AI Restaurants ← Back to homepage
Legal

Privacy Policy

How AI Restaurants collects, processes and protects personal data for restaurants, platform users and guests.

Effective: 20 April 2026Last updated: 20 April 2026Version 1.0
This policy applies to restaurant owners, administrators and guests who interact with AI Restaurants public QR landing pages and platform workflows.

01Who we are

AI Restaurants operates a loyalty and guest management platform for restaurants, including branded QR landing pages, automated messaging, visit tracking, coupons, feedback and campaign management.

AI Restaurants is controller for its own platform, account, billing, security and website data. For restaurant guest data processed through QR pages and guest workflows, AI Restaurants generally acts as processor under GDPR Art. 28 on behalf of the restaurant operator.

02Data we collect

  • Owner and admin account data, restaurant profile data, subscription records, usage and support communications
  • Guest names, email addresses, visit history, QR scan and form submission timestamps, rewards and redemption records
  • Consent proof including timestamp, consent text version and country-level IP geolocation
  • Technical data such as IP address, browser, operating system, referrer and secure session tokens

03How we use data

We use data to provide the platform, send transactional communications, enable consent-based loyalty and marketing messages for restaurants, improve and secure the service, meet legal obligations and respond to support requests. We do not sell personal data or use restaurant guest data for our own marketing without separate consent.

04Legal bases

  • Contract performance for account management and platform delivery
  • Legitimate interests for fraud prevention, platform security and aggregated service improvement
  • Consent for guest data collection and marketing communications on QR landing pages
  • Legal obligations such as tax, accounting and valid law-enforcement requests

05Data sharing

We share data only with processors required to operate the platform, such as database hosting, email delivery and application hosting providers. All processors are bound by GDPR-compliant processing agreements. Restaurant guest data is not shared with other restaurants, third-party advertisers or data brokers.

06Cookies and tracking

  • Strictly necessary session cookies for dashboard authentication
  • CSRF tokens to protect form submissions
  • Local language preferences stored in the browser

We do not use advertising cookies, cross-site tracking pixels or Google Analytics.

07Retention

  • Guest contact data remains active until deletion request, restaurant account closure or inactivity cleanup after 24 months
  • Visit and redemption logs are retained for 24 months from last activity
  • Owner account data is retained for the subscription term plus 90 days
  • Audit logs are retained for 12 months, IP addresses are anonymized after 30 days and backups rotate after 30 days

08Security

  • bcrypt password hashing, TLS transport encryption and encrypted database connections
  • httpOnly, Secure, SameSite=Strict cookies
  • CSRF protection, input validation, audit logging and restricted production access with MFA

Report security issues to security@ai-restaurants.de.

09Your rights

  • Access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority

To exercise your rights, contact privacy@ai-restaurants.de. We respond within applicable legal deadlines.

10International transfers

We primarily process data in the EEA. Where a processor is outside the EEA, we use safeguards such as standard contractual clauses, adequacy decisions and supplementary technical measures.

11Children

The platform is not directed to people under 16. If you believe we accidentally processed child data, contact privacy@ai-restaurants.de and we will delete it promptly.

12Changes

We may update this policy when practices, technology or law change. Material changes are communicated to restaurant owners at least 14 days before they take effect.

13Contact

Privacy contact

Email: privacy@ai-restaurants.de

Subject: Use "PRIVACY REQUEST" for faster routing.

14Restaurant guest data and processing

When guests submit data through a restaurant QR landing page, the restaurant is generally the controller and AI Restaurants processes the data on documented instructions as processor.

Guest portal and rectification

In the guest portal, guests can view their guest profile, visits, rewards, and communication preferences. To protect reward integrity, birthday and phone number can be updated once through self-service. The right to rectification of inaccurate or incomplete personal data remains available at any time; requests can be sent to privacy@ai-restaurants.de. Email address changes require additional verification because the email address is used for secure guest access.

Restaurant operators enter into a data processing agreement under GDPR Art. 28. Copies can be requested at privacy@ai-restaurants.de.