Hawana Cafe is a customer ordering and café-services mobile application. We process account, order, loyalty, and support-related data to run the service. We use third parties where necessary (for example Google Sign-In and payment processing). We do not sell your personal information. This document explains what we collect, why, how long we keep it, your rights, and how to contact us.
1 Scope
This Privacy Policy applies to the Hawana Cafe mobile application (the “App”, package name com.novavantage.hawanacafe) and the backend services the App uses to provide ordering, appointments, loyalty, and related café operations. It does not govern third-party websites or payment pages opened in a browser when you complete a payment with a payment provider.
2 Who we are
The data controller responsible for personal data processed through the App and our Hawana Cafe platform is NovaVantage Innovations. For privacy requests, email privacy@novavantage.io. For operational café matters (hours, orders at the counter), use the contact options shown in the App’s Help section.
3 Data we collect
We collect information you provide, information generated when you use the App, and limited technical information from your device. Categories include:
3.1 Account and profile
- Registration and sign-in: name; email address (for email/password accounts); password (stored on our servers only as a secure hash — we do not store your password in plain text); optional Google Sign-In identifier when you choose Google authentication.
- Profile: phone number when required or provided for orders and bookings; language preference; optional profile photo (we may store a URL to an image hosted with our cloud file provider after you upload a picture from your device library).
- Session security: authentication tokens issued to the App so you stay signed in until you sign out or the session ends.
3.2 Orders, payments, and fulfilment
- Cart and orders: items, quantities, selected options or customizations, prices, order type (for example pickup, delivery, or dine-in where available), timestamps, and order status history.
- Payments: payment method category (for example cash, card, or PayPlus). Card payments are handled by our payment partner (PayPlus or another processor we configure). We do not store full payment card numbers on the App; payment details are entered with the processor under their terms and PCI scope.
- PayPlus references: where PayPlus is used, we may store transaction or page-request identifiers returned by PayPlus to match payments to orders and to comply with accounting and dispute handling.
- Delivery and addresses: saved delivery addresses may include a human-readable address and coordinates (latitude/longitude) to validate service areas and calculate fees where delivery is offered.
- Dine-in: if you order linked to a table or QR flow, we process identifiers needed to associate the order with the correct table or session.
3.3 Loyalty, favorites, and engagement
- Loyalty (“Haven” / titles / XP): points, levels, equipped titles, and related progression data as implemented in the service.
- Favorites: which menu products you mark as favorites.
- Ratings and feedback: star ratings and optional notes you submit after an order, and structured feedback fields we may collect for quality improvement.
- Pickup reliability: where our policies apply, we may record pickup no-show events and temporary restrictions on placing new orders to protect operations.
3.4 Appointments and events
- Event type, party size, requested date/time, status, optional notes, and deposit flags as supported by the booking flow.
3.5 Communications and support
- Information you send when you contact us (for example email content), and in-app notifications content as implemented.
- FAQ and Help content is served from our systems; we log routine technical events needed to operate support.
3.6 Technical, security, and anti-abuse logs
- Device and connection data: IP address, user agent, language headers, and similar metadata associated with sign-in sessions and API requests, used for security, fraud prevention, troubleshooting, and legal compliance.
- Audit trail: administrative and security-sensitive actions on the platform may be written to audit logs (for example authentication events and operational changes).
- Real-time updates: the App may open a WebSocket connection to our servers for live order or loyalty updates while you are using the App.
- Localization: we read device or App language settings to show the correct language where supported.
3.7 Permissions
- Photos / media library: used when you choose to update your profile photo from your gallery (via the system picker).
- Microphone (Android): the App’s manifest may declare microphone-related permissions required by included platform or SDK components. We do not use the microphone to record your voice for advertising or to build voice profiles. If a future feature explicitly uses the microphone, we will update this Policy and, where required, provide an in-app explanation before collection.
- Network: the App requires internet access to reach our APIs.
4 Purposes and legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases:
- Contract: processing necessary to provide the service you request (account, orders, payments orchestration, delivery validation, appointments).
- Legitimate interests: securing the platform, preventing fraud and abuse, improving reliability, analytics that does not require consent under applicable law, and internal reporting — balanced against your rights.
- Legal obligation: tax, invoicing, and regulatory record-keeping where applicable.
- Consent: where required for optional marketing communications or non-essential cookies or trackers (we aim to minimize such processing).
5 How we share information
We do not sell your personal information. We disclose information only as follows:
- Service providers (processors): hosting, database, file storage, email delivery, and payment partners who process data on our instructions under contracts.
- Google: if you use Google Sign-In, Google processes authentication data under Google’s policies in addition to our processing described here.
- PayPlus (or other payment processors): to authorize and settle payments and to handle refunds or disputes.
- Expo / platform vendors: limited technical data as needed for app delivery, updates, and platform services (for example over-the-air updates where enabled).
- Legal and safety: when required by law, court order, or governmental request, or to protect the rights, safety, and security of customers, staff, and the public.
- Business transfers: if we merge, are acquired, or sell assets, your information may transfer as part of that transaction, subject to standard protections.
6 International transfers
Our servers and providers may be located outside your country (including in Israel, the European Economic Area, the United States, or other regions). Where required, we implement appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) for transfers of personal data from the EEA, UK, or Switzerland.
7 Retention
We retain personal data only as long as necessary for the purposes above, including legal, tax, and accounting obligations. Examples:
- Account data for the life of the account and a short period after deletion where needed to resolve disputes or enforce terms.
- Order and payment records for the period required by law and legitimate business needs (for example chargeback windows).
- Security logs on a rolling basis consistent with industry practice.
8 Security
We use administrative, technical, and organizational measures designed to protect personal data, including encrypted transport (HTTPS/TLS) for client–server communication, secure password hashing on our backend, access controls for staff systems, and separation of duties where feasible. No method of transmission or storage is 100% secure; if we become aware of a breach that affects you where notification is required by law, we will follow applicable notification rules.
9 Your rights
Depending on your location, you may have rights to:
- Access, correct, or update your personal data;
- Delete your account or certain data (subject to legal exceptions);
- Restrict or object to certain processing;
- Data portability for data you provided where technically feasible;
- Withdraw consent where processing is consent-based;
- Lodge a complaint with a supervisory authority (for example in your EU member state).
To exercise rights, email privacy@novavantage.io. We may need to verify your identity before fulfilling requests.
9.1 Account deletion requests (Google Play)
You can request account deletion in either of these ways:
- In-app: open Settings → Delete account and confirm.
- Email request: send your request from the email linked to your account to privacy@novavantage.io with subject
Account Deletion Request.
When deletion is confirmed, we delete profile and account-linked personal data from active systems. For legal/accounting compliance, we may retain limited transaction records for statutory retention periods; when retained, records are minimized and no longer tied to an active user account.
10 Children’s privacy
The App is intended for general café customers. We do not knowingly collect personal information from children under 13 without appropriate parental consent. If you believe a child has provided us with personal information, contact us and we will take steps to delete such information where required by law. If your product experience is directed to children, you must configure Play age targets and child-data programs in line with Google’s policies — this Policy should then be reviewed by counsel for COPPA and related rules.
11 Marketing
We may send transactional messages about your orders and account. Promotional communications, if any, will be sent in accordance with applicable law and your preferences where opt-in or opt-out is required.
12 Automated decision-making
We do not use fully automated decisions that produce legal or similarly significant effects solely by automated means, except where operational rules are simple and transparent (for example temporary ordering holds based on published no-show policies). You may contact us for human review where applicable law requires.
13 Third-party links
The App may open links to third-party sites (for example payment pages or maps). Those services have their own privacy policies.
14 Changes to this Policy
We may update this Privacy Policy from time to time. We will post the new effective date at the top and, where changes are material, provide additional notice as required by law (for example in-app notice or email).
15 Regional notices
Israel
We process personal data in accordance with the Israeli Privacy Protection Law, 5741-1981, and related regulations, including registration of databases where required.
California (if applicable)
California residents may have additional rights under the CCPA/CPRA (for example to know, delete, and opt out of “sale” or “sharing” as defined by California law). We do not sell personal information for money. To submit requests, use the privacy contact above.
16 Disclaimer
This document is provided for transparency and operational use. It is not legal advice. Have qualified counsel review it for your jurisdictions, payment flows, marketing practices, and Google Play / App Store programs before publication.