Noctessa — platform

Privacy Policy

Noctessa is a reservations and marketing platform for nightlife venues. This policy describes what the platform itself processes (including our Meta publishing integration). Each venue running on Noctessa also publishes its own guest notice at its site's /privacy page — that is a separate, per-venue document.

What we process

Venue accounts: admin names, emails and passwords (stored only as hashes), plus an audit log of admin actions. Guest reservations: processed on the venue's behalf (the venue is the controller, we are the processor) — name, contact details, party size, event, table and note.

Social publishing (Meta): the venue's long-lived Facebook Page / Instagram access token (encrypted at rest, AES-256-GCM), the Page and profile identifiers, granted scopes and token expiry — plus the posts the venue itself authored (caption, image, target channels, publish results/permalinks). We do NOT collect follower data, direct messages, or audience data.

Technical records: server logs (IP address, user agent) for security and rate limiting.

Why

Solely to operate the service: receiving and managing the venue's reservations, and publishing the venue's own marketing posts to the venue's own accounts, only on the venue's instruction. Tokens are never logged and never sent anywhere except Meta's Graph API.

Retention

Access tokens are kept until the venue disconnects (or they expire); they are refreshed before the ~60-day expiry. Reservation data is retained per the venue's retention settings. Deleting a venue purges all of its data — including social accounts, posts and uploaded assets.

Security & isolation

Every record carries the venue's identifier and is enforced by database-level isolation (Postgres Row-Level Security) — one venue's data is never accessible to another. Tokens are encrypted at rest; all traffic runs over HTTPS.

Cookies & tracking

On the Noctessa platform site (this marketing site only — not the venue sites we host), we use our own first-party, self-hosted analytics (Caymland) to measure how the site is used. It runs only after you opt in through our cookie banner; declining is as easy as accepting, and nothing below is loaded or stored until you consent.

Legal basis: your consent (ePrivacy Directive Art. 5(3); GDPR Art. 6(1)(a)). You can withdraw at any time via the “Manage cookies” control at the bottom of the page — withdrawing deletes the cookies below and reloads the page so no further tracking occurs.

Separately, when you make a choice we store one strictly-necessary first-party cookie, noctessa_consent (about 12 months), that simply records your preference so we don't ask again. It sets no tracking and needs no consent.

Your choices & deletion

How to request deletion of data (for venues and for guests) is described on our data deletion page: /legal/data-deletion.

Contact

Privacy questions: [email protected].