Privacy policy
Last updated: 14 August 2026
Sunhail provides poolside ordering software to hotels. This policy explains what personal data moves through the service, why, and what rights you have. We've tried to write it the way we'd want to read it.
Who is responsible
When you order as a guest, your hotel decides what data is needed and why — the hotel is the data controller, and Sunhail processes data on its behalf as a data processor. For staff accounts and for visitors to this website, Sunhail is the controller. Contact for anything in this policy: ozzieintheuk@gmail.com.
What we collect, and why
- Guests ordering at a hotel — room number and surname (to check you're on the hotel's guest list before an order is accepted), your orders (items, spot, notes, payment method — needed to make and deliver them and to put room charges on your bill), your language preference, and — only if you opt in — a push-notification subscription so your phone can be told your order is on its way.
- Walk-in guests — just the name you give (“Blue towel, pool 3” is fine) and the order itself.
- Hotel staff — username, display name, role, and a password we store only as a salted hash. Orders taken by staff are stamped with the staff member's display name for the hotel's records.
- Security telemetry — failed guest-validation attempts are recorded with a coarse network identifier, briefly, to rate-limit guessing attacks.
- Anonymous operational counts — the guest ordering page records when a menu is viewed, a cart is started, checkout is opened, and an order is placed. These first-party events are scoped to the hotel and ordering spot and may include the selected language, drink/food, item count, payment method, or whether a safe retry was replayed. They never include a room number, surname, IP address, free-text note, cookie identifier, or device identifier.
That's the list. We do not collect browsing history, precise location, contact lists, or anything from your phone beyond what you type in.
What we never do
- No advertising, and no selling or renting data to anyone — ever.
- No third-party analytics or tracking scripts anywhere in the product or this site. The bounded first-party operational counts described above are not used to follow anyone across visits, hotels, apps, or websites.
- No card numbers: payment happens through your hotel's existing till, card machine or front desk. Sunhail records only how an order will be paid.
Where data lives
Data is stored in a database in the European Union (Ireland), with the application hosted in EU regions, encrypted in transit. Our subprocessors are Vercel (application hosting) and Supabase (database hosting). Push notifications, if you enable them, are delivered through your browser vendor's push service (e.g. Apple or Google), which receives only an opaque delivery endpoint — never the content of your orders alongside your identity.
How long we keep it
- Order history is retained as part of the hotel's trading records for as long as the hotel uses the service (hotels typically need this for accounting).
- Guest-list entries are managed by the hotel and can be removed by it at any time.
- Push subscriptions are deleted the moment delivery fails or you revoke permission.
- Rate-limiting records expire automatically within minutes.
- Anonymous guest-funnel events are automatically deleted after 90 days.
Your rights
Under UK and EU data-protection law you can ask for access to, correction of, or deletion of your personal data, object to or restrict processing, and complain to a supervisory authority (in the UK, the ICO). For data handled on a hotel's behalf, the quickest route is the hotel itself; we support every such request. Either way, you can always write to us directly and we'll make it happen.
Cookies
The short version: only strictly-necessary session cookies, no trackers, no consent theatre. Details in the cookie policy.
Changes
If this policy changes materially, the date above changes with it and hotels are told directly. This page is always the current version.