DocsData and privacy
Data and privacy
Servers in Germany, nothing passed on, counting only with consent.
Where the data sits
On servers in Germany. Orders, menus and guest data are not passed on to third parties and not used for advertising.
There is no resale of guest data, to anybody. That is the difference an ordering channel without a middleman makes: your guest's address belongs to you and to them.
The guest
orders, gives name and phone
The business
CONTROLLER
Flavoso
Processor
What is stored
- The order with its lines, time and amount
- Name, phone, e-mail, and for delivery the address
- Reservations
What is NOT stored
- Card numbers: only the payment provider knows those
- without consent: no statistics at all
- no IP address for the country: that comes from the time zone
Servers in the EU. Connections encrypted. Separated per business, at row level in the database.
A guest's access request goes to the BUSINESS, not to Flavoso. It is answered with the data export, and that sits in the dashboard.
Measuring
Without the visitor's consent nothing is measured, not even anonymously. Whoever agrees is counted: page views, where they came from, kind of device, country.
The country comes from the browser's time zone, not from the IP address. That is less precise, and in exchange it is not location data.
No Google Analytics runs alongside, and no other outside service either.
What the restaurant has to do itself
In law the ordering page belongs to the restaurant. The imprint and the privacy notice are therefore its own business, and Flavoso supplies building blocks for them that describe what happens technically on that page.
You enter both under Settings, Contact & legal, and both then appear as their own line at the foot of your ordering page. For each you can either enter the address of your own page, which becomes a link, or the text itself, which then opens in a window. As long as one of the two is missing, that line says so.
- Imprint: required by § 5 of the German Digital Services Act. Name, legal form, an address that can be served with process, phone and e-mail, plus register entry and VAT ID where they exist.
- Privacy notice: required by Art. 13 GDPR, because your ordering page collects names, phone numbers and delivery addresses. You are the controller for them, not Flavoso; there we are your processor.
- Terms: optional. Without them the law applies.
- Right of withdrawal: not your problem. There is none for prepared food (§ 312g(2) nos. 2 and 9 German Civil Code), and the ordering page says so by itself, in the guest's language.
- Allergens: required by Art. 14 of the Food Information Regulation, and BEFORE the order is sent. The ordering page shows them on the dish as soon as you have entered them in the menu.
Not a substitute for legal advice
The building blocks are a draft and not legal advice. If you want to be safe, have somebody who is allowed to do that look at them once.
And one special case that is easily missed: since 28 June 2025 the German Accessibility Strengthening Act applies to ordering systems too. Micro-enterprises (fewer than ten employees and at most two million euros in annual turnover) are exempt. Anyone above that checks the requirements for their own offering; Flavoso aligns its interfaces with WCAG 2.1 level AA anyway.
Who else is involved
A few features need service providers, and every one of them is named in the dashboard and in the privacy policy: the server operator in Germany, the payment provider for online payment, the SMS sender for SMS, Google for maps, address suggestions and reviews, and Google Gemini for the menu import and the AI help.
For the AI import the uploaded menu is processed, not stored permanently and not used for training.
Still unclear? Ask the assistant in the corner or write to us