Legal
Privacy Policy
Version 2026-10-01 · last updated 1 October 2026
How Orevyo handles information about restaurant accounts, restaurant guests and website visitors. We collect as little as we can and use no tracking.
Some business details in this document are still being completed; they are marked in orange. The rest describes how Orevyo works today.
1. Who we are
Orevyo is software that restaurants use to publish digital menus and, on the NFC Table Ordering plan, to receive orders from their tables. It is operated by [operator's legal name: to be completed] ([legal form: to be completed], registration number [registration number: to be completed], registered address [registered address: to be completed]), referred to here as “Orevyo”, “we” or “us”.
For privacy questions, contact [privacy email address: to be completed].
Orevyo is not the restaurant. Each restaurant decides what is on its menu, prepares and serves the food, and is responsible for its own service and its own handling of personal information.
2. Whose information this covers
- Restaurant account users: owners and staff who sign in to the Partner Portal. For their accounts and the restaurant content they manage, Orevyo decides how information is used.
- Restaurant guests: people who open a restaurant's menu or order at a table. Guests don't need an account. When a guest sends an order or a request, we process it to deliver it to that restaurant, on the restaurant's behalf. Questions about how a restaurant uses an order are best sent to the restaurant.
- Website visitors and enquirers: people who browse orevyo.com, try the demo or the menu builder, or contact us.
3. What we collect
Restaurant accounts
- Name, email address and password. Passwords are stored only as a secure hash by our sign-in provider.
- Which restaurants you belong to and your role (owner or cashier), staff invitations you send or receive.
- The date and version of the Terms of Service you accepted.
- Sign-in records kept by our sign-in provider for security, which can include your IP address and browser details.
Restaurant content
- Restaurant name, web address, description, opening hours, branding, logo and photos.
- Menus: categories, dishes, prices, choices, translations, allergen notes and sold-out status.
- Tables and NFC table-card records, plan and subscription status.
Restaurant guests
- Viewing a menu needs no personal information. Your language choice is applied in your browser.
- Table sessions (NFC Table Ordering): when you tap a table's NFC card, we check the card and create a temporary ordering session for that table. Your browser keeps a random session code in a cookie; we store only a scrambled (hashed) form of it, with the table and an expiry time.
- Orders and requests: the dishes, choices, quantities, any note you type, the table, the time and the total; and requests such as help, an allergy question or the bill. Please don't put personal or health details in notes; speak to staff instead.
- We don't ask guests for names, phone numbers or payment details, and Orevyo does not take payment for meals.
Enquiries
- What you send through the contact form: name, email, restaurant name, table count, plan of interest and your message.
Menu builder (before you have an account)
- A menu you build without an account is saved only in your own browser. It is sent to us only when you create an account and choose to add it to your restaurant.
Security and technical records
- Our hosting provider processes IP addresses and request details to deliver the website and protect it from abuse, and keeps request logs for a short period.
- We record security events such as rejected NFC card taps (card and restaurant, not your IP address).
Subscriptions and payments
- Paid subscriptions are not switched on yet. When they are, payments will be handled by Stripe; we will keep the subscription status and Stripe's customer and subscription references, never full card numbers.
4. Why we use it, and our legal basis
- Providing the service (accounts, menus, publishing, table sessions, delivering orders and requests to the restaurant): necessary for our contract with the restaurant account holder. For guests, the restaurant relies on its own basis; we act on its behalf.
- Security and preventing misuse (sign-in records, logs, NFC card checks): our legitimate interest in keeping the service and its users safe.
- Answering enquiries: steps you asked us to take before a contract, or our legitimate interest in replying.
- Billing, tax and accounting (once subscriptions start): our contract and our legal obligations.
- Records of accepted Terms: our legitimate interest in showing which terms applied.
5. Cookies and browser storage
We use only what is strictly necessary for the service to work, so there is no cookie consent banner. We don't use analytics, advertising or tracking cookies.
- Sign-in cookies (names starting “sb-”): keep restaurant users signed in.
- Table session cookie (names starting “ogs_”): lets a guest order for the table whose NFC card they tapped, until the session ends.
- Theme preference (browser storage): remembers Light or Dark if you choose one.
- Menu introduction (browser storage): remembers that a guest has seen the short introduction.
- Menu builder draft (browser storage): keeps the menu you are building on this device.
If we ever add anything that is not strictly necessary, we will ask first and let you change your choice later.
7. International transfers
Our main data storage is in the European Union. Some of our providers are based in the United States or use staff and systems outside the EU, for example for support or global content delivery. Where personal information leaves the European Economic Area, we rely on the safeguards in our providers' data processing agreements [confirm the transfer safeguards in each provider's agreement: to be completed].
8. How long we keep it
- Accounts and restaurant content: [retention period for accounts: to be completed].
- Orders and requests: [retention period for orders: to be completed].
- Table sessions stop working when they expire (by default 60 minutes, set by each restaurant) or when staff end them.
- Contact enquiries: [retention period for enquiries: to be completed].
- Billing records: [retention period for billing records: to be completed].
- Menu builder drafts stay in your browser until you delete them or clear your browser's storage.
9. Security
Connections are encrypted (HTTPS). Access to restaurant data is limited to that restaurant's own accounts and enforced in the database itself. Session codes and invitation links are stored only in hashed form, and NFC table cards are checked cryptographically on our server. No system is perfectly secure; if a breach affects your information, we will inform you and the authorities where the law requires.
10. Your rights
Under data protection law (including the GDPR) you can ask us to: access your information; correct it; delete it; restrict or object to how we use it; and receive information you gave us in a portable format. Where we rely on your consent, you can withdraw it at any time.
Write to [privacy email address: to be completed]. We may need to confirm who you are. Guests asking about an order may also contact the restaurant directly.
You can complain to a data protection authority, in particular where you live or work. Our lead authority is [supervisory authority: to be completed].
11. Children
Partner Portal accounts are for adults acting for a business. Anyone can view a restaurant's menu without giving personal information, and we don't knowingly collect personal information from children.
12. Changes
If we change this policy, we will update the version date above and, for significant changes, tell account holders by email or in the Partner Portal.
13. Contact
[operator's legal name: to be completed], [registered address: to be completed]. Privacy: [privacy email address: to be completed]. You can also use the contact form.

