Legal
Privacy Policy
1. Who We Are
HAMR Ltd, trading as Covered, provides an online booking and table-management system to restaurants, bars and other hospitality venues.
- Registered name: HAMR Ltd
- Trading name: Covered
- Company number: 17190046, registered in England & Wales
- Registered office: 25 Lowther Street, Whitehaven, United Kingdom, CA28 7DG
- Email: hello@covered.technology
- Website: www.covered.technology
References to "we", "us" or "our" in this policy mean HAMR Ltd. References to "you" mean anyone whose personal data this policy covers. That means venue operators and their staff, people who contact us or visit our website, and guests of the venues that use Covered, for the data we handle on a venue's behalf.
1.1 Where we are the controller
We are the data controller for the personal data we need to run Covered as a business:
- the details of the person who opens a venue's Covered account and manages its subscription, which we need to open, secure and run that account (section 2.1);
- our billing records for a venue's Covered subscription;
- enquiries (including the enquiry form on our website) and support correspondence sent to us (section 2.9); and
- technical data from visits to our website and use of the platform (section 2.8).
1.2 Where the venue is the controller
When a guest books a table, places a pre-order, leaves card details or receives a message through a venue's Covered booking page, the venue is the data controller of that guest's details. The venue decides why they are collected and what happens to them. We process them on the venue's behalf, as its processor. We act only on its instructions, under our Data Processing Agreement, and we do not use them for any purpose of our own. This covers the booking, customer profile, pre-order, payment and communications data described in sections 2.2 to 2.7. The venue is also the controller of the records it keeps in Covered about its own staff, such as their names, email addresses and access roles.
Each venue publishes its own privacy notice, linked from its booking page. That notice explains how the venue uses its guests' details and how long it keeps them. Where this policy describes guest data, it explains how we handle that data for the venue.
1.3 If you are a guest
Please send any request about your booking details to the venue you booked with. That includes asking for a copy, a correction or deletion, or asking it to stop marketing to you. The venue decides these requests, not Covered. We do not forward requests about a venue's guest data, so please contact the venue directly. Its privacy notice, linked from its booking page, explains how to contact it.
2. Personal Data We Collect
Sections 2.2 to 2.7 describe data we process on behalf of venues, which are the controllers of that data (section 1.2).
2.1 Account Data
When someone opens a venue's Covered account, we collect their name, email address, telephone number, business name, business address, and role within the organisation. Details of other staff that a venue adds to its account are the venue's records (section 1.2).
2.2 Booking and Reservation Data
Guest name, email, telephone number, party size, date and time of booking, seating preferences, and any special requests or dietary requirements provided by the guest.
2.3 Customer Profile Data
Guest visit history, preferences, tags assigned by venue staff, no-show records, VIP status, and notes entered by venue operators.
2.4 Floor Plan Data
Table layouts, seating capacity, section names, and zone configurations created by venue operators.
2.5 Pre-Order and Menu Data
Items selected, quantities, customisations, dietary flags, and associated pricing when guests place pre-orders through the platform.
2.6 Payment Data
Payments are processed by Stripe and Square. We do not store full card numbers. We receive and retain transaction identifiers, amounts, currency, payment status, and the last four digits of the card used.
2.7 Communications Data
Confirmation messages, reminders, and marketing communications sent via email (Resend) and WhatsApp (Meta / WhatsApp Business API), including delivery and read receipts.
2.8 Technical Data
IP address, browser type and version, device type, operating system, referring URL, pages viewed and timestamps.
2.9 Enquiry Data
When you send us an enquiry, including through the enquiry form on our website, we collect your name and role, email address, phone number, your venue's name, phone number, country and address, which Covered products you're interested in, the answers you give on the form, and notes of our conversations with you. We use them to reply to you and to arrange and set up your account. If you go ahead, they become part of your account data (section 2.1).
3. Lawful Bases for Processing
The table below covers the data we control (section 1.1). For guest data, the venue decides the lawful basis and sets it out in its own privacy notice.
We rely on the following lawful bases under Article 6 of the UK GDPR:
| Purpose | Lawful Basis |
|---|---|
| Providing the Covered platform and managing your account | Performance of a contract (Art. 6(1)(b)) |
| Providing bookings, pre-orders and payments to venues | Performance of a contract (Art. 6(1)(b)) |
| Sending account and service emails to venue operators | Performance of a contract (Art. 6(1)(b)) |
| Replying to enquiries, and arranging and setting up the account you ask us for (section 2.9) | Legitimate interests (Art. 6(1)(f)), or steps you ask us to take before a contract (Art. 6(1)(b)) |
| Sending our own marketing communications to venue operators | Consent (Art. 6(1)(a)) |
| Platform security, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f)) |
| Analytics and service improvement | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal and tax obligations | Legal obligation (Art. 6(1)(c)) |
| Responding to data subject rights requests | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have conducted balancing tests to ensure our interests do not override your fundamental rights and freedoms. You may request a copy of our balancing assessments by contacting us.
4. Recipients and Sub-Processors
We share personal data only where necessary to operate the platform. Our current sub-processors are:
| Sub-Processor | Purpose | Country |
|---|---|---|
| Vercel Inc. | Application hosting and edge delivery | United States |
| Supabase Inc. | Database hosting and authentication | European Union |
| Stripe Inc. | Payment processing | United States / European Union |
| Square (Block Inc.) | Point-of-sale integration | United States |
| Meta Platforms (WhatsApp Business API) | Guest messaging and notifications | United States / European Union |
| Resend (Plus Five Five, Inc.) | Email delivery: account and staff emails; and, for venues without their own email server, all guest emails — booking messages (confirmations, reminders, changes and cancellations, pre-orders, card and payment notices, waitlist offers), post-visit review requests, and marketing emails to guests who opted in | United States |
| GitHub, Inc. | Runs the job that makes our 6-hourly interim copy of the database. Each copy is encrypted on GitHub’s servers before it is stored, so stored copies are encrypted. Copies made before we added this encryption were not, and expire within 7 days of being made. | United States |
| Cloudflare, Inc. | Bot check (Cloudflare Turnstile) on the booking form, the website enquiry form and sign-in. During the check it processes the visitor’s IP address and browser and device signals, to tell people from bots. Cloudflare also uses these signals under its own privacy terms to improve its bot detection. | United States / global network |
To place a venue on our own internal map, we send its postcode, and nothing else, to postcodes.io, a free UK postcode service, which tells us where that postcode is.
We may also share data with professional advisers (accountants, lawyers) and with law enforcement or regulators when required by law.
5. Google User Data
If your venue chooses to connect its Google Business Profile, Covered asks Google for your permission using the scope https://www.googleapis.com/auth/business.manage. You are shown Google's own consent screen and the connection is entirely optional — Covered works fully without it.
With that permission, we access and store:
- The list of Google Business Profile accounts and locations your Google account manages, so you can pick which listing belongs to your venue.
- The identifiers of the location you select, so we can show its reviews on your dashboard.
- The OAuth access and refresh tokens Google issues, encrypted at rest, so the connection continues to work without asking you to sign in again.
We use this data only to display and manage your own venue's Google presence inside your Covered dashboard. We do not use it for advertising, we do not sell or transfer it, we do not use it to train machine-learning models, and no human at Covered reads it except where you ask us to for support or where the law requires it.
Covered's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect at any time from Settings → Integrations in Covered, or revoke Covered's access directly from your Google Account permissions page. Revoking access deletes the stored tokens at our next sync.
6. International Transfers
Some of our sub-processors are based in the United States. Where personal data is transferred outside the United Kingdom, we rely on one or more of the following safeguards:
- The UK International Data Transfer Agreement (UK IDTA) issued by the ICO, incorporating the appropriate risk assessment.
- The EU Standard Contractual Clauses together with the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (the UK Addendum) issued by the ICO, incorporating the appropriate risk assessment.
- The UK Extension to the EU-US Data Privacy Framework (EU-US DPF) for sub-processors that are certified under the EU-US DPF and its UK Extension.
- An adequacy decision by the UK Secretary of State, where applicable.
You may request a copy of the relevant transfer mechanism by contacting us at hello@covered.technology.
7. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this policy:
- Account data (the account owner's details, section 2.1): For the duration of your account plus 2 years after closure, to allow reactivation and to resolve any outstanding disputes. Staff records a venue keeps in Covered are the venue's, and the venue decides how long they are kept.
- Our billing records (a venue's Covered subscription invoices and payments): 6 years from the end of the financial year they relate to, as HMRC requires, and to deal with legal claims (Limitation Act 1980).
- Guest data we hold for a venue: The venue decides how long it is kept. The venue is the controller of its guests' data, and we act on its instructions under our Data Processing Agreement. When a guest asks a venue to erase them, their name, contact details and preferences are erased, and the venue's booking and payment records are kept without the name. If the venue charged the guest in the last 120 days, or a payment dispute is open, the venue may instead keep that booking's details (name, contact details, the booking, the terms accepted and the charge) sealed as evidence in case the payment is disputed, until 120 days after the charge or, while a dispute about that payment is open, until the dispute is resolved; they are then erased automatically.
- Marketing consent records we hold for a venue: Kept as the venue instructs. When a guest withdraws consent, the venue's suppression record is kept so they are not contacted again.
- Technical and analytics data: Aggregated and anonymised within 26 months.
- Support correspondence: 2 years from resolution of the enquiry.
- Enquiries that don't lead to an account: kept for 2 years from our last contact, then deleted.
8. Your Rights
Under the UK GDPR you have the following rights in relation to your personal data:
- Right of access -- request a copy of the personal data we hold about you.
- Right to rectification -- ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") -- ask us to delete your data where there is no compelling reason for continued processing.
- Right to restrict processing -- ask us to suspend the processing of your data in certain circumstances.
- Right to data portability -- receive your data in a structured, commonly used, machine-readable format.
- Right to object -- object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making -- not be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
- Right to withdraw consent -- where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
If you are a guest of a venue, please send your request to that venue (see section 1.3). If you work at a venue, the records it keeps about you in Covered are the venue's (section 1.2), so please send requests about them to the venue.
For data we control, please email us at hello@covered.technology. We will respond within one calendar month of receiving your request. If we need to extend this period (by up to two further months), we will inform you within the first month and explain why.
9. Complaints
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
If your concern is about a booking, please contact the venue you booked with first. For anything else, we would appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first.
10. Children's Data
Covered is a business-to-business platform designed for use by hospitality operators and their staff. Covered accounts are for businesses and are not for under-16s. Details about children that a venue or a booker enters, such as a child's dietary needs, are handled for the venue as described in section 1.2.
11. Changes to This Policy
We may update this privacy policy from time to time. Where changes are material, we will tell account holders by email or by a notice in the platform. The "Last updated" date at the top of this page indicates when the policy was most recently revised.
12. Contact Us
If you have any questions about this privacy policy or our data practices, please contact us:
- Email: hello@covered.technology
- Website: www.covered.technology