Legal
Privacy Policy
Last updated: April 1, 2026
1. Data We Collect
At Restomas, we collect the following personal data to provide and improve our services:
- Identity: Name, surname, email address, phone number
- Business: Restaurant name, branch addresses, tax ID
- Account: Username, password (hashed), login records
- Usage Data: IP address, browser info, page views, session durations
- Order Data: Menu interactions, order details, payment amounts
- Cookie Data: Session cookies, preference cookies, analytics cookies
2. How We Use Your Data
Collected data is processed for the following purposes:
- Providing, managing, and improving our services
- Creating and securing user accounts
- Managing and reporting order processes
- Handling customer support requests
- Fulfilling legal obligations
- Marketing communications (with consent)
- Statistical analyses and improving service quality
3. Third-Party Sharing
Your data may only be shared in the following cases:
- Payment Processors: PCI-DSS compliant providers (Stripe etc.)
- Infrastructure: Server hosting and cloud service partners
- Legal Requirement: Court orders or authorized public authority requests
Your data is never sold or rented for advertising purposes.
4. Cookie Policy
- Essential: Required for session management and security
- Preference: Remembers settings like language and theme
- Analytics: Collects anonymous usage statistics
You can disable cookies through your browser settings.
5. Data Retention
- Account Data: While account active + 30 days after deletion
- Order Data: Legal accounting requirements — 10 years
- Usage Logs: 12 months
- Marketing Data: Until consent is withdrawn
6. Data Security
- SSL/TLS encryption for all data transfers
- Passwords stored hashed using bcrypt
- Regular security audits and penetration testing
- Access control and authorization mechanisms
- Backup and disaster recovery procedures
7. Your Rights (KVKK & GDPR)
- Right to know whether your data is being processed
- Right to request information about processing
- Right to learn the purpose of processing
- Right to know third parties data is transferred to
- Right to request correction of inaccurate data
- Right to request deletion when conditions are met
- Right to object to automated analysis outcomes
- Right to data portability (GDPR)
8. Contact
For questions about our privacy policy or to exercise your rights: