Privacy
Privacy Policy
Effective date: May 31, 2026 · Last updated: May 31, 2026
The short version
We collect the minimum data needed to run Cartely: your email and name from Google sign-in, the menu content you create, and anonymous daily counts of how many times your menu was scanned. We do not sell your data. We do not show ads. We do not track diners. You can delete your account at any time and we will remove your data within 30 days.
Who we are (Data controller)
For purposes of GDPR, CCPA, and similar laws, the data controller is the operator of cartely.app. Contact: privacy@cartely.app. You may also reach our team at support@cartely.app.
What we collect
- Account information — your email address and name from Google when you sign in. Source: Google OAuth.
- Restaurant information — anything you enter: restaurant name, menu URL slug, logo, brand color, menus, sections, items, prices, descriptions. Source: you.
- Billing information — handled entirely by Stripe. We store a Stripe customer ID, subscription status, and billing interval. We never see or store your card number, CVV, or expiration date.
- Menu view counts — when someone scans your QR code, we increment a daily counter (for example, "12 scans on May 31"). We do not store who scanned, their IP, their device fingerprint, or any identifying information about the diner.
- Authentication cookies — a session cookie set by Supabase to keep you signed in. No tracking, analytics, or advertising cookies.
- Standard server logs — request paths, timestamps, and error traces from Vercel for operational reliability. Retained for up to 30 days then deleted.
What we do not collect
- We do not track diners who scan your QR code beyond an anonymous daily count.
- We do not use third-party advertising trackers, pixels, retargeting tags, or any analytics that share data with ad networks.
- We do not fingerprint browsers.
- We do not read your Google contacts, files, calendar, or any other Google data — only your name and email.
- We do not sell, rent, or trade your personal information to anyone.
Legal bases for processing (GDPR Article 6)
If you are in the European Economic Area, United Kingdom, or Switzerland, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the service you signed up for, process billing, and deliver transactional emails.
- Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve the service, including anonymous scan counters, server logs, and fraud prevention.
- Compliance with legal obligations (Art. 6(1)(c)) — to retain billing records as required by law.
- Consent (Art. 6(1)(a)) — for any future marketing communications, which we will request explicit opt-in for.
How we use your data
- To authenticate you and let you manage your menus.
- To render your public menu pages to your guests.
- To process billing and provide customer support.
- To send transactional emails (sign-in confirmations, billing receipts, important account notices). We do not send marketing emails without explicit opt-in.
- To detect abuse, fraud, and security incidents.
- To comply with our legal obligations.
Subprocessors
We use a small set of vetted infrastructure providers. Each one only sees the data necessary to provide their service. We maintain Data Processing Agreements with each subprocessor.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Vercel | Application hosting, edge delivery | United States (global edge) |
| Stripe | Payment processing | United States |
| Google (OAuth) | Sign-in authentication | United States |
| Cloudflare | DNS, edge security | Global |
We will provide at least 30 days' notice before adding or changing material subprocessors. To object to a new subprocessor or request our current DPA, email privacy@cartely.app.
International data transfers
Our infrastructure providers operate primarily in the United States. If you are in the EEA, UK, or Switzerland, your data may be transferred to the US. These transfers are protected by Standard Contractual Clauses (SCCs) signed with our subprocessors.
Your rights
If you are in the EEA, UK, or Switzerland (GDPR), you have the right to:
- Access (Art. 15) — request a copy of the personal data we hold about you.
- Rectification (Art. 16) — correct inaccurate or incomplete data. Most data can be edited directly in your Cartely dashboard.
- Erasure / right to be forgotten (Art. 17) — request deletion of your account and personal data.
- Restriction (Art. 18) — ask us to stop processing your data while a dispute is resolved.
- Portability (Art. 20) — receive your data in a machine-readable format.
- Object (Art. 21) — object to processing based on legitimate interests.
- Lodge a complaint with your local data protection authority.
If you are a California resident (CCPA / CPRA), you have the right to know what personal information we collect, request deletion, correct inaccuracies, and to non-discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising, so the "Do Not Sell or Share My Personal Information" right does not require action.
If you are a Virginia, Colorado, Connecticut, or Utah resident, you have similar access, deletion, correction, and portability rights under the VCDPA / CPA / CTDPA / UCPA.
To exercise any right, email privacy@cartely.app. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.
Cookies and similar technologies
| Name | Purpose | Type | Duration |
|---|---|---|---|
| sb-* (Supabase) | Keeps you signed in | Strictly necessary | Session / up to 1 year |
| cartely_location | Which restaurant you're editing (multi-location) | Strictly necessary preference | 1 year |
| cartely_currency | Localized pricing on the billing page (set only after sign-in) | Strictly necessary preference | 1 year |
| cartely_cookie_notice_v1 | Remembers you've dismissed the cookie notice (browser localStorage) | Strictly necessary | Until cleared |
Under the EU ePrivacy Directive (Art. 5(3)), UK PECR (Reg. 6), and analogous rules in Switzerland, Brazil, California, Virginia, Colorado, Connecticut, Utah, and other jurisdictions, strictly necessary cookies do not require prior opt-in consent. We still display a one-time cookie notice on first visit so you are informed before any preference cookie is set.
If we ever add analytics or marketing cookies, we will (a) update this policy, (b) replace the one-time notice with a granular consent prompt that offers Accept and Reject equally prominently, and (c) honor Global Privacy Control (GPC) signals automatically.
"Do Not Sell or Share My Personal Information" (California CPRA / CCPA, Colorado, Connecticut, Texas): Cartely does not sell your personal information for money or share it for cross-context behavioral advertising. There is nothing to opt out of. If our practices change, this section will be updated and you will be presented with an explicit opt-out link both here and in the footer of every page. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out request.
Data retention
We keep your account data for as long as your account is active. If you delete your account, we permanently remove your data within 30 days, with two exceptions: standard infrastructure backups may retain it for up to 90 days, and billing records that we are legally required to keep (typically 7 years for tax purposes).
Anonymous scan counters are retained indefinitely in aggregated form because they contain no personal information.
Security
All connections to Cartely are encrypted with TLS (HTTPS). Data at rest is stored in Supabase's managed Postgres with AES-256 encryption and row-level security enforcing per-account isolation. We do not store passwords because we use Google OAuth.
In the event of a personal data breach affecting your data, we will notify you and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Article 33.
If you become aware of a security issue, please email security@cartely.app.
Children
Cartely is a tool for restaurants and is not directed to children. We do not knowingly collect data from anyone under 16. If you believe we have collected data from a child, contact us and we will delete it.
Changes to this policy
If we make material changes, we will update the "Last updated" date and notify you by email at least 30 days before the changes take effect.
Contact
Questions, requests, or concerns? Email privacy@cartely.app. We respond within 5 business days.