Last updated: 26 August 2026 (version 2026-08-26)
Privacy Policy
ENGLISH — CONTROLLING VERSION
N S Vu ("Sen Kasa", "we", "us") provides the Sen Kasa mobile application and website. Contact: privacy@senkasa.com; address: Fijnjekade 187, 2521DT 's-Gravenhage.
1. Scope and current release status
This policy covers the current release. Sen Kasa Pro is an auto-renewable subscription for point-of-sale and business management. Billing is handled by the App Store, Google Play, or — for website purchases — Stripe Managed Payments. The EET fiscal layer is built into the app but is inactive in this release: the app does not transmit any sale to an EET/tax-authority endpoint, and a receipt it produces is not proof that a sale was registered with a tax authority. If we later activate EET, the EET-related processing described below applies.
2. Data processed on your device
The app stores the information you enter to operate the app, including shop and register settings, product catalog, inventory, customer profiles, staff/profile names and PIN-related local settings, transaction and receipt history, VAT/payment details, reports, supplier orders, loyalty/gift-card/promotion records, and offline-retry records. This information is stored locally on your device by default.
Transaction location is optional and disabled by default. If you enable it and grant foreground location permission, the app requests one approximate location when a transaction completes and stores the rounded coordinates, reported accuracy, and capture time with that transaction. A sale always completes if location is denied or unavailable. Sen Kasa does not use this feature for continuous or background tracking.
When you import a .p12 EET certificate, the app reads the certificate and password to create EET requests. The certificate private key is not sent to Sen Kasa. Do not email certificates or passwords to support. The current Android release does not package a shared certificate in the public app.
3. Sen Kasa account and data we store
Sen Kasa Pro requires a Sen Kasa account hosted on Supabase (a managed PostgreSQL service in the EU). When you create an account we store:
- Your email address and authentication details (Supabase Auth).
- Merchant identity: business name, address, tax ID, and contact details you provide.
- Staff memberships: names, roles (owner/manager/cashier), and PIN-related account bindings. We do not store staff PIN values directly.
- Device registrations: platform, app version, and last-seen timestamp for each registered till.
- Your acceptance of the Terms of Service and of this policy: which document version you accepted, the language you read it in, whether you registered on the website or in the iOS or Android app, and the time. We keep this to evidence the agreement; no IP address or device fingerprint is stored with it.
- Completed-sale reporting records, including optional transaction coordinates only when the merchant enabled transaction location and the device supplied a position.
- Subscription entitlement: billing source (Apple, Google, Stripe, or complimentary), status, current period dates, and a provider-specific reference. We do not store complete payment-card details — card processing is handled entirely by Apple, Google, or Stripe under their own privacy terms.
You do not need a Sen Kasa account to apply for the First 25 pilot. If you use the website application form, we process the business name, contact person's name, email address, telephone number, city/postcode, business type, number of checkouts, current hardware choices, preferred language, and any note you choose to provide. We use this information only to assess the pilot application and contact you about the programme.
Your business data remains local on your device unless you explicitly migrate it to your account, use an integration, or choose Sen Kasa Cloud backup. The current managed-backup release covers the catalog, customers, supplier orders, gift cards, promotions, and loyalty balances; it does not yet claim complete sales or accounting recovery. You control when a managed snapshot is uploaded.
4. Network transfers
- Account and entitlement: when you sign in or refresh your subscription, the app sends your account credentials to Supabase and receives your merchant identity, staff list, device registrations, and entitlement status. This synchronisation keeps your POS Pro access, staff permissions, and account state consistent across devices.
- EET (when activated): the EET fiscal layer is inactive in this release, so no transaction data is sent to any EET endpoint. If EET is activated in a future release, choosing Send transmits the signed transaction data required by that service to the selected EET endpoint.
- Apple App Store subscriptions: when you purchase or restore Sen Kasa Pro through the App Store, Apple processes the payment under its own privacy policy. We receive a signed purchase token from Apple to verify your entitlement, and we store the resulting status and period dates. We do not receive your payment-card details.
- Google Play subscriptions: when you purchase or restore Sen Kasa Pro through Google Play, Google processes the payment under its own privacy policy. We receive a purchase token verified through the Google Play Developer API, and we store the resulting status and period dates. We do not receive your payment-card details.
- Stripe website billing: when you purchase Sen Kasa Pro on the Sen Kasa website, payment processing is handled by Stripe Managed Payments under Stripe's privacy policy. We store a Stripe customer identifier, subscription identifier, and entitlement status and period dates. We do not receive or store complete payment-card details. Stripe's processing of your payment data is governed by Stripe's own privacy and subprocessor terms.
- Complimentary access: some accounts receive complimentary Sen Kasa Pro access granted by us. This is recorded as a manual entitlement entry with the grant date, scope, and revocation status. No payment data is involved.
- Offline retry: if a transmission fails because of transport/network conditions, the app retains the necessary transaction data locally for a later retry. Server-side rejection is shown as an error and is not represented as an offline success.
- Optional transaction location: when enabled, the app may include the one-shot approximate coordinates, reported accuracy, and capture time in the merchant's completed-sale reporting record. Turning this setting off stops collection for future transactions.
- Sen Kasa Cloud backup: after an account owner connects the business and chooses Back up now, the supported portable-business data is sent to Sen Kasa's tenant-scoped Supabase infrastructure. The app records the source device, schema version, size, checksum, and backup time so a later download can be checked before restore. Restore is an explicit whole-backup replacement, not automatic background backup or real-time conflict merging. EET certificates, private keys, account sessions, bearer tokens, provider secrets, and payment-card data are excluded.
- Payment and accounting integrations: these transfer configuration and business data only when you configure a provider and actively test or use that integration. A payment provider, accounting provider, or printer-network service has its own privacy terms. Payment capture is not presented as available until its production contract is configured.
- Crash reports and usage analytics (optional, off by default): only if you turn them on, the app sends crash diagnostics and/or app-usage events to Google (Firebase Crashlytics and Google Analytics for Firebase). Nothing is sent while these options are off, which is the state a new installation starts in. Section 5 describes exactly what is and is not included.
- Email support: if you email us, your email and information you voluntarily include are processed to respond. Do not send certificates, passwords, card data, or unnecessary customer data.
- Public booking pages: when a guest books a table or an appointment on a business's Sen Kasa booking page, the booking is sent to Sen Kasa's Supabase infrastructure in the EU and appears in that business's till and portal, and the form's bot-protection challenge is verified with Cloudflare Turnstile. Section 6 describes this in full, and is addressed to the guest rather than the merchant.
- First 25 pilot form: when you submit the public website form, Resend transports the application from Sen Kasa's server to our
support@senkasa.cominbox. Your contact email is set as the reply address so our team can answer you. Do not include certificates, passwords, payment data, fiscal records, or customer data in the optional note.
5. Crash reporting and usage analytics
Sen Kasa offers two optional reporting settings. Both are off when you install the app and stay off unless you turn them on. We ask you once, after you have completed your first sale, and never again. You can change either setting at any time in Settings → General → Privacy, and you can decline without losing any app functionality.
- Crash reports. Technical diagnostics when the app crashes, stops responding, or hits an internal error. Processed by Google via Firebase Crashlytics.
- Usage statistics. Which screens you open and which features you use, so we can find what is broken or confusing. Processed by Google via Google Analytics for Firebase.
What a crash report contains: device model, operating-system version, app version and build, device language, the crash or error stack trace, the name of the screen you were on, the name of your last action, and a small set of diagnostic flags such as your business type, whether a printer is connected, and how many receipts are waiting in the offline retry queue.
What a usage event contains: the name of a screen or action, taken from a fixed list defined in the app, plus a small number of descriptive values drawn from a fixed vocabulary — for example a payment method (cash, card_terminal), an outcome (printed, failed), or a coarse size range. The app cannot send a value that is not on that list; free-text values are rejected before transmission.
What is never sent, whichever settings you choose:
- Receipts, order contents, or the names of your products, tables, tabs, or categories.
- Your amounts, prices, or revenue. Where the size of a sale is relevant we send only a coarse range (for example
300-699CZK), never a figure. - Customer, loyalty, or gift-card data, and staff names or PINs.
- EET certificates, private keys, fiscal identifiers (BKP, PKP, FIK), or the contents of any fiscal message.
- Your business name, address, tax ID, email address, or telephone number.
- Anything you type. No free-text field is ever transmitted.
How you are identified. Reports carry the pseudonymous merchant identifier for your account — a random identifier that means nothing outside Sen Kasa — together with an installation identifier generated by Firebase. If you are using the app in demo mode, no merchant identifier is attached at all.
No advertising and no cross-app tracking. We do not use advertising identifiers. The iOS app does not request App Tracking Transparency permission and does not access the IDFA; the Android app does not request the advertising ID. Google Signals and ads personalisation are disabled on our analytics property, and no advertising identifier is included in any export. We do not use this data for advertising, we do not sell personal data, and we do not combine it with data from other apps or websites.
Legal basis and withdrawal. We rely on your consent (Article 6(1)(a) GDPR). You may withdraw it at any time in Settings, with no effect on the lawfulness of processing before withdrawal. When you switch a setting off we stop collection, delete the installation identifier, clear the merchant identifier, and discard any reports still queued on your device.
Recipients and international transfer. Google acts as our processor under the Google Cloud/Firebase Data Processing Terms. Crashlytics and Analytics data is processed on Google infrastructure in the United States, on the basis of the European Commission's Standard Contractual Clauses. We also keep raw copies in our own Google BigQuery datasets so we can query them: the usage-analytics export is stored in the EU, and the crash export — the same crash and stack-trace data described above, no more — is stored in the United States, again under the Standard Contractual Clauses.
What Google is allowed to do with this data beyond running the service. We have switched off the setting that would let Google use your data to improve its own products and services, and we have switched off Google Signals and ads personalisation. Three narrower settings remain on: Google may use aggregated, de-identified measurement data for modelling and industry benchmarking; Google technical-support staff may access the analytics account when we ask them to help with a fault; and Google may use data about our account — how we configure and use Analytics — to make product recommendations to us. None of these gives Google your receipts, your amounts, or anything from the "never sent" list above, and none of them is used for advertising.
6. Bookings and appointments you make on a Sen Kasa booking page
This section is for guests, not merchants. Some businesses that use Sen Kasa publish a public booking page on this website so their guests can reserve a table or an appointment. The business decides how it uses your booking and is the controller of it; Sen Kasa operates the page and stores the booking on the business's behalf as its processor. If you have not booked through such a page, this section does not apply to you.
When you book, we store what you enter and what the booking needs: your name, the email address and/or telephone number you provide, the date and time, the party size (restaurant) or the service and staff member you chose (appointments), any note you add, the language you used, and the fact that the booking came from the public page rather than from staff. It is stored with the business's other data on Supabase in the EU and appears in that business's till and merchant portal. Contact details you enter are checked for format only — we do not verify that an address or number belongs to you.
Abuse protection. The booking form is protected by Cloudflare Turnstile, which receives a challenge token, the page's hostname, and your connecting IP address in order to distinguish a person from an automated script. We also apply rate limits computed from a keyed hash of your connecting IP address, so that one source cannot flood a business with bookings. We do not use either mechanism to profile you or to advertise to you.
Your management link. After booking you receive a private management link. It is a key, not an identifier: anyone holding that link can see and change that booking, so do not share it. Your browser keeps it for the current session only, unless you choose Remember on this device; both a copy control and a forget control are on the page. Access through the link ends 24 hours after the booking is due to finish, and immediately if the booking is cancelled or completed. Expired, revoked and unknown links all get the same answer, so the link cannot be used to test whether a booking exists.
What we email you. If you give an email address, Sen Kasa sends you a confirmation when the booking is made, a notice if it is moved or cancelled, and — only where the business has switched reminders on — one reminder before it starts. Nothing else: no marketing, no newsletter, no tracking pixel. Each message repeats the booking, carries your management link, and names the business so a reply reaches them rather than us. Resend is the provider that delivers the message for us and processes your address for that purpose alone. A cancellation notice deliberately carries no link, because cancelling ends your access in the same moment. We do not send text messages at all.
Book by phone instead if you would rather receive nothing. A booking made with only a telephone number gets no email, and the booking page says so before you confirm.
Retention and your choices. The booking remains in the business's records, which the business controls, and the management credential expires as described above. To correct or delete a booking, use your management link while it is valid or contact the business. You may also write to privacy@senkasa.com and we will act on it or pass it to the business as its processor. We do not use guest bookings for marketing, profiling, or model training.
7. What we do not do
Sen Kasa contains no advertising and no advertising SDK. We do not sell personal data, and we do not use your business data to train models. If we add a further analytics tool, a payment processor, or another cloud service that changes these practices, we will update this policy and the store disclosures before that release ships.
8. Retention and deletion
Local business data remains on your device until you delete it in the app where that control exists, clear the app's data, or uninstall the app. Deleting the app may not delete files you exported, printer records, or backups held by a cloud provider.
Your Sen Kasa account data (email, merchant identity, staff list, device registrations, entitlement records, and managed backup snapshots) is retained while your account is active, subject to any legally required retention. You may delete your account and associated Sen Kasa-controlled data through the website portal or by contacting privacy@senkasa.com. Account deletion removes the merchant's managed Sen Kasa Cloud snapshots. It does not delete local app data, files you exported, or data controlled independently by Apple, Google, Stripe, or another integration provider.
If you enable the optional reporting settings: usage-analytics event and user data is retained by Google for 14 months from your last activity; crash reports are retained for approximately 90 days; and rows in either of our raw BigQuery exports expire after 60 days. Switching the settings off stops further collection and deletes the identifiers described in section 5, and you may ask us to delete already-collected reporting data by emailing privacy@senkasa.com.
Guest bookings made on a public booking page are retained by the business that took them; the private management link expires 24 hours after the booking ends, or immediately once it is cancelled or completed. Section 6 explains how to correct or delete one.
Support emails are retained only as long as reasonably necessary to resolve the request, maintain security, or meet legal obligations.
Pilot applications are retained only as long as reasonably necessary to assess the application, contact the applicant, operate the pilot, or meet a legal obligation. To request deletion of a pilot application, email privacy@senkasa.com from the address used in the form.
To request access to or deletion of a specific managed backup, provide the account email and relevant reference to privacy@senkasa.com with the subject "Privacy deletion request". We may need to verify account ownership before acting.
9. Security and your responsibilities
Use a device passcode, keep your operating system current, protect certificate files and passwords, enable multi-factor authentication where available, and restrict staff access. No internet transmission or device storage is completely risk-free. We apply reasonable safeguards appropriate to the service, but you remain responsible for your merchant credentials and exported files.
10. Your rights and contact
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability for personal data we control. Contact privacy@senkasa.com. You may also contact your local data-protection authority. We may need to verify your request and may retain data when law requires it.
11. Changes
We may update this policy when the app or legal requirements change. The updated date identifies the current version.
ČEŠTINA — INFORMATIVNÍ PŘEKLAD
Zásady ochrany soukromí
N S Vu provozuje aplikaci a web Sen Kasa. Adresa: Fijnjekade 187, 2521DT 's-Gravenhage. Kontakt pro soukromí: privacy@senkasa.com.
Aplikace ve výchozím stavu ukládá obchodní údaje lokálně v zařízení. Režim EET je v této verzi neaktivní. Sen Kasa Pro vyžaduje účet hostovaný na Supabase (EU). Ukládáme e-mail, identitu provozovny, seznam zaměstnanců, registrace zařízení a stav oprávnění předplatného. Předplatné může být účtováno přes Apple, Google nebo Stripe — neukládáme kompletní údaje o platebních kartách.
Poloha transakce je volitelná a ve výchozím stavu vypnutá. Po zapnutí a udělení oprávnění aplikace při dokončení transakce jednorázově uloží přibližné souřadnice, přesnost a čas. Prodej funguje i bez polohy a aplikace polohu nesleduje nepřetržitě ani na pozadí.
Certifikát, heslo, token, údaje karty ani zákaznická data neposílejte podpoře. Účet můžete smazat přes webový portál nebo e-mailem na privacy@senkasa.com.
Při přihlášení do pilotu Prvních 25 přes webový formulář zpracujeme název provozovny, kontaktní jméno, e-mail, telefon, město/PSČ, typ provozovny, počet pokladen, zvolené vybavení, jazyk a dobrovolnou poznámku. Resend doručí přihlášku do schránky support@senkasa.com. Údaje používáme k posouzení přihlášky a kontaktování zájemce a uchováváme je jen po přiměřeně nutnou dobu. O výmaz lze požádat na privacy@senkasa.com.
Hlášení chyb a statistiky používání jsou volitelné a ve výchozím stavu vypnuté. Zeptáme se jednou po vašem prvním prodeji; kdykoli je můžete zapnout nebo vypnout v Nastavení → Obecné → Soukromí. Po zapnutí zpracovává data společnost Google (Firebase Crashlytics a Google Analytics for Firebase) jako náš zpracovatel, na serverech v USA na základě standardních smluvních doložek. Vlastní kopie v BigQuery uchováváme v EU (statistiky) a v USA (hlášení chyb). Sdílení dat pro zlepšování produktů Google, Google Signals i personalizaci reklam máme vypnuté; ponechána zůstávají jen agregovaná a anonymizovaná data pro modelování a srovnávání, přístup technické podpory Google a doporučení týkající se našeho účtu. Nikdy neodesíláme účtenky, názvy položek, částky ani tržby (pouze hrubá rozmezí), údaje zákazníků, jména či PINy zaměstnanců, certifikáty EET, fiskální identifikátory ani žádný volný text. Nepoužíváme reklamní identifikátory ani sledování napříč aplikacemi. Právním základem je souhlas, který můžete kdykoli odvolat; po vypnutí sběr ustane a identifikátory se smažou. Doba uchování: statistiky 14 měsíců, hlášení chyb přibližně 90 dní, náš surový export 60 dní.
Rezervace na veřejné rezervační stránce. Tento odstavec je určen hostům, nikoli provozovatelům. Když si u provozovny používající Sen Kasu rezervujete stůl nebo termín, ukládáme jméno, e-mail a/nebo telefon, datum a čas, počet osob (restaurace) nebo zvolenou službu a pracovníka (objednávky), poznámku, jazyk a údaj, že rezervace přišla z veřejné stránky. Správcem rezervace je provozovna; Sen Kasa je jejím zpracovatelem a data ukládá na Supabase v EU. Formulář chrání Cloudflare Turnstile, který dostává token výzvy, název hostitele stránky a vaši IP adresu; limity četnosti počítáme z klíčovaného otisku IP adresy. Odkaz pro správu rezervace je klíč, ne identifikátor — kdokoli s ním rezervaci zobrazí i změní, proto jej nesdílejte. Přístup končí 24 hodin po skončení rezervace a okamžitě při zrušení či dokončení. Co vám posíláme e-mailem: pokud uvedete e-mail, pošleme vám potvrzení rezervace, zprávu při jejím přesunu nebo zrušení a — jen pokud to provozovna zapne — jednu připomínku před začátkem. Nic jiného; žádný marketing. Zprávu doručuje poskytovatel Resend, který vaši adresu zpracovává výhradně k tomuto účelu. Zpráva o zrušení záměrně neobsahuje odkaz, protože zrušením váš přístup končí. SMS neposíláme. Rezervujte telefonicky, pokud si nepřejete dostávat nic. Rezervace nepoužíváme k marketingu, profilování ani trénování modelů.
E-maily na podporu uchováváme jen po přiměřeně nutnou dobu k vyřešení požadavku, udržení bezpečnosti nebo splnění právních povinností. Úplná anglická verze je rozhodná; před zveřejněním vyžaduje právní kontrolu.
NEDERLANDS — INFORMATIEVE VERTALING
Privacybeleid
N S Vu exploiteert de Sen Kasa-app en -website. Adres: Fijnjekade 187, 2521DT 's-Gravenhage. Contact over privacy: privacy@senkasa.com.
De app slaat uw bedrijfsgegevens standaard lokaal op uw apparaat op. De EET-laag is Tsjechische fiscale wetgeving en is in deze versie niet actief; in Nederland geldt geen verplichting tot een fiscale kassa. Sen Kasa Pro vereist een account dat wordt gehost op Supabase (EU). Wij bewaren uw e-mailadres, de identiteit van de onderneming, de personeelslijst, apparaatregistraties en de status van uw abonnement. Het abonnement kan worden afgerekend via Apple, Google of Stripe — volledige kaartgegevens leggen wij niet vast.
Transactielocatie is optioneel en staat standaard uit. Zet u die aan en geeft u toestemming, dan legt de app bij het afronden van een verkoop eenmalig een globale locatie, de nauwkeurigheid en het tijdstip vast. Een verkoop wordt altijd afgerond, ook zonder locatie; de app volgt u niet doorlopend of op de achtergrond.
Stuur nooit een certificaat, wachtwoord, token, kaartgegevens of klantgegevens naar support. U kunt uw account verwijderen via het webportaal of per e-mail aan privacy@senkasa.com.
Foutrapportages en gebruiksstatistieken zijn optioneel en staan standaard uit. Wij vragen dit eenmalig na uw eerste verkoop; u kunt het altijd aan- of uitzetten via Instellingen → Algemeen → Privacy. Staat het aan, dan verwerkt Google (Firebase Crashlytics en Google Analytics for Firebase) deze gegevens als onze verwerker, op servers in de VS op basis van de standaardcontractbepalingen. Wij versturen nooit bonnen, artikelnamen, bedragen of omzet (alleen grove bandbreedtes), klantgegevens, namen of pincodes van personeel, EET-certificaten, fiscale identificatiegegevens of vrije tekst. Wij gebruiken geen advertentie-identificatoren en volgen u niet tussen apps. De grondslag is uw toestemming, die u altijd kunt intrekken.
Reserveringen via de openbare reserveringspagina. Deze alinea is bedoeld voor gasten, niet voor ondernemers. Reserveert u een tafel of afspraak bij een onderneming die Sen Kasa gebruikt, dan bewaren wij uw naam, e-mailadres en/of telefoonnummer, de datum en tijd, het aantal personen of de gekozen dienst, uw opmerking en uw taal. De onderneming is verwerkingsverantwoordelijke; Sen Kasa is verwerker en slaat de gegevens op bij Supabase in de EU. De beheerlink is een sleutel, geen identificatie — iedereen met die link kan de reservering inzien en wijzigen, dus deel hem niet. Wij sturen u een bevestiging, een bericht bij wijziging of annulering en — alleen als de onderneming dat aanzet — één herinnering. Verder niets, en geen marketing.
Supportmails bewaren wij niet langer dan redelijkerwijs nodig is om uw vraag af te handelen, de beveiliging te waarborgen of aan een wettelijke plicht te voldoen. De volledige Engelse versie is bepalend en vereist juridische toetsing vóór publicatie.
TIẾNG VIỆT — BẢN DỊCH THAM KHẢO
Chính sách quyền riêng tư
N S Vu vận hành ứng dụng và trang web Sen Kasa. Địa chỉ: Fijnjekade 187, 2521DT 's-Gravenhage. Liên hệ quyền riêng tư: privacy@senkasa.com.
Ứng dụng mặc định lưu dữ liệu kinh doanh cục bộ trên thiết bị. EET trong bản này chưa được kích hoạt. Sen Kasa Pro yêu cầu tài khoản lưu trữ trên Supabase (EU). Chúng tôi lưu email, danh tính cửa hàng, danh sách nhân viên, đăng ký thiết bị và trạng thái đăng ký. Đăng ký có thể được thanh toán qua Apple, Google hoặc Stripe — chúng tôi không lưu thông tin thẻ đầy đủ.
Vị trí giao dịch là tùy chọn và mặc định tắt. Khi bạn bật và cấp quyền vị trí lúc dùng ứng dụng, Sen Kasa chỉ ghi một vị trí gần đúng, độ chính xác và thời gian khi giao dịch hoàn tất. Giao dịch vẫn hoàn tất nếu không có vị trí và ứng dụng không theo dõi liên tục hoặc trong nền.
Không gửi chứng chỉ, mật khẩu, token, dữ liệu thẻ hoặc dữ liệu khách hàng cho bộ phận hỗ trợ. Bạn có thể xóa tài khoản qua cổng web hoặc email tới privacy@senkasa.com.
Khi đăng ký chương trình 25 cửa hàng đầu tiên qua biểu mẫu web, chúng tôi xử lý tên cửa hàng, tên người liên hệ, email, điện thoại, thành phố/mã bưu điện, loại hình kinh doanh, số quầy, thiết bị được chọn, ngôn ngữ và ghi chú tự nguyện. Resend chuyển đăng ký tới hộp thư support@senkasa.com. Chúng tôi chỉ dùng dữ liệu để đánh giá đăng ký, liên hệ và vận hành pilot, đồng thời chỉ lưu trong thời gian hợp lý cần thiết. Bạn có thể yêu cầu xóa qua privacy@senkasa.com.
Báo cáo lỗi và thống kê sử dụng là tùy chọn và mặc định tắt. Chúng tôi hỏi một lần sau giao dịch đầu tiên của bạn; bạn có thể bật hoặc tắt bất cứ lúc nào trong Cài đặt → Chung → Quyền riêng tư. Khi được bật, Google (Firebase Crashlytics và Google Analytics for Firebase) xử lý dữ liệu với tư cách bên xử lý cho chúng tôi, trên máy chủ tại Hoa Kỳ theo Điều khoản hợp đồng tiêu chuẩn của EU. Bản sao thô của chúng tôi trong BigQuery được lưu tại EU (thống kê) và Hoa Kỳ (báo cáo lỗi). Chúng tôi đã tắt việc chia sẻ dữ liệu để cải thiện sản phẩm của Google, tắt Google Signals và cá nhân hóa quảng cáo; chỉ còn dữ liệu tổng hợp đã ẩn danh dùng cho mô hình hóa và đối chiếu ngành, quyền truy cập của bộ phận hỗ trợ kỹ thuật Google, và các đề xuất liên quan đến tài khoản của chúng tôi. Chúng tôi không bao giờ gửi hóa đơn, tên món, số tiền hay doanh thu (chỉ khoảng giá trị thô), dữ liệu khách hàng, tên hoặc mã PIN nhân viên, chứng chỉ EET, mã số tài chính, hay bất kỳ nội dung tự nhập nào. Chúng tôi không dùng mã định danh quảng cáo và không theo dõi giữa các ứng dụng. Cơ sở pháp lý là sự đồng ý của bạn và bạn có thể rút lại bất cứ lúc nào; khi tắt, việc thu thập dừng lại và các mã định danh bị xóa. Thời gian lưu: thống kê 14 tháng, báo cáo lỗi khoảng 90 ngày, bản xuất thô của chúng tôi 60 ngày.
Đặt chỗ trên trang đặt chỗ công khai. Đoạn này dành cho khách, không dành cho chủ cửa hàng. Khi bạn đặt bàn hoặc đặt lịch hẹn tại một cơ sở dùng Sen Kasa, chúng tôi lưu tên, email và/hoặc số điện thoại, ngày giờ, số khách (nhà hàng) hoặc dịch vụ và nhân viên bạn chọn (lịch hẹn), ghi chú, ngôn ngữ và thông tin rằng đơn đặt đến từ trang công khai. Cơ sở kinh doanh là bên kiểm soát dữ liệu đặt chỗ; Sen Kasa là bên xử lý và lưu trên Supabase tại EU. Biểu mẫu được bảo vệ bằng Cloudflare Turnstile — dịch vụ này nhận mã xác thực, tên miền trang và địa chỉ IP kết nối của bạn; giới hạn tần suất được tính từ mã băm có khóa của địa chỉ IP. Đường dẫn quản lý là một chiếc chìa khóa, không phải mã định danh: bất kỳ ai có nó đều xem và thay đổi được lịch đặt, vì vậy đừng chia sẻ. Quyền truy cập kết thúc 24 giờ sau khi lịch đặt kết thúc, và ngay lập tức khi bị hủy hoặc đã hoàn tất. Những email chúng tôi gửi cho bạn: nếu bạn cung cấp email, chúng tôi gửi xác nhận khi đặt chỗ, thông báo khi lịch đổi hoặc bị hủy, và — chỉ khi cơ sở bật tính năng này — một lời nhắc trước giờ hẹn. Không gì khác, không tiếp thị. Nhà cung cấp Resend chuyển thư giúp chúng tôi và chỉ xử lý địa chỉ của bạn cho mục đích đó. Thư báo hủy cố ý không kèm đường dẫn, vì khi hủy thì quyền truy cập cũng chấm dứt. Chúng tôi không gửi tin nhắn SMS. Hãy đặt chỗ qua điện thoại nếu bạn không muốn nhận gì cả. Chúng tôi không dùng dữ liệu đặt chỗ để tiếp thị, lập hồ sơ hay huấn luyện mô hình.
Email hỗ trợ chỉ được lưu trong thời gian hợp lý cần thiết để xử lý yêu cầu, duy trì bảo mật hoặc đáp ứng nghĩa vụ pháp lý. Bản tiếng Anh là bản áp dụng và cần được tư vấn pháp lý rà soát trước khi phát hành.
Sen Kasa