Privacy Policy
1. Overview
This privacy policy explains how matbord (“we”, “us”) collects, uses, and protects your personal data when you use our website and services. We are based in Germany and primarily comply with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Where applicable, we also honor the rights granted by the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and other regional privacy laws.
2. Responsible party
Erika Willis
c/o flexdienst – #20489
Kurt-Schumacher-Straße 76
67663 Kaiserslautern, Germany
Email: [email protected]
3. Data we collect
When you use matbord, we may collect:
- Account information (name, email, restaurant name)
- Menu content you upload (photos, text, prices)
- Usage data (pages visited, features used, timestamps)
- Payment information (processed by Stripe, we don’t store card details)
- Technical data (IP address, browser type, device information)
4. How we use your data
- Providing and improving the matbord service
- Processing menu uploads and AI text extraction
- Managing your account and subscription
- Sending service-related communications
- Analyzing usage to improve the product
5. Third-party services
We use the following third-party services:
- Hetzner — Application hosting (Germany, EU)
- Supabase — Database, file storage and authentication (EU region)
- Cloudflare — CDN, DNS and security (US, EU Standard Contractual Clauses in place)
- Upstash — Cache for rate limiting and abuse prevention; processes IP addresses (EU region)
- OpenRouter — Routing layer for the AI models used for menu text extraction, text correction, translations and photo checks (US, EU Standard Contractual Clauses in place)
- OpenAI — Fallback for menu text extraction and text correction (US, EU Standard Contractual Clauses in place)
- Google Gemini — Menu text extraction, exclusively via OpenRouter (US, EU Standard Contractual Clauses in place)
- Anthropic Claude — Generated SEO content for restaurant area pages (US, EU Standard Contractual Clauses in place)
- fal.ai — Image enhancement and background removal for dish photos (US)
- Stripe — Payment processing (Ireland/US, EU Standard Contractual Clauses in place)
- Resend — Transactional email delivery (US, EU Standard Contractual Clauses in place)
- PostHog — Cookieless product analytics (EU region, anonymous unless signed in)
- Sentry — Error logging for fault diagnosis (EU region; account and organisation data is stored in the US, EU Standard Contractual Clauses in place)
- Mapbox — Address autocomplete for delivery orders (US, EU Standard Contractual Clauses in place)
- Google Firebase Cloud Messaging — Push notifications (US, EU Standard Contractual Clauses in place)
- fiskaly — Technical security device (TSE) for point-of-sale receipts (Germany/Austria, EU)
- 360dialog — Sending and receiving WhatsApp messages (Germany, EU)
6. Cookies
We only use strictly necessary cookies for authentication and session management. These are required for the service to function and cannot be disabled. We do not use any analytics or tracking cookies. Our website analytics are fully cookieless — all data collected is 100% anonymous unless you are signed in to your account.
7. Data retention
Account data is retained while your account is active. Menu content is stored as long as you use the service. After account deletion, your data is removed within 30 days. Payment records are retained as required by tax law (typically 10 years in Germany).
8. Your rights
Depending on your jurisdiction, you have rights regarding your personal data. These include:
- Access your personal data
- Correct inaccurate data
- Delete your data (“right to be forgotten” / right to delete)
- Export your data in a portable format
- Object to or restrict data processing
- Withdraw consent at any time
- Non-discrimination for exercising your rights
- Lodge a complaint with a supervisory authority
To exercise any of these rights, email us at [email protected]. We respond within 30 days under the GDPR (extendable to 60 days for complex requests) and within 45 days under the CCPA/CPRA (extendable to 90 days).
9. International data transfers
Some of our service providers (Stripe, Anthropic, Google, OpenAI, Cloudflare) are based in the United States. When personal data is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses and supplementary safeguards to ensure your data receives an equivalent level of protection. EU-based providers (Supabase EU region, PostHog EU region, Hetzner) process data within the EU.
10. California residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, use, and disclose
- Right to delete personal information we have collected
- Right to correct inaccurate personal information
- Right to limit the use of sensitive personal information
- Right to opt out of the sale or sharing of personal information
- Right to non-discrimination for exercising your rights
We do not sell or share your personal information for cross-context behavioral advertising or any other purpose, and we have not done so in the preceding 12 months. We also do not knowingly collect or sell the personal information of minors under 16. To exercise your CCPA/CPRA rights, email us at [email protected].
11. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. We will notify you by email of significant changes.
Last updated: April 2026