01Who we are
AI Restaurants operates a loyalty and guest management platform for restaurants, including branded QR landing pages, automated messaging, visit tracking, coupons, feedback and campaign management.
AI Restaurants is controller for its own platform, account, billing, security and website data. For restaurant guest data processed through QR pages and guest workflows, AI Restaurants generally acts as processor under GDPR Art. 28 on behalf of the restaurant operator.
02Data we collect
- Owner and admin account data, restaurant profile data, subscription records, usage and support communications
- Guest names, email addresses, visit history, QR scan and form submission timestamps, rewards and redemption records
- Consent proof including timestamp, consent text version and country-level IP geolocation
- Technical data such as IP address, browser, operating system, referrer and secure session tokens
03How we use data
We use data to provide the platform, send transactional communications, enable consent-based loyalty and marketing messages for restaurants, improve and secure the service, meet legal obligations and respond to support requests. We do not sell personal data or use restaurant guest data for our own marketing without separate consent.
04Legal bases
- Contract performance for account management and platform delivery
- Legitimate interests for fraud prevention, platform security and aggregated service improvement
- Consent for guest data collection and marketing communications on QR landing pages
- Legal obligations such as tax, accounting and valid law-enforcement requests
05Data sharing
We share data only with processors required to operate the platform, such as database hosting, email delivery and application hosting providers. All processors are bound by GDPR-compliant processing agreements. Restaurant guest data is not shared with other restaurants, third-party advertisers or data brokers.
06Cookies and tracking
- Strictly necessary session cookies for dashboard authentication
- CSRF tokens to protect form submissions
- Local language preferences stored in the browser
We do not use advertising cookies, cross-site tracking pixels or Google Analytics.
07Retention
- Guest contact data remains active until deletion request, restaurant account closure or inactivity cleanup after 24 months
- Visit and redemption logs are retained for 24 months from last activity
- Owner account data is retained for the subscription term plus 90 days
- Audit logs are retained for 12 months, IP addresses are anonymized after 30 days and backups rotate after 30 days
08Security
- bcrypt password hashing, TLS transport encryption and encrypted database connections
- httpOnly, Secure, SameSite=Strict cookies
- CSRF protection, input validation, audit logging and restricted production access with MFA
Report security issues to security@ai-restaurants.de.
09Your rights
- Access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority
To exercise your rights, contact privacy@ai-restaurants.de. We respond within applicable legal deadlines.
10International transfers
We primarily process data in the EEA. Where a processor is outside the EEA, we use safeguards such as standard contractual clauses, adequacy decisions and supplementary technical measures.
11Children
The platform is not directed to people under 16. If you believe we accidentally processed child data, contact privacy@ai-restaurants.de and we will delete it promptly.
12Changes
We may update this policy when practices, technology or law change. Material changes are communicated to restaurant owners at least 14 days before they take effect.
13Contact
14Restaurant guest data and processing
When guests submit data through a restaurant QR landing page, the restaurant is generally the controller and AI Restaurants processes the data on documented instructions as processor.
Guest portal and rectification
In the guest portal, guests can view their guest profile, visits, rewards, and communication preferences. To protect reward integrity, birthday and phone number can be updated once through self-service. The right to rectification of inaccurate or incomplete personal data remains available at any time; requests can be sent to privacy@ai-restaurants.de. Email address changes require additional verification because the email address is used for secure guest access.
Restaurant operators enter into a data processing agreement under GDPR Art. 28. Copies can be requested at privacy@ai-restaurants.de.
