Privacy
Last updated 28 September 2026
Eataaa helps restaurant guests choose a dish. We built it to work without collecting personal data from guests.
Guests (people who scan a table card)
- No account, no login, no cookies, no advertising trackers, no fingerprinting.
- We store anonymous usage events: a random session ID kept only in your browser tab, the answers you tap, which dishes were shown and opened, your browser language and the menu version. We do not store your IP address with these events.
- If you choose to rate a dish (“Would order again”), that anonymous answer is stored and may help the restaurant and other guests.
- If you choose to share a dish photo, we store it privately. The restaurant decides whether to use it. We remove location data from photos before upload. Please don't photograph other people.
- Purpose and legal basis: providing the service you requested and improving recommendations (legitimate interest, Art. 6(1)(f) GDPR). Photos: your consent, which you can withdraw by emailing us.
Restaurants
- Account email (for sign-in codes), restaurant details, uploaded menus, dish photos and settings. Billing is handled by Stripe; we don't store card numbers.
- Menu files are processed by an AI model provider to read dishes, prices and ingredients. We don't use your data to train third-party models.
- You can delete a restaurant at any time in Settings. This deletes its menus, analytics and photos.
Processors
- Supabase (database, authentication, file storage; EU region), Vercel (hosting and AI Gateway), Stripe (billing), Resend (email), Google (optional: linking your Google Maps place ID only).
Retention
Anonymous guest events are kept for up to 24 months. Restaurant data is kept while the account exists and deleted on request.
Your rights
You can request access, correction or deletion, or object to processing, by emailing hello@eataaa.com. You may also complain to your data protection authority.
Controller
See the Imprint. · hello@eataaa.com