Privacy policy
1. Data controller
The data controller for the DigitalMeni platform is DigitalCentar (contact: support@digitalcentar.com). This policy explains how we process personal data when you use our website, apply for an account, subscribe or operate your restaurant admin panel.
2. Personal data we collect
- Account data — restaurant name, contact person, email, phone, username, city, country and business details you provide during registration.
- Billing data — subscription status, plan, invoices and payment metadata processed by Stripe. We do not store full card numbers on our servers.
- Menu and business content — categories, products, images, prices, operators/waiters and translations you enter in the admin panel.
- Order data — table number, waiter, ordered items, amounts and timestamps when guests place orders through QR menus.
- Technical data — IP address, browser type, device information, server logs, error reports and anonymous usage beacons.
- Communications — support emails and messages you send to us.
3. Purposes and legal basis (GDPR)
- Providing and operating the service — performance of a contract (Art. 6(1)(b) GDPR).
- Subscription billing and accounting — contract and legal obligation (Art. 6(1)(b) and (c)).
- Security, fraud prevention and abuse detection — legitimate interests (Art. 6(1)(f)).
- Product improvement and anonymous usage statistics — legitimate interests (Art. 6(1)(f)).
- Marketing emails — consent where required (Art. 6(1)(a)).
- Cookie consent records — legitimate interest / consent depending on cookie type.
4. How long we keep data
Account and menu data are retained while your subscription is active and for a reasonable period afterward to handle support, disputes and legal obligations. Billing records may be kept longer where tax or accounting law requires. You may request deletion after account closure, subject to mandatory retention periods.
5. Processors and international transfers
We use trusted processors for hosting, email delivery, payment processing (Stripe) and infrastructure. Some processors may process data outside the European Economic Area. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
6. Sharing with third parties
We do not sell your personal data. We share data only with processors acting on our instructions, when required by law, or to protect rights and safety. Restaurant guests' order data is processed on behalf of the restaurant; the restaurant is typically the controller for guest-facing processing and we act as processor.
7. Your rights
Under GDPR you may have the right to access, rectify, erase, restrict processing, data portability and to object to processing based on legitimate interests. You may withdraw consent at any time where processing is consent-based. Contact support@digitalcentar.com. You may lodge a complaint with your local supervisory authority.
8. Security
We apply technical and organizational measures appropriate to the risk, including access controls, encryption in transit and secure payment handling via Stripe. No method of transmission over the internet is 100% secure.
9. Children
The service is not directed at children. Account holders must be adults acting on behalf of a business.
10. Changes to this policy
We may update this policy from time to time. The “last updated” date at the bottom indicates the latest revision. Material changes will be communicated where appropriate.
Last updated 2026.