Mesily

Privacy policy

Last updated: September 28, 2026

This policy explains what personal data we process when you use Mesily, what we use it for and what rights you have. We apply it in accordance with Andorra’s Law 29/2021 on the protection of personal data and, where applicable, Regulation (EU) 2016/679 (GDPR).

Data controller

  • Controller: [Nombre o razón social del titular]
  • NRT: [NRT]
  • Address: [Dirección completa, parroquia]
  • Email: [email de contacto]

What data we process

  • When you book: name, mobile number, email (optional), any comments you write, and the date, time, number of people and table.
  • If you create an account: name, email and password (stored with a one-way algorithm, so nobody can read it) and, if you add it, your phone number and whether it is verified.
  • To verify your phone: the number and a one-time code we send you by text message. We only store an encrypted digest of the code.
  • Technical data: your IP address, which we use to limit text messages and sign-in attempts and prevent abuse, and the session cookie if you sign in.
  • Restaurants: contact details of the restaurant and of the person who manages it.
  • If you write to us from Support: your email, the subject and the message, which reach us by email so we can reply.

What we use it for

  • Managing your booking: confirming it, sending you the code and the confirmation, and letting you change or cancel it.
  • Passing the booking on to the restaurant so it can serve you.
  • Managing your account, if you create one, and filling in your details for future bookings.
  • Keeping the website secure and preventing fraud and abuse.

We do not use your data for advertising and we do not create profiles.

Legal basis

  • Providing the service you ask for (the booking or the account).
  • Your consent, which you give by accepting this policy and can withdraw at any time.
  • Our legitimate interest in keeping the website secure and preventing abuse.
  • Compliance with legal obligations, where they exist.

Who we share data with

We do not sell your data. We only share it with:

  • The restaurant you book with: your name, phone number, email, comments and the booking details. 30 days after the booking it can no longer see your personal data.
  • Service providers working for us, under contract and only for that purpose: text messages (Twilio), emails (Resend) and website hosting ([proveedor de alojamiento]).
  • Public authorities, when required by law.

International transfers

Some providers, such as Twilio and Resend, may process data outside Andorra and the European Union, for example in the United States. In those cases we require appropriate safeguards, such as standard data protection contractual clauses.

In addition, when you view a map, your browser downloads the images from OpenStreetMap servers, which receive your IP address.

How long we keep it

  • Bookings: as long as needed to manage them and then for the period in which claims may arise, one year from the booking date. After that they are anonymised: your name, phone number, email and comments are deleted, and only the booking without personal data remains, for statistics.
  • Account: for as long as you keep it. If you booked with your account, your bookings stay in your history for as long as you keep it (after the period above, without your personal data). If you delete it, your account data is removed and your bookings are no longer linked to it.
  • Text message codes: they expire after 10 minutes.
  • Security records (text message codes, sign-in attempts and password reset requests, with the IP address): deleted after 30 days.
  • Session: the cookie lasts 30 days for customers and 12 hours for restaurants, or until you sign out.

Your rights

At any time you can ask to access, rectify or erase your data, restrict or object to its processing, or request data portability, and you can withdraw your consent. Write to [email de contacto] saying which right you want to exercise; we may ask you to prove your identity. You can also correct your details or delete your account from your account page.

If you believe we have not handled your data properly, you can file a complaint with the Andorran Data Protection Agency (Agència Andorrana de Protecció de Dades, www.apda.ad) or, if you live in the European Union, with the data protection authority of your country.

Security

We apply technical and organisational measures to protect your data: encrypted connections, passwords stored with a one-way algorithm, sessions stored as an encrypted digest, and limits on sign-in attempts and bulk sending.

Minors

The service is intended for adults. If you are a minor, you need permission from your parents or guardians to use it.

Changes to this policy

We may update this policy. We will publish the current version here with its date and, if the change is significant, we will let you know.