Cookie Policy
This policy describes what cookies and similar technologies HERMES PMS uses across hermespms.com (marketing site), admin.hermespms.com (operator/hotelier admin), and the per-tenant booking sites that we host under each hotelier’s domain.
We rely on the legal framework set by GDPR Art. 4(11) + Recital 32 (consent), the ePrivacy Directive Art. 5(3) as transposed into Greek Law 3471/2006 Art. 4, and the HDPA’s Guidelines 1/2020 on cookies and trackers. The short version: strictly necessary cookies do not require consent; everything else does.
1. hermespms.com (marketing site)
hermespms.com sets one strictly-necessary cookie when a visitor submits the signup form. No analytics, no advertising, no third-party trackers. No consent banner is shown because consent is not required for strictly-necessary cookies.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
astro-session | CSRF + double-submit defence on signup | Strictly necessary | Session |
2. admin.hermespms.com (HERMES admin panel)
The admin panel is behind authentication — only registered hoteliers see it. All cookies are strictly necessary for the auth + CSRF + session machinery.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
hermespms_api_session | Laravel session ID | Strictly necessary | 2 hours, sliding |
XSRF-TOKEN | CSRF token | Strictly necessary | 2 hours |
remember_web_* | ”Remember me” if ticked at login | Strictly necessary (login) | 30 days |
No third-party cookies are set on the admin panel.
3. Per-tenant booking sites (<your-domain>.com)
When a hotelier’s branded booking site is hosted on HERMES, the only cookie set during anonymous browsing is the Astro session cookie used by the booking flow. No tracking cookies, no analytics cookies, no cross-site identifiers are set by HERMES.
If the hotelier explicitly configures a third-party analytics or advertising tag through the Marketing tags setting (when shipped), the hotelier — as controller — is responsible for surfacing a consent banner on their booking site.
The CalDAV / CardDAV endpoints under dav.<your-domain>.com are accessed by Mac / iOS clients over Basic Auth — no cookies are exchanged.
4. Payment iframes
When a guest pays for a reservation, Viva Smart Checkout or Stripe Checkout is loaded on the payment provider’s domain. Cookies set in that context are governed by Viva’s or Stripe’s own cookie policy. HERMES does not read those cookies.
5. Local storage
The admin panel uses browser localStorage for UI state — column toggles, dark-mode preference, sidebar state. These are not cookies and are not transmitted to the server.
6. Do Not Track
HERMES does not set tracking cookies in the first place, so there is nothing to disable via DNT. We do not log DNT explicitly.
7. Changes
If we ever start using non-strictly-necessary cookies, this policy will be updated and a consent banner will appear before any such cookie is set. We will announce ≥ 14 days in advance to active tenants.
8. Contact
Bizr Single-Member P.C. Email: [email protected]