Privacy Policy

Last updated: 26 August 2026

1. Who we are

Restoraq is a website, online ordering, reservation, and restaurant-management platform operated by:

Badesha Webdesign
Org. no. 931 011 413
Aagot Christophersens veg 74, 2040 Kløfta, Norway
Email: info@restoraq.com

Badesha Webdesign is the data controller for the personal data described in this Privacy Policy, within the meaning of the EU General Data Protection Regulation (GDPR) and the corresponding Norwegian implementation of the GDPR under the Personal Data Act (Personopplysningsloven). We serve restaurants and their customers primarily in Sweden and Norway.

2. Scope of this policy

This policy explains how we collect, use, store, and protect personal data when you use Restoraq - whether you are a restaurant owner or staff member using our dashboard and admin tools, or a customer placing an order or booking a table through a restaurant's Restoraq-powered website or ordering widget.

Each restaurant using Restoraq is itself a data controller for the personal data of its own customers (for example, order and reservation details). Restoraq acts as a data processor on the restaurant's behalf for that data, and as a data controller for account data relating to restaurant owners and staff who use our platform.

3. What personal data we collect

Depending on how you use Restoraq, we may collect:

  • Restaurant owner/staff accounts: name, email address, phone number, password (stored as a salted hash, never in plain text), role/permissions, and login activity.
  • Business information: restaurant name, address, business registration details, menu content, images, and payment/billing details processed through our payment provider (we do not store full card numbers ourselves).
  • Customer order/reservation data: name, phone number, email address, delivery address, and order or booking history, submitted when placing an order or reservation with a restaurant on our platform.
  • Technical data: IP address, device/browser information, and basic usage data needed to operate and secure the service (e.g. session cookies, rate limiting, fraud prevention).
  • Support communications: anything you send us via support tickets, email, or in-app messages.

4. Why we process your data, and our legal basis

  • Performance of a contract (GDPR Art. 6(1)(b)) - to create and operate your account, process orders and reservations, and provide the subscription service you signed up for.
  • Legal obligation (Art. 6(1)(c)) - to keep accounting and invoicing records as required by Swedish and Norwegian bookkeeping law.
  • Legitimate interests (Art. 6(1)(f)) - to keep the platform secure, prevent fraud and abuse, and improve our service.
  • Consent (Art. 6(1)(a)) - for optional features such as marketing communications or non-essential cookies, which you can withdraw at any time.

5. Who we share data with

We do not sell personal data. We share it only with service providers who help us run the platform, under data processing agreements that require them to protect it, including:

  • Payment processors, to handle subscription billing and, where applicable, online order payments.
  • Cloud hosting and infrastructure providers, to run and store the application and its data.
  • Email delivery providers, to send transactional emails (receipts, password resets, notifications).
  • Optional third-party integrations a restaurant owner chooses to connect themselves - for example WhatsApp Business, Google Business Profile, or social media publishing - which are only activated when a restaurant owner explicitly connects them, and are governed by that provider's own privacy terms.

Some of these providers may process data outside the European Economic Area (EEA). Where that happens, we rely on appropriate safeguards recognized under GDPR, such as the European Commission's Standard Contractual Clauses.

6. How long we keep your data

We keep personal data only as long as necessary for the purposes described above. As a general guide:

  • Active account data is kept for as long as your account remains active, plus a reasonable period afterward in case you wish to reactivate it.
  • Invoices and accounting records are retained for the period required by applicable bookkeeping law (currently up to 7 years in Sweden and 5 years in Norway), even after an account or restaurant is otherwise deleted.
  • Data linked to a deletion request is erased or anonymized once processed, except where we are legally required to retain it (see above).

7. Your rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request erasure of your personal data ("right to be forgotten"), subject to our legal retention duties described above.
  • Restrict or object to certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your national supervisory authority - the Swedish Authority for Privacy Protection (IMY, imy.se) or the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no).

8. How to exercise your rights

If you have a Restoraq account, the quickest way to request deletion of your personal data is directly from your dashboard, under Settings → Privacy & data. This submits a request our team reviews and processes within 30 days.

For any other request - access, correction, or a question about this policy - email us at info@restoraq.com. If you're a restaurant customer and your question concerns an order or reservation, the restaurant you ordered from is usually best placed to help first, since they control that data as its own controller.

9. Cookies

We use strictly necessary cookies to keep you logged in, remember your cart while ordering, and keep the platform secure. We do not use third-party advertising cookies. Where a restaurant enables optional analytics on their own website, that restaurant is responsible for informing their visitors and obtaining any required consent.

10. Security

We use industry-standard measures to protect personal data, including encryption of data in transit (HTTPS), encryption of sensitive credentials at rest, hashed passwords, and access controls limiting who can see what data. No system is perfectly secure, but we take reasonable steps appropriate to the risk.

11. Children

Restoraq is not directed at children, and we do not knowingly collect personal data from children without appropriate parental consent.

12. Changes to this policy

We may update this policy from time to time, for example to reflect changes in the law or in how the platform works. We'll update the "Last updated" date above when we do. Material changes will be communicated to restaurant owners by email.

13. Contact

Badesha Webdesign (org. no. 931 011 413), Aagot Christophersens veg 74, 2040 Kløfta, Norway · info@restoraq.com