Skip to content

Privacy Policy

This privacy policy informs you pursuant to Art. 13 and 14 GDPR about which personal data we process when you visit the website www.gastronomx.com, use the gastronomx platform (registration, dashboard, billing) and contact us, for which purposes and on which legal basis this is done, and which rights you have.

Last updated: September 2026

Note: The German version of this page is legally binding. This translation is provided for information only.

1. Controller

The controller within the meaning of the GDPR is: Jonas Reuber – gastronomx Mozartring 32 88436 Eberhardzell Germany Phone: +49 157 80994060 Email: service@agentur-reuber.com No data protection officer has been appointed, as the statutory requirements for this are not met. Please direct privacy enquiries to the email address above.

2. Hosting and content delivery (Vercel)

The website and the platform are hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel provides the content delivery network (CDN) and the server functions; the server functions are executed in the Frankfurt am Main region (Germany). With each request, Vercel processes technically necessary connection data (IP address, date and time, requested URL, referrer, browser type and version, operating system) in server logs to ensure delivery, defend against attacks and analyse errors. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and performant operation). Server logs are stored only briefly (usually a few days) unless they are needed to investigate a security incident. A data processing agreement is in place with Vercel; for any transfer to the USA, the EU standard contractual clauses (Art. 46(2)(c) GDPR) have been agreed.

3. Database, authentication and file storage (Supabase)

Accounts, business data and content are stored in a database operated by Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992. Database, authentication and storage services run in the AWS region eu-central-1 (Frankfurt am Main, Germany); in regular operation the data does not leave the EU. For sign-in, Supabase processes your email address, your password (as a hash only), sign-in timestamps and technical session data. The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR (system security). A data processing agreement including EU standard contractual clauses for any support access from third countries is in place with Supabase.

4. Registration, account and use of the dashboard

When you register we process your email address, your password (as a hash only), the name of your business, the selected language and the time of registration and of the confirmation of your email address. In the dashboard we process the business data you enter (e.g. menus, opening hours, address, website content, domain), your plan and module selection and technical log data of your use (timestamps, IP address, actions performed). The purpose is to provide the platform, manage your account, billing and system security. The legal basis is Art. 6(1)(b) GDPR (contract or pre-contractual measures, including a free trial); for security logs Art. 6(1)(f) GDPR. We send you the emails required for the contract (registration confirmation, invoice and payment notices, security notices, material changes); you cannot unsubscribe from these while the contract is in force. You will receive promotional emails only with your consent.

5. Payments and billing (Stripe)

To conclude and bill your subscription we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Stripe processes your payment data (payment method, card details or bank account, billing address, email address, VAT identification number where applicable) and transaction data. Card and account data are entered and stored exclusively at Stripe; our servers only receive a customer identifier, the subscription status and invoice information. For payment processing, Stripe is partly an independent controller (e.g. fraud prevention and statutory obligations as a payment service provider); information is available at https://stripe.com/privacy. The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR (legal obligations). We retain invoice data and accounting records for ten years pursuant to Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB). Payments by your guests via Stripe Connect are explained in section 9.

6. Email delivery (Resend)

We send transactional emails (e.g. confirmations, notifications, double-opt-in emails of the newsletter module, replies to contact requests) via Resend Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. Resend processes the recipient address, subject, content and delivery status; we use the service's EU region (data centre in Ireland). The legal basis is Art. 6(1)(b) GDPR (performance of the contract) or Art. 6(1)(f) GDPR (reliable delivery). A data processing agreement is in place with Resend; for any transfer to the USA, the EU standard contractual clauses have been agreed.

7. Contact and demo requests

If you contact us via the contact form, the demo form, by email or by phone, we process the details you provide (name, email address, phone number where applicable, name and type of your business, your message) as well as the time, the page visited, the language and the browser type in order to process your request and answer follow-up questions. The details are stored in our database (Supabase, Frankfurt am Main) and forwarded by email (Resend) to our mailbox. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request) or Art. 6(1)(f) GDPR (legitimate interest in answering requests); where you consent to the processing in the form, additionally Art. 6(1)(a) GDPR. We delete requests no later than twelve months after final processing, provided no contract is concluded and no retention obligations apply. The forms contain an invisible protection field against automated input (spam); no additional data is collected in the process.

8. Cookies, consent and web analytics

To operate the platform we use technically necessary cookies, in particular session cookies for signing in to the dashboard (Supabase Auth) and a storage entry that records your cookie decision. These are required to provide the service (Section 25(2) no. 2 TDDDG; Art. 6(1)(b) and (f) GDPR) and are set without consent. We use non-essential cookies and comparable technologies only with your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR), which you give via the cookie banner and can withdraw at any time with effect for the future via the “Cookie settings” link in the footer. Web analytics: If activated by us and only after your consent to the “Statistics” category, we use Plausible Analytics (Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia), a privacy-friendly analytics service with servers in the EU. Plausible does not set cookies and does not permanently store personal data; IP addresses are used only transiently to form a daily-changing, non-reversible identifier. Evaluated are pages visited, referrer, device type, country and events such as the submission of a form (without its content). We currently do not use marketing cookies (e.g. for campaign measurement); should we do so in the future, this will only happen after your consent to the “Marketing” category.

9. Guest data of connected businesses (processing on behalf)

Restaurants, cafés and other businesses use gastronomx to serve their guests: reservations, online orders and voucher purchases, reviews, newsletter sign-ups, loyalty programmes and CRM data. For this data, the respective business is the controller under data protection law; gastronomx processes it exclusively on its behalf and according to its instructions as a processor (Art. 28 GDPR). The basis is the data processing agreement available at www.gastronomx.com/en/dpa. If, as a guest, you make a reservation, order, review or newsletter sign-up with a business, please contact that business for information and to exercise your rights; its contact details can be found in the legal notice of its site. We support the business in responding. Guest payments are processed via Stripe Connect directly between guest, business and Stripe; gastronomx does not receive any card or account data.

10. Recipients and transfers to third countries

Recipients of your data are the processors named in this policy (Vercel, Supabase, Stripe, Resend, Plausible where applicable) and – where required by law – authorities, tax advisers or legal advisers. Data processing takes place in data centres in Frankfurt am Main and Ireland. Insofar as service providers based in the USA (Vercel, Resend) could access data in individual cases – for example for support or maintenance – this is safeguarded by the EU standard contractual clauses (Art. 46(2)(c) GDPR) including supplementary measures. Data is not passed on to third parties for advertising purposes.

11. Retention period

We store personal data only for as long as necessary for the stated purposes: • Account and business data: for the duration of the contract; deleted 30 days after the end of the contract (exception: statutory retention obligations). • Invoice and payment data: ten years (Section 147 AO, Section 257 HGB). • Contact and demo requests: up to twelve months after completion of processing. • Server logs: briefly, usually a few days. • Cookie decisions and consents: until withdrawal, at most twelve months. • Guest data of the businesses: according to the instructions of the respective business; after the end of the contract in accordance with the data processing agreement.

12. Your rights

You have the following rights vis-à-vis us regarding your personal data: the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR). To exercise your rights, an email to service@agentur-reuber.com is sufficient.

13. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The supervisory authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg) Lautenschlagerstraße 20 70173 Stuttgart, Germany Phone: +49 711 615541-0 Email: poststelle@lfdi.bwl.de www.baden-wuerttemberg.datenschutz.de You may also contact the supervisory authority of your place of residence or work.

14. Data security

We take technical and organisational measures pursuant to Art. 32 GDPR to protect your data: encryption of all connections via TLS (HTTPS), encryption of the database at rest, strict separation of the data of different businesses at database level through Row Level Security (RLS), role-based access rights, two-factor authentication for administrative access, regular backups, logging of security-relevant access and operation in data centres within the EU. The measures are reviewed regularly and adapted to the state of the art. Details can be found in the annex to our data processing agreement.

15. No automated decision-making

Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place.

16. Changes to this privacy policy

We adapt this privacy policy when the legal situation, our services or the service providers used change. The current version is always available at www.gastronomx.com/en/privacy. The German version is legally binding. Last updated: September 2026