Sandtick
ItalianoPrivacy Policy
Last updated: 2 October 2026
1. Data controller
Sandtick is an online booking management service for restaurants and beach clubs, operated by 266 La Barraca SRL, registered office Lungomare delle Meduse 266, 00071 Pomezia (RM), Italy, VAT no. 16691711002, e-mail 266labarraca@gmail.com.
266 La Barraca SRL is the data controller for the data of the restaurant accounts using Sandtick (owners and staff).
The data of the restaurants' customers (bookings, names, contact details, any allergies and notes) is processed on behalf of each restaurant, which is its controller. For this data Sandtick acts as data processor under Article 28 of Regulation (EU) 2016/679 (GDPR) and uses it solely to provide the service to the restaurant. The privacy notice for customers is published by each restaurant on its booking page.
2. Data processed and purposes
- Account data: name, e-mail address, role, date of last access and password, stored only in hashed form. Processed to give access to and provide the service (Art. 6(1)(b) GDPR).
- Security data: IP address of login attempts, used to block repeated attempts and deleted after 24 hours; log of changes made in the management area, kept for 2 years. The legal basis is our legitimate interest in the security of the service (Art. 6(1)(f) GDPR).
- Data of the restaurants' customers: the data entered by the restaurant or by the customer when booking, processed only to manage the bookings of that restaurant.
- Bug reports: text, optional photo, page and device type, used to fix errors in the service.
Data is not used for advertising or profiling and is not sold or transferred to third parties. The management area uses only technical cookies (sign-in and display preferences); the customers' booking page uses no cookies.
3. WhatsApp integration
A restaurant can connect its WhatsApp Business number to Sandtick through Meta's WhatsApp Business Platform. The connection takes place in a window managed by Meta: Sandtick does not receive the Facebook password or the personal profile data of the person connecting.
Once connected, Sandtick receives from Meta the ID of the WhatsApp Business account and of the phone number, the number's display name and an access token for sending messages on behalf of the restaurant. This data is used only to:
- create the restaurant's message templates (booking confirmation, change, cancellation and reconfirmation) and submit them to Meta for approval;
- send the restaurant's customers messages about their booking, when the restaurant has requested it;
- receive from Meta the status of the messages sent (delivered, read, not delivered) and show it to the restaurant.
Sandtick does not send promotional messages and does not store the messages customers write to the restaurant, which remain on WhatsApp. The restaurant can revoke the connection at any time; the tokens received from Meta are then deleted.
4. Service providers and transfers outside the EU
To provide the service we use the following providers, appointed as processors or sub-processors:
- Cloudflare, Inc. – hosting, database and file storage, with data stored in Western Europe;
- Meta Platforms Ireland Ltd – sending WhatsApp messages, if enabled by the restaurant;
- Plus Five Five, Inc. (Resend) – sending e-mails, if enabled.
Any transfer of data outside the European Union is based on the standard contractual clauses approved by the European Commission or on the EU-U.S. Data Privacy Framework.
5. Retention
Account data is kept for as long as the account exists. A restaurant's customer data is kept while the restaurant uses the service, unless the restaurant deletes it earlier; when the service ends it is deleted or returned to the restaurant, at its request. The periods stated in section 2 and legal obligations remain unaffected.
6. Security
All communication takes place over an encrypted connection (HTTPS). Passwords are stored in hashed form, each restaurant can access only its own data and each account only the functions allowed by its role.
7. Your rights
You may at any time request access to your data, rectification, erasure, restriction of processing or portability, or object to processing, by writing to 266labarraca@gmail.com. You may also lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
Customers of the restaurants can contact the restaurant directly, as controller of their data. Requests about this data that reach us are forwarded to the restaurant concerned.
8. Data deletion
- Restaurants: send the request to 266labarraca@gmail.com from the account's e-mail address. Within 30 days we delete the account, the venue's data (including bookings and customer list) and the WhatsApp connection with the related Meta tokens. The account owner can also delete staff accounts and individual customer records directly in the management area.
- WhatsApp connection: it can be revoked from the management area or from Meta Business Suite (Settings → Integrations). From that moment the tokens received from Meta are no longer valid and are deleted.
- Restaurants' customers: the request should be made to the restaurant, which can delete the record in the management area. Alternatively, write to 266labarraca@gmail.com stating the restaurant and the phone number used for the booking.
9. Changes
This policy may be updated; the date of the latest version is shown at the top.