Privacy policy

Last updated: 14 August 2026

Sunhail provides poolside ordering software to hotels. This policy explains what personal data moves through the service, why, and what rights you have. We've tried to write it the way we'd want to read it.

Who is responsible

When you order as a guest, your hotel decides what data is needed and why — the hotel is the data controller, and Sunhail processes data on its behalf as a data processor. For staff accounts and for visitors to this website, Sunhail is the controller. Contact for anything in this policy: ozzieintheuk@gmail.com.

What we collect, and why

  • Guests ordering at a hotel — room number and surname (to check you're on the hotel's guest list before an order is accepted), your orders (items, spot, notes, payment method — needed to make and deliver them and to put room charges on your bill), your language preference, and — only if you opt in — a push-notification subscription so your phone can be told your order is on its way.
  • Walk-in guests — just the name you give (“Blue towel, pool 3” is fine) and the order itself.
  • Hotel staff — username, display name, role, and a password we store only as a salted hash. Orders taken by staff are stamped with the staff member's display name for the hotel's records.
  • Security telemetry — failed guest-validation attempts are recorded with a coarse network identifier, briefly, to rate-limit guessing attacks.

That's the list. We do not collect browsing history, precise location, contact lists, or anything from your phone beyond what you type in.

What we never do

  • No advertising, and no selling or renting data to anyone — ever.
  • No third-party analytics or tracking scripts anywhere in the product or this site.
  • No card numbers: payment happens through your hotel's existing till, card machine or front desk. Sunhail records only how an order will be paid.

Where data lives

Data is stored in a database in the European Union (Ireland), with the application hosted in EU regions, encrypted in transit. Our subprocessors are Vercel (application hosting) and Supabase (database hosting). Push notifications, if you enable them, are delivered through your browser vendor's push service (e.g. Apple or Google), which receives only an opaque delivery endpoint — never the content of your orders alongside your identity.

How long we keep it

  • Order history is retained as part of the hotel's trading records for as long as the hotel uses the service (hotels typically need this for accounting).
  • Guest-list entries are managed by the hotel and can be removed by it at any time.
  • Push subscriptions are deleted the moment delivery fails or you revoke permission.
  • Rate-limiting records expire automatically within minutes.

Your rights

Under UK and EU data-protection law you can ask for access to, correction of, or deletion of your personal data, object to or restrict processing, and complain to a supervisory authority (in the UK, the ICO). For data handled on a hotel's behalf, the quickest route is the hotel itself; we support every such request. Either way, you can always write to us directly and we'll make it happen.

Cookies

The short version: only strictly-necessary session cookies, no trackers, no consent theatre. Details in the cookie policy.

Changes

If this policy changes materially, the date above changes with it and hotels are told directly. This page is always the current version.