All legal documents
This is the current version. A permanent copy of this exact text lives at volt.lk/venue-operator/privacy/v1.0.

Venue Operator Privacy Notice

Version 1.0Effective 1 September 2026Organisation and venue administrators using the Volt Admin web portal

1. Who We Are

Volt is operated by VOLTLK (PVT) LTD, a company incorporated under the laws of Sri Lanka (Company Registration No. PV 00370874).

Our registered address is on file with the Registrar of Companies and is available on request.

Privacy Contact: Email: privacy@volt.lk

This Notice explains how we collect, use, store, share, and protect your personal information as a venue operator using the Volt Admin web portal.

It does not describe your obligations towards players whose data you receive, those are set out in Section 6 of the Venue Operator Terms and summarised in Section 5 below.

If you also book venues as a player through the Volt mobile app, the separate Player Privacy Notice applies to that activity.


We process your personal information in compliance with the Personal Data Protection Act No. 9 of 2022 (PDPA) of Sri Lanka and, where applicable, the General Data Protection Regulation (GDPR).

We process your personal data on one or more of the following bases:

Where we rely on consent, you can withdraw it at any time. See Section 8.


3. Information We Collect About You

3.1 Information You Provide Directly

Data Why
Email address Account creation, authentication, transactional email, invitations
Full name Account identification and audit trail of administrative actions
Password (hashed) Authentication, we never store plaintext passwords
Role within the organisation Determining what you can access in the Admin Portal
Organisation and venue details Listing your venue: name, address, description, opening hours, photos
Bank account details: bank name, account number, account holder name, branch Displayed to players so they can pay your venue by bank transfer, and used for payment reconciliation
Contact phone number (where provided) Support and account recovery

Bank details. These are business payment details entered in your venue's payment settings. They are shown to players making a booking at your venue so they can transfer payment to you. Do not enter a personal account you do not wish players to see.

3.2 Information Generated by Your Use of the Admin Portal

Data Why
Booking and payment records for your venues Operating your venue and financial reconciliation
Customer records you create (walk-ins) Managing bookings for customers who are not registered Volt users
Payout and commission records Calculating what is owed to and by your organisation
Notifications Booking requests, updates, and platform notices
Consent records Evidence of which version of the Operator Terms and this Notice you accepted, and when

3.3 Information from Third-Party Sign-In

If you sign in using Google, we receive from Google the email address and display name associated with your Google account. We do not receive or store your Google password. Your use of Google Sign-In is also governed by Google's Privacy Policy.

3.4 Automatically Collected Technical Information


4. How We Use Your Information

4.1 Providing the Admin Portal

4.2 Platform Operations

We do not use your personal data to:


5. Player Data You Receive: Your Role

When a player books your venue, Volt discloses their name, contact information, and booking details to you so you can service the booking.

For that data you act as an independent controller in your own right. This Notice does not cover your processing of it. Your obligations, permitted purposes, security, breach notification, and retention, are set out in Section 6 of the Venue Operator Terms, and you are responsible for your own PDPA compliance in respect of it, including handling any data subject request a player makes directly to you.

Volt may audit or suspend access where we have reasonable grounds to believe player data is being misused.


6. Information We Share

We do not sell your personal data. We share it only in the following circumstances:

6.1 Within Your Organisation

Other administrators in your organisation can see your name, email, role, and a record of administrative actions you take in the Admin Portal.

6.2 With Players

Your venue's public listing, including venue name, address, description, photos, opening hours, pricing, and (where you provide them) the bank account details used for transfer payments, is visible to players. Your personal name is not published to players unless you include it in venue content.

6.3 With Service Providers (Data Processors)

We engage the following third-party processors who act on our instructions and are bound by data processing agreements:

Provider Purpose Country Privacy Policy
Supabase Inc. Database, authentication, and real-time infrastructure United States supabase.com/privacy
Cloudflare, Inc. File and image storage (R2) via global CDN United States cloudflare.com/privacypolicy
PostHog, Inc. Product analytics (opaque user IDs only, no email sent) United States posthog.com/privacy
Sentry (Functional Software, Inc.) Crash and error monitoring (opaque user IDs only, no email sent) United States sentry.io/privacy
Resend, Inc. Transactional email delivery United States resend.com/legal/privacy-policy
Google LLC Google Sign-In (OAuth 2.0) United States policies.google.com/privacy
Google LLC Google Analytics: measures how the Admin Portal is used. Sets cookies in your browser United States policies.google.com/privacy
Vercel Inc. Hosting and content delivery for the Admin Portal United States vercel.com/legal/privacy-policy

Cross-border transfers: Several of these providers are located in the United States. When personal data is transferred to these providers, we rely on standard contractual clauses and/or the providers' data processing agreements as the lawful transfer mechanism under the PDPA. We only send the minimum data necessary to each provider. Notably, we send only opaque user IDs (not email addresses or names) to PostHog and Sentry.

Google Analytics. Unlike PostHog and Sentry, Google Analytics sets cookies in your browser (identifiers beginning _ga), and Google processes the data on its own global infrastructure rather than in the EU. It records the pages you visit, approximate location derived from your IP address, and device and browser information. We send the page path only, never query strings, which can carry search terms or password-reset tokens.

You can stop Google Analytics running by installing Google's opt-out browser add-on or by blocking cookies for this site.

We may disclose personal data if required by a court order, law enforcement request, or other lawful legal process in Sri Lanka or another jurisdiction where we operate.

6.5 Business Transfers

If Volt or its assets are acquired, personal data held by us may be transferred to the acquiring entity, subject to the same privacy protections described in this notice.


7. Data Retention

Data Category Retention Period
Operator account data (name, email, role) Until account closure, then deleted within 30 days
Organisation and venue records Until the organisation is closed, then deleted within 30 days
Bank account details Until removed by you or the organisation is closed, then deleted within 30 days
Booking and payment records 7 years from the date of booking (for financial record-keeping under Sri Lankan law)
Payout and commission records 7 years from the transaction date
Consent records 7 years from withdrawal or account closure, as proof of the lawful basis relied on
Analytics event data (PostHog) 30 days
Analytics event data (Google Analytics) Event and user level data as configured in Google Analytics, maximum 14 months. Aggregated reports are retained by Google indefinitely.
Web hosting request data (Vercel) Handled transiently to route and serve requests. The Admin Portal is a static site with no server-side functions, so no application request logs are produced or retained by us.
Error logs (Sentry) 90 days
Automated database backups 30 days, encrypted

Booking and payment records may be retained for the legally required period in anonymised or pseudonymised form after account closure.


8. Your Rights

Under the Personal Data Protection Act No. 9 of 2022 of Sri Lanka, you have the following rights in respect of your own personal data:

Right What it means
Right of access You can request a copy of the personal data we hold about you
Right to rectification You can correct inaccurate or incomplete personal data
Right to erasure You can request deletion of your data (subject to legal retention obligations)
Right to restrict processing You can ask us to limit how we use your data in certain circumstances
Right to data portability You can request your data in a structured, machine-readable format
Right to object You can object to processing based on our legitimate interests
Right to withdraw consent Where processing is based on consent, you can withdraw it at any time

You can review and withdraw the consents you have given from Settings → Privacy & Consent in the Admin Portal:

Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out before you withdrew. We keep a record of consents given and withdrawn (see Section 7) as evidence of the basis we relied on.

Withdrawing your own consent closes your administrator account. It does not automatically close your organisation or delete its venues and bookings, contact support@volt.lk to close an organisation.

8.2 Exercising Other Rights

Email us at privacy@volt.lk. We will respond within 30 days of receiving your request. In complex cases, we may extend this by an additional 30 days with prior notice.

Complaints: If you believe we have not handled your data appropriately, you have the right to lodge a complaint with the Data Protection Authority of Sri Lanka once it is operational under the PDPA, or seek remedies through the courts.


9. Security

Despite these measures, no system is completely secure. If you believe your account has been compromised, or that player data has been exposed, contact us immediately at privacy@volt.lk.

Reporting a breach to you

If a security incident affects your personal data and is likely to put you at risk, we will notify you and the Data Protection Authority of Sri Lanka without undue delay, and within 72 hours of becoming aware of it where that is required. Our notice will say what happened, what data was involved, what we are doing about it, and what you should do.


10. Changes to This Notice

We may update this Notice from time to time. When we make material changes, we will:

Continued use of the Admin Portal after the effective date constitutes acceptance of the updated notice.


11. Contact Us

For any privacy-related questions, requests, or complaints:

VOLTLK (PVT) LTD Company No. PV 00370874 · Sri Lanka

Email: privacy@volt.lk
Business hours: Monday–Friday, 9:00 AM – 5:30 PM (SLST, UTC+5:30)