Privacy Policy
How RestroNivo collects, uses and protects personal data — for restaurants using the platform and for their guests.
Who we are
- RestroNivo is a product of Global (BD) IT Solution, the company that operates this service and is responsible for the personal data described in this policy. Contact: [email protected].
- RestroNivo is restaurant management software provided as a hosted service and, on request, for self-hosted installation. Where a restaurant uses RestroNivo to manage its own guests, that restaurant is the data controller and RestroNivo acts as its data processor. For account and billing data about the restaurant itself, RestroNivo is the controller.
What we collect
- Restaurant account data — business name, address, contact details, staff names, roles and login credentials.
- Guest data entered by the restaurant — name, phone number, email address, order history, loyalty balance, allergen and dietary notes, and delivery address where a delivery is placed.
- Transaction data — orders, payments, refunds and invoices, including the last four digits and card brand returned by the payment provider.
- Technical data — IP address, browser and device type, and timestamped audit records of actions taken in the system.
- We do not collect full payment card numbers. Card details are entered on the payment provider’s own hosted page and never reach our servers.
Why we use it
- To provide the service the restaurant has subscribed to — taking orders, printing tickets, managing stock, paying staff and producing reports.
- To send transactional messages a guest has asked for, such as an order confirmation or a delivery update.
- To send marketing messages only where the guest has opted in, and only through channels the restaurant has configured.
- To secure the service — rate limiting, fraud checks, and audit logs of who changed what.
- To meet legal obligations, including tax and fiscal invoicing rules in the countries where a restaurant operates.
Sub-processors
- Payment processing — Stripe, PayPal, Mollie, Moyasar, Telr, HyperPay, bKash, SSLCommerz and PayTabs, depending on which the restaurant enables.
- Messaging — Meta (WhatsApp Business), Twilio and email delivery providers, where configured.
- Artificial intelligence — Anthropic, for features such as menu extraction, campaign drafting and demand forecasting. Prompts may contain business data; they are not used to train third-party models.
- Image generation — Replicate, where a restaurant generates marketing imagery.
- Hosting and storage — our infrastructure provider, and object storage for uploaded files and backups.
Where data is held
- Data is stored on servers in the region selected for the deployment. Self-hosted installations keep all data on the restaurant’s own infrastructure, and in that case RestroNivo has no access to it.
- Where data is transferred outside its region of origin, that transfer relies on standard contractual clauses or an equivalent lawful mechanism.
How long we keep it
- Operational records are retained while the account is active and for 90 days after closure, after which they are deleted or irreversibly anonymised.
- Financial and fiscal records are retained for the period the applicable tax law requires — commonly six to ten years — and cannot be deleted earlier.
- Audit logs are retained for 12 months.
- Backups are retained for 30 days on a rolling basis.
Your rights
- You may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, and you may object to processing.
- Where a restaurant holds your data as a guest, address the request to that restaurant; we will assist them in answering it.
- Marketing messages can be stopped at any time, and stopping them never affects transactional messages about an order you placed.
- Requests can be sent to the contact address below and are answered within 30 days.
Security
- Access to the service requires authentication, and permissions are enforced per role and per outlet.
- Credentials are stored hashed. API credentials for payment and messaging providers are stored encrypted and are never returned to the browser in full.
- Traffic is encrypted in transit. Administrative access is logged.
- No system is perfectly secure; if a breach affects your data we will notify you and the relevant regulator as the law requires.
Changes
- We will post any change to this policy on this page and update the date above. Material changes affecting how personal data is used will be notified to account holders in advance.
Contact
- Questions about this policy, or a request concerning your data, can be sent to [email protected].