1. Overview
This Privacy Policy explains how LeisureOS, operated by Aiby Technologies, collects, uses, stores and protects personal information when people use the LeisureOS website, business dashboard, Staff interface, customer QR experience and related services.
For some information, LeisureOS acts as the organization responsible for deciding why the information is used. For data that a business enters about its own customers, Staff or operations, the business may be the primary decision-maker and LeisureOS processes the information to provide the service.
2. Information we collect
| Category | Examples | Why it is used |
|---|---|---|
| Business account data | Business name, branch details, Owner name, email, phone and login credentials | Create and secure the business account and provide the service |
| Staff and Manager data | Name, role, branch, permissions, job title and account status | Control access, assign responsibility and operate staff workflows |
| Customer operational data | Table session, orders, service requests, running bill and payment-request status | Provide QR ordering and table service |
| Customer contact details | Name, phone or email when a business chooses to collect them for bookings, pool admissions or customer records | Operate the business workflow requested by the venue |
| Payment metadata | Method, amount, reference, amount received and outstanding balance | Record operational payment status and reporting |
| Booking and pool data | Booking resource, date, time, party size, pool admission, wristband code and status | Manage reservations, access and capacity |
| Inventory and business records | Products, stock levels, buying prices, expenses, sales and reports | Provide business operations and financial reporting features |
| Security and technical data | Session identifiers, IP-derived security hashes, audit records, authentication attempts and device/browser information available to the web server | Secure accounts, prevent abuse and diagnose issues |
3. Payment information
In the current core product, LeisureOS records operational payment information such as Cash, POS or Transfer, the amount recorded and an optional transaction reference. LeisureOS does not intentionally require customers to enter full payment-card numbers into the core platform.
If payment-processing integrations are introduced later, this Policy should be updated to explain which provider processes card or bank details and what information LeisureOS receives from that provider.
4. How we use information
We use information where necessary to:
- create and authenticate accounts;
- provide the LeisureOS features selected by a business;
- route orders, requests and responsibilities between customers and Staff;
- record sales, payments, stock, expenses, bookings, pool activity and reports;
- protect the platform against fraud, unauthorized access, spam and abuse;
- maintain, troubleshoot and improve the service;
- communicate service-related information;
- comply with legal obligations where applicable.
5. Businesses using LeisureOS
A venue or business using LeisureOS may decide what personal information it collects from its Staff and customers and why it collects that information. In those situations, the business is responsible for its own notices, permissions and legal obligations.
LeisureOS processes that business-controlled data to provide the software. Additional processor terms are described in the Data Processing Addendum.
7. Data retention
We aim to retain personal information only for as long as needed for the purposes described in this Policy, to maintain legitimate business records, resolve disputes, enforce agreements, comply with legal obligations and support backup/recovery requirements.
Specific retention periods should be finalized before commercial launch based on customer needs, legal requirements and the backup architecture used in production.
8. Security
LeisureOS uses safeguards designed to protect account and business information, including authenticated sessions, password hashing, access controls, tenant and branch separation, CSRF protections, signed QR links, rate limiting, server-side validation, audit records and encrypted HTTPS transport when deployed in production.
No system can guarantee absolute security. Businesses should protect account credentials and devices and should notify LeisureOS if unauthorized access is suspected.
10. Privacy rights
Depending on the law that applies to you, you may have rights relating to access, correction, deletion, restriction, objection, portability or withdrawal of consent.
If the information is held by a business using LeisureOS, requests may need to be directed to that business because it controls the relationship with the customer or Staff member. LeisureOS will reasonably assist business customers with valid requests where required.
11. International processing
LeisureOS may use infrastructure or service providers located in different countries. Where applicable law requires safeguards for international transfers, appropriate contractual or technical measures should be used.
12. Children
LeisureOS business accounts are intended for organizations and authorized adult users. The platform is not designed as a consumer service directed at children. A venue that records information about minors is responsible for ensuring that collection is lawful and appropriate for the service being provided.
13. Changes to this Policy
We may update this Privacy Policy as the product, infrastructure or legal requirements change. The “Last updated” date will show when the current version was published.
14. Contact
Privacy questions can be raised through the LeisureOS contact page until a dedicated privacy email or postal contact is formally published.