The controller in the sense of the General Data Protection Regulation (GDPR) is:
Marner Softwareentwicklung UG (haftungsbeschränkt)
Hundestraße 63
23552 Lübeck
Germany
Email: info@gastrotodo.de
You can reach our data protection officer at:
Maximilian Marner
Hundestraße 63
23552 Lübeck
Germany
Email: max@gastrotodo.de
The following information explains how personal data is processed when you use our website. Personal data is any data that can be used to identify you personally.
As a data subject you have the following rights:
If you have given us consent, you may withdraw it at any time with effect for the future. The withdrawal or objection can be addressed informally to the data protection officer named above.
You also have the right to lodge a complaint with a competent data protection supervisory authority about the processing of your personal data. An overview of the German supervisory authorities is available at bfdi.bund.de/Anschriften_Links.
Our website is hosted by:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
When you visit our website, the hosting provider automatically processes so-called log files. These contain in particular:
The processing of this data is necessary in order to provide the website technically and to ensure its stability and security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest).
Hetzner Online GmbH acts as a processor under Art. 28 GDPR. A corresponding data processing agreement has been concluded. The log data is only stored for as long as is necessary to ensure security and stability.
You can find more information about data processing by Hetzner at hetzner.com/legal/privacy-policy.
If you contact us by email, the personal data you transmit (e.g. name, email address, phone number) will be processed for the purpose of handling your request. The data will be deleted as soon as it is no longer required for processing, unless statutory retention periods apply.
When you use our contact form, we process the following personal data:
The processing serves exclusively to handle your request. Legal basis for general inquiries: Art. 6(1)(f) GDPR. Legal basis for product- or service-related inquiries: Art. 6(1)(b) GDPR. Your data is deleted once the request has been handled, unless statutory retention periods apply.
Our website uses cookies. Cookies are small text files stored on your device that do not contain malware. We distinguish the following cookie types:
Optional cookies are only set after your express consent. You can withdraw or adjust your consent at any time via the cookie settings. If you withdraw your consent, the cookies concerned are deleted.
These cookies are required to operate the website and are set without consent (Section 25(2) no. 2 TDDDG).
| Name | Purpose | Storage duration |
|---|---|---|
token | Identifier of your logged-in session. Only set on login, not readable via JavaScript. | 30 days |
next-i18next / NEXT_LOCALE | Remembers the language you selected. | 30 days / until you close the browser |
gt-brand | Colours and logo of your organisation's workspace, so the app doesn't briefly render in the default design while loading. | 30 days |
app-plattform | Remembers that the application was opened from the installed app. | permanent, until you clear your browser data |
Your choice in the cookie banner itself is not stored as a cookie but in your browser's local storage (see "Consent management").
These cookies are only set once you release the relevant category in the cookie banner.
| Name | Provider | Purpose | Storage duration |
|---|---|---|---|
_ga, _ga_<ID> | Distinguishes visitors for reach measurement. | 2 years | |
_gcl_au, _gcl_aw | Attributes an ad click to a later sign-up (conversion measurement). | 90 days | |
gt_lead_source | gastrotodo | Records which channel brought you to the website (campaign parameters, referring page). | 30 days |
gtt-ref | gastrotodo | Attributes a sign-up to the referral link you arrived through. | 90 days |
On development and testing environments we additionally set individual cookies for internal tooling; these are not used on the publicly accessible website.
We use the consent management solution "c15t" to manage your consent. We run it in what is called offline mode: your selection is stored in your browser (local storage) and is not transmitted to an external provider. We store the categories you released and the time of your selection so that the banner does not reappear on subsequent visits.
The legal basis for this storage is Section 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(c) GDPR (documenting your consent decision). If you clear your browser data, the banner will appear again.
We additionally log your decision on our own server in Germany so that we can evidence the consent you gave or refused. Nothing is transmitted to an external provider in the process. The record contains:
The IP address is truncated before it is stored (IPv4 to the first three blocks, IPv6 to the first three groups); we do not keep the full address. We store neither your name nor any identifier that would let us link this entry to you — no user account is required to make the decision.
The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (the obligation to be able to demonstrate consent). The record is deleted once it is no longer required for that purpose.
Our website uses services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Specifically:
The data processed includes your truncated IP address, information about your browser and device, the pages you visit, the referrer URL, the time of access and a pseudonymous user ID stored in cookies.
These services are only loaded after your explicit consent via the cookie banner. Before you consent, no script is requested from Google and no data is transmitted to Google. The legal basis is Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with future effect via the cookie settings.
We have enabled IP anonymisation. Your IP address is therefore truncated within the European Union or the European Economic Area before being transmitted to the USA. For transfers to the USA, Google relies on the EU-US Data Privacy Framework and on EU standard contractual clauses (SCCs).
Further information is available at google.com/analytics/terms and policies.google.com/privacy.
On our demo page you can book a call directly via "Calendly", a service provided by Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. The booking window only opens once you actively click the booking option — no connection to Calendly is established before that.
Once you open the booking window, Calendly processes in particular your IP address, information about your browser and device, and the details you enter in the form (name, email address, chosen slot, optional message). We receive those details in order to prepare and hold the appointment.
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request) and Art. 6(1)(f) GDPR (legitimate interest in efficient scheduling). For transfers to the USA, Calendly uses EU standard contractual clauses (SCCs).
Further information is available at calendly.com/legal/privacy-notice.
On some pages we embed videos hosted on YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We use the extended data protection mode ("youtube-nocookie.com"): simply opening the page loads a preview image only. A connection to YouTube's servers is established only once you actively start a video.
YouTube then learns in particular your IP address, which of our pages you visited and information about your browser and device. If you are logged in to YouTube at the same time, YouTube can attribute the request to your account; you can prevent this by logging out. In extended data protection mode, YouTube states that it only sets cookies or comparable technologies once the video starts.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in presenting our offering attractively); where information is stored on or read from your device, this happens on the basis of your active start of the video.
Further information is available at policies.google.com/privacy.
To detect and fix technical faults we use "Sentry", provided by Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, San Francisco, CA 94105, USA. If an error occurs in your browser or on our server, an error report is transmitted to Sentry.
The data processed includes in particular:
Your session is not recorded ("session replay"); that feature is disabled. Error reports are used solely for troubleshooting and are deleted after 90 days at the latest.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the stable and secure operation of our service). Sentry acts as a processor under Art. 28 GDPR; for transfers to the USA, Sentry uses EU standard contractual clauses (SCCs).
Further information is available at sentry.io/privacy.
We use the following payment service provider for processing payments:
Stripe
Legal Process, 510 Townsend St.
San Francisco, CA 94103
USA
As part of payment processing, the following data is transmitted to Stripe — to the extent necessary:
The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in secure payment processing). Stripe acts either as controller or as processor depending on the processing operation. For international data transfers, Stripe uses EU standard contractual clauses (SCCs).
You can find more information at stripe.com/privacy-center/legal.
Team leads can optionally enable our AI assistant ("Radish") for their team in the app settings. The assistant is only switched on after explicit consent by the team lead; the feature can be revoked at any time from the same place.
When the assistant is active and a team member talks to it, the following data is sent to our processor OpenAI, L.L.C., 1455 3rd Street, San Francisco, CA 94158, USA in order to answer the request:
The following are explicitly not transmitted: real names of individual employees, their calendar entries, personal shift schedules, or individual completions.
Processing takes place under a data processing agreement pursuant to Art. 28 GDPR. Legal basis is Art. 6(1)(a) GDPR (consent of the team lead) and Art. 6(1)(b) GDPR (performance of the contract with the team). OpenAI processes the transmitted content exclusively to answer the request and does not use it to train its models ("API data usage" policy). For international data transfers, OpenAI uses EU standard contractual clauses (SCCs).
gastrotodo itself does not permanently store or analyse the chat content; gastrotodo staff also have no access to the conversation histories of teams.
You can find more information at openai.com/policies/privacy-policy and openai.com/enterprise-privacy.
To protect our public forms (in particular registration and password reset) against automated attacks and abuse, we use the "Turnstile" captcha of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA whenever an elevated level of security is required.
Turnstile is not loaded permanently, but only when we have activated security mode (for example after detected attack attempts). While security mode is active, a Cloudflare script is loaded when the affected form is opened and checks in the background whether the request originates from a human or a bot. As part of this check, Cloudflare processes in particular:
According to Cloudflare, Turnstile works without tracking cookies and does not use the collected data for profiling or advertising purposes. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in defending against bots, spam and abusive sign-in attempts as well as in the security of our systems).
For data transfers to the USA, Cloudflare uses EU standard contractual clauses (SCCs).
You can find more information at cloudflare.com/privacypolicy.

Start with gastrotodo — try free for 7 days, then carry on with the plan that fits your business.