Krypton Technology (“we”, “us”) operates SmartMenu and is the data controller for personal data processed through the platform. This policy explains what we collect, why, and your rights under the GDPR (EU 2016/679) and Irish data-protection law.
1. Data we collect
- Restaurant account data: business name, address, contact, logo, menu content.
- Payment data: billing details processed by Stripe — we never store full card numbers.
- Customer order data: table number, items ordered, totals, timestamps.
- Technical data: IP address, device and browser data, basic analytics.
2. How we use data
- To operate the SmartMenu service and process orders.
- To process subscription payments and prevent fraud.
- To improve product quality and provide customer support.
- To comply with legal obligations (tax, accounting, regulatory).
3. Third parties (processors)
- Stripe — payment processing and subscription billing.
- Supabase — database, authentication and file storage.
- Cloud hosting providers — infrastructure delivery.
We do not sell personal data to third parties.
4. Customer menu sessions
Customers using a restaurant’s QR code menu interact anonymously. We do not require login and do not store personal identifiers for diners beyond the contents of their order.
5. Data retention
- Order data: retained for up to 24 months for analytics and accounting.
- Account and billing data: retained while the account is active and for 7 years thereafter for tax law.
- Anonymous customer-session data: retained for up to 90 days.
6. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction or update of inaccurate data.
- Request erasure of your data (“right to be forgotten”).
- Object to or restrict processing.
- Data portability.
- Lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).
7. Security
Data is encrypted in transit (TLS) and at rest. Payment data is handled by Stripe under PCI-DSS Level 1.
8. Contact
Data requests: privacy@bestfriendtechnology.com. We respond within 30 days.