Privacy policy
Last updated: 15 July 2026
This policy explains how Kelvo (“Kelvo”, “we”, “us”) handles personal data when you use our platform at usekelvo.com and on organisation subdomains at *.kelvo.co. We are committed to the UK GDPR and the Data Protection Act 2018.
Controller vs processor — who is responsible
Kelvo plays two roles depending on the data:
- We are the controllerfor the data we collect to run Kelvo itself — operator account holders’ details, billing information, marketing enquiries, and usage/analytics of our own site.
- We are a processor for the customer and participant data an operator collects through the platform (bookings, attendees, contact details). For that data the operator is the controller and decides how it is used; we process it on their instructions under our Data Processing Agreement. Questions about how a specific academy uses your data should go to that academy.
What data we process
- Account & identity: name, email address, password (stored hashed), and organisation details for operators.
- Booking & participant data: the name and details of participants (which may include children), the classes booked, attendance, and any notes an operator or parent adds.
- Payment data: card payments are handled by Stripe. We do not store full card numbers; we retain payment metadata such as amounts, status, and Stripe identifiers.
- Communications: transactional emails we send you, and any support or enquiry messages you send us.
- Technical data: IP address, device/browser information, and strictly-necessary cookies used for authentication and session continuity (see our Cookie Policy).
Children’s data
Kelvo is used to book activities for children, so we process children’s personal data on behalf of operators. Bookings for a child are made by a parent or guardian, who provides and consents to that data. We do not knowingly let children create their own accounts, and we apply the same security measures to children’s data as to any other personal data.
Why we process it, and our lawful bases
- To provide the service (create accounts, take bookings, process payments, manage schedules) — performance of a contract.
- To send service messages (booking confirmations, trial reminders, payment receipts) — performance of a contract / legitimate interests.
- To keep the platform secure and fix problems — legitimate interests.
- To meet legal and financial obligations (accounting, fraud prevention, responding to lawful requests) — legal obligation.
- Marketing to operators (product updates, prospect follow-up) — consent or legitimate interests; you can opt out at any time.
Who we share data with (sub-processors)
We use carefully selected third parties to run Kelvo. Each has access only to the data needed for their function:
- Stripe — payment processing and card handling.
- Resend — sending transactional and verification emails.
- Amazon Web Services (S3, London / eu-west-2) — file and image storage.
- MongoDB Atlas — hosted application database.
- Vercel — hosting for the web application.
- DigitalOcean — hosting for the API server.
We do not sell your personal data. We may disclose data where required by law, to protect our rights, or as part of a business transfer, in which case we will tell affected users.
International transfers
We aim to keep data in the UK/EU where possible (our file storage is in the London region). Where a sub-processor transfers data outside the UK, that transfer is covered by an adequacy decision or appropriate safeguards such as the UK International Data Transfer Agreement / Addendum.
How long we keep data
We keep personal data for as long as your account is active and as needed to provide the service. After an account or booking relationship ends, we retain data only as long as necessary for legal, accounting and fraud-prevention purposes (typically up to six years for financial records), then delete or anonymise it. Where Kelvo acts as processor, an operator can instruct us to delete their customers’ data.
How we protect data
Passwords are hashed, connections are encrypted in transit, access to production systems is restricted, and payment card data is handled by Stripe rather than stored by us. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data and will notify the ICO and affected individuals of a qualifying breach as the law requires.
Your rights
Under UK GDPR you have the right to:
- access a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- data portability;
- withdraw consent where processing relies on it.
Where Kelvo is the controller, contact us to exercise these rights. Where an operator is the controller (booking/participant data), we will forward your request to them or help them respond. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
Contact
For any privacy question, or to exercise your rights, email jason@letscreateweb.com.