HORIZON
  • Ask
  • Features
  • Questions
Register interest
Ask Features Questions Terms Register interest

HORIZON · Legal

Privacy Policy

How Horizon collects, uses, stores and protects information — under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.


Back to homepage Read the Terms & Conditions
Draft — not yet lawyer reviewed

This policy was prepared in-house by Horizon and has not yet been reviewed by a lawyer. It is published as a plain statement of our practices, not as legal advice to you. Please obtain independent legal advice before relying on it.

In short — the five things most people ask
  1. We only ever read. We never write. Our access is read-only — Horizon cannot create, edit or delete anything in your systems.
  2. We never see your passwords. You grant access by adding our operator accounts as API users in your own system, or by issuing us an API key from your account.
  3. Your data stays in Australia. It is stored in Sydney (ap‑southeast‑2). We do not send venue data offshore for storage.
  4. We do not touch payment data. No card numbers, no bank details.
  5. You can cut us off at any time. When you disconnect or stop paying, we delete your venue data.
Effective date
21 September 2026
Published at
joinhorizon.net/privacy.html
Privacy contact
hello@joinhorizon.net
Governing law
South Australia, Australia — with the Privacy Act 1988 (Cth)

1.Who we are

1.1

HORIZON is a venue-intelligence platform for hospitality businesses. It reads the systems a venue already runs on — point-of-sale, rostering and bookings — and turns them into plain-language answers and live operational views. You can ask Horizon a question about your venue in plain English and get the number, the reason and the next move.

1.2

In this policy, “Horizon”, “we” and “us” mean Mitchell James Parker and Peter Mercuri, trading as Horizon. We currently operate under the interim business vehicle ABN 51 371 377 898 (Peter Mercuri, trading as Horizon) until a company is incorporated. “You” and “your venue” mean the hospitality business that connects its systems to Horizon, and the people who use it on the venue’s behalf.

1.3

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and hold ourselves to that standard whether or not the Act’s small-business exemption would otherwise apply at our current size.

1.4

Horizon holds no security or privacy certifications. We do not claim SOC 2, ISO 27001, PCI DSS, HIPAA or any equivalent accreditation. What we do claim is set out in section 6, and we are happy to be tested on it.

2.What we collect — and what we never collect

2.1

We collect three kinds of information, and no more than we need for each.

CategoryWhat it includes
Venue business dataRead (read-only) from the systems you connect: sales totals and line items with timestamps, product and category names and discounts (point-of-sale); rostered and worked hours and labour cost (rostering); booking times, party sizes, covers and status (bookings).
Account informationWhat we need to give your team access and stay in contact — your name and work email, your role at the venue, and the venue’s business contact details. If you contact us, we keep the correspondence.
Technical & usage logsSign-in events, IP address, browser and device type, timestamps, views accessed, connection and disconnection events, and error and diagnostic logs.
2.2

Some venue business data may relate to identifiable individuals — most obviously rostering data, which concerns your staff. We treat that as personal information. Your venue holds the direct relationship with those individuals and is responsible for making its staff aware that their rostering data is used for operational reporting.

2.3

Booking data is used for covers, timing and status. We do not seek guest names or guest contact details, and Horizon does not need them.

2.4

The following are outside what Horizon reads. We do not receive them, do not store them, and do not want them:

  • Payment card data — no card numbers, expiry dates, cardholder names or security codes.
  • Bank details — no account numbers, BSBs or banking credentials.
  • Your account passwords, for any connected system, ever.

Because we never hold cardholder data, Horizon sits outside the card-payment chain. We also do not collect sensitive information as the Privacy Act defines it — health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record. Please do not send it to us.

3.How we collect it

3.1

Directly from you — when you talk to us, email us, complete a form, or set up your venue in Horizon.

3.2

Through read-only API connections that you authorise. This is how venue business data reaches Horizon. Your venue grants access in one of two ways:

  1. you add Horizon’s operator accounts as API users inside your own system; or
  2. you generate an API key or token from your own account and supply it to us.

Either way the authorisation is yours, granted from a system you control, and revocable there. We never request or accept your account passwords.

3.3

The systems Horizon connects to. Deputy is live and running today. The others are built and go live as the first venue on each system connects, and are then self-serve for every venue after:

  • Deputy (rostering & labour) — connected and running today.
  • Square (point-of-sale) — built; goes live as the first venue connects, then self-serve.
  • Lightspeed (point-of-sale) — built; goes live as the first venue connects, then self-serve.
  • Xero (accounting & finance) — built; goes live as the first venue connects, then self-serve.
  • Doshii (point-of-sale data) — built; goes live as the first venue connects, then self-serve.
  • NowBookIt (reservations) — built; goes live as the first venue connects, then self-serve.

Only the systems you choose to connect are read, and only once you have granted access.

3.4

Automatically — technical and usage logs are generated as a by-product of running the service securely.

4.Why we collect it and how we use it

4.1

We use information only to:

  • provide the platform — your live views, comparisons, analytics, alerts and the plain-English Ask;
  • set up, maintain and troubleshoot your system connections;
  • support you and respond to incidents;
  • keep the service secure, detect misuse and maintain audit records;
  • improve Horizon’s reliability and features; and
  • communicate with you about your account.
4.2

We do not sell information. We do not share it with advertisers or data brokers. We do not use your venue’s data to build products for, or give any advantage to, a competing venue.

4.3

We may use aggregated, de-identified information — from which no venue and no individual can reasonably be identified — to improve our analytics and describe the platform’s performance generally.

4.4

We name a venue as a reference or case study only with that venue’s permission, and the venue approves the wording first. If we ever want to use information for a purpose not set out above that you would not reasonably expect, we will ask you first.

5.Who we disclose it to, and where it is stored

5.1

We keep the list of parties who touch your data deliberately short.

RecipientRole
Hosting providerSupabase, providing the managed PostgreSQL database and hosting in Sydney. It processes data on our instructions, not for its own purposes.
Connected providersThe systems your venue already uses — Deputy, Square, Lightspeed, Doshii, Xero and NowBookIt. We read from them under the access you grant; your contract with each is direct and their own policies apply.
The foundersMitchell James Parker and Peter Mercuri, on a need-to-know basis, to operate and support the platform.
Professional advisersLegal, accounting and insurance advisers, where genuinely necessary and under a duty of confidence.
Where law requiresA court, regulator or law-enforcement agency, to the minimum extent required. Where we may lawfully tell you first, we will.
5.2

Storage and residency. Venue data is stored on Supabase (PostgreSQL) in the Sydney, Australia region (ap-southeast-2). It stays in Australia; we do not replicate it to overseas regions.

5.3

Overseas access. We do not disclose venue data to overseas recipients. One matter we should state plainly: one founder is based overseas for part of the year and may access the platform, including venue data, from outside Australia while working. That is access by us under our own controls and for the purposes in section 4 — not a disclosure to any foreign organisation — and the data remains stored in Sydney, reached through the same encryption, isolation and audit logging described in section 6.

5.4

We engage no other subprocessor. If that changes we will update this policy before the new provider handles venue data. If Horizon is ever incorporated, restructured or sold, information may pass to the incoming entity, which will be bound by this policy or one no less protective, and we will tell affected venues.

6.How we keep it secure

6.1

These are the specific, checkable measures we rely on.

ControlWhat it means
Read-only scopeOur access cannot create, edit or delete anything in your systems. The blast radius of a problem at our end is limited to reading.
No passwords heldWe never ask for, receive or store your account passwords. Access is by API user, or a key you issue and can revoke.
EncryptionCredentials are encrypted with AES-256-GCM in a per-venue vault — the database only ever stores ciphertext. Connections are made over encrypted channels.
Tenant isolationEnforced at the database layer with PostgreSQL row-level security (RLS), not merely in application code. One venue cannot read another’s rows.
Audit loggingConnection and disconnection events are audit-logged.
Need-to-know accessOnly the founders access venue data, only to run and support the platform, and only when there is a reason to.
RevocationYou can revoke our access at any moment from your own system, or by disconnecting in Horizon.
6.2

No system is perfectly secure and we will not pretend otherwise. We take reasonable steps to protect information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and we keep those steps under review as Horizon grows.

7.How long we keep it, and deletion

7.1

We keep venue data while your venue is connected and we need it to provide the service. When your venue disconnects, or stops paying and its subscription ends, we delete your venue data within 30 days and confirm in writing. You may ask us to delete your data sooner, and we will act within that same window from your request.

7.2

Two honest qualifications. Deleted data may persist briefly in routine encrypted backups until those age out; while it remains, it stays protected by this policy. And we retain aggregated, de-identified information and any records the law requires us to keep. Otherwise, where we no longer need personal information for a purpose in this policy, we destroy or de-identify it.

8.Access, correction and complaints

8.1

You can ask what personal information we hold about you, ask for a copy, and ask us to correct it if it is wrong, out of date, incomplete or misleading. Write to hello@joinhorizon.net. We will respond within 30 days. There is no charge to make a request; if giving access takes substantial work we may charge a reasonable cost-based fee, and we will tell you before we do anything.

8.2

We may ask you to verify your identity first. Where your request concerns data that originated in your venue’s own systems — rostering records, for example — the fastest route is usually your venue or the system provider, because that is where the source record lives. We will still help, and we will correct our copy.

8.3

If you think we have mishandled your information or breached the APPs, tell us — nothing formal is required. We will acknowledge within 5 business days and respond in writing within 30 days. If we need longer we will say why and when to expect an answer.

8.4

If our response does not satisfy you, you can escalate to the Office of the Australian Information Commissioner (OAIC), the independent regulator, whose complaint process and current contact details are published at www.oaic.gov.au. You do not need our permission, and you may approach the OAIC directly at any time.

9.Data breaches — our commitment

9.1

We commit to the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), and apply it as our standard whether or not it is compulsory for us at our current size. If we suspect a breach we assess it promptly, and where we have reasonable grounds to believe an eligible data breach has occurred — one likely to result in serious harm — we notify the affected individuals and the OAIC as soon as practicable.

9.2

Beyond the statutory minimum, we commit to telling any affected venue about a breach involving its data within 48 hours of becoming aware of it, even where the statutory threshold is not met. You should hear it from us, early, not from somewhere else. We will tell you what happened, what data was involved, what we have done, what we recommend you do, and what we have changed so it does not recur.

10.Cookies and changes to this policy

10.1

Horizon uses cookies or equivalent browser storage only where necessary to keep you signed in and your session secure. These are essential and cannot be switched off without breaking sign-in. We do not use advertising cookies and we run no third-party advertising or tracking pixels on our website. You can block or delete cookies in your browser, but you will not be able to sign in.

10.2

We may update this policy as Horizon changes — for example when an integration goes live, or when a company is incorporated. The current version is always published here with its effective date at the top. Where a change materially affects how we handle your information, we will tell connected venues directly, by email to the venue’s named contact, before it takes effect. We will not apply a materially less protective policy to information we already hold without your consent.

11.How to contact us

11.1

For any privacy question, request or complaint — or simply to understand what we hold and why — contact us:

Who we are
Mitchell James Parker and Peter Mercuri, trading as HorizonInterim operating vehicle: Peter Mercuri, ABN 51 371 377 898, trading as Horizon
Privacy contact
hello@joinhorizon.net
Governing law
South Australia, Australia — together with the Privacy Act 1988 (Cth)
This policy is a public statement of how we handle information. Where an agreement between Horizon and your venue gives you stronger protection than this policy, that agreement prevails.
HORIZON · Privacy Policy · Draft v1.0 Draft — not yet lawyer reviewed · 21 September 2026
HORIZON
Venue intelligence for Australian hospitality operators. Built in Adelaide.
HomeFeaturesPrivacyTerms
© 2026 HORIZON. All rights reserved.