Privacy notice
What we record when you use a Sere stay pass, and what we do not.
The short version
You do not need an account to use a Sere pass, and we never ask for your name, email address or phone number. The data we hold does not directly identify you. What we do record is how the pass itself is used, so that we can show partner restaurants that the pilot works and keep discount limits fair.
Who is responsible for your data
Sere is an early-stage pilot run by two founders, Roope Pasanen and Joonas Seppanen. We are not yet a registered company, so we are jointly responsible for this data as private individuals, as joint controllers under Article 26 of the GDPR. We have agreed between us that either of us can handle any privacy request in full, so one message to the address below is always enough.
You can reach us at [email protected] or on +358 44 273 4820.
What we record
- A label for the pass. Your host writes a short label so they can tell their passes apart, for example "Apartment 4B". Hosts are instructed not to enter guest names, and the pass does not need one.
- The check-in and check-out dates of the stay the pass belongs to, which decide when the pass works.
- How the pass is used. When the pass is opened, which restaurants are viewed, which discounts are used and when, and whether a discount was started but not completed.
- How many people were eating, if you choose to tell us after using a discount. This is optional and you can skip it.
- Your browser language and device type (phone or computer). We keep only the two-letter language code, so that partner restaurants know roughly which languages their guests speak.
- Feedback you send us, meaning the star rating and any comment you write.
What we do not record
- No account, no password, no name, no email address, no phone number.
- No payment or card details. Sere never handles your payment.
- No location is sent to us. If you tap "Sort by nearest", your browser asks your permission and uses your location only on your own device to order the restaurant list. It is never sent to or stored by Sere.
- We do not link IP addresses to your pass or your activity. Our hosting and security providers keep standard, short-lived connection logs to run and protect the service.
- No device fingerprinting, no advertising trackers and no third-party analytics. There is no Google Analytics, no Meta pixel and no advertising cookie on this site.
- No tracking of you across different passes, different stays or other websites.
One honest note: while we hold nothing that directly identifies you, your host naturally knows which booking their pass belongs to. That is between you and your host; Sere does not receive it.
Why we record it, and on what legal basis
We use this information to run the pass and enforce any limits on discount use, to show partner restaurants that Sere brings them customers, to show hosts that their guests actually use the pass, and to find and fix the places where the service is confusing.
The legal basis is our legitimate interest under Article 6(1)(f) of the GDPR in running and improving this service. We have kept the data deliberately minimal and free of anything that directly identifies you, which is what makes that balance reasonable. The optional questions about party size and feedback are based on your consent, given by answering them, and you can simply skip them. If you change your mind about an answer you gave, send us your pass link and we will delete it.
Who else sees it
- Partner restaurants see totals only, such as how many discounts were used and how many people came. They never see individual passes.
- Your host sees the passes they created themselves, including whether a pass has been used.
- Sere's founders, acting as administrators, see pass and usage data only as needed to run the service. No one else has admin access.
- Railway, our hosting provider, stores the data on our behalf under the European Commission's standard contractual clauses.
- Cloudflare carries the traffic between your browser and our site and protects it from attacks, also under the European Commission's standard contractual clauses. It is contractually limited to using your connection data only to provide that service.
We do not sell your data, and we do not share it for advertising.
How long we keep it
- Page views and restaurant views: 90 days, then deleted.
- Passes and discount redemptions: 6 months after the check-out date, then deleted.
- Feedback: 12 months, so we can compare the service across seasons, then deleted.
- Anonymous totals that can no longer be traced back to a single pass, for example "42 discounts used in July", are kept indefinitely.
If the pilot ends, we delete all pass and usage data within 30 days, keeping only those anonymous totals.
Your rights and how to use them
You have the right to ask what we hold about you, to have it corrected or deleted, to object to our use of it, and to receive a copy. Because we do not collect anything that directly identifies you, we usually cannot find your data from your name alone. If you still have your pass link, send it to us and we can act on everything connected to that pass. Write to [email protected] and we will answer within one month.
If a data breach ever affects pass data, we will inform the affected hosts and, where we can reach them, guests without undue delay.
If you are unhappy with how we handle your data, you can complain to the Finnish Data Protection Ombudsman at tietosuoja.fi, or to the supervisory authority of the country where you live.
Storage on your device
We store your pass code in your browser so that you do not have to scan the QR code again during your stay. This is strictly necessary for the pass to work, which is why no consent banner is shown for it. You can clear it at any time by clearing your browser data.
Automated decisions
We do not profile you and we make no automated decisions about you.
Last updated 9 August 2026.
See also our terms of use.