Sandivers RO My account

Privacy policy

Last updated: 18 August 2026 Version 1.3

We care about your data and your child's, so here is a plain explanation of what we collect, why, who we share it with, and what you can do about it. If anything is unclear, write to us — we answer.

1. Who we are

The controller of your personal data is:

  • MINIVERS BABY SRL, trading as Sandivers
  • CUI 55164353 · Reg. Com. J2026043540000
  • Strada Luminii, Valea Lupului, Iași county, Romania
  • Email: receptie@sandivers.ro

We are not legally required to appoint a Data Protection Officer, because we do not process data at large scale. For any question about personal data, the address above reaches us directly.

2. What we collect, and why

We collect only what we need in order to operate. Below is the complete list, by category.

Opening-list signup

What
Your email address. We also keep the consent wording you ticked and when. Your IP address is NOT stored as such — we keep only a derived code that cannot be turned back into your IP, so we can defend against automated signups.
Why
To email you once, when we open.
Legal basis
Your consent (Art. 6(1)(a) GDPR).
Retention
Until opening and at most 12 months after, or until you ask us to delete it.

Parent account

What
Name, email address, password (kept only in an irreversible cryptographic form — we do not know it and cannot read it) and, optionally, a phone number. We record when you accepted this policy and your last sign-in.
Why
So you can create and use your account, on the website and in the app.
Legal basis
Performance of our contract with you (Art. 6(1)(b) GDPR).
Retention
While your account is active. See section 7.

Child profile

What
Only a first name and an age band (for example 3–4 years). We do not ask for a surname, we do not ask for a date of birth, and we do not upload photographs.
Why
So reception knows who is coming to play and which zone suits them.
Legal basis
Performance of the contract (Art. 6(1)(b) GDPR). The profile is created by you, as parent or legal guardian.
Retention
While your account is active, or until you delete the profile.

Allergies and dietary needs

What
Free text, entered by you, only if you want to. See section 4 — this information has a stricter regime.
Why
Your child's safety at the bar and at parties.
Legal basis
Your separate, explicit consent (Art. 9(2)(a) GDPR). Without that tick, the system refuses to store it.
Retention
Until you delete it or withdraw consent.

Sign-in with Google, Apple or Facebook

What
If you choose this: the identifier the provider sends us, your email address and display name. We never receive your password from these providers.
Why
So you can sign in without a separate password.
Legal basis
Performance of the contract (Art. 6(1)(b) GDPR), at your request.
Retention
For as long as you keep that connection linked.

Sessions and devices

What
A session code (also stored in cryptographic form), the client type — web, iOS or Android — and when it was last used.
Why
To keep you signed in, and to let you sign out everywhere.
Legal basis
Performance of the contract and our legitimate interest in keeping accounts secure (Art. 6(1)(b) and (f) GDPR).
Retention
Until expiry or sign-out (30 days on the web, 180 in the app).

Visits, passes and points

What
Which pass you hold, visits remaining, when you came, which child came in, and points earned or spent.
Why
So passes and the points programme work, and so you can see your own history.
Legal basis
Performance of the contract (Art. 6(1)(b) GDPR).
Retention
While your account is active; payment-related records are kept as the law requires (section 7).

Payments and invoices

What
Amount, currency, method, status and invoice number. We do not store card details on our servers.
Why
So we can sell you a pass, issue the invoice and keep our accounts.
Legal basis
Performance of the contract and our legal, tax and accounting obligations (Art. 6(1)(b) and (c) GDPR).
Retention
The period required by Romanian tax and accounting law (section 7).

Party enquiries

What
Name, contact details and whatever you tell us about the event. You can ask for a quote without an account.
Why
So we can reply and prepare the party.
Legal basis
Performance of the contract or steps prior to it, at your request (Art. 6(1)(b) GDPR).
Retention
12 months after the event or after the enquiry closes, if it does not become a booking.

Contact form messages

What
Your name, email address, optionally your phone number, the subject you chose and the message you wrote. We also keep a code derived from your IP address, to defend against automated submissions.
Why
To reply to you, and so we can check whether someone actually got an answer.
Legal basis
Your consent, ticked in the form (Art. 6(1)(a) GDPR), or pre-contractual steps if you're asking about a booking (Art. 6(1)(b)).
Retention
12 months after the conversation closes. Deleted immediately if you delete an account on the same address.

Security log (sign-in activity)

What
For every account action — creating an account, a successful sign-in, a failed sign-in, a password reset request, an email confirmation — we record when it happened, what it was, the IP address it came from and the browser type. Here we keep the IP address itself rather than a derived code: if someone is attacking accounts, a code tells us nothing about what else that address did. We never record the password that was typed, right or wrong.
Why
So we can stop automated account creation and password guessing, temporarily lock an account that is under attack, and reconstruct what happened if something does go wrong.
Legal basis
Our legitimate interest in keeping the service secure (art. 6(1)(f) GDPR). It is in your interest too — without it we could not defend your account.
Retention
12 months, then deleted automatically. The record of failed attempts used for the temporary lock is deleted after 24 hours.

Account deletion requests

What
The email address deletion was requested for, when it was requested and when it was carried out. The confirmation link is only ever stored as a cryptographic fingerprint, and that is erased as soon as it's used.
Why
To verify the request, and to be able to show we completed it.
Legal basis
Our legal obligation to act on requests about your rights (Art. 6(1)(c) GDPR).
Retention
3 years, as evidence the request was handled. Only the address and those two dates remain, nothing else.

Withdrawal requests (the 14-day form)

What
Your name, email address, phone if you give one, the order number if you fill it in, which pass, and — if you choose to write one — your reason. We also keep when you sent it, the language of the page, and a code derived from your IP address, to defend against automated submissions. The reason is optional: the law does not require you to explain why you are withdrawing.
Why
So we can process the withdrawal and the refund, and so we can show when you told us — the 14 days in which we owe you the money run from that date.
Legal basis
Performance of the contract and the legal obligation arising from OUG 34/2014 (Art. 6(1)(b) and (c) GDPR).
Retention
3 years after it is settled, together with the credit note, as evidence that we refunded. If you delete your account sooner we remove the name, phone and reason and keep only the row with the dates and amounts — see the section on account deletion.

Technical and security logs

What
Records of significant account actions (for example an erasure request) and server logs.
Why
So we can investigate problems and abuse.
Legal basis
Our legitimate interest in keeping the service secure and working (Art. 6(1)(f) GDPR).
Retention
At most 12 months.

Website traffic measurement

What
For each page opened: the page address, the time, the language, whether the browser is a phone or a computer, the site you came from if there was one, and your approximate area — country, county and roughly the town. We also record presses on the page's main buttons. Your IP address is not stored — we use a code derived from it that changes every night, so we cannot follow you from one day to the next. The location is looked up on our own server, not at an outside service. No cookies and no outside tool. See section 8.
Why
So we know whether people are finding the site and what interests them, ahead of opening.
Legal basis
Our legitimate interest in understanding whether the site is useful (Art. 6(1)(f) GDPR). You can object at any time.
Retention
90 days. Only anonymous per-day totals remain.

We do not ask for your national ID number, we do not ask for card details, we do not use advertising tracking, and we do not buy data about you from anyone else.

3. Children's data

We treat children's data more carefully than adults', and the best way to protect it is to collect as little as possible.

  • A child's profile is created by you, from your parent or guardian account. Children do not have accounts with us.
  • We ask for only a first name and an age band. No surname, no date of birth, no address, no photographs.
  • A child's data is visible only to you and to the colleagues who need it to do their job at reception.
  • We never send marketing to children and never build marketing profiles from their data.
  • You can delete a child's profile from your account at any time, and the deletion is immediate.

4. Allergy information

Allergies and dietary needs are, in legal terms, health data — a special category with stricter protection. So:

  • Filling this in is entirely optional. The account works exactly the same without it.
  • We store it only if you tick the separate consent box. If you type something in the field and don't tick, the system refuses to save it and explains why.
  • We also record when you gave that consent.
  • We use it strictly for your child's safety — at the bar and at parties. Nothing else.
  • You can delete it or withdraw consent at any time, from your account.

This information reaches the colleagues who prepare food and drink. If your child's allergy is severe, please also tell us in person — a field in an app is no substitute for a conversation.

5. Who we share data with

We do not sell data to anyone. We share it only with the providers we need in order to operate, and they may use it only for us:

  • Hetzner Online GmbH (Germany) — hosts our server, in a data centre in Finland. The data stays in the European Union.
  • Google Ireland Limited — Google Workspace, for email. The emails we send you, and your replies to receptie@sandivers.ro, pass through Google's services.
  • Cloudflare — hosts only the DNS zone for sandivers.ro, translating the site name into our server's address. Your traffic with our site does not pass through Cloudflare.
  • Google, Apple or Meta — only if you choose to sign in with one of those accounts. Verification happens between our server and that provider.
  • Public authorities — only where the law requires it, for example reporting invoices to the Romanian tax authority (ANAF).
  • Our accountant — for financial records, within our legal obligations.

Online payments and automated invoicing are not active yet. When we switch them on, we will update this policy before we start processing payments, and those providers will appear in the list above.

6. Transfers outside the European Union

Our server and database are in the European Union. Some of the providers above — Google, Cloudflare, Apple, Meta — belong to groups with a United States presence, and some technical operations may take place there.

Where that happens, the transfer relies on the mechanisms the GDPR provides: the European Commission's adequacy decision for the EU–US Data Privacy Framework, or the Commission's standard contractual clauses together with additional technical safeguards.

7. How long we keep data

  • Account data — while the account is active.
  • After you ask us to delete your account — we close it immediately, cancel your sessions and active passes, and remove the data we are not legally required to keep. Financial records remain, because the law obliges us to keep them.
  • Financial and tax records — the period required by Romanian accounting and tax law, generally between 5 and 10 years depending on the document.
  • The opening-list signup — until opening and at most 12 months after.
  • Sessions, reset and confirmation links — these expire on their own: a reset link in 60 minutes, a confirmation link in 48 hours.
  • Technical logs — at most 12 months.
  • Traffic measurement — individual records are deleted automatically after 90 days. Only the per-day totals remain (how many pages, how many visitors), and there is nothing about any person in those.

8. Cookies and traffic measurement

We use one kind of cookie: the one that keeps you signed in. It is called sv_session (or sv_staff for our own team), it cannot be read by scripts in the page, and it goes when you sign out.

We do want to know whether anyone is finding the site, so we count visits — but we do it ourselves, on our own server, as quietly as we can. For each page opened we keep: the page address, the time, whether the browser is a phone or a computer, the language of the page, and the site you arrived from if there was one — “google.com” or “facebook.com”, for instance. We also record whether one of the page's main buttons was pressed, such as “notify me when you open”.

We do not use Google Analytics or any other outside tool. We have no advertising pixels, no third-party cookies, and we do not track you across other sites. Fonts are hosted on our own server, so merely visiting the page does not send your IP address to Google. None of this data goes anywhere: only we see it, in our admin page.

Your IP address is not stored. So that we don't count the same person ten times in one afternoon, we compute a code from the IP address and the browser type. The code cannot be turned back into your address and it changes every night, so not even we can connect today's visit to next week's. It is a statistic, not a file on you. For the same reason, the “unique visitors” figure we see is only exact for a single day.

Approximate location. From the IP address we also work out roughly where you are visiting from — the country, the county, and approximately the town. What we want to know is whether the people looking at us are near Iași or somewhere else. The lookup happens on our own server, against a public list of address ranges that we keep locally: your address is not sent to anyone and, as above, it is not stored. We keep only the name of the place. The accuracy is limited — town level is often wrong, particularly for phones — and it does not tell us your street, your neighbourhood or your address.

We put nothing on your device for this — no cookie, nothing saved in the browser — and we do not fingerprint your device. The legal basis is our legitimate interest in understanding whether the site is useful (Art. 6(1)(f) GDPR). You can object at any time, by writing to the address in section 1. If your browser sends the “Global Privacy Control” or “Do Not Track” signal, we don't count you at all, without your having to ask.

Because we store nothing on your device beyond the sign-in cookie, we do not show you a cookie consent banner — the law does not require one in this case. If we ever add an outside analytics tool, or any form of advertising, we will ask you first, not afterwards.

The list of address ranges we use for location comes from the IP to City Lite database provided by DB-IP under the Creative Commons Attribution 4.0 licence.

9. How we protect data

  • All traffic with the site is encrypted (HTTPS).
  • Passwords go through a modern cryptographic function built specifically for passwords (argon2id). We do not keep your password in readable form and cannot recover it — which is why we reset it rather than send it to you.
  • Session codes and reset links are also stored in cryptographic form, not as text.
  • Server access is by cryptographic key only, behind a firewall, with protection against repeated sign-in attempts.
  • We take daily backups of the database.
  • Colleagues cannot reach what they don't need: the staff area is separate from customer accounts, with distinct roles and permissions.

No measure is an absolute guarantee. If a breach occurs that puts your rights at risk, we will notify you and the authority within the deadlines the GDPR sets.

10. Your rights

Under the GDPR you have the right:

  • of access — to know what data we hold about you and receive a copy;
  • to rectification — to correct anything wrong or incomplete;
  • to erasure — to ask us to delete data, so far as we are not legally required to keep it;
  • to restriction — to ask us to stop using it temporarily;
  • to portability — to receive your data in a format you can take elsewhere;
  • to object — to object to processing based on our legitimate interest;
  • to withdraw consent at any time, where processing rests on it. Withdrawal does not affect what was lawfully done before.

You can exercise several of these yourself, immediately, from your account: change your details, delete a child's profile, withdraw consent for marketing emails, sign out of every device, or request deletion of your account.

For the rest, write to receptie@sandivers.ro. We reply within one month at the latest. If a request is complex we will tell you and say how much longer we need. We do not charge a fee.

11. If you are not satisfied

Write to us first — it is usually quicker. But you always have the right to complain to the supervisory authority:

  • The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
  • B-dul General Gheorghe Magheru 28–30, Sector 1, 010336 Bucharest, Romania
  • Web: www.dataprotection.ro

You may also go to court.

12. Automated decisions

We do not make automated decisions with significant effects on you, and we do not build behavioural profiles. Bonus points are calculated by a simple, published rule, not by an algorithm that assesses you.

13. Changes

Sandivers is a new project and still being built. When we add something that changes how we use data — online payments, bookings, an app — we update this policy before that feature launches.

The last-updated date and version are shown at the top of this page. If a change is significant and you have an account with us, we will tell you by email.

14. Contact

For any question about personal data: receptie@sandivers.ro, or write to MINIVERS BABY SRL, Strada Luminii, Valea Lupului, Iași county, Romania.