How personal data is collected and processed on the Heselo platform, and what rights apply.
Signing in to or using the System counts as acceptance of this Privacy policy.
1. Who it covers and roles
- This policy applies to the venue owner, director, admin, reception, waiters, and other staff accounts.
- The Customer (venue) is primarily responsible for guest / customer data entered in the System: what is recorded and who can see it.
- Heselo processes that data to provide the Service; ownership belongs to the Customer under the Service agreement.
- For Heselo accounts (email, name, password hash, sign-in session), Heselo processes data in its own right.
- If there is a conflict: commercial matters — Service agreement; usage behaviour — Terms of use; personal data — this policy.
2. What data is processed
The System may typically hold the following (if a field is empty, that data is not present):
Guest / customer card
- name or full name;
- phone;
- email (if entered);
- age (if entered);
- info source (how they heard about the venue);
- visit count and spend summary (statistics).
Reservations, live sessions, and operations
- date and time, resource (
table / area / roomtable / room); - notes and pre-order lines;
- payment amounts, method (e.g. cash, bank, POS), and cash / shift links.
Staff and account
- first name, last name, email;
- role and permissions;
- invite and registration status;
- password as a hash (plain passwords are not stored);
- last sign-in time.
Venue and subscription
- venue name, city, address, timezone;
- director and contact email;
- billing identity details provided by the Customer (e.g. tax ID / VOEN under the agreement).
Technical
- browser cookie for the sign-in session (`refresh_token`, HttpOnly);
- operation logs for security and support (sensitive fields are masked);
- temporary codes for email OTP / invites.
What we do not collect
- full bank card number, CVV, or PIN;
- passport / ID scans;
- biometrics;
- third-party marketing tracking cookies (not used in the current version).
When POS or card is selected, the System records only the payment method and amount; card details stay with the terminal / bank.
3. Purposes of processing
- Running reservations, live floor, cash drawer, inventory, and reports.
- Account sign-in, security, permissions, and protection-code checks.
- Subscription, notices, and support contact.
- The venue’s own statistics (customer and payment summaries).
- Legal obligations and dispute handling.
4. Legal basis
- Processing is for performing the Service agreement and providing the System.
- When entering guest data, the Customer must act on a lawful basis and for venue needs.
- Security logs and sessions — to protect the service and prevent misuse.
- When the law requires it — the corresponding legal basis.
5. Who data may be shared with
- Inside the venue — only staff with permissions (configured by the Customer).
- Heselo’s trusted infrastructure providers (hosting, email, etc.) — only as needed.
- Public authorities when required by law.
- There is no access to other venues’ data or sale of lists between venues.
- Heselo does not sell guest lists to third parties for advertising.
6. Retention
- Data is kept while the subscription is active and the Service is provided.
- After the agreement ends, Heselo may retain data for a limited time for technical and legal needs, then delete or anonymise it (except mandatory legal retention).
- Sign-in sessions and OTP codes are short-lived.
- Recommendation: regularly back up reports via Excel / export (Service agreement).
7. Security
- Passwords are stored as hashes; plain passwords are not disclosed.
- Sensitive operations may use the venue protection code and staff permissions.
- Logs mask passwords, tokens, OTPs, and similar fields.
- No online system is 100% risk-free; report suspicious sign-ins to the director and Heselo when possible.
8. Rights and requests
- A guest / customer should address requests about their data first to the venue (Customer).
- Requests about a staff account (email, name) can go through the director or Heselo support channels.
- Possible requests: access, correction, deletion, or restriction of processing — within law and the agreement.
- Deletion may affect operational and report integrity; some records may remain limited for legal retention.
9. Cookies and similar technologies
- The System uses a necessary cookie for the sign-in session (`refresh_token`).
- This cookie renews sign-in; it is not for advertising tracking.
- The browser may store technical data (session / language) only for the System to work.
10. Children and special categories
- The System is not aimed at children; the age field is for venue business needs, not deliberate child profiles.
- Special categories (health, religion, biometrics, etc.) are not required and are not collected.
11. International transfers
- Hosting and infrastructure may be in Azerbaijan or other countries.
- When transfers occur, Heselo aims to apply the same privacy and security principles.
12. Changes
- Heselo may update this Privacy policy. The new text is published under System → Documents; material changes may also be emailed to the director.
- Continued use after publication counts as acceptance.
13. Law and language
- This policy is governed by the laws of the Republic of Azerbaijan.
- If language versions conflict, Azerbaijani prevails.