not discriminate against you for exercising a privacy right.
13. Account and data deletion#
You may initiate deletion through Settings > Account > Delete Account. The App will explain and resolve pending Bookings, stop future Membership renewals, remove saved payment tokens that are no longer needed, revoke access credentials, and identify records that must be retained. After verification, VEL deletes or de-identifies remaining Account data that it is not legally or operationally required to keep within 90 days and sends a completion confirmation.
VEL will also maintain a public, mobile-friendly account-deletion page linked from myvel.com for users who no longer have the App. Temporary deactivation or deleting the App is not Account deletion. Certain transaction, security, fraud, safety, tax, and legal records may be retained for the periods described above and isolated from ordinary use. See the Data Deletion Instructions for the step-by-step request.
14. United States state privacy notice#
This section supplements the Policy for residents of states with applicable comprehensive privacy laws, including California. In the preceding 12 months, VEL has collected the categories below for the business purposes described in Sections 5 and 6. VEL has not sold these categories or shared them for cross-context behavioral advertising.
Statutory category | Examples in the VEL service | Disclosed to |
|---|---|---|
Identifiers and customer records | Name, contact details, Account ID, authentication reference, organization, billing metadata, legal acceptance and consent records. | Service providers; enterprise sponsor; Venue Partner where needed. |
Commercial information | Bookings, Membership, credits, purchase and refund history, service preferences. | Payment and service providers; enterprise sponsor; Venue Partner. |
Internet or device activity | IP address, device/app data, screens, cookies, diagnostics, security logs. | Cloud, analytics, diagnostics, security, and support providers. |
Geolocation | Approximate or precise location when enabled; selected Facility and arrival event. | Mapping, access, security, and Facility providers as needed. |
Audio, visual, and sensory information | Optional voice input, security footage where posted, Facility sensor and equipment events. | AI/transcription or security providers; Venue Partner where needed. |
Professional information | Employer, enterprise eligibility, business-use program information. | Enterprise sponsor and program providers. |
Inferences and preferences | Preferred locations, services, settings, and recommendations. | Service and analytics providers acting for VEL. |
Sensitive personal information | Precise location, Account access information, voice content, limited payment metadata. | Only providers needed for the requested service, security, or legal purpose. |
Sources are described in Section 4. California residents may request to know, access, correct, or delete personal information and may exercise rights concerning sale, sharing, or sensitive information where applicable. Because VEL does not sell or share personal information for cross-context behavioral advertising and uses sensitive information only for permitted service and security purposes, there is currently no separate Do Not Sell or Share opt-out required for those practices. VEL will honor recognized opt-out preference signals where applicable.
15. Children#
The services, including Guest access, are for adults age 18 or older and are not directed to minors. We do not knowingly allow a person under 18 to create an Account or enter through a Guest flow, and we do not knowingly collect personal information from a person under 18. If you believe a minor provided information, contact us so we can investigate and delete it as appropriate.
16. International transfers#
VEL is based in the United States and uses providers in the United States and other countries. Information may therefore be processed where privacy laws differ from those in your location. Where required, VEL uses an approved transfer mechanism, contractual safeguards, or another lawful basis. A country-specific notice may provide additional details before launch in that market.
Residents of the EEA, UK, Switzerland, Bahrain, the United Arab Emirates, Saudi Arabia, and other jurisdictions may have additional rights under local law. VEL will honor applicable rights and provide any required local contact or supplement before offering registration, Booking, or another localized service in that market. Registration and Booking must remain limited to markets VEL has approved for launch.
17. Changes to this Policy#
We may update this Policy to reflect product, provider, legal, or operational changes. We will post the updated version and effective date. If a change materially expands how we use previously collected information, we will provide appropriate notice and obtain affirmative permission where required rather than relying only on a revised policy.
18. Contact and complaints#
For privacy questions, requests, complaints, or an appeal:
Web: myvel.com/privacy-choices
Email: support@myvel.com (subject: Privacy Request)
Mail: Space 3, Inc. d/b/a VEL, 1417 Sadler Road, Suite 412, Fernandina Beach, Florida 32034, United States
You may also complain to the privacy or data-protection authority in your jurisdiction. Please contact VEL first if you are comfortable doing so; we will try to resolve the issue.