Privacy policy.
This policy explains what personal information Aura Lounge collects through this website, how we use it, who else gets to see it, and the rights you have over it under EU and Cyprus data-protection law (GDPR + Law 125(I)/2018).
The short version
- We collect the details you give us when you book a table or send a message — your name, email, phone, party size, and anything you write in the notes.
- We use them to handle your reservation, reply to your message, and (only if you ticked the consent box) send you occasional news, events, and offers.
- Your data sits in Supabase (EU region, Frankfurt) and Resend (EU region, Ireland) — both operate under GDPR.
- You can ask us to show, correct, or delete any of it at any time — email info@aura-hookah.com.
1 · Who is responsible
The “controller” of your personal data is Aura Lounge, Alfredou 21, Agios Theodoros, 8010 Paphos, Cyprus. For data-related questions, write to info@aura-hookah.com.
2 · What we collect and why
| Data | Why we have it | Legal basis |
|---|---|---|
| Name, email, phone, party size, date/time, seating, hookah, occasion, notes | To process your reservation request, confirm or decline it, and contact you about it. | Contract performance (GDPR Art. 6(1)(b)) |
| Name, email, subject, message | To respond to your contact-form message. | Legitimate interest (Art. 6(1)(f)) |
| Email + above (only if you ticked “marketing consent”) | To send occasional news, events, and offers. | Consent (Art. 6(1)(a)) |
| Sign-in session cookies / local-storage tokens (admin only) | To keep the admin user logged in. | Strictly necessary |
3 · Where it’s stored and for how long
- Supabase (EU/Frankfurt) hosts the database — reservations, messages, venue settings.
- Resend (EU/Ireland) sends the confirmation and notification emails on our behalf.
- Hostinger (EU/Frankfurt) hosts the website itself; its server logs may briefly hold your IP for security reasons.
We keep reservation and message data for as long as we’re actively operating the venue, plus the period needed to satisfy tax, accounting, or other legal duties (typically 6 years). Marketing-consent records are kept until you opt out, then for an additional period to evidence the opt-out.
4 · Who we share it with
We share data only with the service providers above, who process it on our written instructions and under GDPR-compliant data-processing agreements. We don’t sell your information. We may disclose it to authorities if we’re legally required to.
5 · Your rights
Under GDPR you may, at any time:
- Ask us for a copy of the personal data we hold about you (“right of access”).
- Ask us to correct anything that’s wrong (“rectification”).
- Ask us to delete it (“right to erasure”), unless we’re obliged to keep it.
- Ask us to restrict or object to how we use it.
- Withdraw consent for marketing emails — every email also has an opt-out link.
- Lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (dataprotection.gov.cy).
To exercise any of these rights, email info@aura-hookah.com. We’ll respond within 30 days.
6 · Cookies
The site uses a small number of strictly-necessary cookies and a couple of local-storage entries:
aura-auth— keeps the admin session signed in (set by Supabase on the admin pages only).aura-cookie-ok— remembers that you’ve accepted the cookie banner.
No third-party analytics or advertising cookies are set today. If we add them, we’ll update this policy and ask for consent.
7 · Changes
If we change this policy materially, we’ll update the “Last updated” line. Continued use after a change means you’ve accepted it.