Privacy Policy

Last updated: 2026-04-17

1. Data controller

  • Company:[PENDIENTE: razón social, p.ej. Restaur.ai S.L.]
  • Owner:[PENDIENTE: nombre y apellidos del responsable]
  • Address:[PENDIENTE: calle y número], [PENDIENTE: código postal] [PENDIENTE: ciudad], [PENDIENTE: país, p.ej. España / Deutschland]
  • Email:info@restaur.ai
  • Phone:[PENDIENTE: teléfono de contacto]
  • VAT ID:[PENDIENTE: CIF/NIF o USt-IdNr.]
  • Register:[PENDIENTE: ej. Registro Mercantil de Madrid, Tomo X, Folio Y / o Handelsregister Berlin HRB 123456]

2. Purposes of processing

We process your personal data for the following purposes:

  • Create and maintain your user account.
  • Manage billing and subscription payments.
  • Provide the service: host your menu, generate QR codes, import content, AI generation.
  • Analyze product usage to improve it (only with your consent).
  • Detect and prevent abuse, fraud and security incidents.

3. Legal basis

  • Performance of a contract (Art. 6.1.b GDPR): to provide the service you contracted.
  • Legitimate interest (Art. 6.1.f GDPR): for security, fraud prevention and product improvement.
  • Consent (Art. 6.1.a GDPR): for analytics cookies and commercial communications.
  • Legal obligation (Art. 6.1.c GDPR): billing, accounting, legal requirements.

4. Data we process

  • Account: name, email, encrypted password, preferred language.
  • Billing: address, tax data, payment history (card data is handled by Stripe; we never store it).
  • Restaurant content: name, address, photos, menu, allergens, social media.
  • Technical: IP, user agent, access logs (90 days).
  • Analytics: pages visited, product events (only with consent).

5. Retention period

We keep your data while your account is active. After requesting deletion, data is deleted within 30 days, except for data we are legally required to keep (e.g. invoicing for 6 years).

6. Data processors

To provide the service we share strictly necessary data with the following providers, all with GDPR-equivalent protection guarantees:

7. International transfers

Some providers are based outside the EEA (e.g. Vercel, PostHog, Sentry, OpenAI). In all cases we have Standard Contractual Clauses (SCC) approved by the European Commission or a Data Processing Agreement (DPA).

8. Your rights

As a data subject you have the right to:

  • Access: know what data we process about you.
  • Rectification: correct inaccurate data.
  • Erasure ("right to be forgotten"): delete your data.
  • Restriction: temporarily stop processing.
  • Portability: receive your data in a structured format.
  • Objection: object to processing based on legitimate interest.

To exercise any of these rights, write to info@restaur.ai

9. Complaints to the supervisory authority

If you believe we process your data improperly, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es) or, if you are in Germany, with the BfDI (www.bfdi.bund.de).

10. Changes to this policy

We may update this policy. The date of the last update appears above. If changes are substantial, we will notify you by email or with a notice in the app.