Legal
Hostera privacy policy
This privacy policy belongs to the Hostera application (hostera.nl). It explains which personal data Hostera processes, including Google user data when a restaurant connects Hostera to Google Calendar.
Google API Services User Data
Hostera's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Hostera accesses Google Calendar data only after an authorized restaurant administrator explicitly connects a Google account. Hostera uses this access solely to allow the restaurant to select a calendar and to create, update and delete calendar events corresponding to Hostera reservations. Sections 4.1–4.11 below describe the access, use, storage, sharing, protection, retention and deletion of Google user data in detail.
1. Controller
The controller for Hostera is Hostera (the organisation behind hostera.nl). For privacy questions, access requests or deletion requests, use our contact page.
2. Who this policy covers
This policy covers visitors to hostera.nl, restaurants that use the Hostera application, their staff, and guests whose data is stored in Hostera (for example for a reservation). Specific Google user data applies only if a restaurant enables the optional Google Calendar connection.
3. What data we process
Depending on how Hostera is used, we may process:
- Restaurant user account and team data (name, email, login and authorization data).
- Reservation data (date/time, party size, guest name, contact details, notes, table assignment).
- Technical data needed to run the service (such as session cookies). Analytics cookies only with consent; see our cookie policy.
- Google user data if a restaurant connects Google Calendar, as described in section 4.
4. Google user data (Google Calendar)
Hostera is a reservation application for restaurants. The Google Calendar connection is optional and one-way: Hostera remains the source of truth. New, changed and cancelled Hostera reservations can be sent to the restaurant’s selected Google calendar. Changes made in Google itself are not written back to Hostera.
4.1 Google user data Hostera accesses
Only after an authorized restaurant manager clicks “Connect with Google” in Hostera (Settings → Integrations) and grants consent via Google OAuth does the Hostera application ask Google for access to:
- The email address or identifier of the connected Google account, so the restaurant can see in Hostera which account is linked.
- A list of calendars that Google account can write to (Google scope calendar.calendarlist.readonly), so the restaurant can choose the right calendar.
- Permission to create, update and delete calendar events (Google scope calendar.events). Hostera uses this to add Hostera reservations as Google Calendar events, update them, or delete them when a reservation is cancelled.
- No other Google products. Hostera does not read Gmail, Drive, Contacts, or existing calendar events in order to import reservations. We do not request Google scopes beyond the Calendar connection.
4.2 How Hostera uses Google user data
We use Google user data solely to provide and improve the Google Calendar feature the user requested in Hostera, namely:
- Listing calendars so the restaurant can choose a destination calendar.
- Syncing Hostera reservations to that calendar (create, update, delete on cancellation) and retrying failed syncs.
- A calendar event may include reservation details already stored in Hostera (for example guest name, party size, phone, table, notes), according to the event layout the restaurant configures.
4.3 What we store
Per restaurant we store: an encrypted Google refresh token, an identifier or email for the connected Google account, the selected calendarId/calendar name, whether sync is enabled, event-layout templates, and optionally a last error message. Access tokens are kept only briefly in memory to call the Google Calendar API. We do not send the Client Secret, refresh tokens or access tokens to the browser, and we do not log them.
4.4 How we protect sensitive Google data
Security procedures are in place to protect the confidentiality of Google user data. Refresh tokens are stored in our PostgreSQL database and encrypted with ASP.NET Data Protection. Access to Hostera is limited to signed-in users with restaurant permissions (capacity.view / capacity.edit). Communication with Google and with Hostera uses HTTPS. We use encryption to protect these tokens and the connection.
4.5 Sharing, transfer or disclosure
Hostera does not sell Google user data. We do not transfer or disclose that information to third parties for purposes other than providing or improving the Calendar feature. In particular:
- We do not share restaurant A’s Google tokens or calendars with restaurant B, advertisers, data brokers or information resellers.
- We send calendar events to Google on the restaurant’s behalf because the user enabled that sync. Google processes those events under Google’s privacy policy.
- Hosting and infrastructure providers (for example database and server hosting) may process data on Hostera’s behalf only to run the service, under appropriate processor terms.
- We may disclose data if required by law, or to protect our rights. Otherwise only with the user’s consent.
4.6 Retention
We keep Google refresh tokens, account identifier, calendar selection and event layout while the connection is active, or for as long as needed to provide the requested Calendar feature. Temporary access tokens are not kept longer than needed for API calls. Reservation data in Hostera (separate from Google) is kept while the restaurant uses Hostera, or until a valid deletion request, unless a longer period is required by law.
4.7 Deletion
A restaurant manager can disconnect Google in Hostera (Settings → Integrations → Disconnect). We then revoke the Google token where Google allows it and delete that restaurant’s local Google authorization (refresh token, account, calendar link). Existing events in Google Calendar are not deleted automatically. Managers can also revoke access in their Google account under “Third-party apps with account access”. To request deletion of other Hostera data, use our contact page; we respond within the statutory time limits. When a retention period expires, we delete or destroy that data.
4.8 What we do not do
- We do not use Google Calendar as a source of availability in Hostera.
- We do not use Google user data for targeted, personalized, retargeted or interest-based advertising, remarketing, determining credit-worthiness, lending, or building databases for other purposes.
- We do not sell Google user data to third parties or data brokers.
- We do not import reservations from existing Google calendars. Disconnect does not delete existing Google events; it only ends the Hostera connection and tokens.
- We do not use Google user data for reasons other than providing or improving the Calendar feature in Hostera.
- We do not transfer Google user data to third parties for advertising, data brokers, or training generalized AI/ML models.
4.9 AI and machine-learning use
Hostera does not use Google user data obtained via Google APIs (including Google Calendar / Google Workspace APIs) to develop, improve, or train generalized or non-personalized AI or machine-learning models. Hostera’s optional AI features (such as reservation conversations) use restaurant settings and reservation data inside Hostera; they do not use Google Calendar tokens or Google calendar data to train such models.
4.10 Limited Use
Google user data we receive via Google APIs is used only to provide and improve the Calendar features the user requested in Hostera, in line with the Google API Services User Data Policy, including the Limited Use requirements.
4.11 Disconnecting or withdrawing consent
The Google connection is based on consent via Google OAuth. You can withdraw that consent by disconnecting in Hostera, or in your Google account. Hostera then no longer has access to that Google account or calendar.
5. Legal basis (other Hostera data)
We process restaurant and guest data to perform the Hostera service (contract) and, where needed, on legitimate interests or legal obligation. The Google connection is based on consent; it can be withdrawn as described in section 4.
6. Transfers outside the EU
We use hosting and infrastructure providers to run Hostera. If Google Calendar is connected, events are sent to Google; Google may process data outside the EU. See also the Google Privacy Policy. Analytics tools (Google Analytics, Microsoft Clarity) load only after cookie consent; that is separate from the Calendar API connection.
7. Your rights
Under the GDPR you may request access, correction, deletion, restriction and portability, and object to certain processing. Restaurant users manage their Google connection in Hostera. For other requests, including deletion of Google authorization data: contact. We respond within the statutory time limits.
8. Cookies
How we use cookies is explained in our cookie policy.
9. Changes
We may update this policy if the service or the law changes, or if Hostera changes how it uses Google user data. The date at the top of this page shows the latest update. If we materially change how we use Google data, we will update this page before that change takes effect.