Privacy policy

Controller

The controller in the sense of the General Data Protection Regulation (GDPR) is:

Marner Softwareentwicklung UG (haftungsbeschränkt)
Hundestraße 63
23552 Lübeck
Germany
Email: info@gastrotodo.de

Data protection officer

You can reach our data protection officer at:

Maximilian Marner
Hundestraße 63
23552 Lübeck
Germany
Email: max@gastrotodo.de

General notes on data processing

The following information explains how personal data is processed when you use our website. Personal data is any data that can be used to identify you personally.

Your rights

As a data subject you have the following rights:

  • Right of access to your personal data (Art. 15 GDPR)
  • Right to rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • Right to erasure of your personal data (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to object to processing (Art. 21 GDPR)
  • Right to data portability (Art. 20 GDPR)

If you have given us consent, you may withdraw it at any time with effect for the future. The withdrawal or objection can be addressed informally to the data protection officer named above.

You also have the right to lodge a complaint with a competent data protection supervisory authority about the processing of your personal data. An overview of the German supervisory authorities is available at bfdi.bund.de/Anschriften_Links.

Hosting

Our website is hosted by:

Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany

When you visit our website, the hosting provider automatically processes so-called log files. These contain in particular:

  • IP address
  • Date and time of the request
  • The page or file requested
  • HTTP status code
  • Amount of data transferred
  • Referrer URL
  • Information about the browser and operating system

The processing of this data is necessary in order to provide the website technically and to ensure its stability and security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest).

Hetzner Online GmbH acts as a processor under Art. 28 GDPR. A corresponding data processing agreement has been concluded. The log data is only stored for as long as is necessary to ensure security and stability.

You can find more information about data processing by Hetzner at hetzner.com/legal/privacy-policy.

Contacting us by email

If you contact us by email, the personal data you transmit (e.g. name, email address, phone number) will be processed for the purpose of handling your request. The data will be deleted as soon as it is no longer required for processing, unless statutory retention periods apply.

Contact form

When you use our contact form, we process the following personal data:

Mandatory information

  • Name
  • Email address
  • Subject
  • Message

Additionally processed data

  • Company (optional)
  • Time of submission
  • IP address

The processing serves exclusively to handle your request. Legal basis for general inquiries: Art. 6(1)(f) GDPR. Legal basis for product- or service-related inquiries: Art. 6(1)(b) GDPR. Your data is deleted once the request has been handled, unless statutory retention periods apply.

Cookies

Our website uses cookies. Cookies are small text files stored on your device that do not contain malware. We distinguish the following cookie types:

  • Technically necessary cookies required for the operation of the website
  • Optional cookies, in particular for statistics and analysis

Optional cookies are only set after your express consent. You can withdraw or adjust your consent at any time via the cookie settings. If you withdraw your consent, the cookies concerned are deleted.

Technically necessary cookies

These cookies are required to operate the website and are set without consent (Section 25(2) no. 2 TDDDG).

NamePurposeStorage duration
tokenIdentifier of your logged-in session. Only set on login, not readable via JavaScript.30 days
next-i18next / NEXT_LOCALERemembers the language you selected.30 days / until you close the browser
gt-brandColours and logo of your organisation's workspace, so the app doesn't briefly render in the default design while loading.30 days
app-plattformRemembers that the application was opened from the installed app.permanent, until you clear your browser data

Your choice in the cookie banner itself is not stored as a cookie but in your browser's local storage (see "Consent management").

Cookies that require consent

These cookies are only set once you release the relevant category in the cookie banner.

NameProviderPurposeStorage duration
_ga, _ga_<ID>GoogleDistinguishes visitors for reach measurement.2 years
_gcl_au, _gcl_awGoogleAttributes an ad click to a later sign-up (conversion measurement).90 days
gt_lead_sourcegastrotodoRecords which channel brought you to the website (campaign parameters, referring page).30 days
gtt-refgastrotodoAttributes a sign-up to the referral link you arrived through.90 days

On development and testing environments we additionally set individual cookies for internal tooling; these are not used on the publicly accessible website.

We use the consent management solution "c15t" to manage your consent. We run it in what is called offline mode: your selection is stored in your browser (local storage) and is not transmitted to an external provider. We store the categories you released and the time of your selection so that the banner does not reappear on subsequent visits.

The legal basis for this storage is Section 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(c) GDPR (documenting your consent decision). If you clear your browser data, the banner will appear again.

Record of your decision

We additionally log your decision on our own server in Germany so that we can evidence the consent you gave or refused. Nothing is transmitted to an external provider in the process. The record contains:

  • the categories you released
  • whether you decided via the banner or via the cookie settings
  • the language and the wording version of the banner shown to you
  • the time of your decision
  • your truncated IP address and your browser identifier (user agent)

The IP address is truncated before it is stored (IPv4 to the first three blocks, IPv6 to the first three groups); we do not keep the full address. We store neither your name nor any identifier that would let us link this entry to you — no user account is required to make the decision.

The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (the obligation to be able to demonstrate consent). The record is deleted once it is no longer required for that purpose.

Google services (Analytics, Google Ads, Google Tag)

Our website uses services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Specifically:

  • Google Analytics 4 — reach measurement and analysis of website usage.
  • Google Ads incl. conversion tracking — measuring the success of our ads, in particular whether an ad click led to a demo request or a sign-up. If you consented to the marketing category, we also use enhanced conversions: your email address or phone number is hashed with SHA-256 in your browser and transmitted in hashed form only.
  • Google Tag containers — technical delivery of the measurement functions above.

The data processed includes your truncated IP address, information about your browser and device, the pages you visit, the referrer URL, the time of access and a pseudonymous user ID stored in cookies.

These services are only loaded after your explicit consent via the cookie banner. Before you consent, no script is requested from Google and no data is transmitted to Google. The legal basis is Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with future effect via the cookie settings.

We have enabled IP anonymisation. Your IP address is therefore truncated within the European Union or the European Economic Area before being transmitted to the USA. For transfers to the USA, Google relies on the EU-US Data Privacy Framework and on EU standard contractual clauses (SCCs).

Further information is available at google.com/analytics/terms and policies.google.com/privacy.

Appointment booking via Calendly

On our demo page you can book a call directly via "Calendly", a service provided by Calendly LLC, 271 17th St NW, Atlanta, GA 30363, USA. The booking window only opens once you actively click the booking option — no connection to Calendly is established before that.

Once you open the booking window, Calendly processes in particular your IP address, information about your browser and device, and the details you enter in the form (name, email address, chosen slot, optional message). We receive those details in order to prepare and hold the appointment.

The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request) and Art. 6(1)(f) GDPR (legitimate interest in efficient scheduling). For transfers to the USA, Calendly uses EU standard contractual clauses (SCCs).

Further information is available at calendly.com/legal/privacy-notice.

YouTube videos

On some pages we embed videos hosted on YouTube (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). We use the extended data protection mode ("youtube-nocookie.com"): simply opening the page loads a preview image only. A connection to YouTube's servers is established only once you actively start a video.

YouTube then learns in particular your IP address, which of our pages you visited and information about your browser and device. If you are logged in to YouTube at the same time, YouTube can attribute the request to your account; you can prevent this by logging out. In extended data protection mode, YouTube states that it only sets cookies or comparable technologies once the video starts.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in presenting our offering attractively); where information is stored on or read from your device, this happens on the basis of your active start of the video.

Further information is available at policies.google.com/privacy.

Error logging via Sentry

To detect and fix technical faults we use "Sentry", provided by Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, San Francisco, CA 94105, USA. If an error occurs in your browser or on our server, an error report is transmitted to Sentry.

The data processed includes in particular:

  • the technical error message and the program flow (stack trace)
  • the address (URL) called at the time of the error
  • information about browser, operating system and screen size
  • the IP address
  • for logged-in users, an internal user and team identifier

Your session is not recorded ("session replay"); that feature is disabled. Error reports are used solely for troubleshooting and are deleted after 90 days at the latest.

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the stable and secure operation of our service). Sentry acts as a processor under Art. 28 GDPR; for transfers to the USA, Sentry uses EU standard contractual clauses (SCCs).

Further information is available at sentry.io/privacy.

Payment processing via Stripe

We use the following payment service provider for processing payments:

Stripe
Legal Process, 510 Townsend St.
San Francisco, CA 94103
USA

As part of payment processing, the following data is transmitted to Stripe — to the extent necessary:

  • Cardholder name
  • Email address
  • Customer and order number
  • Bank or credit card details
  • Transaction date and amount

The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in secure payment processing). Stripe acts either as controller or as processor depending on the processing operation. For international data transfers, Stripe uses EU standard contractual clauses (SCCs).

You can find more information at stripe.com/privacy-center/legal.

AI assistant ("Radish") via OpenAI

Team leads can optionally enable our AI assistant ("Radish") for their team in the app settings. The assistant is only switched on after explicit consent by the team lead; the feature can be revoked at any time from the same place.

When the assistant is active and a team member talks to it, the following data is sent to our processor OpenAI, L.L.C., 1455 3rd Street, San Francisco, CA 94158, USA in order to answer the request:

  • The question or message that the team member sends to Radish.
  • Excerpts from the team's knowledge sources that are relevant to the answer: documents and knowledge articles, task titles and task descriptions, training content, and product/equipment manuals.
  • The language and team configuration related to tasks (shifts, departments) so Radish can give matching suggestions.

The following are explicitly not transmitted: real names of individual employees, their calendar entries, personal shift schedules, or individual completions.

Processing takes place under a data processing agreement pursuant to Art. 28 GDPR. Legal basis is Art. 6(1)(a) GDPR (consent of the team lead) and Art. 6(1)(b) GDPR (performance of the contract with the team). OpenAI processes the transmitted content exclusively to answer the request and does not use it to train its models ("API data usage" policy). For international data transfers, OpenAI uses EU standard contractual clauses (SCCs).

gastrotodo itself does not permanently store or analyse the chat content; gastrotodo staff also have no access to the conversation histories of teams.

You can find more information at openai.com/policies/privacy-policy and openai.com/enterprise-privacy.

Bot protection via Cloudflare Turnstile

To protect our public forms (in particular registration and password reset) against automated attacks and abuse, we use the "Turnstile" captcha of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA whenever an elevated level of security is required.

Turnstile is not loaded permanently, but only when we have activated security mode (for example after detected attack attempts). While security mode is active, a Cloudflare script is loaded when the affected form is opened and checks in the background whether the request originates from a human or a bot. As part of this check, Cloudflare processes in particular:

  • IP address
  • information about the browser and operating system
  • a verification token generated by Cloudflare
  • technical characteristics used to distinguish humans from bots

According to Cloudflare, Turnstile works without tracking cookies and does not use the collected data for profiling or advertising purposes. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in defending against bots, spam and abusive sign-in attempts as well as in the security of our systems).

For data transfers to the USA, Cloudflare uses EU standard contractual clauses (SCCs).

You can find more information at cloudflare.com/privacypolicy.

Ready to structure your business?

Start with gastrotodo — try free for 7 days, then carry on with the plan that fits your business.

Start your 7-day free trialOr book a demo
gastrotodo

Structured operations for hospitality and retail — checklists, HACCP, training and daily reports in one app.

Product
Contact
+49 451 58241800
App StoreGoogle Play

Servers in Germany
GDPR-compliant
Made in Europe
Support hotline +49 451 58241800 (Mon–Fri 9am–5pm CET)
Free setup support

© 2023–2026 gastrotodo.de. All rights reserved.