This policy explains how Slotify ("we", "us") handles personal data on slotify.app and on the booking websites we host for venues. Slotify is operated by Supun Wijegunawardhana. It is written to meet Sri Lanka's Personal Data Protection Act No. 9 of 2022.
1. Who is responsible
- For venue owners and their staff (your Slotify account and billing), we are the controller.
- For players and other customers of a venue, the venue is the controller: it decides what to collect and why. We process that data on the venue's behalf to run its booking website and portal.
- Questions about a booking or your account at a venue should go to that venue first. You can always contact us too.
2. Who owns the data
- Each venue owns its own business data: its customers, bookings, payments, content and settings.
- We do not sell personal data, and we never use one venue's customer data for another venue or for our own marketing.
- Slotify owns the software, the platform and its brand. Anonymous, aggregated statistics (for example total bookings on the platform) may be used to improve the service.
3. What we collect
- Account details: name, email, phone number, password (stored hashed, never readable).
- Booking details: venue, space, date and time, amounts, discounts, notes and booking history.
- Payment records: amounts, method, status and references. Card payments are processed by the venue's payment gateway (Stripe or PayHere); we never receive or store card numbers.
- Uploaded files: bank-transfer slips and venue images.
- Messages we send for the venue: booking confirmations, reminders and receipts by email, SMS or WhatsApp.
- Technical and security data: IP address, browser, sign-in times and an audit log of actions, used to keep accounts secure and investigate problems.
- Cookies: only what's needed to keep you signed in, hold a slot while you check out, and remember your display settings. We don't use advertising cookies.
4. Why we use it
- To provide bookings, payments, receipts, reminders and the venue portal (performing the service you or the venue asked for).
- To keep the platform secure, prevent fraud and meet legal and tax obligations.
- To bill venues for their plan and commission.
- To send service messages. Marketing messages are sent only with consent and can be switched off at any time.
5. Who we share it with
- The venue you book with, which sees your booking and contact details.
- Service providers that help us run the platform: hosting and database, email (Microsoft Azure Communication Services or Resend), SMS and WhatsApp providers, and the payment gateways the venue uses. They process data only on our instructions.
- Authorities when the law requires it.
6. Where it's stored and for how long
- Data may be processed outside Sri Lanka by our hosting and service providers, with appropriate safeguards.
- We keep data while the venue's account is active. When a venue leaves, its data is deleted within 90 days, except records we must keep by law (for example billing records).
- Audit and security logs are kept for as long as needed to protect the service.
7. Security
- Passwords are hashed; payment and messaging credentials are encrypted at rest; each venue's data is kept separate; all actions by staff and administrators are logged.
- No system is perfectly secure. If a breach affects your personal data, we'll tell the venue and, where required, you and the authorities.
8. Your rights
- You can ask to see, correct or delete your personal data, or object to how it's used, subject to legal limits.
- Players: ask the venue (or us, and we'll pass it on). You can also update your details from "My account".
- We'll respond within the time the law allows.
9. Children
- The service isn't aimed at children under 16. A parent or guardian should make bookings for them.
10. Changes
- We'll post any update here with a new date, and tell venues about material changes in advance.
11. Contact