Who runs Oceans Social Club
Oceans Social Club is the trade name of OCEAN S LOUNGE VALENCIA SL, which runs the venue, this website, the members app and the till, and is the controller of the personal data described in these documents.
- Company name
- OCEAN S LOUNGE VALENCIA SL
- Tax ID (NIF)
- B05586888
- Address
- C/ Vicente Sancho Tello, 25, bajo, 46021 València (Valencia)
- Contact
- hola@oceanssocialclub.com
Pending
- Commercial Registry entry (volume, folio, sheet and entry number): pending, to be added here.
1. Controller and contact
The controller is OCEAN S LOUNGE VALENCIA SL, tax ID (NIF) B05586888, with its tax address at C/ Vicente Sancho Tello, 25, bajo, 46021 València (Valencia), which is also the venue’s address. Under the trade name Oceans Social Club it runs that venue, this website, the members app and the till the team uses on the floor.
For anything about your data, or to exercise your rights, write to hola@oceanssocialclub.com or by post to the address above.
2. Information we process
What we hold depends on what you do. We do not ask everyone for everything.
- Members: name, email, date of birth, phone if you give it, language, account status, your acceptance of the membership terms and of this notice (which version, when, on the web or at the till, and which team member collected it at the till), points, tier, discounts, the member card with its QR code and the short-lived codes you show a waiter.
- Age checks: when the team checks a member’s ID at the door we keep the result, the kind of document (DNI, NIE, passport…), the reason if entry is refused, a note if needed, who checked and when. Never the document number, a copy or photo of it, the nationality or the expiry date.
- Reservations and events: name, email, phone if you give it, date, time, table, party size, notes, status and attendance, event places and wait-lists and, for a web booking without an account, your confirmation that everyone in the party is 18 or over. Phone bookings and walk-ins are entered by the team with a name and, if you give them, a phone number or email. Please do not put health or other sensitive details in the notes; tell the team in person instead.
- Orders and payments: what the table orders, preparation notes, times, the team member who serves, discounts, complimentary items, voids, the payment method (cash or card), amounts, tips and refunds. The card terminal is separate from the platform: the till records the amount and the method, never card details. If you tell us about an allergy, the team can note it on the bill or on a line so that whoever prepares your order sees it.
- Receipts and invoices: your email and language when you ask for the receipt by email and, when you ask for a full invoice, also your tax ID, name or company name and address. The digital receipt opens from a link or QR code that carries no personal data.
- Club news and notifications: whether you want club news, with the record of your consent when you gave it at sign-up, at the till or while booking (the till and booking records keep the version and language of the text, the till record who collected it, and a booking without an account a hash of your email instead of the email). If you turn on notifications, your browser’s push subscription (a technical address and its keys) and an identifier for that device.
- Security: session cookies, the IP address of each sign-in request and code attempt, a hash of the IP address used to limit repeated requests, and the server’s technical logs.
- Team: work name and email, role, status, the preparation PIN (stored hashed), one session per device (device type and browser), sign-ins and a record of who changed each access and who did what on bills, payments, approvals and cash-ups, including the tips each waiter took.
3. Purposes and legal bases
This notice informs you; it is not a blanket consent. We ask for consent separately, and only where it is the right basis.
| Purpose | Legal basis |
|---|---|
| Create and run your membership: account, points, tiers, discounts, member card and member bookings | Performance of the membership contract you accept (GDPR art. 6.1.b). |
| Handle bookings made online, by phone or at the door, events, wait-lists and their emails and reminders | Steps you ask for before and while we provide the service (GDPR art. 6.1.b). |
| Make sure only people aged 18 and over come in and are served | The legal duty not to sell or serve tobacco or alcohol to minors (GDPR art. 6.1.c) and the club’s legitimate interest in an adults-only venue (GDPR art. 6.1.f). |
| Take payment, issue receipts and invoices and keep the billing records and the accounts | Performance of the sale (GDPR art. 6.1.b) and tax and accounting duties (GDPR art. 6.1.c). |
| Email you the receipt or the invoice | Your request at checkout (GDPR art. 6.1.b). |
| Note an allergy you tell us about, so we can serve you safely | Your explicit consent when you ask us to (GDPR art. 9.2.a). |
| Send you club news by email | Your consent (GDPR art. 6.1.a and art. 21 of Spanish Law 34/2002), which you can withdraw at any time. |
| Send booking and event reminders and club messages as notifications | Your consent when you turn them on for a device (GDPR art. 6.1.a). |
| Protect accounts, access and the service: sessions, attempt limits and fault diagnosis | The club’s legitimate interest in a secure and available service (GDPR art. 6.1.f). |
| Manage the team, its permissions and who did what on bills, voids, tips and cash-ups | The employment relationship (GDPR art. 6.1.b), legal duties (GDPR art. 6.1.c) and the club’s legitimate interest in internal control (GDPR art. 6.1.f). |
| Answer requests to exercise your rights, and complaints | Legal duty (GDPR art. 6.1.c). |
4. Where data comes from and what is required
Most information comes from you. At the till a team member enters what you tell them, or you type it yourself on the till’s guest screen, and joining there is only completed once you confirm it with the code or link we email you. Phone bookings and walk-ins are entered by the team. Purchases, points and attendance arise from using the service.
Sign-in with Google is not offered today. If it is switched on, Google would give us an account identifier, your verified email and your name, never your password, and this notice will be updated first.
Joining requires your email, name, date of birth and acceptance of the membership terms. Booking without an account requires a name, an email and your confirmation that the whole party is 18 or over. Phone number, club news and notifications are optional. Tax details are needed only for a full invoice; without them you get a simplified receipt.
5. Service providers, recipients and transfers
Cloudflare, Inc. hosts the platform and processes the data on our behalf: the servers (Workers), the database (D1), file storage (R2), queues, email sending and technical logs. Cloudflare is a US company and may process data outside the European Economic Area; those transfers rely on the EU-US Data Privacy Framework, under which Cloudflare is certified, and on the European Commission’s standard contractual clauses in its data processing agreement. If you agreed to receive club news by email, we send it from our own platform through this same Cloudflare service, never a third-party newsletter tool, and you can withdraw that consent at any time.
If you turn on notifications, your browser’s push service (Google, Apple or Mozilla, depending on the device) receives each notice encrypted in order to deliver it, and may do so outside the EEA. If you save the member card to Google Wallet, Google receives a serial number and your member code, not your name. If you choose to load the map on the About page, your browser connects to Google.
Our accounting advisers access billing and its exports on our behalf, including the tax ID and name of anyone who asks for a full invoice. The Spanish Tax Agency, other authorities and the courts receive data when the law requires it; today the system does not send billing records to the Tax Agency automatically. We do not sell personal data or pass it on for advertising.
6. Retention
We keep data only as long as it is needed for its purpose. After that, what the law requires us to keep is blocked, available only to courts and authorities while liabilities can still be claimed, and then deleted. Some periods are set by the system itself; for the rest, the legal criterion in the table applies.
Apart from the automatic deletions in the table, the platform does not yet delete accounts, bookings or other records by itself: closing a membership and erasure are handled on request at hola@oceanssocialclub.com, and whatever the law requires us to keep is blocked instead of deleted.
| Data | Period |
|---|---|
| Sign-in links and codes, and the member code for the till | Single use. They expire after 15 minutes; the member code after 5. |
| Joining requests at the till awaiting confirmation | The code expires after 15 minutes and the request is deleted 7 days later. |
| Code attempts, with the IP address | Deleted after 7 days. |
| Emails waiting to be sent (stored encrypted) | Deleted 30 days after they are sent, fail or expire. |
| Sessions | A member session lasts up to 30 days; a team session lasts 30 days and renews while in use. Signing out ends it on that device. |
| Push subscription | Until you turn notifications off or your browser invalidates it. |
| Membership, points, acceptances and age checks | While you are a member. If you close the membership or ask for erasure, they are blocked for the limitation periods of any liability and then deleted. |
| Bookings, events and club-news consents | While needed to handle the booking or to prove the consent, then blocked for the applicable limitation periods. |
| Bills, receipts, invoices, billing records and accounts, with what they contain (such as a table’s allergy note) | The statutory periods: at least 4 years under tax law and 6 years under commercial law. The system does not let them be changed or deleted earlier. |
| Sign-in requests with their IP address | While they help investigate misuse of an account and, at most, for the limitation periods; then deleted. |
| Team accounts and records | During the working relationship and afterwards for the statutory employment, tax and limitation periods. |
| Server technical logs (Cloudflare) | A short period set by Cloudflare. |
7. Your rights
You may ask for access, correction, erasure, restriction, objection and portability where each applies, and withdraw any consent at any time without affecting earlier lawful processing. In the members app you can change your name, phone, language and club-news choice, and turn notifications off on each device.
Write to hola@oceanssocialclub.com, or by post to OCEAN S LOUNGE VALENCIA SL, C/ Vicente Sancho Tello, 25, bajo, 46021 València (Valencia), saying which right you want to exercise. We may ask for proportionate proof of identity and will answer within one month. If you disagree with our answer, you can complain to the Spanish Data Protection Agency.
8. Automated rules and age restriction
The platform calculates points and assigns a tier from published thresholds. That produces a discount, not a decision with legal or similarly significant effects. The team can correct the points ledger with an audited reason.
The service is only for people aged 18 and over. The date of birth prevents under-age membership, a web booking without an account requires confirming that the whole party is 18 or over, and the team checks ID at the door. We keep the result and the kind of document, never a copy.
9. Security and changes to this notice
We use single-use links and codes, signed secure cookies, team sessions that can be revoked per device, role-based permissions, encrypted storage of emails waiting to be sent and audit records that cannot be altered. No measure removes every risk; please report suspected misuse to hola@oceanssocialclub.com.
Material changes to this notice get a new version and date. A new purpose that needs your consent will not start merely because this notice was edited.
Official reference
Related documents
