⚠️ STAGING ENVIRONMENT – TEST DATA ONLY ⚠️

Privacy Policy

Privacy Policy

Last Updated: September 2026

Hallsy is booking software for shared spaces — community halls, venues and municipal facilities. The Hallsy platform is operated by 1595052 B.C. LTD., and in this policy "Hallsy" and "we" mean that company. This policy explains what personal information Hallsy handles, why, who it is shared with, and what you can ask us to do about it.

It describes what the software actually does today. Where Hallsy does not have a control or a process, this policy says so rather than implying one.

1. Two different roles

Venues. Each venue or organization using Hallsy decides what it asks renters for, which of its staff can see it, how long it keeps its bookings, and what it does with them. For that information the venue is in charge, and Hallsy handles it on the venue's behalf and under its instructions. A venue's own terms, refund policy and cancellation rules are published by that venue, not by Hallsy.

Hallsy. For our own operation of the service — administrator accounts, enquiries from people asking about using Hallsy, security, error monitoring, product analytics and billing — Hallsy decides how information is used. This policy covers both roles and says which is which throughout.

Hallsy remains the authoritative record of a booking. Where a venue connects an external service such as Google Calendar, that service is an integration, not the booking system of record.

2. Information collected from renters

When you submit a booking request or an enquiry, Hallsy stores what the venue's form collects. Depending on how that venue has configured its form, this includes:

  • Your name, email address and phone number.
  • Your postal address, where the venue requires it. Venues can set this to required, optional or hidden.
  • The date, time and space you are requesting, and your estimated attendance.
  • What the booking is for, including free-text you type into "purpose" and "anything else we should know" fields.
  • Your answers to any additional questions the venue has added to its form.
  • Any documents you upload when a venue requires them — for example a certificate of insurance, a permit, or a signed rental agreement.
  • A record that you agreed to the venue's terms, and when.

Renters do not have Hallsy accounts and do not set a password. You reach your booking through a link containing a long, unguessable token. Anyone who has that link can view that booking, so treat it as private.

If you accept a rental agreement online, Hallsy also records the name and email you typed, the date and time, your IP address, and a copy of the agreement text as it was shown to you. This is kept as evidence of what was agreed.

Hallsy keeps a per-venue contact record — name, email, phone and notes — so a venue recognises a returning renter, and logs every notification email sent to you, including the recipient address and whether it was delivered.

3. Information collected from venue administrators

For staff who sign in to Hallsy: email address, display name, a bcrypt hash of the password (never the password itself), role and permissions, and last sign-in time. Sessions are held in a signed cookie that expires after 8 hours.

Administrator actions that change a booking — approvals, denials, cancellations, payment entries, waivers — are recorded in an audit log with the administrator's identity, so a venue can see who did what.

If you submit an in-app issue report, Hallsy records your message, the page you were on and your browser's user-agent string.

4. Information collected from people who contact Hallsy

When you contact Hallsy about using it for your own venue — through the form on the Hallsy home page, or by writing to us — Hallsy stores what you send:

  • Your name and email address, and your phone number if you give one.
  • The name of the venue or organization you are asking about.
  • Whatever you write in your message.
  • How you arrived: the page you were on when you sent the form, and the site that referred you, if your browser sent one. This is recorded once, at the moment you make contact. Hallsy does not follow you around the site or across visits to build it, and does not store anything on your device to do so.

This is Hallsy's own record, not a venue's. It is not shared with any venue. It is not used to advertise to you, and it is not sold.

If you go on to run a venue on Hallsy, this record is how we know where the enquiry came from. If you do not, it stays an enquiry and nothing further happens with it.

5. Google Calendar integration

Venues can optionally connect a Google account so that Hallsy has a calendar of its own in that account. This section describes exactly what that connection does.

What Hallsy asks for. One scope, and no others:

https://www.googleapis.com/auth/calendar.app.created

This scope grants access only to calendars that Hallsy itself created. Hallsy is technically unable to open, read or modify the other calendars in the connected Google account — not merely undertaking not to.

What Hallsy does not ask for. Hallsy does not request the email, profile or openid scopes. It therefore never learns the Google account's email address, name or profile picture, and does not store them.

What Hallsy does with the connection. When an administrator connects an account, Hallsy creates one new, empty calendar named "Hallsy Bookings" in it. Afterwards, Hallsy periodically asks Google whether that one calendar still exists and whether its access is still valid, so the venue can be told if the connection has broken.

What Hallsy reads. Only whether that single Hallsy-created calendar is reachable, and its name and time zone. Hallsy does not read the events in it, and does not read any other calendar. No event — title, time, description, attendee or guest list — from any Google calendar is copied into Hallsy or stored in Hallsy's database.

What Hallsy writes. The creation of that one calendar, using the venue's time zone. Nothing else is currently written to Google.

What Hallsy stores. A Google refresh token and access token, both encrypted at rest with AES-256-GCM under a key held outside the database and bound to the venue's organization, together with the token's expiry, the scope Google granted, the identifier of the calendar Hallsy created, and which administrator connected it.

How to disconnect. An administrator can disconnect at any time from Settings → Calendar sync. Disconnecting asks Google to revoke the token and deletes the stored credentials from Hallsy's database. You can also remove Hallsy's access yourself under "Third-party apps with account access" in your Google Account; if you do that, Hallsy's stored credentials remain until an administrator disconnects in Hallsy or the organization is deleted, because nothing deletes them automatically.

The calendar Hallsy created is deliberately left in your Google account when you disconnect, so you keep anything in it.

Hallsy does not sell Google user data, does not use it for advertising, and does not transfer it to anyone other than the service providers listed in section 10.

6. Payments

Payments are processed by Stripe, using Stripe Connect. The venue is the merchant of record for its rentals; Hallsy takes a platform fee.

Card and bank details never reach Hallsy's servers or database. Payment is taken on a payment page hosted by Stripe. Hallsy sends Stripe the amount, the currency, a description of what is being paid for, and your email address to pre-fill the form. Hallsy does not send your name, phone number or postal address to Stripe.

Hallsy stores Stripe's identifiers for the payment — such as the payment intent, charge and refund ids — and a copy of the event data Stripe sends back when a payment completes. Venue staff can also record payments taken outside Hallsy, such as cash, cheque or e-transfer.

7. Email

Hallsy sends transactional email through Postmark: request received, approved, declined, changed or cancelled notices, payment and deposit confirmations, reminders with a calendar attachment, and post-event follow-ups. Notifications to venue staff about a new request include the renter's name, email address and phone number.

Follow-up and feedback emails carry an unsubscribe link, and unsubscribing is recorded against your contact record. Operational email about a booking you have made — such as an approval or a cancellation — is not something you can unsubscribe from while the booking is active.

8. Analytics, error monitoring and cookies

Product analytics. Hallsy uses PostHog (US hosting) to understand how the product is used. Analytics requests are proxied through Hallsy's own domain rather than sent to PostHog directly by your browser.

Renters are not identified to PostHog: Hallsy does not send a renter's name, email address or phone number as an analytics identity, and this is enforced by an automated test. Signed-in administrators are identified by an internal user id and their organization, never by email address.

Being straightforward about a current limitation: PostHog's automatic event capture is presently enabled on public booking pages, and Hallsy does not yet show a cookie or analytics consent banner or offer an in-product analytics opt-out. Reducing this collection is decided work that has not yet shipped, and this policy will be updated when it does. You can block analytics today using your browser's tracking protection or an ad blocker; doing so does not affect your ability to make a booking.

Error monitoring. Hallsy uses Sentry to capture errors. Sentry is configured not to send request headers, cookies or request bodies, and identifies a signed-in user by internal id only. Credentials and tokens are stripped from error reports by pattern. Free-form personal information that happens to appear inside an error message is not guaranteed to be removed.

Session replay is not enabled. Hallsy does not record your screen, your mouse movements or your keystrokes, and does not use session replay or heatmaps.

Rate limiting. Hallsy uses Upstash Redis to limit abusive traffic. This is keyed on the IP address of the request.

Cookies. Hallsy sets a session cookie when an administrator signs in, short-lived cookies during the Google Calendar connection flow, and a PostHog analytics cookie. Hallsy does not use advertising cookies and does not run third-party ad or marketing trackers.

9. How the information is used

  • To receive, evaluate, approve, decline, change and cancel booking requests.
  • To show a venue its calendar and prevent double-booking.
  • To send the notifications, reminders and receipts described above.
  • To take and reconcile payments, deposits and refunds.
  • To keep an audit record of who changed a booking and when.
  • To keep the service secure, diagnose faults and limit abuse.
  • To understand product usage in aggregate.
  • To answer enquiries from people asking about using Hallsy for their venue.
  • To understand which sources bring venues to Hallsy.

Hallsy does not sell personal information, and does not use it for advertising or behavioural profiling.

10. Who the information is shared with

  • The venue you booked with, and its authorised staff.
  • Supabase — database and file storage.
  • Vercel — application hosting.
  • Stripe — payments.
  • Postmark — transactional email.
  • PostHog — product analytics (United States).
  • Sentry — error monitoring.
  • Upstash — rate limiting.
  • Amazon Web Services — database and file backups, US West region.
  • Google — only where a venue has connected Google Calendar, and only as described in section 5.

Information may also be disclosed where required by law, or to establish or defend a legal claim.

One venue's staff cannot see another venue's bookings. That separation is enforced in the application on every request, and independently in the database for the tables covered by row-level security.

11. Where information is stored

Hallsy runs on cloud infrastructure operated by the providers listed above. Analytics are held in the United States and backups are held in Amazon's US West region. Information you give a venue may therefore be processed outside the province or country you live in.

12. Security

  • Every request for a venue's data is scoped to that venue in the application, and Postgres row-level security independently enforces that separation for the tables it covers.
  • The database account the application uses cannot bypass row-level security.
  • Administrator passwords are hashed with bcrypt. Password-reset and feedback tokens are stored only as hashes, are single-use and expire.
  • Google OAuth tokens are encrypted with AES-256-GCM, bound to the owning organization, under a rotatable key held outside the database.
  • Uploaded files are held in private buckets and served through short-lived signed links issued only to people authorised to see them.
  • Booking access links use 256-bit random tokens.
  • Traffic is served over HTTPS.

No system is perfectly secure, and Hallsy does not claim otherwise.

13. How long information is kept

Booking records are kept indefinitely. Cancelling or archiving a booking changes its status; it does not delete it. The booking, the renter details on it, its payment ledger and its audit history are retained so a venue keeps an accurate record of what happened at its facility.

Hallsy has no automatic deletion schedule for bookings, contacts, enquiries, payment records, notification logs or audit logs.

An enquiry from someone who contacts Hallsy about using it is treated differently. Where it does not result in a venue joining Hallsy, it is deleted 24 months after the last contact. Where it does, the enquiry is kept as part of that venue's record.

Some data is deleted automatically:

  • Practice bookings are deleted 14 days after creation.
  • Internal diagnostic traces are deleted after 30 days.
  • Demonstration organizations are reset nightly.

Deleting an organization deletes its stored Google credentials.

Nightly backups are taken to Amazon S3. Information can persist in those backups after it has been removed from the live system.

14. Your choices and requests

  • Unsubscribe from follow-up and feedback email using the link in those messages.

  • Disconnect Google Calendar at any time, as described in section 5.

  • Delete an enquiry you sent Hallsy. Write to hello@bookhallsy.com. No venue record is involved, so we can action this directly.

  • Correction or deletion. Hallsy does not currently offer a self-serve way to delete a booking or the personal information on it. Because the venue controls its own booking records, ask the venue you booked with first. You can also write to hello@bookhallsy.com, and we will pass the request to the venue and help action it; where Hallsy holds information in its own right, we will deal with it directly.

    To be clear about what that is and is not: this is a route for making the request, not a guarantee that everything will be deleted. Some information cannot be removed on request — where the venue needs it for its accounting, where it is evidence of what was agreed for a booking, or where a record must be kept to resolve a dispute or to meet a legal obligation. We will tell you what we can and cannot do, and why.

If you are unhappy with how a request was handled, you can raise it with the privacy regulator in your jurisdiction.

15. Children

Hallsy is software for booking facilities and is not directed at children. Hallsy does not knowingly collect personal information from children, and does not ask for a date of birth or age.

16. Changes to this policy

This policy will be updated as the product changes — including when the analytics collection described in section 8 is reduced, and when the Google Calendar integration begins projecting bookings onto a calendar. The "Last Updated" date above will change when it does.

17. Contact

The Hallsy platform is operated by 1595052 B.C. LTD. Questions about this policy, or about information Hallsy holds, go to hello@bookhallsy.com.

For information a venue holds about your booking, contact that venue directly; its contact details are on its booking pages and its own policy documents.

Powered by Hallsy

Power your space bookings with Hallsy