← Back to app Terms of Service Refund Policy

Privacy Policy

Effective: 9 July 2026

This Privacy Policy explains how Marcus Barta ("we", "us", "our"), operator of HostMate (the "Service"), collects, uses, and handles personal information. It applies to venue operators, their staff, and the guests whose booking details are entered into the Service.

1. Information we collect

We collect:

  • Venue account information — venue name, login slug, PINs, plan, and configuration settings.
  • Booking data entered by venue staff — which may include guest names, party size, contact details, timing, and table/seating information, depending on what a venue chooses to record.
  • Push notification subscriptions — if a venue enables push notifications, we store the browser-issued subscription endpoint needed to deliver them.
  • Technical data — standard web server logs (IP address, browser type, timestamps) generated by our hosting infrastructure in the course of serving the Service.

We do not currently use third-party analytics, advertising, or tracking scripts within the Service.

2. Who provides this information

Venue account information and PINs are provided by the venue operator. Guest booking details are entered by venue staff, not collected directly from guests by us. Venues are responsible for ensuring they have an appropriate lawful basis for entering guest personal information into the Service (for example, because the guest made a booking directly with the venue).

3. How we use information

We use the information collected to: operate and provide the Service; authenticate venue, host, and admin logins; deliver booking reminders and push notifications a venue has configured; maintain the security and integrity of the Service; and communicate with venue operators about their account.

We do not sell personal information, and we do not use guest booking data for any purpose other than providing the Service to the venue that entered it.

4. Where information is stored

The Service is hosted on Cloudflare Pages and Cloudflare Workers. Application data is stored in Supabase (a hosted PostgreSQL database provider). These providers may store data outside your country of residence. We rely on these providers' security measures and our own access controls (including PIN-based authentication and service-role API access) to protect stored data.

5. Data retention

We retain venue and booking data for as long as a venue account remains active, plus a reasonable period afterward in case the venue wishes to reactivate. You may request deletion of your venue's data at any time by contacting us (see Section 8).

6. Sharing of information

We do not share personal information with third parties except: with the infrastructure providers described in Section 4, to the extent needed to operate the Service; where required by law, regulation, or valid legal process; or with your consent.

7. Your rights

Depending on your location, you may have rights to access, correct, or request deletion of personal information we hold about you. Venue operators can correct or delete most booking data directly within the app. For anything else, or if you are a guest whose details were entered by a venue, contact us at the email below and we will assist, referring guest data requests to the relevant venue where appropriate.

8. Contact

Questions about this Privacy Policy, or requests relating to your personal information, can be sent to marcusbarta@icloud.com.

9. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "Effective" date above when we do.

See also: Terms of Service · Refund Policy