Sandtick

Italiano

Privacy Policy

Last updated: 2 October 2026

1. Data controller

Sandtick is an online booking management service for restaurants and beach clubs, operated by 266 La Barraca SRL, registered office Lungomare delle Meduse 266, 00071 Pomezia (RM), Italy, VAT no. 16691711002, e-mail 266labarraca@gmail.com.

266 La Barraca SRL is the data controller for the data of the restaurant accounts using Sandtick (owners and staff).

The data of the restaurants' customers (bookings, names, contact details, any allergies and notes) is processed on behalf of each restaurant, which is its controller. For this data Sandtick acts as data processor under Article 28 of Regulation (EU) 2016/679 (GDPR) and uses it solely to provide the service to the restaurant. The privacy notice for customers is published by each restaurant on its booking page.

2. Data processed and purposes

Data is not used for advertising or profiling and is not sold or transferred to third parties. The management area uses only technical cookies (sign-in and display preferences); the customers' booking page uses no cookies.

3. WhatsApp integration

A restaurant can connect its WhatsApp Business number to Sandtick through Meta's WhatsApp Business Platform. The connection takes place in a window managed by Meta: Sandtick does not receive the Facebook password or the personal profile data of the person connecting.

Once connected, Sandtick receives from Meta the ID of the WhatsApp Business account and of the phone number, the number's display name and an access token for sending messages on behalf of the restaurant. This data is used only to:

Sandtick does not send promotional messages and does not store the messages customers write to the restaurant, which remain on WhatsApp. The restaurant can revoke the connection at any time; the tokens received from Meta are then deleted.

4. Service providers and transfers outside the EU

To provide the service we use the following providers, appointed as processors or sub-processors:

Any transfer of data outside the European Union is based on the standard contractual clauses approved by the European Commission or on the EU-U.S. Data Privacy Framework.

5. Retention

Account data is kept for as long as the account exists. A restaurant's customer data is kept while the restaurant uses the service, unless the restaurant deletes it earlier; when the service ends it is deleted or returned to the restaurant, at its request. The periods stated in section 2 and legal obligations remain unaffected.

6. Security

All communication takes place over an encrypted connection (HTTPS). Passwords are stored in hashed form, each restaurant can access only its own data and each account only the functions allowed by its role.

7. Your rights

You may at any time request access to your data, rectification, erasure, restriction of processing or portability, or object to processing, by writing to 266labarraca@gmail.com. You may also lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

Customers of the restaurants can contact the restaurant directly, as controller of their data. Requests about this data that reach us are forwarded to the restaurant concerned.

8. Data deletion

9. Changes

This policy may be updated; the date of the latest version is shown at the top.