Privacy Policy
VELVET is built so that there is as little about you, your people and your clients in it as possible. This page explains exactly what we hold, what we deliberately do not hold, and what you can ask us to do with it.
- Effective
- 16 September 2026
- Last updated
- 16 September 2026
1. Who we are
VELVET is a job, shift and payout management product for multi-branch venue operators, published by Augustus Solutions from Melbourne, Australia. In this policy, "VELVET", "we" and "us" mean Augustus Solutions; "you" means the account holder and the people you authorise to use the account.
We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). Where you or your people are in a place with its own data protection law, we apply the protections in this policy to everyone rather than running two standards.
2. The principle this product is built on
Most systems in this category start by asking who everyone is. VELVET does not. The product is designed so that it can do its job — record work, calculate payouts, report takings — without ever learning the identity of a worker, a staff member or a client.
We will never require the real name, contact details, address, identity documents or immigration status of an owner, worker, staff member or client. We will never require real business registration details in order to record work. Labels in VELVET can be nicknames, initials, numbers or anything else that means something to your counter and nothing to anyone else.
There is no client database, no marketing list, no consent trail and no contact history in VELVET, because the product never asks for the information those things are made of.
3. What we collect
We collect three kinds of information, and no more than each one needs.
- Account information
- The email address you sign in with, and — if you sign in with Google or GitHub — the basic profile that provider returns to confirm the sign-in. This is the one place a real identity may reasonably appear, because someone has to own the account and receive the receipts.
- Billing information
- Your subscription status, plan, billing period and invoice history. Card numbers are entered directly with our payment processor and are never sent to, seen by or stored on VELVET’s servers. We store only the identifier that links your account to your record with the processor.
- Operational data you enter
- Branches, trading day settings, services and prices, recorded jobs, shifts, splits, payables and the labels you use for workers, staff and rooms. This is your business record. It is yours, we treat it as confidential, and we do not sell it, rent it, mine it or use it to build anything outside your account.
- Technical data
- Server and security logs (IP address, timestamp, page or endpoint, browser and device type, error traces) and aggregate usage analytics. We use these to keep the service running, to investigate faults and to detect abuse.
4. What we do not collect
To be explicit, VELVET does not ask for and has no field for:
- Real names, dates of birth, addresses or phone numbers of workers, staff or clients.
- Identity or right-to-work documents, visa or immigration status, or photographs of people.
- Client contact details, client history tied to an identifiable person, or any marketing list.
- Health information, health records or anything about the nature of a client’s treatment beyond the service label on your own menu.
- Biometric data, location tracking of individuals, or worker surveillance of any kind.
- Bank account numbers or card numbers for you or your people.
- Business registration, licensing or landlord details as a condition of recording work.
Free-text fields are the one exception, and they are in your hands. If you type real personal information into a label, a note or a service name, VELVET will store it, because it stores what you enter. It then becomes personal information that you are responsible for — so don’t put it there. Use a nickname.
5. How we use it
- To provide the service: record jobs, calculate payables, report takings on your trading day, and keep your branches in sync.
- To authenticate you and keep your account secure.
- To take payment and manage your subscription.
- To send service email you need — sign-in links, receipts, security notices and material changes to the service. These are not marketing and you cannot be opted out of them while you hold an account.
- To investigate faults, prevent abuse and meet our legal obligations.
We do not use your operational data to train machine learning models, to build market reports, or for any purpose other than running VELVET for you.
7. Where it lives and how it is protected
Data is stored with our infrastructure providers and may be processed on servers outside Australia, including in the United States and the European Union. Wherever it sits, it remains subject to this policy and to our agreements with those providers.
- All traffic is encrypted in transit; data is encrypted at rest by our infrastructure providers.
- Database row-level security restricts each account to its own records; separate credentials are used for the narrow set of trusted server-side operations that must bypass it.
- Access by our staff is limited to what is needed to support or repair the service.
No system is perfectly secure. If a data breach occurs that is likely to cause serious harm, we will notify affected account holders and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
8. How long we keep it
We keep your operational data for as long as your account is open, because it is your business record and you may need it. If you close your account, we delete or irreversibly anonymise your operational data within 90 days, except where we must keep something longer to meet a legal obligation — billing and tax records being the usual example.
Security and server logs are retained for a short period and then discarded on a rolling basis.
9. Your rights
You can ask us to do any of the following, at any time, at no charge:
- Tell you what personal information we hold about you.
- Correct anything that is wrong.
- Export your operational data in a machine-readable format.
- Delete your account and the data in it.
Email privacy@velvetspas.com and we will respond within 30 days. If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
11. Children
VELVET is a business product and is not directed at anyone under 18. We do not knowingly create accounts for minors, and we will delete any account we learn belongs to one.
12. Changes to this policy
If we change this policy in a way that materially affects you, we will email the account holder and update the date at the top of this page before the change takes effect. Continuing to use VELVET after that date means you accept the updated policy.
13. Contact
Privacy questions, access requests and complaints: privacy@velvetspas.com. Anything else: support@velvetspas.com. We are Augustus Solutions, Melbourne, Australia.