Privacy

Data Collection Policy

Your trust matters more than any data point. Here's exactly what we collect, why we collect it, and the promises we make about keeping it safe.

Our Promise to You

We will never sell, rent, trade or share your personal information with third parties for marketing, advertising or any commercial purpose — full stop.

The information you give us is used only to serve you: to confirm your booking, prepare for your visit, process payment for events, and contact you if anything changes. That's it.

1. What We Collect

When you book a table, request an event reservation, or otherwise contact us, we collect only what is necessary to provide the service:

  • Your full name
  • Phone number
  • Email address
  • Reservation details (date, time, party size, area, special requests)
  • For paid events: payment is processed by Stripe — we never see or store your card number, CVV, or full bank details
  • Basic technical data your browser sends automatically (IP address, device type) used only for security and to prevent abuse of our booking system

2. Why We Collect It

  • To create, confirm, modify and (if needed) cancel your booking
  • To contact you if there is a problem with your reservation
  • To process payment for ticketed events through Stripe
  • To meet legal record-keeping and tax obligations
  • To protect our booking system from spam, fraud and abuse

We do not use your information for marketing emails, profile-building, advertising, retargeting, or analytics that identify you personally.

3. What We Will Never Do

  • We will never sell your personal data
  • We will never rent, trade or share it with marketers, data brokers, or advertising networks
  • We will never publish your contact details publicly
  • We will never use it for purposes you have not consented to

4. Who Can See It

Access to your information is strictly limited to:

  • Authorised NOVA staff who need it to manage your booking
  • Trusted service providers that operate parts of our system (for example Stripe for payments, our email provider, and our hosting provider) — and only with the minimum data required for that specific task
  • Government or law-enforcement bodies, if we are legally required to comply with a valid court order or regulation

5. How We Keep It Safe

  • All data is transmitted over encrypted HTTPS connections
  • Passwords and sensitive credentials are hashed; payment data is tokenised by Stripe and never touches our servers in raw form
  • Access to the admin system is gated by individual accounts with role-based permissions and is fully audit-logged
  • We retain personal data only for as long as needed to provide the service and meet legal obligations — then we delete or anonymise it

6. Your Rights

At any time you may ask us to:

  • Show you a copy of the personal information we hold about you
  • Correct anything that is inaccurate or out of date
  • Delete your information (subject to records we must legally keep)
  • Withdraw your consent for any future use

We will action reasonable requests promptly and at no cost to you.

7. Cookies

We use a small number of strictly necessary cookies to keep the website working (for example, to remember an admin session). We do not use third-party advertising cookies and we do not track you across the web.

8. Changes to This Policy

If we ever update this policy we will publish the new version on this page. Material changes will be highlighted clearly. Continued use of the website after a change means you accept the updated policy.

9. Contact Us

If you have any questions about this policy, or you would like to exercise any of the rights listed above, please get in touch:

Last updated: June 2026