Hawana Cafe — Privacy Policy

Transparency about how we handle your information

Effective date
May 2, 2026
Controller
NovaVantage Innovations (Hawana Cafe)
Privacy contact
Summary

Hawana Cafe is a customer ordering and café-services mobile application. We process account, order, loyalty, and support-related data to run the service. We use third parties where necessary (for example Google Sign-In and payment processing). We do not sell your personal information. This document explains what we collect, why, how long we keep it, your rights, and how to contact us.

1 Scope

This Privacy Policy applies to the Hawana Cafe mobile application (the “App”, package name com.novavantage.hawanacafe) and the backend services the App uses to provide ordering, appointments, loyalty, and related café operations. It does not govern third-party websites or payment pages opened in a browser when you complete a payment with a payment provider.

2 Who we are

The data controller responsible for personal data processed through the App and our Hawana Cafe platform is NovaVantage Innovations. For privacy requests, email privacy@novavantage.io. For operational café matters (hours, orders at the counter), use the contact options shown in the App’s Help section.

3 Data we collect

We collect information you provide, information generated when you use the App, and limited technical information from your device. Categories include:

3.1 Account and profile

3.2 Orders, payments, and fulfilment

3.3 Loyalty, favorites, and engagement

3.4 Appointments and events

3.5 Communications and support

3.6 Technical, security, and anti-abuse logs

3.7 Permissions

4 Purposes and legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases:

5 How we share information

We do not sell your personal information. We disclose information only as follows:

6 International transfers

Our servers and providers may be located outside your country (including in Israel, the European Economic Area, the United States, or other regions). Where required, we implement appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) for transfers of personal data from the EEA, UK, or Switzerland.

7 Retention

We retain personal data only as long as necessary for the purposes above, including legal, tax, and accounting obligations. Examples:

8 Security

We use administrative, technical, and organizational measures designed to protect personal data, including encrypted transport (HTTPS/TLS) for client–server communication, secure password hashing on our backend, access controls for staff systems, and separation of duties where feasible. No method of transmission or storage is 100% secure; if we become aware of a breach that affects you where notification is required by law, we will follow applicable notification rules.

9 Your rights

Depending on your location, you may have rights to:

To exercise rights, email privacy@novavantage.io. We may need to verify your identity before fulfilling requests.

9.1 Account deletion requests (Google Play)

You can request account deletion in either of these ways:

When deletion is confirmed, we delete profile and account-linked personal data from active systems. For legal/accounting compliance, we may retain limited transaction records for statutory retention periods; when retained, records are minimized and no longer tied to an active user account.

10 Children’s privacy

The App is intended for general café customers. We do not knowingly collect personal information from children under 13 without appropriate parental consent. If you believe a child has provided us with personal information, contact us and we will take steps to delete such information where required by law. If your product experience is directed to children, you must configure Play age targets and child-data programs in line with Google’s policies — this Policy should then be reviewed by counsel for COPPA and related rules.

11 Marketing

We may send transactional messages about your orders and account. Promotional communications, if any, will be sent in accordance with applicable law and your preferences where opt-in or opt-out is required.

12 Automated decision-making

We do not use fully automated decisions that produce legal or similarly significant effects solely by automated means, except where operational rules are simple and transparent (for example temporary ordering holds based on published no-show policies). You may contact us for human review where applicable law requires.

13 Third-party links

The App may open links to third-party sites (for example payment pages or maps). Those services have their own privacy policies.

14 Changes to this Policy

We may update this Privacy Policy from time to time. We will post the new effective date at the top and, where changes are material, provide additional notice as required by law (for example in-app notice or email).

15 Regional notices

Israel

We process personal data in accordance with the Israeli Privacy Protection Law, 5741-1981, and related regulations, including registration of databases where required.

California (if applicable)

California residents may have additional rights under the CCPA/CPRA (for example to know, delete, and opt out of “sale” or “sharing” as defined by California law). We do not sell personal information for money. To submit requests, use the privacy contact above.

16 Disclaimer

This document is provided for transparency and operational use. It is not legal advice. Have qualified counsel review it for your jurisdictions, payment flows, marketing practices, and Google Play / App Store programs before publication.