Tavolino

Privacy policy

Tavolino (tavolino.menu) processes personal data in compliance with Regulation (EU) 2016/679 (GDPR). Data controller: Tavolino. Contact: privacy@tavolino.menu.

Data we process

Account: name, email and (encrypted) password of registered restaurateurs. Content: the menus, photos and venue information you publish. Orders: shipping address for prints; payments are handled by Stripe and we never store card data. Statistics: QR scans are logged in anonymous, aggregate form (country, device type and browser language), with no IP addresses or personal identifiers of your guests.

Purpose and legal basis

We process data to provide the service (contract performance), for invoicing (legal obligation) and for service communications (legitimate interest).

Retention and your rights

Data is retained while the account is active. You can request access, rectification, deletion and portability at privacy@tavolino.menu. Data is hosted on EU/US infrastructure with adequate safeguards (Vercel, Neon, Stripe).

Cookies

We only use technical cookies, so no consent banner is required. Public menu pages set no cookies at all. The dashboard uses the session cookie required for authentication and a cookie storing your interface language, written only when you change it explicitly. We use no profiling or third-party advertising cookies.