Cookie Notice
Version 2026-10-09 · Effective 9 October 2026
This notice explains how Data Accommodation uses cookies and similar technologies on the public website and in the platform (the hotel back office, staff app, guest pages and QR ordering pages). In short: we use only what is needed to sign you in, keep the service secure and make the apps work. We do not use advertising, analytics, social media or session-replay technologies.
1. What cookies are
Cookies are small data files placed on your computer or phone when you visit a website. A first-party cookie is set by the site you are visiting; a third-party cookie is set by another company, often to recognise you across websites. Session cookies end when you close the browser; persistent cookies stay until they expire or you delete them.
Websites can also keep information in your browser’s storage (local storage, session storage, IndexedDB and Cache Storage). We describe our use of those below as well.
2. The public website
The public website (the pages you are reading now) sets no cookies and loads no tracking scripts, pixels or third-party analytics. Our fonts are served from our own domain, so loading a page does not contact a font provider. Forms you submit — such as the contact form — are sent to our servers as described in our Privacy Policy.
3. Cookies in the platform
When you sign in to Data Accommodation, we set three first-party cookies. All of them are strictly necessary: without them you cannot stay signed in or make changes securely. In production they are marked Secure (sent only over HTTPS) and SameSite=Lax, and they are not used for tracking or advertising.
| Cookie | Purpose | Expires | Access |
|---|---|---|---|
| hos_access | Keeps you signed in to the platform. A short-lived token proving who you are on each request. | 15 minutes | httpOnly — page scripts cannot read it |
| hos_refresh | Renews the sign-in when the access token expires. Sent only to the sign-in endpoints. | One day, or up to 30 days if you choose to stay signed in; 12 hours for our own platform staff | httpOnly |
| hos_csrf | Protects against cross-site request forgery: every change you make must carry a matching token. | Same as hos_refresh | Readable by our own pages, by design |
Signing out deletes these cookies. The live demo uses the same cookies for its fictional hotel.
4. Browser storage
Parts of the platform keep information in your browser so they work quickly and, for the staff app, without a connection. This information stays on your device and is used only by Data Accommodation’s own pages.
| Where | What is stored | Type |
|---|---|---|
| Hotel back office | The property and restaurant outlet you last selected, and onboarding steps you chose to skip. | Local storage |
| Staff mobile app | A copy of your signed-in profile, checklist progress, recently viewed task lists and changes made while offline (sent when the connection returns). The app’s pages and files are cached so it opens without a connection. | Local storage, IndexedDB, Cache Storage |
| Guest pages | The link to your booking or guest portal, so you can return to it on the same device. | Local storage |
| Room and table QR ordering | Your cart until the order is sent. | Session storage (cleared when the tab closes) |
On a shared device, sign out when you finish and clear the browser’s site data if you want to remove these copies.
5. What we do not use
- No advertising or interest-based advertising cookies.
- No analytics or performance-measurement cookies, and no third-party analytics tools.
- No social media plug-ins or “log in with” buttons.
- No session-replay or keystroke-recording tools.
- No web beacons or pixels on the website.
6. Your choices
Because every cookie we use is strictly necessary, we do not show a cookie consent banner: there is nothing optional to accept or refuse. If we ever add cookies that are not strictly necessary, we will update this notice first and ask for your consent before setting them where the law requires it.
You can block or delete cookies in your browser settings. If you block our cookies, you will not be able to sign in to the platform; the public website will keep working.
7. Hotels’ own websites
A hotel can link to its Data Accommodation booking pages from its own website. The hotel’s website, and any tools it uses there, are governed by the hotel’s own cookie and privacy notices, not this one.
8. Changes and questions
We will update this notice when the technologies we use change, and revise the version and date at the top. Questions are welcome through our contact form (choose “Privacy, data and legal requests”) or email support@datadoodlestech.com.
Related documents
- Terms of ServiceThe agreement between Data Accommodation and the hotel or business that subscribes, and the rules for using this website.
- Subscription & Billing TermsTrials, plans, invoices, renewals, cancellation, refunds and what happens to your data when a subscription ends.
- Acceptable Use PolicyWhat every person using the platform may and may not do with it, and with the guest data inside it.
- Data Processing AgreementHow we process guest and staff personal data on a hotel’s behalf, the safeguards we apply and the subprocessors we use.
- Privacy PolicyWhat personal data Data Accommodation collects for itself, why, who receives it, how long it is kept and your rights.
Portions of this document are adapted from the Cookie Notice template published by General Legal, PC under CC0 1.0. General Legal has not reviewed, and takes no position on, this adaptation, and its templates are not legal advice.