Venue Operator Privacy Notice
1. Who We Are
Volt is operated by VOLTLK (PVT) LTD, a company incorporated under the laws of Sri Lanka (Company Registration No. PV 00370874).
Our registered address is on file with the Registrar of Companies and is available on request.
Privacy Contact: Email: privacy@volt.lk
This Notice explains how we collect, use, store, share, and protect your personal information as a venue operator using the Volt Admin web portal.
It does not describe your obligations towards players whose data you receive, those are set out in Section 6 of the Venue Operator Terms and summarised in Section 5 below.
If you also book venues as a player through the Volt mobile app, the separate Player Privacy Notice applies to that activity.
2. Legal Basis for Processing
We process your personal information in compliance with the Personal Data Protection Act No. 9 of 2022 (PDPA) of Sri Lanka and, where applicable, the General Data Protection Regulation (GDPR).
We process your personal data on one or more of the following bases:
- Contractual necessity: to provide the Admin Portal and administer your organisation's account and subscription
- Legitimate interests: to operate and improve the platform, prevent fraud, and ensure security
- Consent: for optional features such as marketing communications (where we ask for this separately)
- Legal obligation: where required by Sri Lankan law, including financial record-keeping
Where we rely on consent, you can withdraw it at any time. See Section 8.
3. Information We Collect About You
3.1 Information You Provide Directly
| Data | Why |
|---|---|
| Email address | Account creation, authentication, transactional email, invitations |
| Full name | Account identification and audit trail of administrative actions |
| Password (hashed) | Authentication, we never store plaintext passwords |
| Role within the organisation | Determining what you can access in the Admin Portal |
| Organisation and venue details | Listing your venue: name, address, description, opening hours, photos |
| Bank account details: bank name, account number, account holder name, branch | Displayed to players so they can pay your venue by bank transfer, and used for payment reconciliation |
| Contact phone number (where provided) | Support and account recovery |
Bank details. These are business payment details entered in your venue's payment settings. They are shown to players making a booking at your venue so they can transfer payment to you. Do not enter a personal account you do not wish players to see.
3.2 Information Generated by Your Use of the Admin Portal
| Data | Why |
|---|---|
| Booking and payment records for your venues | Operating your venue and financial reconciliation |
| Customer records you create (walk-ins) | Managing bookings for customers who are not registered Volt users |
| Payout and commission records | Calculating what is owed to and by your organisation |
| Notifications | Booking requests, updates, and platform notices |
| Consent records | Evidence of which version of the Operator Terms and this Notice you accepted, and when |
3.3 Information from Third-Party Sign-In
If you sign in using Google, we receive from Google the email address and display name associated with your Google account. We do not receive or store your Google password. Your use of Google Sign-In is also governed by Google's Privacy Policy.
3.4 Automatically Collected Technical Information
- Device and browser information: operating system, browser, app version
- Usage events: pages visited, features used (collected via PostHog and Google Analytics, see Section 6.3)
- Error and crash reports: collected via Sentry to help us diagnose and fix bugs (see Section 6)
- IP address: used for security, fraud prevention, and infrastructure purposes
4. How We Use Your Information
4.1 Providing the Admin Portal
- Creating and managing your account and your organisation's account
- Enabling venue, court, booking, customer, and payment management
- Calculating platform fees, commission, and payouts
- Sending operational notifications
4.2 Platform Operations
- Diagnosing crashes and technical errors (Sentry)
- Understanding how features are used to improve the product (PostHog and Google Analytics)
- Preventing fraud and unauthorized access
- Communicating service updates and critical notices
4.3 Legal and Safety
- Complying with legal obligations under Sri Lankan law, including financial record-keeping
- Enforcing the Venue Operator Terms
- Responding to lawful requests from government authorities
- Investigating suspected misuse of player data
We do not use your personal data to:
- Build advertising profiles for third-party advertising networks
- Sell your data to any third party
5. Player Data You Receive: Your Role
When a player books your venue, Volt discloses their name, contact information, and booking details to you so you can service the booking.
For that data you act as an independent controller in your own right. This Notice does not cover your processing of it. Your obligations, permitted purposes, security, breach notification, and retention, are set out in Section 6 of the Venue Operator Terms, and you are responsible for your own PDPA compliance in respect of it, including handling any data subject request a player makes directly to you.
Volt may audit or suspend access where we have reasonable grounds to believe player data is being misused.
6. Information We Share
We do not sell your personal data. We share it only in the following circumstances:
6.1 Within Your Organisation
Other administrators in your organisation can see your name, email, role, and a record of administrative actions you take in the Admin Portal.
6.2 With Players
Your venue's public listing, including venue name, address, description, photos, opening hours, pricing, and (where you provide them) the bank account details used for transfer payments, is visible to players. Your personal name is not published to players unless you include it in venue content.
6.3 With Service Providers (Data Processors)
We engage the following third-party processors who act on our instructions and are bound by data processing agreements:
| Provider | Purpose | Country | Privacy Policy |
|---|---|---|---|
| Supabase Inc. | Database, authentication, and real-time infrastructure | United States | supabase.com/privacy |
| Cloudflare, Inc. | File and image storage (R2) via global CDN | United States | cloudflare.com/privacypolicy |
| PostHog, Inc. | Product analytics (opaque user IDs only, no email sent) | United States | posthog.com/privacy |
| Sentry (Functional Software, Inc.) | Crash and error monitoring (opaque user IDs only, no email sent) | United States | sentry.io/privacy |
| Resend, Inc. | Transactional email delivery | United States | resend.com/legal/privacy-policy |
| Google LLC | Google Sign-In (OAuth 2.0) | United States | policies.google.com/privacy |
| Google LLC | Google Analytics: measures how the Admin Portal is used. Sets cookies in your browser | United States | policies.google.com/privacy |
| Vercel Inc. | Hosting and content delivery for the Admin Portal | United States | vercel.com/legal/privacy-policy |
Cross-border transfers: Several of these providers are located in the United States. When personal data is transferred to these providers, we rely on standard contractual clauses and/or the providers' data processing agreements as the lawful transfer mechanism under the PDPA. We only send the minimum data necessary to each provider. Notably, we send only opaque user IDs (not email addresses or names) to PostHog and Sentry.
Google Analytics. Unlike PostHog and Sentry, Google
Analytics sets cookies in your browser (identifiers
beginning _ga), and Google processes the data on its own
global infrastructure rather than in the EU. It records the pages you
visit, approximate location derived from your IP address, and device and
browser information. We send the page path only, never query strings,
which can carry search terms or password-reset tokens.
You can stop Google Analytics running by installing Google's opt-out browser add-on or by blocking cookies for this site.
6.4 Legal Requirements
We may disclose personal data if required by a court order, law enforcement request, or other lawful legal process in Sri Lanka or another jurisdiction where we operate.
6.5 Business Transfers
If Volt or its assets are acquired, personal data held by us may be transferred to the acquiring entity, subject to the same privacy protections described in this notice.
7. Data Retention
| Data Category | Retention Period |
|---|---|
| Operator account data (name, email, role) | Until account closure, then deleted within 30 days |
| Organisation and venue records | Until the organisation is closed, then deleted within 30 days |
| Bank account details | Until removed by you or the organisation is closed, then deleted within 30 days |
| Booking and payment records | 7 years from the date of booking (for financial record-keeping under Sri Lankan law) |
| Payout and commission records | 7 years from the transaction date |
| Consent records | 7 years from withdrawal or account closure, as proof of the lawful basis relied on |
| Analytics event data (PostHog) | 30 days |
| Analytics event data (Google Analytics) | Event and user level data as configured in Google Analytics, maximum 14 months. Aggregated reports are retained by Google indefinitely. |
| Web hosting request data (Vercel) | Handled transiently to route and serve requests. The Admin Portal is a static site with no server-side functions, so no application request logs are produced or retained by us. |
| Error logs (Sentry) | 90 days |
| Automated database backups | 30 days, encrypted |
Booking and payment records may be retained for the legally required period in anonymised or pseudonymised form after account closure.
8. Your Rights
Under the Personal Data Protection Act No. 9 of 2022 of Sri Lanka, you have the following rights in respect of your own personal data:
| Right | What it means |
|---|---|
| Right of access | You can request a copy of the personal data we hold about you |
| Right to rectification | You can correct inaccurate or incomplete personal data |
| Right to erasure | You can request deletion of your data (subject to legal retention obligations) |
| Right to restrict processing | You can ask us to limit how we use your data in certain circumstances |
| Right to data portability | You can request your data in a structured, machine-readable format |
| Right to object | You can object to processing based on our legitimate interests |
| Right to withdraw consent | Where processing is based on consent, you can withdraw it at any time |
8.1 Withdrawing Consent In-Portal
You can review and withdraw the consents you have given from Settings → Privacy & Consent in the Admin Portal:
- Marketing communications: withdraw at any time. We stop sending marketing email; your account and your venues are unaffected.
- Venue Operator Terms / this Privacy Notice: these are the basis on which we can operate your account at all. Withdrawing them means we can no longer provide the Admin Portal to you, so doing so starts closure of your operator account. We will tell you this clearly before you confirm, and you remain responsible for honouring bookings already confirmed.
Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out before you withdrew. We keep a record of consents given and withdrawn (see Section 7) as evidence of the basis we relied on.
Withdrawing your own consent closes your administrator account. It does not automatically close your organisation or delete its venues and bookings, contact support@volt.lk to close an organisation.
8.2 Exercising Other Rights
Email us at privacy@volt.lk. We will respond within 30 days of receiving your request. In complex cases, we may extend this by an additional 30 days with prior notice.
Complaints: If you believe we have not handled your data appropriately, you have the right to lodge a complaint with the Data Protection Authority of Sri Lanka once it is operational under the PDPA, or seek remedies through the courts.
9. Security
- Encryption in transit: all data is transmitted over HTTPS/TLS
- Encryption at rest: database and file storage are encrypted at rest
- Row-Level Security (RLS): database access is enforced at the database layer; you cannot access another organisation's data
- Authentication: passwords are hashed using bcrypt; we support Google SSO with PKCE flow
- Least-privilege access: the Admin Portal uses the Supabase anonymous key with RLS; the service role key is never exposed to clients
- Backup encryption: automated database backups are encrypted with AES-256 before being stored
- No payment card data: we do not process or store credit card data; payments are manual (cash/bank transfer)
Despite these measures, no system is completely secure. If you believe your account has been compromised, or that player data has been exposed, contact us immediately at privacy@volt.lk.
Reporting a breach to you
If a security incident affects your personal data and is likely to put you at risk, we will notify you and the Data Protection Authority of Sri Lanka without undue delay, and within 72 hours of becoming aware of it where that is required. Our notice will say what happened, what data was involved, what we are doing about it, and what you should do.
10. Changes to This Notice
We may update this Notice from time to time. When we make material changes, we will:
- Update the Version and Last Updated fields at the top of this document
- Notify you via in-app notification and/or email at least 14 days before the change takes effect
- Ask you to accept the new version when you next sign in to the Admin Portal, where renewed consent is legally required
Continued use of the Admin Portal after the effective date constitutes acceptance of the updated notice.
11. Contact Us
For any privacy-related questions, requests, or complaints:
VOLTLK (PVT) LTD Company No. PV 00370874 · Sri Lanka
Email: privacy@volt.lk
Business hours: Monday–Friday, 9:00 AM – 5:30 PM (SLST, UTC+5:30)