Privacy Policy
Last updated: 29 September 2026
1. Who we are
SuperHoreca is operated by Sidestream OÜ, a company registered in the Republic of Estonia.
- Registry code: 17374822
- Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551
- Contact: info@superhoreca.app
In this policy, “we”, “us”, and “our” refer to Sidestream OÜ. “You” refers to anyone who uses the SuperHoreca platform (“Service”).
2. What data we collect
We collect the following categories of personal data:
2.1 Account data
When you register, we collect your name, email address, and password (hashed). If you create or join an organization, we also store your role and organization membership.
Registration also offers an optional phone number. It is used for one thing: so we can contact you — by WhatsApp or phone — to help you get your venue set up. We do not use it for marketing, we do not share it, and leaving it blank changes nothing about your account. You can add or remove it at any time on your profile page.
2.2 Usage data
We automatically collect information about how you interact with the Service, including pages visited, features used, browser type, device type, IP address, and timestamps.
2.3 Scheduling & availability data
When you or your manager create schedules, shifts, or availability entries, that data is stored in your organization’s workspace.
2.4 Payment data
Payments are processed by Stripe. We do not store your full credit card number. Stripe provides us with a token, the last four digits of your card, the card brand, and the expiration date. See Stripe’s Privacy Policy.
2.5 Newsletter subscribers
Where a venue runs a newsletter via SuperHoreca, we store the email addresses of guests who signed up through the public newsletter widget (single opt-in, with a confirmation email). This data is used only to send that venue’s newsletter and is never used for cross-venue marketing. Every newsletter email includes a one-click unsubscribe link compliant with RFC 8058.
2.6 Reservation guests
When a guest books via a venue’s embedded booking widget, we store the guest’s name, email, phone number, party size and booking notes. This data is used to deliver booking confirmations, reminders, cancellations and to allow staff to manage the reservation. We also keep a log of the messages sent to and received from the guest (address, subject and delivery status — not message content beyond the guest’s own replies) so venue staff can verify a confirmation actually arrived; it is kept for at most 24 months and is deleted earlier if the venue account is deleted.
For this category of data, SuperHoreca acts as a Data Processor and the venue is the Data Controller under Article 28 GDPR. The terms of that processing are set out in our Data Processing Agreement.
2.7 Supplier contacts
Venues may store the contact email addresses of their suppliers in order to route product orders through SuperHoreca. Same Processor / Controller distinction as section 2.6 — the venue is the Controller, SuperHoreca is the Processor, and the DPA governs the processing.
2.8 Onboarding emails
When a manager signs up, SuperHoreca sends a 6-step welcome email series over roughly two weeks to help them set up their venue. Every onboarding email contains an unsubscribe link; managers can also opt out from their profile settings at any time.
For every email we send you we record whether it was accepted, delivered or bounced, so we can tell a message that never arrived from one that was ignored. For marketing emails only — product announcements and campaigns, the ones that carry an unsubscribe link — we also record whether and when you opened the message, using a small tracking image. We do not do this for transactional email: verification links, password resets, sign-in links, schedule notifications and guest booking confirmations are never measured for opens. Opt out of marketing email and no open is recorded, because no marketing email is sent.
2.9 Cookies and analytics
Essential cookies keep you signed in and protect the account. They are exempt from consent under Article 5(3) of the ePrivacy Directive because the Service cannot work without them.
Everything else is off until you switch it on, in two separate choices: analytics (Google Analytics 4, PostHog) and marketing (Google Ads, an X advertising pixel served through Google Tag Manager, Microsoft Advertising’s UET tag and the Meta pixel of Meta Platforms Ireland Ltd), used to measure which ad brought you here and to show you our ads again later on those platforms. The legal basis for both is your consent under Article 6(1)(a) GDPR — a notice is not a substitute for it, so nothing in these two groups loads until you agree. You can change or withdraw either choice at any time from the footer of any page or the Cookie Policy, which also lists every cookie by name and lifetime. Withdrawing is as easy as consenting and takes effect immediately.
On the guest-facing pages of a venue — booking forms, polls, newsletter pages — we load no analytics or advertising code at all.
For the Meta pixel, Sidestream OÜ and Meta Platforms Ireland Ltd (Merrion Road, Dublin 4, Ireland) are joint controllers under Article 26 GDPR for collecting data on this site and passing it to Meta — which pages you saw, and whether you started a demo or signed up. What Meta does with it after that is Meta’s own responsibility, described in Meta’s privacy policy. The arrangement between us is Meta’s Controller Addendum. You can exercise your rights with either of us; requests about Meta’s own processing are best sent to Meta.
2.10 Demo venues
You can try SuperHoreca in a demo venue without an account. When you start one we keep a demo record: when you started, the page and campaign you arrived from (utm labels, the referring site and the kind of ad click — never the click’s own identifier), your type of device (phone, tablet or computer), the language, and what you did in the demo, counted as actions (shifts changed, the week sent, a clock-in). We keep it to learn whether the demo helps people decide, on the basis of our legitimate interest (Article 6(1)(f) GDPR). Everything inside the demo venue — names, shifts, bookings — is made up, and the venue is deleted after 14 days.
If you give us your email address in the demo — to receive the week, book a call or get the link back in — we use it for that and for one reminder before your demo expires. It only joins our mailing list if you tick “Keep me posted about SuperHoreca”. If you tap “WhatsApp Gaetan” we note that you did; the conversation itself runs on WhatsApp (Meta), under its own terms. If you create an account from the demo, the demo record stays linked to it as the record of how you found us; otherwise it is deleted 12 months after your last visit.
3. Legal basis for processing (GDPR)
We process your data based on the following legal grounds under the EU General Data Protection Regulation:
- Contract performance — processing necessary to provide the Service you signed up for (Art. 6(1)(b) GDPR).
- Legitimate interest — analytics, fraud prevention, and improving the Service (Art. 6(1)(f) GDPR).
- Legal obligation — complying with applicable laws, such as tax and accounting requirements (Art. 6(1)(c) GDPR).
- Consent — where required, for example for marketing emails (Art. 6(1)(a) GDPR). You may withdraw consent at any time.
4. How we use your data
- To provide, maintain, and improve the Service.
- To send transactional emails (schedule notifications, invites, password resets).
- To process payments and manage subscriptions.
- To monitor usage patterns and prevent abuse.
- To respond to support requests.
- To comply with legal obligations.
5. Data sharing & third-party processors
We share personal data only with vetted subprocessors that are contractually bound to GDPR-equivalent obligations:
- Vercel — hosting and edge delivery (USA, EU-US Data Privacy Framework).
- Neon — managed Postgres database (EU, Frankfurt region).
- Resend — transactional and marketing email delivery (USA, EU-US Data Privacy Framework).
- Stripe — payment processing (Ireland, EU-located entity).
- Google — Analytics, Tag Manager and OAuth sign-in (USA, EU-US Data Privacy Framework).
- GitHub — source code hosting; no customer data (USA, EU-US Data Privacy Framework).
- Vercel AI Gateway & Anthropic — the optional in-app assistant. Only when a manager asks it a question: that question and the schedule data needed to answer it are processed to produce the answer, and are not used to train models (USA, EU-US Data Privacy Framework).
The full current list — with purpose, location and safeguards — is published on our Subprocessors page. We notify Customers at least 30 days in advance before adding a new subprocessor.
We do not sell, rent, or trade your personal data. Advertising platforms receive only what the marketing tags send, and only once you have consented to them (section 2.9).
6. International data transfers
Your account and scheduling data live in the EU: the database (Neon) is in Frankfurt, payments run through Stripe Payments Europe in Ireland, product analytics (PostHog) run on EU infrastructure, and rate-limiting (Upstash) is EU-hosted.
Four providers involve a transfer to the United States, and we name them rather than leaving it vague:
- Vercel — application hosting and delivery.
- Resend — sending the emails the Service generates.
- Vercel AI Gateway & Anthropic — answering questions put to the in-app assistant. Nothing is sent unless a manager asks it something, and it is never used to train models.
- Google — analytics, advertising measurement and “sign in with Google”. The analytics and advertising parts run only if you consent to them.
Each is certified under the EU-US Data Privacy Framework, which the European Commission found adequate in its decision of 10 July 2023, and each is additionally covered by the Commission’s Standard Contractual Clauses. The current list, with purpose and location per provider, is at /subprocessors.
7. Data retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal, tax, or accounting purposes (up to 7 years for financial records as required by Estonian law).
8. Your rights
Under the GDPR, you have the right to:
- Access your personal data.
- Rectify inaccurate or incomplete data.
- Erase your data (“right to be forgotten”).
- Restrict processing of your data.
- Port your data to another service.
- Object to processing based on legitimate interest.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, email info@superhoreca.app. We answer without undue delay and in any case within one month of receiving the request, as Article 12(3) requires; if a request is unusually complex we may extend that by two further months and will tell you why within the first month. Exercising these rights is free. Data export and deletion are handled manually on request — self-service is on the roadmap.
If your personal data sits in a venue’s account — because you work there, booked a table, or subscribed to their newsletter — that venue is the controller and we act on their instructions. Send your request to the venue; if you send it to us we will forward it to them and tell you we have done so.
You can also lodge a complaint with a supervisory authority. Because Sidestream OÜ is established in Estonia, ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) — but Article 77 GDPR lets you complain to the authority in your own country of residence or workplace instead. In Belgium that is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, dataprotectionauthority.be), and in France the CNIL.
8a. Automated decision-making
We do not make decisions about you by automated means alone that produce legal effects or similarly significantly affect you, and we do not profile you for such decisions. Scheduling suggestions, conflict warnings and coverage indicators in the app are aids for a manager, who decides. No feature scores, ranks or evaluates staff automatically.
9. Breach notification
If we discover a personal-data breach, we will notify the relevant supervisory authority within 72 hours in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay.
For breaches affecting Customer Data (data the venue, as Controller, has put into the Service), we notify the Customer’s primary contact without undue delay so they can discharge their own Article 34 obligations to their data subjects.
10. Security
We implement industry-standard security measures including encrypted data transmission (TLS), hashed passwords, role-based access controls, and regular security reviews. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
11. Children
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the revised policy.
13. Contact & data-protection enquiries
For questions about this Privacy Policy, to exercise your rights under the GDPR, or to report a suspected data-protection incident, contact our privacy team:
Sidestream OÜ
Ahtri tn 12, 15551 Tallinn, Estonia
Privacy contact: info@superhoreca.app
General support: info@superhoreca.app
Registry code: 17374822
Sidestream OÜ is below the GDPR thresholds that mandate the formal appointment of a Data Protection Officer. The privacy mailbox above is monitored by the team responsible for data-protection matters and acts as the practical equivalent.