OMNIA The Club

PrivacyPolicy

What we collect, why we collect it, and what you can do about it.

This policy describes what personal information omniatheclub.com collects when you create an account, book a table or send us an enquiry — and exactly who it is shared with.

Last updated

01

Who we are

OMNIA The Club is a nightclub on Thabahi Sadak, Thamel, Kathmandu, Nepal. This policy explains what personal information we collect through our website at omniatheclub.com, why we collect it, who we share it with, and what you can do about it.

It covers the website, the guest account you can create on it, and the ticket and VIP table booking flow. It does not cover what happens inside the venue, or anything you send us on Instagram, Facebook or WhatsApp, which are governed by those services' own policies. If anything here is unclear, write to us at omniatheclub89@gmail.com.

This policy covers omniatheclub.com and the account you create on it.

02

What we collect

We collect the following, and nothing else. We do not ask for your date of birth, your home address, or a copy of an identity document, and the website has no facility to upload one.

  • Account details — your name, email address, and whether that address has been verified. If you register with an email and password, the password is handled by Google's Firebase Authentication and is never visible to us or stored on our systems.
  • Profile details — your phone number (stored as a country, a dialling code and the national number), an optional self-declared gender, and the illustrated avatar you pick. The avatar is one of twelve drawings we ship with the site; we never copy a profile photograph from your Google account.
  • Booking details — the event, the tables or tickets you chose, the number of guests, the total in Nepalese rupees, and the name, email address and phone number attached to the booking. Anything you type into the notes field is stored with it.
  • Enquiry details — for a VIP table or private-event enquiry: your name, email address, phone number, whether that number is on WhatsApp, the date and party size you have in mind, your floor and tier preference, and your message.
  • Payment evidence — the receipt or screenshot you upload for a bank or wallet transfer, along with the amount, transaction reference, payment date and bank or wallet name read from it. See “Payment receipts” below, which describes this in detail because it is the most sensitive thing we hold.
  • Technical information — ordinary server and platform logs generated when a browser requests a page, such as the request and the time it was made. We do not run any analytics, advertising or visitor-tracking product on this site.

Only what an account, a booking or an enquiry actually needs.

03

Signing in with Google

You can create your account with an email address and password, or by choosing “Continue with Google”. Both are optional routes to the same account, and you can book a table either way.

If you choose Google, we ask Google only for the basic profile information every Google sign-in provides: your name, your email address, your profile picture and your Google account identifier. We do not request access to Gmail, Google Drive, your contacts, your calendar or any other Google service, and we cannot read them.

We use that information for one purpose: to create your OMNIA account and sign you in to it. Your name and email address are stored on your profile so that a booking can be attached to you and a confirmation can be sent to you. We do not copy your Google profile picture — the avatar on your account is one of our own illustrations, which you can change.

Information obtained through Google sign-in is never sold, never rented, never shared with advertisers or data brokers, and never used to build an advertising profile or to train an artificial-intelligence model.

We always show Google's account chooser rather than reusing whichever Google account the browser happens to be signed in to, so that a shared or public computer cannot put you into someone else's session by accident.

Basic profile only. Never sold, never used for advertising.

04

How we use it

We use your information to:

  • Create your account, verify your email address and let you sign in. An unverified email address cannot complete a booking, which is why verification is not optional.
  • Hold your table, take your booking, work out what it costs, and check the payment evidence you send us.
  • Send you transactional email about a booking you made — that it was received, that a receipt arrived, that a payment was verified or not verified, that a booking was updated, cancelled or expired, that an event changed, or that a refund was recorded.
  • Reply to a VIP table or private-event enquiry by email, phone or WhatsApp, using whichever you gave us.
  • Let staff at the club see and manage bookings, payments and customer records in our admin panel, and keep an audit record of what each member of staff did.
  • Protect the site — rate-limiting repeated sign-in and registration attempts, and refusing uploads that are not payment documents.

To run your account, take your booking, and tell you what happened to it.

05

Payment receipts

We do not take card payments and there is no payment gateway on this website. You pay the club by bank transfer or mobile wallet, outside the site, and then upload a receipt or screenshot as evidence. You can attach up to five documents to one booking.

Your receipt is stored privately. It is never made publicly readable, it is never listed, and staff can only open it through a short-lived link generated at the moment they view it.

Where the club has switched it on, an uploaded receipt may be sent to OpenRouter — an external service that routes it to a third-party AI model — so that staff do not have to retype the figures. The model reads the amount, transaction reference, payment date and bank or wallet name off the document and checks that it really is payment evidence. This step is optional and is configured by the club: while it is switched off, no document you upload leaves our systems at all, and staff read every receipt themselves.

When it does run, the whole file is transmitted, images and PDF receipts alike. A bank slip usually carries your name and account or wallet number, so please be aware that those details would leave our systems as part of this step. We do not make any claim here about how long that provider keeps a document it receives, whether it deletes it, or whether it is used to train a model — those are settings on the provider's side that we have not stated to you as verified. Write to us before uploading if you want to know the current position.

The result is only ever a suggestion. No automated system can approve, reject or verify a payment on this site. A member of staff looks at the receipt and decides, and your booking is not confirmed until they do.

Read automatically by a third-party AI service, then checked by a person.

06

Who we share it with

We do not sell your personal information, and we do not share it with advertisers or data brokers. We share it only with the service providers that make the site work, and with anyone we are legally required to disclose it to.

  • Google (Firebase and Google Cloud) — hosts our database, sign-in, file storage and background jobs. Effectively everything described in this policy is stored on Google infrastructure.
  • Vercel — hosts and serves the website itself, and produces the ordinary request logs any web host produces.
  • Brevo — sends transactional email about your booking. Brevo receives your email address, your name, the subject and the contents of the message, which include your booking reference, the event, the date, your table or ticket details and the total. Receipts, internal notes and staff names are deliberately never included in that email.
  • OpenRouter — where the club has switched the feature on, reads uploaded payment receipts, as described above. It is the only place a document you upload could be sent outside our own systems, and it receives nothing while the feature is off.
  • Google Maps — our Contact and Visit pages embed a Google map. Loading those pages loads content from Google in your browser, and Google will see that request.
  • WhatsApp — only if you choose it. Some buttons on the site open WhatsApp with a message already written for you; nothing is sent until you press send in WhatsApp yourself.

A short list of service providers. We do not sell your data.

07

Where it is stored

Our database — accounts, profiles, bookings, payments and the staff audit log — is hosted in Google Cloud's asia-south1 region, in India.

Uploaded files, which means payment receipts and refund evidence, are stored in Google Cloud's us-east1 region, in the United States.

These two locations were fixed when the project was created and cannot be changed without rebuilding it. If you are using the site from outside those countries, your information is transferred to and stored in them.

India and the United States, on Google infrastructure.

08

Cookies and browser storage

This site sets no advertising cookies and no analytics cookies. It does not run Google Analytics, Google Tag Manager, a Meta pixel or any other visitor-tracking product, and it does not track you across other websites. That is the reason you have not been shown a cookie consent banner: there is nothing to consent to beyond what is strictly necessary to sign you in.

If you are a member of club staff, signing in sets one cookie, omnia_session. It holds a signed session token, is restricted to our own domain, cannot be read by JavaScript, is sent only over HTTPS, and expires after five days. Guest accounts are not given this cookie at all.

When you sign in, the site also keeps a small amount of information in your own browser's storage so that a page reload does not sign you out or flash the wrong state: your name, email address, phone number, gender if you set one, and chosen avatar, under the key omnia.auth.v1, together with your light or dark theme preference. Google's Firebase Authentication separately keeps your sign-in session in your browser's IndexedDB storage. All of it stays on your device, and clearing your browser data removes it.

Essential only. No analytics, no advertising, no tracking.

09

How we protect it

Our database and file storage deny every request by default. Nothing is readable by a visitor unless a rule explicitly allows it, and the collections holding bookings, payments, receipt readings, emails and the staff audit log allow no direct access from a browser at all — they are reachable only through server code that checks who is asking.

Payment receipts and refund evidence are never publicly readable and are never given a permanent link. Passwords are handled by Google's Firebase Authentication and are subject to a minimum-length and character policy. The site is served over HTTPS with a content security policy that blocks foreign scripts and prevents the site being framed by another. Repeated sign-in and registration attempts from the same source are rate-limited.

Staff accounts hold explicit, named permissions rather than blanket access — reading a customer record, exporting customer data, verifying a payment and issuing a refund are each a separate grant — and every privileged action is written to an audit log recording who did it and when.

No system is perfectly secure, and we cannot guarantee that transmission over the internet is completely safe. If you believe your account has been accessed by someone else, write to us immediately.

Locked by default; opened deliberately, one thing at a time.

10

How long we keep it

We keep your account and profile for as long as your account exists.

Bookings, payments, refunds and the staff audit log are the club's financial and operational history. They are kept after an event has passed, and they are kept even if the account that made them is deleted, so that a receipt or a report from months ago still reads correctly.

A few things do expire by themselves: an unpaid table hold is released after ten minutes, and artwork replaced on an event is cleared after seven days.

We have not yet set a fixed retention period for the remaining records. Until we do, they are retained for as long as they are needed to run the club and to keep an accurate financial record. If you want to know what we hold about you, or want it removed, write to us and we will tell you what is possible.

Bookings and payment records are kept as financial history.

11

Your choices and rights

You can change your name, phone number, gender and avatar yourself at any time on your account page. Your email address is fixed to the sign-in identity you registered with, because email verification depends on it — write to us if it needs to change.

You can delete your account yourself from your account page. Deleting it removes your sign-in identity, permanently deletes every payment receipt you uploaded, and replaces the personal details on your customer record — your name, email address and phone number — with anonymous values. Your bookings and payment records remain as an anonymised financial record, no longer linked to a name or an address you can be identified by. Deletion cannot be undone.

You can also ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we are using it. Write to omniatheclub89@gmail.com and tell us what you want; we may need to confirm your identity before we act, so that nobody else can make that request about you.

You can stop receiving enquiry replies by telling us to stop. Transactional email about a booking you have actually made — that a payment was verified, that an event was cancelled — is not marketing and cannot be switched off while the booking is live, because it is how we tell you what happened to your money and your table. We do not send marketing newsletters from this site.

Correct it yourself, or ask us — including deletion.

12

Age

OMNIA is strictly an 18-and-over venue, and a valid government photo ID is checked at the door for every guest, every night. Accounts and bookings on this site are intended for people aged 18 or over, and you confirm that you are when you register or book.

We do not knowingly collect information from anyone under 18. If you believe a child has given us their information, write to us and we will delete it.

18+. Accounts are for adults only.

13

Changes to this policy

We may update this policy as the club and the website change. The date shown at the top of this page tells you when it was last revised. Where a change materially affects how we handle your information, we will take reasonable steps to bring it to your attention rather than relying on you noticing the date.

The date at the top of the page is the version.

14

Contact us

For anything in this policy — a question, a correction, a copy of your data, a deletion request or a complaint — write to omniatheclub89@gmail.com.

OMNIA The Club, Thabahi Sadak, Thamel, Kathmandu 04600, Nepal.

One address, read by the club.