Legal documents › ViaVela Bona
ViaVela Privacy Policy
ViaVela Privacy Policy
DRAFT — for U.S. (Nebraska) counsel review. Not legal advice and not final. Have a licensed Nebraska attorney review before publishing. Company master (2026-09-05). Product-specific terms are supplied by the Product Schedule named in the Order; jurisdiction riders (Puerto Rico) are applied by
jurisdictions/PR.md. Attorney review required before use.
Last updated: 2026-07-10
This Privacy Policy explains how ViaVela Solutions LLC ("ViaVela," "we") collects, uses, and shares personal information through the ViaVela software platform and the end-user-facing experience (together, the "Services"). For the end-user-facing experience, ViaVela acts on behalf of the business you interact with (the "Business"). "Business" means the business that subscribes to the Product and that you deal with — a salon, a property-management company, a landscaping company, a clinic, or a repair shop, as identified in the applicable Product Schedule. "Product" means the ViaVela software application(s), surfaces, and features identified in the Product Schedule named in the applicable Order.
1. Roles
- Business = controller of its client data. The Business decides what data to collect from its clients and staff and why. ViaVela processes that data on the Business's behalf to provide the Services.
- ViaVela = processor/service provider for Business data, and controller for limited data we use to operate and improve the platform.
2. Information we collect
You provide: the information the Business's Product asks of you — for example your name, phone, and email; the details of an appointment, request, account, or unit; preferences; personnel profile details (for the Business's staff); and, where the Product records an acknowledgment or waiver, your typed-name signature. Which of these apply, and which are optional, is described in the Product Schedule.
Bona has no liability-waiver feature, so no waiver-acceptance data element is collected. The staff profile detail is role and company affiliation for the Business's own staff (office administrators) and for maintenance technicians, whose profile identifies the jobs assigned to them.
Generated by use: the records the Product creates as you and the Business use it — for example bookings or requests and their history, payments recorded (cash, or — where enabled — card, bank, or digital-wallet transactions processed by a third party), messages, and device or pairing identifiers for personnel-facing apps — as described in the Product Schedule.
Bona has no separately-paired personnel-facing application; maintenance technicians sign in to the same web application with staff credentials, and no device or pairing identifiers are generated or stored.
Technical: app/usage logs, IP address, and similar diagnostic data.
Payment cards: Where card payments are enabled, full card numbers are handled directly by our payment processor under its own terms. ViaVela does not store full card numbers or CVV — only references such as the last four digits or a processor token (processor-hosted / SAQ-A posture).
ViaVela Bona names Stripe, Inc. as its payment processor for rent and fee payments.
Where this data lives: The Product Schedule states where the Business's data is stored — on the Business's own device, on ViaVela-operated hosting in the United States, or both — and which system is the primary record.
Bona has no local-first data store. It is a hosted, cloud-based platform: all Customer Data is stored by ViaVela's hosted application and database (Render, United States), which is the Platform's primary system of record — there is no separate point-of-sale device and no local mirror split.
3. How we use information
To: provide and operate the Services; process bookings, requests, check-ins, and payments; send transactional messages (confirmations, reminders); maintain security, help prevent fraud, and keep audit logs; comply with law (including tax and recordkeeping); and improve the Services. We use waiver acceptances solely to record that a guest agreed to the Business's waiver and which version.
4. How we share information
- With the Business you interact with (and its authorized staff/technicians).
- Service providers that help us run the platform, under contracts limiting their use of the data, including: Render (hosting for the relay/API and static pages, United States region); Google LLC (Gmail API) for transactional email delivery; the OpenStreetMap Foundation (map tiles on the property portfolio map) — the viewer's browser sends its IP address and the map area viewed; where address geocoding is enabled, the configured geocoding service (such as OpenStreetMap Nominatim) receives the addresses it looks up; where error reporting is enabled, the configured error-reporting service receives the errors themselves: the type of error, its message, where in the code it occurred and which part of the Service was handling it. An error message can contain information entered in the Service if it appears in the message; nothing else from the request (its contents, cookies or IP address), no user or sign-in identifiers, no variable values, no log records and no performance traces are sent; and, where card payments are enabled, Stripe, Inc. for payment processing. We do not currently use any SMS, analytics, or advertising vendor.
- Legal/safety: when required by law or to protect rights and safety.
- Business transfers: in a merger, acquisition, or asset sale.
- We do not sell personal information.
5. Messaging
If you provide a phone number and/or email (both optional), you may receive transactional messages such as confirmations and reminders.
The current messaging channel is in-app message threads between staff, owners, residents, and technicians; the platform does not send SMS or text messages.
Any promotional message requires your separate opt-in consent, and you may opt out — including a global do-not-contact request — at any time by contacting the Business or ViaVela at legal@viavelahq.com. Consent and opt-out records may be retained as required by law.
6. Data retention
We retain personal information for as long as needed to provide the Services and for legitimate business or legal purposes. For example, transaction and tax records are typically kept for the period required by applicable law, and waiver-acceptance records are retained for the Business's liability-record purposes unless the Business instructs deletion and no legal hold applies. Businesses may request export or deletion of their data per their agreement with ViaVela (see the Data Processing Addendum); we honor verified requests subject to legal retention requirements.
7. Your choices & rights
Depending on your location, you may have rights to access, correct, delete, or restrict use of your personal information. Because the Business controls its client data, direct client requests to the Business; ViaVela will assist the Business in responding. Contact us at legal@viavelahq.com for platform-level questions or to submit a rights request; we will route Business-client requests to the relevant Business.
8. Security
We use administrative, technical, and physical safeguards designed to protect personal information — NIST-aligned practices including encryption in transit, access controls, account lockout, and audit logging. No system is perfectly secure; we cannot guarantee absolute security.
9. Children
The Services are not directed to children under 13, and we do not knowingly collect their personal information. A parent/guardian acting for a minor is responsible for that information.
10. Location of processing
The Services are operated from and hosted in the United States. By using the Services, you consent to the processing of your information in the United States.
11. Changes
We may update this Policy; material changes will be posted with a new "Last updated" date.
12. Contact
ViaVela Solutions LLC — legal@viavelahq.com — P.O. Box 13001, Offutt AFB, NE 68113.