Privacy Policy
Last updated: 22 August 2026
Introduction
Restocarte is a digital menu and ordering platform operated by Infinity Curve LLC (“we”, “our”, or “us”), a company registered in Georgia. Paid Restocarte subscriptions are sold and billed by Paddle.com Market Ltd, which is the merchant of record for those charges and handles your payment details.
This policy explains what personal data we collect, why, who we share it with, and what rights you have. It covers both the businesses that use Restocarte and the guests who view a menu or place an order through it.
Our Role: Controller and Processor
For the account data of the businesses that use Restocarte — the owner's name and email, subscription and billing status, sign-in records and usage of the dashboard — we are the data controller. This policy describes how we handle it.
For everything a venue puts into the platform and everything its guests send through it — menu content, order details, guest contact details and open tabs — the venue is the controller and we act as its processor. We hold that data on the venue's behalf and act on its instructions; we do not use it for our own purposes, and we never sell it or use it for advertising.
If you are a guest who ordered from a venue using Restocarte and you want your data corrected or removed, contact that venue first — it decides what happens to it. You can also contact us at [email protected] and we will pass the request on or act on it where we are permitted to.
Information We Collect
We collect and process the following:
- Account information: your name, email address, profile image and language preference, and your subscription and trial status.
- Venue and menu content: your venue name, slug, logo, branding, currency and the menu itself — categories, items, prices, images, options and allergen or dietary tags.
- Order information: when a guest places an order, the items ordered, table number, notes, amounts, and any email address or phone number the guest provides so the venue can reach them. Card payments are handled by Stripe; we store the payment reference, not card numbers.
- Menu analytics: page views of public menus, including the page path, referrer, browser user-agent, and a truncated one-way hash of the visitor's IP address computed with a salt that rotates daily. The hash gives a venue a rough count of distinct visitors on a given day and cannot be reversed into an IP address or linked across days.
- Push notification tokens: if you install the Restocarte mobile app and allow notifications, the device token and platform, so we can alert you to new orders.
- Third-party sign-in: if you sign in with Google or Facebook, we receive your name, email address and profile image from that provider.
- Messages you send us: the name, email address and message content you submit through our contact form or by emailing us.
We do not use automated decision-making or profiling that produces legal effects, and we do not ask for special-category data.
How We Use Your Information
We use personal data for the following purposes:
- Operating, maintaining and securing the Restocarte platform
- Delivering orders to the venue by email and push notification, and processing payments where the venue has enabled them
- Sending sign-in links, service updates and administrative messages
- Answering your questions and providing support
- Managing subscriptions, trials, invoices and platform fees
- Understanding how the platform is used so we can improve it
- Preventing abuse, fraud and spam, including rate-limiting sign-in and order requests
- Meeting our legal, accounting and tax obligations
Where the GDPR or a comparable law applies, we rely on: performance of a contract (operating your account and delivering orders), our legitimate interests (security, abuse prevention, and improving the platform), your consent (advertising cookies and optional push notifications), and legal obligation (keeping financial records).
Who We Share Data With
We do not sell your personal information.
We share data only with the providers needed to run the Service, and only what each one needs:
| Recipient | Purpose |
|---|---|
| Hosting and infrastructure | Our application servers, database and image storage, plus the CDN and reverse proxy that serve traffic. Connection data such as IP addresses is processed here. |
| Backblaze | Off-site backups of the database and uploaded images, held in the EU Central region. These contain a copy of the same account, menu and order data as the live system. |
| Paddle | Merchant of record for Restocarte subscriptions. Receives your name, email and billing details in order to charge and invoice you, and handles your card data. |
| Stripe | Processes guest card payments for venues that enable them, and runs identity and business verification for the venue's connected account. Receives the order amount, currency, the guest's email where provided, and the venue's verification details. |
| Resend | Sends transactional email — sign-in links, order notifications to venues and contact-form messages. Receives the recipient address and message content. |
| Firebase Cloud Messaging (Google) | Delivers new-order push notifications to the Restocarte mobile app, and forwards to Apple's push service on iOS. Receives the device token and notification content. |
| Sentry | Error and performance monitoring. Receives technical diagnostics about failed requests, which may incidentally include a user identifier or IP address. |
| Meta | The Meta Pixel on our marketing pages measures the effectiveness of our advertising and shares page-visit data with Meta. It does not run on venue menus or in the dashboard. |
| Legal and regulatory authorities | Where we are required to disclose data to comply with applicable law. |
All providers are bound to handle data securely and only on our instructions, other than Paddle and Stripe, which act as controllers in their own right for the payment data they hold.
How Long We Keep Data
We keep personal data only as long as it is needed for the purpose it was collected for:
- Account data — for as long as your account is open, and for 30 days after you close it.
- Menu and venue content — until you delete it, or 30 days after your account closes.
- Orders and tabs — retained for the venue's records and, where a payment was taken, for as long as tax and accounting law requires us to keep records of money received.
- Menu page views — retained in aggregate; the daily-rotating hash means individual visits cannot be linked across days at any point.
- Error diagnostics and security logs — retained for a short period, typically no more than 90 days.
- Backups — copies of the above are held off-site in the EU on a 7-day rotation, so data can persist there for up to 7 days after it is gone from the live system.
Your Rights
Depending on where you are, you may have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Have your data deleted, in the circumstances the law provides for
- Restrict or object to certain processing
- Receive a copy of your data in a portable format
- Withdraw consent where you previously gave it
Deleting your account
To close your account and have your data deleted, email us at [email protected] from the address on the account. We will confirm the request, delete your account, menus and images within 30 days, and tell you when it is done.
We keep records of payments received, without profile details attached, where tax and accounting law requires it. Everything else — your profile, menu content, images and analytics — is deleted. Deletion takes effect on the live system straight away; copies held in off-site backups are removed within 7 days.
Rights Under Specific Laws
Which law applies depends on where you are. The following are relevant to Restocarte:
- European Economic Area and United Kingdom — the GDPR and UK GDPR give you the rights above and the right to complain to your local supervisory authority.
- Switzerland — the Federal Act on Data Protection (FADP) gives you the rights above and the right to complain to the Federal Data Protection and Information Commissioner (FDPIC).
- South Africa — the Protection of Personal Information Act (POPIA) gives you the rights above and the right to complain to the Information Regulator.
- Georgia — the Law of Georgia on Personal Data Protection applies to us directly, as Infinity Curve LLC is established there, and gives you the right to complain to the Personal Data Protection Service.
- Türkiye — the Personal Data Protection Law (KVKK) gives you the right to learn whether your data is processed, to request correction or erasure, and to complain to the Personal Data Protection Authority.
- United States — where state privacy laws such as California's apply, you may request access to or deletion of your personal information and appeal a refusal. We do not sell personal information.
- Elsewhere — comparable rights may apply under your local law, and we will honour them where they do.
To exercise any of these rights, contact us using the details below.
Data Security
We apply technical and organisational measures appropriate to the risk, including:
- Encryption in transit (HTTPS everywhere, with HSTS and a strict Content Security Policy)
- Access controls that scope every menu, order and image to the venue that owns it, checked on every request
- Keeping card data out of our systems entirely — Paddle and Stripe handle it on their own PCI-compliant infrastructure
- Rate limiting on sign-in, ordering and contact endpoints, plus error and security monitoring
No system can guarantee absolute security, but we work continuously to maintain and strengthen these protections.
Cookies and Similar Technologies
Restocarte uses a small number of cookies:
- Essential — the session cookie that keeps you signed in, set when you sign in and removed when you sign out.
- Preferences — your chosen language, so the site opens in it next time.
- Security — a CSRF token that protects sign-in and form submissions from cross-site abuse.
- Analytics — menu page views are recorded on our own servers without setting a cookie or any cross-site identifier.
- Advertising — the Meta Pixel on our marketing pages, which sets cookies readable by Meta. It is loaded only if you accept, and never runs on venue menus or in the dashboard.
Advertising cookies are off until you accept them in the banner. You can change or withdraw that choice at any time from "Cookie settings" in the footer, and you can control or clear cookies through your browser settings. Blocking essential cookies will prevent you from signing in.
International Data Transfers
Restocarte is operated by Infinity Curve LLC in Georgia, and the platform, its database and its image storage run on our own servers in Tbilisi, Georgia — that is where account, menu and order data is stored. Off-site backups are held with Backblaze in its EU Central region, so a second copy of that data resides in the European Union. Our providers operate elsewhere: subscription billing is handled by Paddle in the United Kingdom, guest payments by Stripe, email by Resend, push notifications by Google, and error monitoring by Sentry, all of which may process data in the European Union, the United States or other countries. This means personal data may be transferred outside the country where you live, including to countries whose data protection laws differ from your own. Where we transfer personal data internationally we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an equivalent mechanism under the applicable law, and we transfer only what is needed for the purpose.
Children
Restocarte is a business tool and is not directed at children. We do not knowingly collect personal data from children. If a guest places an order and provides contact details, we treat those details as belonging to the person placing the order on the venue's behalf. If you believe a child's data has reached us, contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. Updated versions are posted on this page with a revised “Last updated” date, and we will notify account holders by email when changes are material.
Contact Us
For any question about this policy or how your data is handled, contact us at [email protected].