Privacy Policy
Last updated: August 10, 2026
This Privacy Policy explains how IQ Rest — a service operated by Bogdan Sokolov, individual entrepreneur (autónomo) registered in Spain, with fiscal address at Calle Boca Del Rio 2, 1A, Oviedo, 33010, Asturias, Spain (Tax ID: ESZ1894474S) ("IQ Rest", "we", "us") — collects, uses, stores and protects your personal data when you use the IQ Rest platform at iq-rest.com and its subdomains.
The short version: everything you and your guests enter into the Service lives in our own database, on our own servers in the European Union. We run no third-party analytics or advertising trackers, and our own usage tracking contains no personal data.
We comply with the General Data Protection Regulation (GDPR), the Spanish Organic Law on Data Protection and Guarantee of Digital Rights (LOPDGDD), and the ePrivacy Directive.
1. Data Controller
IQ Rest is operated by Bogdan Sokolov, individual entrepreneur (autónomo) registered in Spain, who is the data controller responsible for your personal data (Tax ID: ESZ1894474S, fiscal address Calle Boca Del Rio 2, 1A, Oviedo, 33010, Asturias, Spain).
For guest data submitted to a specific restaurant through the Service (orders, reservations), the restaurant is the data controller and we act as its processor — see section 7 of the Terms of Service.
For any privacy inquiries, including the exercise of your data subject rights, contact support@iq-rest.com.
2. Data we collect
We collect only the data needed to operate the Service. The categories below cover everything stored in our database.
Account data — when you register: email address (used for one-time-code sign-in and operational notices); preferred dashboard language; the cuisine type and restaurant name you provide during signup.
Authentication data — short-lived one-time codes (OTPs), hashed session tokens, count of failed verification attempts. Sign-in is passwordless (email code, Google, or Apple); no passwords are stored.
Billing data — your subscription status, selected features and billing interval, and Stripe customer/subscription identifiers. Payment cards are handled entirely by Stripe; we never see or store card details.
Restaurant profile — restaurant name, subtitle, description, public address (slug), currency, brand color, cover image, postal address, geo coordinates, phone number, Instagram handle, WhatsApp number, languages, working hours, timezone, table and reservation settings.
Menu content — categories, dishes (name, description, price, photo, allergens, options, translations), tables (number, capacity, zone, floor position).
Reservations — for each booking: guest name, guest email, guest phone (optional), party size, date, time, duration, table assignment, status, internal notes.
Orders — for each order: customer name (optional), customer phone (optional), comment, table number, items ordered, discounts, total amount, currency, status.
Connected devices — if you pair tablets (kitchen display, waiter board, reservation board): device name, device type, and last-seen time. No personal data of the staff using the tablet is collected.
Support and messaging — content of messages you exchange with our support team, including messages sent over WhatsApp if you contact us there.
Usage tracking — tracking only, without personal data: anonymous first-party events consisting of an action name (e.g. "pricing_view"), a timestamp, and an approximate region (country/region derived from IP). No name, no email, no cross-site identifier — the events cannot identify you as a person. See section 5.
3. Legal basis for processing
Each category is processed under one of the legal bases in GDPR Article 6:
Contract performance (Art. 6(1)(b)) — account data, authentication data, billing data, restaurant profile, menu content, reservations, orders, connected devices, support messages. Required to provide the Service you signed up for.
Legitimate interest (Art. 6(1)(f)) — anonymous usage tracking, short-term operational logs, fraud and abuse prevention, measurement of our own advertising (section 6). Balanced against your rights; you can object at any time by emailing support@iq-rest.com.
Legal obligation (Art. 6(1)(c)) — invoicing data we are required to retain by Spanish tax law.
4. How we use your data
Provide and maintain the Service: run your dashboard and public menu pages, generate QR codes, process orders and reservations, power kitchen and waiter displays.
Authenticate you: send sign-in codes by email, validate Google/Apple sign-in, manage sessions.
Bill you: process subscription payments through Stripe, send invoices.
Assist you with AI features: if you import a menu from photos or use automatic translation, the images or menu text you submit are processed by an AI model to produce the draft menu or translation. The results are stored only in your own menu.
Communicate with you: account and service notices, support replies, important changes to the Service. We do not send marketing emails without your separate consent.
Improve the platform: anonymous usage tracking, debugging, performance monitoring.
Comply with legal obligations: tax records, regulatory reporting when required.
5. Usage tracking — no personal data
We measure how the main website and the dashboard are used with our own first-party events stored in our own database. Tracking is limited to what happened, not who did it: each event records an action name, the moment it occurred, and an approximate region. No analytics cookie is placed on your device, no advertising identifier is created, no data is shared with any analytics company, and the events contain no personal data.
Actions performed inside your own dashboard while signed in may additionally be associated with your account — solely so we can help you in support cases and detect abuse, never for advertising.
6. Advertising measurement (ad-click identifiers)
If you arrive at our site by clicking one of our own ads, the ad platform appends a click identifier to the URL (Google Ads: gclid; Meta: fbclid). We store that identifier in our own database and, if you later sign up, report the conversion back to the ad platform server-to-server so we can tell which ads work. No pixel, tag, or tracker from these platforms runs on our site, and the identifier is not linked to your name or email in these reports.
This processing relies on our legitimate interest in measuring our own advertising (GDPR Art. 6(1)(f)). You may object at any time by emailing support@iq-rest.com (include the click identifier from your original ad URL if you want past attribution excluded).
7. Where data is stored
All customer data — your account, restaurant content, orders, reservations, usage events — is stored in one place: our own database on a dedicated server operated for us by Hetzner Online GmbH, Nuremberg, Germany, under our direct control. Primary processing does not leave the European Union.
Backups are encrypted and stored in the same EU region.
Data is encrypted in transit using TLS and at rest using disk-level encryption.
8. Service providers
We do not sell, rent, or share your personal data with anyone for their own purposes, and we run no third-party analytics or advertising trackers. A small number of infrastructure providers are technically necessary to deliver the Service:
Stripe — payment processing. Receives your billing email and the amount and product of each transaction. Privacy: https://stripe.com/privacy
Hetzner Online GmbH — hosts our server (Germany, EU). A data processor under a Data Processing Agreement; cannot access database contents in normal operation.
Cloudflare — CDN and DDoS protection in front of our server; sees inbound requests as any network carrier does. A data processor.
Google — only in three narrow cases: if you choose "Sign in with Google" (standard OAuth: email, name, picture); if you use the AI menu-import or translation features (the submitted images/text are processed by Google's AI API and not used to train models); and server-to-server ad-conversion reports described in section 6.
Apple — only if you choose "Sign in with Apple" (standard OAuth scope).
Meta — only if you message us on WhatsApp (WhatsApp relays the messages, as with any WhatsApp conversation) and for the server-to-server ad-conversion reports described in section 6.
9. International data transfers
All primary processing happens within the European Union. Where a provider listed above (Stripe, Cloudflare, Google, Apple, Meta) transfers data to the United States, the transfer is covered by the EU-US Data Privacy Framework or by Standard Contractual Clauses.
10. How long we keep your data
Account data — for as long as your account is active. Within 30 days of account deletion, all personal data is permanently removed from our database. Backups are overwritten within 90 days.
OTPs — deleted immediately on successful verification or after 15 minutes (whichever comes first).
Reservations and orders — retained for as long as you keep your restaurant in the Service (they power your order history and statistics), then removed with the account.
Anonymous usage events — retained without a fixed limit; they contain no personal data.
Ad-click identifiers — used for conversion reporting for up to 90 days after the click.
Invoicing data — retained for 6 years as required by Spanish tax law (Ley General Tributaria).
Support messages — retained for 24 months after the last reply.
11. Your rights
Under the GDPR you have the right to:
Access — request a copy of the personal data we hold about you.
Rectification — correct inaccurate or incomplete data.
Erasure ("right to be forgotten") — request deletion of your data; we will comply unless retention is required by law.
Restriction — pause processing while a complaint is investigated.
Portability — receive your data in a structured, machine-readable format and transfer it to another provider.
Object — object to processing based on legitimate interest, including advertising measurement (section 6). Email support@iq-rest.com.
Lodge a complaint — file a complaint with the Spanish data protection authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es.
To exercise any of these rights, email support@iq-rest.com. We respond within 30 days.
12. Children
The Service is not intended for individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will remove it.
13. Security
We apply technical and organizational measures appropriate to the risk: TLS for all traffic, encryption at rest, hashed session tokens, rate-limiting, automated backups, restricted server access, and regular dependency updates. No system is 100% secure; if we become aware of a personal-data breach affecting you, we will notify you and the AEPD within 72 hours as required by GDPR Article 33.
14. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after a change constitutes acceptance.
15. Contact
Questions, complaints, or requests regarding this Privacy Policy can be sent to support@iq-rest.com. We respond within 30 days.