Startling menu ("we", "us") provides a QR-menu and ordering platform used by restaurants, cafés, and bars ("venues"). This policy explains what personal data we process, why, and what rights you have. It covers three groups of people: diners who scan a venue's menu, prospective venue owners who contact us, and venue staff who use our admin dashboard.
Data controller: [COMPANY LEGAL NAME — Estonian OÜ NOT YET REGISTERED, name pending incorporation], Private limited company (Osaühing, OÜ), incorporated in Estonia, [REGISTERED ADDRESS — pending Estonian OÜ registration]. Registration: [REGISTRATION NUMBER — Estonian Business Register code, assigned on incorporation] (Estonian Commercial Register (Äriregister / e-Business Register)). Contact: [email protected].
Depending on which of the three groups above you're in, we act in one of two different roles under data protection law, and the difference matters for who you should contact:
When you view a venue's menu, we set a session cookie so your cart is remembered as you browse, and (only when you pick a language yourself) a language-preference cookie. Both are strictly necessary for the ordering feature to work and do not require consent — see our Cookie Policy for the full list.
If you place a takeaway order, the venue asks for your name and phone number so it can contact you about pickup; this is stored against the order and is visible to that venue's staff. An optional note you add to your order or to individual dishes is stored the same way. We do not process payments ourselves — you pay the venue directly.
If you leave feedback after an order, your star rating and any comment are stored against that order and shared with the venue.
In every case here, the venue is the controller and we are the processor — see the section above.
If you submit a demo request or the contact form on our marketing site, we store the name, restaurant name, city, and contact details (email or phone) you provide, the page you came from, and a truncated version of your IP address, so we can follow up about our service. We are the controller for this data. The legal basis is our legitimate interest in responding to a business enquiry you initiated (and, once we're in discussion about a contract, taking pre-contractual steps at your request).
If a venue signs up, its owner and any staff they invite have an account with an email address, display name, and password (stored as a secure hash, never in plain text). A login session cookie keeps you signed in. The venue is the controller of staff account data; we process it as the venue's processor.
We use a small number of service providers ("sub-processors") to run the platform — infrastructure hosting and DNS/TLS, currently. We do not use advertising networks, and we do not sell personal data to anyone. The full, named list, and what each one does, is published on our Sub-processors page.
Depending on where you live, you have the right to access, correct, delete, restrict, or export your personal data, and to object to how we use it. To exercise any of these rights, use our data request form or contact us at [email protected]. If your data is about an order or account at a specific venue, we may need to forward your request to that venue, since they are usually the controller — we'll tell you when that's the case. We aim to respond within 30 days.
If you are in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority. Ours is Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, AKI).
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
We will update this page if what we do with your data changes, and update the version number and date shown at the top of this page.
Other documents