The Velerenne platform

Every feature you’d build
already built.

Multi-tenancy, white-label, payments, email campaigns, QR check-in, revenue intelligence — it’s a complete production guest and ticketing stack, not a prototype. Every feature ships as a clean JSON API.

40+

Individual capabilities across 9 feature categories. Every single one available as a JSON API endpoint — use the included white-label frontend or bring your own.

One deployment. Every client in their own world.

True isolation means every client company gets a separate Bunny Database instance. There’s no shared schema, no row-level filtering, no risk of cross-tenant data leaks. A bug in client A’s account physically cannot touch client B’s data.

🔒 Isolated databases

Each company gets its own Bunny Database (LibSQL/SQLite). The platform DB stores only encrypted metadata — no event, order, or attendee data is ever shared across tenants.

🔐 AES-256-GCM encrypted tokens

Each company’s database token is encrypted with AES-256-GCM before being stored in the platform DB. Tokens are decrypted in memory per request — never stored in plaintext.

🌐 Host-based routing

Tenant resolution happens on every request via the Host header. The correct company is identified by matching against custom_domain or subdomain in the platform DB, cached for 5 minutes.

⚡ Provisioned in seconds

New company provisioning calls the Bunny Database API, creates the isolated DB, runs the full schema, seeds admin credentials, and returns ready-to-use login details — without a custom build.

📄 Unlimited companies

One Edge Script deployment handles unlimited companies. There’s no per-tenant infrastructure to manage. Add a new company row and they’re live.

📋 Audit log

Every admin action is recorded in a tenant-scoped audit log. Who changed what, when, and from which IP. Non-repudiation baked in from day one.

Your client’s identity, everywhere.

Every touchpoint — the public ticketing site, checkout, ticket confirmation, QR code email, and admin dashboard — is fully branded per client. There’s no “powered by” badge, no shared domain, no indication they’re using third-party infrastructure.

  • 🏠
    Custom domain Point any domain or subdomain at the platform via CNAME. SSL is handled by Bunny. The ticketing site, checkout, and API all serve from the client’s domain.
  • 🎨
    Brand colours & fonts Primary colour, background, font stack, logo URL, and custom CSS are stored per tenant and applied to every page. Changes take effect immediately.
  • 📧
    Branded transactional email Confirmation, reminder, and check-in emails send from the client’s own Mailgun sending domain with their logo and colours. Attendees never see your infrastructure.
  • 🎟
    Branded ticket QR codes Ticket confirmation PDFs and QR code emails carry the event branding. Check-in staff see the event name, not a generic scanner UI.
  • 📄
    Custom CSS override Clients can inject arbitrary CSS for edge cases — custom fonts, layout tweaks, promotional banners — without touching the frontend codebase.
tickets.riverside-events.co.uk
Riverside Events
tickets.riverside-events.co.uk
Riverside Jazz Evening — VIP Table
£120.00
Attendee details
Pay £120.00 — powered by SumUp
Every pixel is Riverside Events. Not us.

Their payment account. Their revenue. Zero intermediary.

Each client connects their own Stripe or SumUp account. When a ticket is purchased, payment flows directly to the client — not through us. We never hold, process, or take a cut of their ticket revenue.

💳 Stripe Checkout

Full Stripe Checkout integration with webhook-verified payment confirmation. Supports all Stripe payment methods. Configuration stored encrypted per tenant.

💴 SumUp

SumUp checkout for clients who prefer it. The same pluggable provider interface — just a different payment button. Mix and match across your client base.

🔓 Encrypted credentials

Provider keys and secrets are stored AES-256-GCM encrypted per company. Decrypted only during payment operations — never logged, never exposed in API responses.

✅ HMAC webhook verification

Every incoming webhook is verified against the provider’s signature before any action is taken. Replay attacks are rejected. Idempotency keys prevent double-processing.

🔄 Pluggable provider interface

Adding a new payment provider means implementing a three-method TypeScript interface: createCheckout, handleWebhook, createRefund. That’s it.

🔷 Free ticket path

Zero-value orders bypass the payment provider entirely. Confirmation emails, QR codes, and attendee records are created identically — no special case handling needed.

Automated emails that feel personal. Blasts that convert.

Two layers of email: automated drip sequences tied to event timing, and manual blast campaigns to targeted audience segments. Both run through the client’s own Mailgun account.

⌛ Drip campaigns

Configure email sequences for each event: “send 7 days before”, “send on the day”, “send 3 days after”. Reusable templates with personalisation tokens for attendee name, event details, and ticket info.

📤 Email blasts

Send a one-off campaign to any audience segment — all attendees, a specific event’s guests, or a CRM segment like “lapsed customers”. Subject, body, filter, fire.

📈 Campaign attribution

Every blast generates a unique campaign ID. When an attendee clicks through and buys, the order is tagged. Revenue Intelligence shows exactly how much each campaign drove.

📨 Transactional confirmations

Instant booking confirmation with ticket summary and QR code. Reminder emails sent automatically before events. All using the client’s own sending domain.

📝 Reusable templates

Create and save email templates once, reuse across events. Personalisation tokens: {{name}}, {{event}}, {{date}}, {{venue}}, {{ticket_type}}.

🔹 Waitlist notifications

When a sold-out event gets a cancellation, waitlisted attendees receive an automated email with a time-limited claim link. First come, first served, fully automated.

Every edge case covered, out of the box.

Multiple ticket types per event, flexible sale windows, capacity management, discount codes, comp tickets, ticket transfers, and custom attendee fields. The full set from day one.

🎟 Multiple ticket tiers

Create Early Bird, General, VIP, Group, and any custom ticket types per event. Each type has its own price, capacity, sale window, and attendee fields.

📅 Sale windows

Set a start and end time for each ticket type. Early Bird closes automatically at the right moment. Sales stop when capacity is reached or the window closes — no manual intervention.

🆕 Discount codes

Percentage or fixed-value discounts. Per-code usage limits. Expiry dates. Codes can be restricted to specific ticket types or events. Full reporting on redemptions.

🆕 Comp tickets

Issue complimentary tickets to any attendee directly from the dashboard. Full audit trail. Comp orders bypass payment processing but follow the same QR code and confirmation flow.

🔄 Ticket transfers

Attendees can transfer their ticket to someone else via a secure tokenised link. The original ticket is voided and a new one issued to the transferee. Full check-in integrity maintained.

📌 Custom attendee fields

Define custom questions per ticket type: dietary requirements, t-shirt size, company name, accessibility needs. Answers captured at checkout, exported with attendee CSV.

⏳ Waitlist management

When an event sells out, attendees can join the waitlist. Cancellations trigger automatic waitlist notifications. Claim links expire after a configurable window.

🖼 Referral tracking

Generate unique referral links per attendee. Track how many tickets each referral drove. Reward your best promoters with discount codes or comp tickets.

📄 Attendee CSV export

Export the full attendee list for any event, including custom field answers, ticket types, order values, check-in status, and referral data. One click, clean spreadsheet.

Know your audience. Act on it.

A lightweight CRM built around event history. Every customer’s attendance record, spend, notes, and tags are in one place. Audience segments are calculated automatically so you always know who to target.

  • 👤
    Customer profiles Every attendee gets a profile showing their full event history, total spend, ticket types, notes, and tags. Built from order data — no manual entry.
  • 📌
    Audience segments Six pre-built segments calculated on demand: lapsed (90+ days), new (first 30 days), high value (top 10% spend), single event, repeat, and at-risk.
  • 📋
    Notes & tags Admin staff can add private notes and custom tags to any customer record. Tags are filterable and exportable. Notes are timestamped with the author.
  • 📤
    Segment blasts Select any audience segment and fire a targeted email campaign directly from the CRM. No CSV export, no external tool, no manual list-building.
  • 🔍
    Flexible audience builder Beyond presets, build custom audiences by filtering on event attendance, spend range, date of last purchase, tags, and more.
Audience overview
High value (top 10% spend)
234
Repeat attendees (2+ events)
892
New this month
156
Lapsed (90+ days inactive)
341
At risk (spending declined)
89
Customer profile — Sarah Mitchell
VIP High value Repeat
14 events · £2,840 total spend · Last seen 8 days ago

Stop guessing what’s working.

Revenue Intelligence is a layer of analytics built on top of your real order and campaign data. No third-party tracking scripts, no GDPR headaches, no BI tool to configure. Everything lives in your client’s isolated database and answers the questions that matter.

📈 Campaign attribution

Every email campaign generates a campaignId that’s tracked through checkout. See exactly how much revenue each blast generated, how many orders it drove, and the conversion rate.

📋 Cohort retention

18 months of cohort analysis. See which monthly cohorts retained well, which churned early, and how retention trends have changed over time. Data per event and across the whole account.

👥 Audience segments

Six pre-calculated audience groups: lapsed, new, high-value, single-event, repeat, and at-risk. Segment counts update on demand. Each segment is blastable in one click.

🔴 At-risk detection

Customers whose average purchase frequency has dropped are automatically flagged. Re-engage them before they lapse — not after.

🆕 Event-level attribution

Attribution is tracked per event as well as at the account level. See which events drove the most returning customers, not just the most first-time buyers.

🔒 Privacy-first

All analytics data is derived from first-party order data in the client’s own isolated database. No third-party tracking scripts, no cookies, no cross-domain data sharing.

Any device. Any venue. No app required.

Venue staff scan QR codes using their phone’s camera. No app install, no dedicated hardware, no Wi-Fi dependency for the QR code itself. The check-in interface is a web page — open it, scan, done.

📱 Any device

The check-in page works on any smartphone, tablet, or laptop with a camera. iOS, Android, desktop — no app to install, no account required for scanning staff.

🔓 Rotatable check-in tokens

Check-in credentials are completely separate from admin credentials. Hand them to venue staff without any risk. Rotate them after the event with one click.

✅ Real-time validation

QR codes are HMAC-signed. Forgery is impossible. Duplicate scans are rejected with a clear “already checked in” status — no double admissions.

📊 Live check-in dashboard

Admins see a live count of attendees checked in vs total tickets sold. Drill down to individual attendee check-in times from the dashboard at any point.

📋 Attendee lookup

Staff can search by name or email on the check-in page for attendees whose phone battery is dead. Manual check-in with a full audit trail.

🆔 Multi-event support

Check-in tokens are scoped to a specific event. Staff at Event A can’t accidentally check in tickets for Event B.

Headless at the core. Bring your own frontend.

Every feature is available via a clean JSON API. The included frontend templates are a starting point — replace any part of them, or build something entirely your own. The platform is the API, not the UI.

  • 🔗
    REST JSON API Every operation — events, tickets, orders, attendees, campaigns, check-in, CRM — is a versioned JSON endpoint. Standard HTTP verbs, standard status codes.
  • ✅
    Idempotency keys Checkout and mutation endpoints accept Idempotency-Key headers. Safe to retry on network failure without double-charging or double-provisioning.
  • 🔒
    JWT authentication HS256 JWTs for admin routes, scoped check-in tokens for venue staff, and separate platform JWTs for the operator. Fully decoupled auth layers.
  • ⚡
    Edge-native — globally deployed The API runs on Bunny Edge Scripting, serving from the nearest of Bunny’s global PoPs. Sub-50ms response times worldwide. No cold starts.
  • 📈
    Rate limiting Per-IP and per-tenant rate limiting on all public endpoints. Configurable thresholds. Abuse is blocked before it reaches the database.
// Example: list upcoming events GET /api/events?status=published // Response { "events": [{ "id": "a1b2c3d4...", "title": "Summer Festival 2026", "starts_at": "2026-07-01T18:00:00Z", "venue": "Hyde Park, London", "tickets": [{ "type": "General Admission", "price": 4500, "available": 388 }] }] }

Every feature. Live in under an hour.

Provisioning is automated. Everything above is available from the moment your first client is created — nothing to configure, nothing to wait for.

Get started → Ask us anything