Privacy

This page describes, in plain language, what this website actually does with your information — not a boilerplate policy, but a description of this exact system as it’s built.

What we keep, and why

When you book a rehearsal, we keep your name, phone number, email address and band name. We use them to hold your booking, confirm it, reach you if something changes, and — if you don’t show up — to recognise your details next time. If you buy an hour pack, we keep the same details against it.

If you create an account, we keep the same information plus your chosen language, a record of which sign-in methods (Google, Telegram) you’ve linked, plus the account identifier Google or Telegram gives us for you — that is what lets us recognise you the next time you sign in that way.

We don’t keep your card or bank details anywhere — we don’t take online payment yet, so there’s nothing to keep.

Signing in

You can sign in with a one-time code sent to your email, or with Google or Telegram if you link them. A successful sign-in sets a session cookie in your browser: it is only ever sent back to this site, and no script running in the browser can read it. That’s what keeps you signed in between visits.

Cookies

This site sets four cookies. All of them are strictly necessary to run the booking system — none of them is for advertising or analytics.

  • venue_session — set when you sign in, and what keeps you signed in for up to 60 days.
  • venue_device — also set when you sign in. It lets us recognise a browser you have signed in from before, so that when the hourly limit on sign-in codes is used up, your own familiar browser can still get a few more and you are not locked out of your account. A browser that goes unused for a year is forgotten.
  • venue_oauth — set only while you are signing in with Google, and only for the ten minutes that takes.
  • venue_telegram — the same thing for Telegram, and set only while you are signing in that way: for ten minutes it holds a random number that lets us check the sign-in came back to the browser that started it, and then, if your Telegram account is new to us, for fifteen minutes it holds the one-time ticket that lets you finish by giving us your email. It is gone as soon as you are signed in.

On the live site each of those names is written with a __Host- prefix — __Host-venue_session, and so on for the other three. That prefix is an instruction to your browser: store these only for this exact site, and let nothing else set or change them.

What your browser keeps

Besides the cookies above, two things are kept in the browser’s own storage rather than sent to us: the booking page keeps your in-progress or just-confirmed booking until you close the tab, so a reload does not lose it, and the staff panel remembers which language it was last used in. Nothing else.

If you book without an account, you get a private link to manage that one booking. It’s built from a long random token, and we only ever store a hash of it — even we can’t read the token back out of our own database, so the link itself is the key. Keep it somewhere safe.

Asking for a table in the bar

When you ask for a table on the Tables page, we keep five things: your name, your phone number, which table, which night and from what time. We use them for one purpose — to ring you back and confirm the table. Nothing else is done with them: no email is sent, you are not signed up to anything, and the number is not used to reach you about anything else. The Tables page itself never shows any of it — other visitors see only that the table is taken, never by whom. We keep the request for 90 days after the night it was for, and then it is deleted automatically, name and number with it.

Rate limiting

To stop the booking form being abused — automated spam, someone guessing at other people’s manage links — we count requests per visitor address over a short time window. We never store your actual IP address, only a one-way hash of it that can’t be turned back into the address it came from.

Bot protection

The booking and sign-in forms ask Cloudflare Turnstile to confirm you’re a real visitor, not a bot. It runs in your browser and talks to Cloudflare directly; we only ever receive the result of that check — passed or not — and no separate profile of you is built there.

Telling our staff

When you book or order an hour pack, our own bar staff get a one-line message in a private Telegram chat: your band name or your own name, the hours, what it costs and how you’re paying, and your phone number, so someone is expecting you. Nothing beyond that line goes there.

Email

Booking confirmations, cancellations, reschedules, sign-in codes, pack updates, session reminders and the notice we send when a new sign-in method is linked to your account are sent through Resend, an email delivery service. We use it only to deliver the emails listed above — never for marketing, and never shared with anyone else for their own purposes.

Hosting

This site and its booking system run entirely on Cloudflare (its Workers platform and D1 database). To know how many people visit, we use Cloudflare Web Analytics: it counts page views, where visitors come from (the linking site, the country) and which browser they use. It sets no cookie, does not recognise you from one visit to the next and does not follow you to other sites. There is no advertising platform in the picture.

No ad tracking

We don’t run advertising pixels or any script that follows you around the web. The only outside services this site talks to are the ones named above: Cloudflare (hosting, bot protection, the visit counter), Resend (email), Telegram (the message to our staff, and signing in if you choose it) and Google (signing in, only if you choose it).

How long we keep things

  • A manage link stops working 30 days after the session it belongs to.
  • Sign-in codes and the rate-limiting counters are deleted within about a day, and a session is removed once it has expired.
  • A browser we remember is forgotten after a year without use.
  • A table request in the bar is deleted 90 days after the night it was for.
  • The booking records themselves we keep until you ask us to delete them.

Asking us to delete your data

To see, correct or delete the information we hold about you, email us at thevenueevn@gmail.com or call +374 93 91 11 93. We’ll act on it as soon as we can.