Privacy policy
Last updated 20 July 2026
karta (“we”) provides QR menus and pay-at-table software to restaurants. This policy explains what personal data we handle and why. We aim to collect as little as possible.
Who is responsible
The data controller is [legal entity name], [registered address]. Data-protection contact: privacy@karta.menu.
Restaurant accounts
When a venue signs up we process the sign-up email address and the venue details the owner enters (name, address, menu, opening hours, contact number). This is done to provide the service, under our contract with the venue. Authentication is handled by Supabase.
Guests using a menu
Guests do not create an account. In the current build, a guest's cart, chosen table, likes and any review are stored in their own browser (localStorage) — not on our servers. When ordering and payments move server-side, this section will be updated to describe order and payment records and their retention.
Payments
The current build does not process real payments and does not collect card details. When payments launch they will run through a licensed provider (Stripe); we will not store full card numbers.
Cookies
We use only strictly-necessary cookies for signed-in sessions in the back office. The guest menu sets no tracking or advertising cookies, so no consent banner is required for it. If that changes, we will ask for consent first.
Where data lives
Our database and authentication run on Supabase in the EU (Frankfurt, eu-central-1). We do not sell personal data.
Your rights
Under the GDPR you can request access, correction, deletion, or a copy of your data, and can object to processing. Email privacy@karta.menu and we will respond within the statutory time limit. You may also complain to your national data-protection authority.