Legal

Privacy Policy

What personal data WaiterSkip handles, why, and what you can do about it — in plain language.

Effective from [Effective date]

Draft.This document is a draft. Highlighted parts still need company details or a decision, and the text needs a legal review before it applies.

1. Who we are

WaiterSkip is operated by [Company legal name, e.g. WaiterSkip s. r. o.], [Registered office address], company ID [Company ID (IČO)] (“we”, “us”). For the personal data described in this policy we are the controller, except where section 4 says we act for a restaurant.

Questions about privacy, or requests about your data: [Privacy contact email, e.g. privacy@waiterskip.com]. Full company details are in the legal notice.

2. Who this policy is for

  • Restaurant owners and their staff who use the WaiterSkip dashboard;
  • Guests who order from a table using a WaiterSkip QR code;
  • Visitors of this website.

3. What we collect and why

DataWhy we need itLegal basis (GDPR)
Account data of owners and staff: first and last name, email, username, password (stored only as a salted hash — we can’t read it), role, which restaurants the person works at, whether the email is confirmed, whether an admin has activated the account, and whether they’ve seen the dashboard tour. Staff invitations: the email address a restaurant invites, the role, who sent it and when.To create and run accounts, let people sign in, and send account emails (confirmation, password reset, security notices, staff invitations and activation).Contract (Art. 6(1)(b)). For staff accounts a restaurant creates: legitimate interest in running the restaurant’s account (Art. 6(1)(f)).
Business data: business name, restaurants (name, address, phone number, opening hours and time zone, logo, cover photo, colours and fonts, welcome text), tables and their PINs, menu (categories, items, descriptions, allergens, prices, the optional cost of each dish, availability, photos), the menu’s language, and its automatic translations into the guest languages together with any translations you correct yourself.This is the content of your WaiterSkip account — needed to show your menu, in the guest’s language, and take orders. Menu texts are sent to our translation provider (section 7) when you save them; they contain no personal data. Uploaded photos are resized, and anything embedded in them (such as where a photo was taken) is removed.Contract (Art. 6(1)(b)).
Orders: table, ordered items with the choices and notes guests add, quantities, prices, times, order status, and calls for a waiter (reason, note, times). See section 4.To send orders to the restaurant’s staff, show guests their order and bill total, and give the restaurant its sales reports (which contain no guest details).Processed on behalf of the restaurant (see section 4).
Subscription data: plan, status, trial and billing dates, and Stripe customer/subscription IDs. Card details are typed into Stripe’s pages and never reach our servers; Stripe also collects billing name, address and email.To run the free trial and paid subscriptions, and to keep invoices.Contract (Art. 6(1)(b)); legal obligation to keep accounting records (Art. 6(1)(c)).
Technical data: IP address, browser, request times (server logs); short-lived security counters such as failed sign-in or PIN attempts; error reports when a page crashes (the error message, the page and the browser, with guest session codes removed).To deliver the site, keep it secure and stop brute-force attempts.Legitimate interest in a secure service (Art. 6(1)(f)).
Messages you send us (e.g. by email).To answer you.Legitimate interest (Art. 6(1)(f)) or contract.

We don’t sell personal data, and we don’t use it for advertising or profiling.

4. Guests ordering at a table

Guests don’t create an account and we don’t ask for their name, email or phone number. Ordering creates a random session code for the table (and a join code for others at the same table), and the order itself. Guests pay the restaurant directly; WaiterSkip doesn’t process guest payments.

We handle order data on behalf of the restaurant, which decides how its orders are used — the restaurant is the controller and we are its processor (Art. 28 GDPR), under our terms. Guests with questions about their orders should contact the restaurant; we’ll help the restaurant answer.

5. Emails we send

Only emails about your account: confirming your email address, password-reset links, and notices when your password or email changes. Stripe sends payment receipts and invoices. We don’t send marketing emails. [If you add a newsletter later, it needs separate consent and a mention here.]

6. Cookies and local storage

We only store what the app needs to work — no analytics, advertising or third-party tracking cookies:

  • staffToken cookie — keeps staff signed in (a session cookie; the sign-in itself expires after 12 hours).
  • Local storage in your browser — the staff sign-in, a guest’s current table session (so they can return to their order) and their basket for that visit (removed once the order is placed or the visit ends), the language a guest chose for the ordering pages, the language chosen for this website and the staff app, your light/dark theme choice, the restaurant’s look (so staff pages open already in its colours), whether notifications are muted, and whether you closed the trial reminder.
  • Session storage in your browser (cleared when the tab is closed) — where you are in the staff walkthrough, and which bill requests you’ve already acknowledged.

Because these are strictly necessary, we don’t ask for cookie consent. Stripe’s checkout and billing pages (on stripe.com) set their own cookies under Stripe’s privacy policy.

7. Service providers

These companies process personal data for us, under data-processing agreements:

ProviderWhat forWhere
[Hosting provider, e.g. Hetzner Online GmbH]Hosting the app, its database and backups[Data centre location, e.g. Germany / Finland (EU)]
Stripe Payments Europe, LimitedSubscription payments, card details, invoices and the billing portalIreland (EU); transfers to the US under the EU Standard Contractual Clauses / EU–US Data Privacy Framework
[Email provider, e.g. Postmark, Resend, Brevo or Amazon SES]Sending account emails (email confirmation, password reset, security notices)[Location / transfer safeguard]
Anthropic, PBCTranslating restaurants' menu texts (dish names, descriptions, choices, categories, welcome text) for guests — menu content only, no personal dataUSA; under the EU Standard Contractual Clauses / EU–US Data Privacy Framework [confirm Anthropic's current safeguard]
[Error monitoring, e.g. Sentry — only if enabled]Reports of unexpected errors in the app and API (sent without personal data)[Location / transfer safeguard]

Where data leaves the EU/EEA, we rely on an adequacy decision or the EU Standard Contractual Clauses. We may also disclose data when the law requires it.

8. How long we keep data

  • Account and business data (restaurants, menus, photos, tables, staff accounts): while the account exists. When the owner closes the account (Account → Close account), everything is deleted automatically 30 days later.
  • Accounts without a paid plan: if an account has had no paid plan for 12 months (for example a trial that was never continued), we email the owner, and delete the account 30 days later unless a plan is chosen.
  • Orders: part of the restaurant’s order history for as long as the restaurant’s account exists. Deleting a restaurant deletes its orders too.
  • Invoices and billing records: [10 years — as required by accounting law; confirm].
  • Password-reset and confirmation links: valid for 1 hour and 7 days; the records are deleted 30 days after they expire.
  • Staff invitations: the link is valid for 24 hours; the invitation (with the invited email address) is deleted 30 days after it was used, canceled or expired.
  • Server logs: [X days]. Security counters (failed attempts, email limits) are kept in memory for at most an hour.
  • Backups: taken nightly and kept for [14] days, then overwritten.

9. How we protect data

Connections are encrypted (HTTPS). Passwords are stored only as salted hashes. Each restaurant’s staff can only reach their own restaurant’s data. Sign-in attempts, table PINs and join codes are rate-limited, a staff member has one active sign-in at a time, and password-reset links are single-use and stored only as hashes. Data is backed up nightly.

10. Your rights

You can ask us to:

  • give you a copy of your personal data (access) or send it in a machine-readable format (portability);
  • correct it (you can also edit your profile in the app);
  • delete it, or restrict how we use it (account owners can also close the account themselves under Account → Close account);
  • stop processing based on legitimate interest (objection).

Email [Privacy contact email, e.g. privacy@waiterskip.com]. We’ll answer within one month. You can also complain to the data protection authority: [Data protection authority, e.g. Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava].

11. Children

The WaiterSkip dashboard is for businesses and not meant for children under 16. Guests of any age can order at a table without giving personal data.

12. Changes to this policy

We’ll post any update on this page with a new effective date, and email account owners about important changes before they take effect.