Privacy Policy
Aus rechtlichen Gründen ist diese Seite nur in englischer Sprache verfügbar.
Effective Date: 2026-07-22
Sea View Software GmbH (“we,” “our,” “us”) operates yourmenu.app (the “Service”) — a platform on which restaurants and other businesses (“Operators”) publish digital menus that guests (“Visitors”) view by scanning a QR code. This Privacy Policy explains how we collect, use, and share information under the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Data Controller
Sea View Software GmbH
Steinstraße 81–83, 35390 Gießen, Germany
Represented by the Managing Director: Robin Heller
Commercial register: HRB 12514, Amtsgericht Gießen · VAT ID (USt-IdNr.): applied for (“beantragt”)
Email: [email protected]
We have not appointed a dedicated Data Protection Officer as we are not required to do so under Art. 37 GDPR / §38 BDSG. For any data protection matters please use the contact details above.
2. Information We Collect
2.1 If you are an Operator (account holder)
Account information: your email address and, optionally, your name. Sign-in is passwordless via one-time email links — we never store a password for you.
Business and menu content: business name, category, menu items, prices, descriptions, photos, logos, translations and related settings you create.
Billing information: handled by our payment processor (Paddle, acting as Merchant of Record). Card details are collected and stored exclusively by Paddle; we never see your full card number.
Team invitations: the email addresses of teammates you invite.
Support communications: messages you send us by email.
2.2 If you are a Visitor viewing a menu
Viewing a published menu requires no account and sets no cookies. We process server logs (IP address, user agent, requested URL, timestamp — legal basis: Art. 6(1)(f) GDPR, legitimate interest in operating and securing the Service). Menu pages also load a first-party, cookie-free counting pixel so the menu’s operator can see how often it is viewed: we store only aggregate daily counts per menu (date, whether the visit came via the QR code, and the visit’s country at country level) — no IP address, no device identifier and no individual profile is stored with these counts. Legal basis: Art. 6(1)(f) GDPR.
2.3 Local storage (Operators, in the menu builder)
The builder app stores strictly necessary entries in your browser’s localStorage: your session tokens, your interface language, and your active workspace. Legal basis: §25(2) Nr. 2 TTDSG / Art. 6(1)(f) GDPR. We use no analytics, advertising or tracking cookies and no third-party trackers — which is why you will not see a cookie banner. Should this ever change, we will introduce a consent mechanism first.
3. Purposes of Processing
We process data to provide and maintain the Service and Operator accounts; to publish menus that Operators choose to make public; to process payments and send transactional email (sign-in links, billing notices, team invitations); to respond to support requests; to detect, prevent and investigate abuse, fraud or security incidents; and to comply with legal obligations (e.g. tax retention, invoicing).
4. Legal Bases
Art. 6(1)(b) GDPR (contract performance) for the Service and payments; Art. 6(1)(f) GDPR (legitimate interests) for security, logging and fraud prevention; Art. 6(1)(c) GDPR for statutory retention duties (e.g. §147 AO: up to 10 years for invoices).
5. Recipients and Sub-processors
We do not sell personal data. We share data only with providers processing on our behalf under Art. 28 GDPR agreements, or where legally required:
| Processor | Purpose | Location / safeguard |
|---|---|---|
| Paddle.com Market Ltd., Judd House, 18–29 Mora St, London EC1V 8BT, UK | Payments, invoicing, tax collection (Merchant of Record) | UK adequacy decision; SCCs for onward US transfers |
| Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA | CDN, DNS, DDoS protection, aggregate request statistics | Global edge network incl. EU PoPs; EU–US Data Privacy Framework; SCCs |
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Server hosting, database, file storage, backups | Germany (intra-EU) |
| Bunny.net (BunnyWay d.o.o.), Cesta komandanta Staneta 4A, 4270 Jesenice, Slovenia | Privacy-friendly web font delivery (fonts.bunny.net) | EU (intra-EU) |
| Email delivery provider (SMTP) | Transactional email (sign-in links, billing, invitations) | EU (intra-EU) |
We may additionally disclose personal data to competent authorities where legally obliged, and to professional advisors under confidentiality duties. In a merger, acquisition or asset sale, personal data may be transferred to the acquiring entity subject to the same protections.
6. International Data Transfers
Our infrastructure is located in Germany. Where personal data is transferred outside the EEA (primarily UK/US, see Section 5), we rely on adequacy decisions, the EU–US Data Privacy Framework for certified recipients, and EU Standard Contractual Clauses (2021/914). Copies of safeguards can be requested via the contact details in Section 1.
7. Your Rights under GDPR
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). Operators can delete their business or entire account directly in the app (Settings → Danger zone); this removes menus, media and account data and requests deletion of the associated payment customer record. To exercise any right, you can also email [email protected] — we respond within one month (Art. 12(3) GDPR).
If you are a Visitor and have questions about the content of a specific menu, the Operator of that business is the controller for the menu’s content; we will forward requests where appropriate.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany — https://datenschutz.hessen.de.
8. Data Retention
Account and menu data: for the duration of your account, plus up to 30 days in backups after deletion. Billing and invoice data: up to 10 years (§147 AO, §257 HGB). Server logs: deleted or anonymised within 30 days. Sign-in link tokens: stored only as hashes and expire within minutes. Support emails: up to 12 months after the case is closed.
9. Data Security
We implement appropriate technical and organisational measures per Art. 32 GDPR: TLS encryption in transit, hashed sign-in tokens (no stored passwords), tenant isolation at the database layer, least-privilege access controls and regular security reviews. In the event of a personal data breach affecting you, we will notify you and the supervisory authority per Art. 33–34 GDPR.
10. Automated Decision-Making
We do not engage in automated decision-making or profiling producing legal or similarly significant effects (Art. 22 GDPR).
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be announced on the website and, where required by law, communicated to you directly. The Effective Date above indicates the current version.