K Karibu โ† Back to home

Privacy Policy

How Karibu handles your data and your guests' data.

โš ๏ธ Placeholder document. A full GDPR-aware Privacy Policy is being prepared. The summary below describes Karibu's actual practices today; it is informational, not a substitute for the formal policy that will replace this page.

Where the real policy will go

Replace this placeholder with the generated Privacy Policy. Keep the <main> wrapper, header, footer, and styles intact.

For Termly: paste their embed script inside <main> and delete the placeholder block.

What we actually do today (summary)

Two categories of data:

Where it lives

All data is stored in Supabase (Postgres on AWS, EU region). Each hotel sees only its own data, enforced at the database level via row-level security policies that check a JWT claim on every query.

Who sees it

Your rights

Hotel customers and their guests have GDPR-equivalent rights: access, correction, deletion, export. Email obliqque1@gmail.com with your hotel name and what you'd like.

Cookies & tracking

Karibu uses localStorage for keeping you logged in, your language preference, and offline-mode caching. We do not use third-party advertising cookies. Errors may be sent to Sentry (anonymised, no PII) when that integration is enabled.

Security

Contact

Privacy or data-handling questions: obliqque1@gmail.com