Privacy Policy

Last updated: August 2, 2026

1. Data Controller

MrGarson
Address: Bari, Italia
Email: info@mrgarson.com
PEC: mrgarson@pec.it

2. Data Collected

We collect the following categories of personal data:

  • Identity data: name, surname, email, phone number, business name, VAT number, fiscal code.
  • Browsing data: IP address, browser type, operating system, pages visited, access time. This data is collected anonymously and in aggregate through logging and analytics systems.
  • Geolocation data: country of origin (determined via IP) for automatic language and currency selection. Precise location is not tracked.
  • Payment data: managed entirely by Stripe and/or PayPal. We do not store credit card numbers on our servers.
  • Voluntarily provided data: menu content, product photos, support messages.

3. Purpose of Processing

  • Providing the digital menu service and managing the user account.
  • Payment and subscription management.
  • Service-related communications (changes, expirations, support).
  • Anonymous statistical analysis to improve the service.
  • Compliance with legal and tax obligations.
  • Management of the Ambassador and Country Manager program.

4. Legal Basis

Data processing is based on: (a) performance of the service contract, (b) explicit user consent where required, (c) legitimate interest of the controller for security and service improvement purposes, (d) compliance with legal obligations.

5. Data Retention

Personal data is retained for the duration of the contractual relationship and for the following 10 years as required by Italian tax regulations. Anonymous browsing data is retained for a maximum of 26 months. Users may request deletion of their data at any time, subject to legal obligations.

6. Data Sharing

Personal data is not sold to third parties. It is shared only with the technical providers strictly necessary for the operation of the service, listed below together with the type of data they receive:

  • Stripe (Ireland/USA) — subscription payments. Receives identity and payment data of the restaurant owner.
  • Aruba S.p.A. (Italy) — server hosting and transactional email delivery via SMTP. Receives all data that transits on the service.
  • Google AI — Gemini (USA) — menu photo recognition ("Snap and Create") and allergen suggestions. Receives the photo or menu text that the restaurant owner explicitly submits for analysis.
  • Groq Inc. (USA) — automatic translation of menu content and description generation. Receives menu text (dish names, descriptions).
  • LibreTranslate (European server) — fallback automatic translation if Groq and Google do not respond. Receives the same texts as above.
  • OpenStreetMap / Nominatim (OSM Foundation, Germany) — conversion of addresses into GPS coordinates (delivery radius, venue map). Receives the addresses typed by the restaurant owner or the end customer.
  • Competent authorities — only when required by law.

A data processing agreement (DPA, art. 28 GDPR) is in place (or will be in place before actual use) with each provider.

7. Extra-EU Transfer

Some technical providers listed in section 6 are based in the United States (Google, Groq, Stripe). In these cases the transfer is based on Standard Contractual Clauses (SCC) approved by the European Commission, or — where available — on the provider's certification under the EU-US Data Privacy Framework. Users may request a copy of the safeguards by contacting the controller at the address shown at the bottom of this document.

8. Data Subject Rights

Under Articles 15-22 of EU Regulation 2016/679 (GDPR), users have the right to:

  • Access their personal data.
  • Obtain rectification of inaccurate data.
  • Obtain erasure of data (right to be forgotten).
  • Restrict processing.
  • Object to processing.
  • Data portability.
  • Withdraw consent at any time.
  • Lodge a complaint with the Data Protection Authority.

To exercise your rights, contact: info@mrgarson.com

9. Security

We adopt adequate technical and organizational measures to protect personal data, including: SSL/TLS encryption for all communications, secure password hashing (bcrypt), regular backups, data access limited on a "need-to-know" basis.

10. Changes

We reserve the right to modify this policy. Changes will be published on this page with the date of last update.

11. End-Customer Data of the Restaurant

When a restaurant customer uses the digital menu (places an order, leaves a review, selects a table, requests home delivery), they may provide personal data such as name, phone, delivery address, comment. For this data:

  • The restaurant owner is the Data Controller: they decide the purposes and means of use of that data.
  • MrGarson acts as Data Processor pursuant to art. 28 GDPR: it provides only the technical infrastructure on the restaurant owner's instructions.
  • The restaurant owner is required to provide their own privacy notice to their end customers and to collect consent where necessary.
  • This data is stored on MrGarson's infrastructure for the time needed to fulfill the order or publish the review, and is deleted when the restaurant owner closes their account or upon their explicit request.