HOREA
Privacy policy
Last updated: 26 August 2026.
Who this policy covers
HOREA ("we", "us") operates a reservation and payments platform used by restaurants. This policy explains what personal data we process, why, and what rights you have — whether you're a restaurant owner or staff member with a HOREA account, or a guest who books a table through a restaurant using HOREA.
[COMPANY NAME], registered at [ADDRESS], [KVK / COMPANY REGISTRATION NUMBER], is the entity operating HOREA. You can reach us for any privacy question or request at info@horea.nl.
Two different roles we play
For restaurant owner and staff accounts, HOREA is the data controller — we decide how that account data is used to run the platform.
For guest data (names, contact details, reservations), the restaurant is the data controller and HOREA is a data processor acting on the restaurant's instructions. If you're a guest with a question about how your data is used, your restaurant is usually the right first point of contact — but you can also reach us directly and we will route your request appropriately.
What we collect
Restaurant owner and staff accounts
- Email address and a securely hashed password.
- Which restaurant(s) you have access to and your role at each (owner, manager, host, staff).
- Actions taken in the product that we log for accountability and troubleshooting (see "Audit logging" below).
Guests
- Name, email address, and/or phone number, as provided at booking.
- Reservation details: date, time, party size, and any notes.
- If you choose to create a guest account for self-service booking management: your email and a securely hashed password.
- Payment information when a deposit or prepayment is required — see "Payments" below.
Payments
Payments are handled by Mollie, our payment service provider. HOREA never sees or stores your full card or bank details — Mollie handles that directly, along with identity verification (KYC), fraud prevention, and PCI DSS compliance. HOREA stores the payment status, amount, currency, and Mollie's own reference for each payment, so restaurants and guests can see what was paid and staff can resolve issues.
Cookies and similar technology
HOREA does not use advertising or tracking cookies, and does not show a cookie consent banner, because every cookie we set is strictly necessary for the service to work:
horea_session/horea_guest_session— keep you signed in. Deleted when you sign out or expire automatically.- A short-lived cookie during the Mollie account-connection flow, used only to prevent cross-site request forgery. Deleted immediately after the connection completes.
Other services we use (sub-processors)
- Mollie — payment processing, described above.
- Sentry — error monitoring, so we notice and fix bugs. Configured not to collect personal data by default; error reports may incidentally include technical details like a request path or a stack trace.
- PostHog (EU-hosted) — product analytics on how restaurants use the product, tied to the restaurant's account, not to individual guests.
- Resend — sends transactional email on our behalf (password resets, reservation confirmations). A reservation confirmation is sent showing the restaurant's own name and reply address, but the message is still delivered through Resend.
- Railway — hosts our application and database.
[CONFIRM: exact sub-processor list and their own data-processing locations, and add a data processing agreement reference for each, before publishing this for real.]
How long we keep data
We keep reservation and payment records for as long as required by applicable tax and accounting law [CONFIRM RETENTION PERIOD WITH AN ACCOUNTANT — commonly 7 years in the Netherlands for financial records]. Account data is kept for as long as your account is active, and deleted (or anonymized where we have a legal reason to keep transaction records) when you close your account — see "Your rights" below.
Audit logging
To keep the platform trustworthy and to help us investigate issues on a restaurant's behalf, HOREA keeps a log of significant account and settings changes (who made the change, and when). This log is used for troubleshooting and accountability, not for monitoring day-to-day activity.
Your rights
Under the GDPR, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing.
- Restaurant owner/staff accounts can export or delete their own account data directly from Settings.
- Guests can request access, export, or deletion of their data by contacting their restaurant, or by emailing us at info@horea.nl; we will action the request within the time required by law. Note that we may need to keep some records (like payment history) where the restaurant has a legal obligation to retain them, even after an erasure request — in that case we anonymize what we can rather than deleting the record outright.
Changes to this policy
We'll update this page as the product changes, and update the "last updated" date above when we do.