HERMES
Last updated: 2026-05-29T00:00:00.000Z · Ελληνικά

Cookie Policy

This policy describes what cookies and similar technologies HERMES PMS uses across hermespms.com (marketing site), admin.hermespms.com (operator/hotelier admin), and the per-tenant booking sites that we host under each hotelier’s domain.

We rely on the legal framework set by GDPR Art. 4(11) + Recital 32 (consent), the ePrivacy Directive Art. 5(3) as transposed into Greek Law 3471/2006 Art. 4, and the HDPA’s Guidelines 1/2020 on cookies and trackers. The short version: strictly necessary cookies do not require consent; everything else does.

1. hermespms.com (marketing site)

hermespms.com sets one strictly-necessary cookie when a visitor submits the signup form. No analytics, no advertising, no third-party trackers. No consent banner is shown because consent is not required for strictly-necessary cookies.

CookiePurposeTypeDuration
astro-sessionCSRF + double-submit defence on signupStrictly necessarySession

2. admin.hermespms.com (HERMES admin panel)

The admin panel is behind authentication — only registered hoteliers see it. All cookies are strictly necessary for the auth + CSRF + session machinery.

CookiePurposeTypeDuration
hermespms_api_sessionLaravel session IDStrictly necessary2 hours, sliding
XSRF-TOKENCSRF tokenStrictly necessary2 hours
remember_web_*”Remember me” if ticked at loginStrictly necessary (login)30 days

No third-party cookies are set on the admin panel.

3. Per-tenant booking sites (<your-domain>.com)

When a hotelier’s branded booking site is hosted on HERMES, the only cookie set during anonymous browsing is the Astro session cookie used by the booking flow. No tracking cookies, no analytics cookies, no cross-site identifiers are set by HERMES.

If the hotelier explicitly configures a third-party analytics or advertising tag through the Marketing tags setting (when shipped), the hotelier — as controller — is responsible for surfacing a consent banner on their booking site.

The CalDAV / CardDAV endpoints under dav.<your-domain>.com are accessed by Mac / iOS clients over Basic Auth — no cookies are exchanged.

4. Payment iframes

When a guest pays for a reservation, Viva Smart Checkout or Stripe Checkout is loaded on the payment provider’s domain. Cookies set in that context are governed by Viva’s or Stripe’s own cookie policy. HERMES does not read those cookies.

5. Local storage

The admin panel uses browser localStorage for UI state — column toggles, dark-mode preference, sidebar state. These are not cookies and are not transmitted to the server.

6. Do Not Track

HERMES does not set tracking cookies in the first place, so there is nothing to disable via DNT. We do not log DNT explicitly.

7. Changes

If we ever start using non-strictly-necessary cookies, this policy will be updated and a consent banner will appear before any such cookie is set. We will announce ≥ 14 days in advance to active tenants.

8. Contact

Bizr Single-Member P.C. Email: [email protected]