This policy explains what personal data Better Menu handles, why, who else sees it, and what you can ask us to do about it. It is written for two different readers: the business owners who use the platform, and the guests who book a table or read a menu through it.
Last updated:
Better Menu is operated by [Ονοματεπώνυμο / Full legal name], a sole trader established in Greece. For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Greek Law 4624/2019, that is the data controller for the processing described in this policy — except where section 3 says otherwise.
We have not appointed a Data Protection Officer, because the scale and nature of our processing does not require one under Article 37 GDPR. Every request under this policy goes to the address above and is answered by us directly.
It covers the Better Menu platform: the marketing site, the owner dashboard, and the public pages we serve for each business — its profile, its digital menu, its booking form and the reservation page a guest is sent after a booking is accepted.
It does not cover what a business does with your data outside our platform, or any other website it links to.
This distinction decides who you send a request to, so it comes before everything else.
Your name, email address, a hashed password (we never store the password itself), whether your email is verified, and — if you turn it on — a two-factor secret and backup codes. Legal basis: performance of the contract between us, Article 6(1)(b) GDPR. Without them there is no account.
For each active session: an IP address, the browser's user-agent string, and the times the session was created and last used. We use it to keep you signed in, to show you your own active sessions, to rate-limit abuse, and to investigate suspicious sign-ins. Legal basis: our legitimate interest in the security of the service, Article 6(1)(f) GDPR.
The name, address, opening hours, description, social links, logo, banner, menu and photographs you enter for your business. This is published deliberately — it is your public page. Anything personal you put into it (a photograph of your staff, a mobile number in your contact details) becomes public because you chose to publish it. Legal basis: performance of the contract.
A Stripe customer identifier, your plan, subscription status and renewal dates, and the invoices Stripe issues. Card numbers are entered on Stripe's own hosted fields and never reach our servers. Legal basis: performance of the contract, and — for invoices — compliance with a legal obligation, Article 6(1)(c) GDPR.
If you order printed items from us — table stands, stickers, QR codes — we store what you ordered, how many, the price at the time, and the note you wrote telling us which codes to print. Nothing is charged in the app: we contact you afterwards to arrange payment and delivery, and to do that we look at the email on your account and the phone number and address on the business the order was placed for. Legal basis: performance of the contract of sale, Article 6(1)(b) GDPR, and compliance with a legal obligation for the resulting invoice.
When a guest books, we store the name, phone number, party size, date and time, any note they add, and later whether they arrived. We process it as the business's processor (section 3). The business's legal basis is its own: normally the steps taken at the guest's request before a contract, Article 6(1)(b) GDPR.
We do not send the guest anything ourselves. When a booking is accepted or declined, the owner's own phone opens their SMS or Viber app with a suggested message — the message is sent from the owner's number, by the owner, through their own carrier or Viber account.
The category and text of your message, and the email address or phone number you ask us to reply on. Legal basis: performance of the contract and our legitimate interest in supporting and improving the service.
If you write to us through the contact form on our website, we store your name and email address and — if you give them — your phone number, business name and message, along with whether you asked a question or for a demo and the language of the page you sent it from. We use them only to reply to you. Legal basis: steps taken at your request before entering into a contract, Article 6(1)(b) GDPR.
Our email is transactional only: verifying your address, resetting your password, billing notices, and material changes to the service or these policies. We do not send marketing email and we do not pass your address to anyone who does. Legal basis: performance of the contract, and compliance with a legal obligation for the notices we owe you.
If you switch on notifications for new reservation requests, we store, for each device you switch them on for, the address your browser's push service gave that device, the keys that encrypt what we send to it, and the language to write in. Each new request is then sent through that service — Google, Apple, Mozilla or Microsoft, depending on your browser — encrypted so that only your device can read it; the service learns only that a message went to that address. Switch notifications off or sign out on that device, and the record is deleted. Legal basis: performance of the contract, at your request, Article 6(1)(b) GDPR.
Sign-in, sign-up, password reset, the public booking form and the contact form are protected by Cloudflare Turnstile. Cloudflare receives the visitor's IP address and signals from the browser in order to tell a person from a script. We receive only the pass or fail. Legal basis: our legitimate interest in preventing abuse.
If you use the background-removal tool on a menu photograph, that image is sent to fal.ai to be processed and returned. Do not use it on photographs of identifiable people. Legal basis: performance of the contract, at your request.
Business owners see how their public page and menu are doing. We record one row per visit, holding the page viewed, a device class (mobile, tablet or desktop), where the visit came from (a QR code, a social app, or direct), the menu language read, which products were opened, and — when the visit began by scanning a code printed on a particular table — which table that was.
Nothing is stored on your device for it and nothing is read from it — no cookie, no identifier, nothing left behind in the browser. That is why these pages carry no consent banner: there is nothing on your device to consent to.
Counting one guest once instead of once per reload still needs us to tell one reader from another for a few hours. We do that from the request rather than from your browser: your IP address and browser user-agent are combined with the business and the page, and immediately turned into a one-way keyed digest. The digest is held for four hours and then gone; the address and the user-agent themselves are never written down, and the visit row holds neither. Legal basis for that brief use of the address: our legitimate interest, and the business's, in knowing whether the menu is being read, Article 6(1)(f) GDPR.
We hold nothing that links a visit to a person, and no identifier travels between businesses or between sites. One honest caveat: a business that knows who was sitting at a table at a given time can put that together with a visit recorded from that table's code. The business already holds that knowledge — from its own reservation book — and we do not.
Separately, the public pages report anonymous loading-speed measurements to Vercel Speed Insights. Those carry no cookie and no identifier either.
Under Directive 2002/58/EC and Greek Law 3471/2006, consent is needed for anything stored on your device that is not strictly necessary for a service you asked for. We store only the following, and each one is either strictly necessary or a preference you set yourself — so no consent banner appears, and there is no advertising, profiling or cross-site tracking to consent to.
| What | Why | How long |
|---|---|---|
| Session cookie | Keeps you signed in. Strictly necessary. | Until the session expires or you sign out |
| locale | The language you picked in the switcher. A preference. | One year |
| Theme | Light or dark, kept in your browser's local storage. A preference. | Until you clear your browser data |
| Cloudflare Turnstile | Bot check on the forms. Strictly necessary for security. | Set by Cloudflare |
The public-page statistics in section 5 are deliberately absent from this list: they store nothing on your device at all. If you have read that measuring visitors normally means a cookie and a consent banner, that is why there is neither here.
We do not sell personal data and we do not share it for anyone else's marketing. It is disclosed only to the providers below, each under a written processing agreement that binds them to our instructions, and to public authorities where the law requires it.
| Provider | What for | Where |
|---|---|---|
| Vercel Inc. | Hosting and delivery of the application | USA |
| Supabase Inc. | Database and storage of images and video | EU (Germany) |
| Redis Ltd. | Session storage and rate limiting | EU (Germany) |
| Stripe Payments Europe, Ltd. | Payments, subscriptions and invoices | EU / EEA |
| Cloudflare, Inc. | Bot protection on the forms (Turnstile) | USA |
| Resend, Inc. | Transactional email (verification, password reset) | USA |
| Google Ireland Ltd. / Google LLC | Reviews from a business's Google listing, and the reviewer photographs shown beside them | EU / USA |
| CARTO (CARTO DB Inc.) | Map tiles for the location shown on a public page | USA |
| fal.ai (Features and Labels, Inc.) | Background removal on menu photographs, on request | USA |
Two things on a public page are fetched from somewhere else, and both are worth naming because a visitor cannot see them happening. If a business has connected its Google listing, we fetch that listing's reviews from Google when the page is rendered — that request comes from our server and identifies the business, not you. The reviewers' profile photographs beside those reviews, however, are loaded by your own browser directly from Google, and the map on the location card is loaded the same way from CARTO. Those two requests carry your IP address and browser user-agent to Google and CARTO respectively, as any image or map on any website does.
We would also disclose data if we were legally compelled to, or if the business were transferred to another owner — in which case we would tell you before it happened and you would be free to close your account first.
Our database, file storage and session storage sit in Germany, and the application itself runs in Frankfurt, so the bulk of the data never leaves the EEA. Some of the providers in the table above are established in the United States. Where data reaches them, the transfer rests on the European Commission's Standard Contractual Clauses under Article 46(2)(c) GDPR (Implementing Decision (EU) 2021/914), or on the provider's certification under the EU–US Data Privacy Framework where it holds one (adequacy decision of 10 July 2023). You may ask us for a copy of the safeguards that apply to a particular provider.
Under Articles 15 to 22 GDPR you may ask us for:
Write to support@better-menu.gr. We answer within one month, and tell you in advance if a complex request needs up to two more. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to confirm who you are, but only enough to be sure we are not handing your data to someone else.
You can also complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), 1–3 Kifisias Avenue, 115 23 Athens, tel. +30 210 6475600, contact@dpa.gr, www.dpa.gr — or to the authority of the EU country you live or work in. You may also go to court under Article 79 GDPR. We would rather you came to us first, but you are not obliged to.
Traffic is encrypted in transit. Passwords are stored as Argon2 hashes, never in a form we could read. Two-factor authentication is available on every account and we recommend turning it on. Sensitive actions — changing your email, deleting your account — require a recent sign-in.
On our side, access to production data is limited to the operator and to any administrator the operator has appointed — today that is the operator alone. An administrator can open a support view of your business, and can sign in as your account in order to reproduce a problem you have reported. We do that to fix something, not to read your data, and every such session is an ordinary session of yours that expires within the hour. If you would rather we did not, say so when you report a problem and we will work from your description instead.
If a breach were ever likely to put your rights at risk, we would notify the Hellenic Data Protection Authority within 72 hours and tell you without undue delay, as Articles 33 and 34 GDPR require.
The platform is a tool for businesses and is not directed at children. We do not knowingly create accounts for anyone under 18. A guest booking a table gives their name and phone number to the business, not to us; if you believe a child's data has reached us, write and we will delete it.
There is none. Nothing on the platform makes a decision with legal or similarly significant effects about you without a person involved. The bot check on the forms is a gate on a single submission, not a decision about you, and a failed check can be retried.
We update this page when what we do changes. The date at the top always says when. If a change materially affects how we handle your data, we will tell account holders by email or in the dashboard before it takes effect.
Questions about this policy, or a request under section 10: support@better-menu.gr. The terms you agree to when you use the platform are in the Terms of Service.