Privacy Policy
What Ordevia collects, why, who it reaches, and the rights you have over it.
Version 2.1 · Effective 10 September 2026
Who is responsible
Ordevia is a digital menu and ordering service for restaurants, operated by a registered business. The operator's full registration details, country of registration included, are provided on request to any customer, data subject, or competent authority — write to support@ordevia.app. Throughout this policy, "Ordevia", "we" and "us" mean that operator.
Ordevia provides restaurants with a digital menu that diners open by scanning a QR code at their table, together with the ordering, kitchen and service tools behind it. Questions about this policy, or any request about your data, go to support@ordevia.app.
Two different relationships are covered here. When a restaurant signs up, we hold data about that business and its team. When you scan a QR code as a diner, we hold a small amount of data about that visit — you never create an account, and we want to keep it that way.
If you scanned a QR code (diners)
Scanning a QR code opens a temporary session so the menu can remember your basket and show you the orders you placed. We collect the minimum needed for that to work and for the restaurant to spot abuse of its QR codes.
- Session record
- The public IP address of the device you scanned with, a coarse device marker, and the start and expiry times of the session. The IP address lets us recognise a returning device during the same visit and helps a restaurant see when its QR image has leaked outside the venue.
- Information about your device
- What kind of device you opened the menu on: whether it is a phone, tablet or computer, its operating system and major version (for example Android 14), and which browser you used. On Android devices we also record the model code the browser reports, such as SM-S911B. We do not store the full technical description your browser sends, and we never use any of this to recognise you on other websites. Restaurants use it to answer practical questions — whether their menu needs to work well on older phones, or whether most of their guests arrive from a link shared in a messaging app. It is attached to your ordering session and deleted with it.
- Location check
- If you allow it, your browser gives us your coordinates so we can measure how far you are from the restaurant. We store only the result of that measurement — a flag meaning near, far, permission refused, or unavailable. Your latitude and longitude are used for that calculation and are never written to our database.
- Your phone number, for a takeaway order only
- If you order to take away, the restaurant may ask for a phone number so it can call you when your food is ready. It is used for that and nothing else: it is shown to the restaurant's own staff on the screen holding your order, it is never used to market anything to you, and it never leaves the restaurant that took the order. Each restaurant decides whether to ask at all — if yours does not, no number is collected. You are asked on the ordering screen, before the order is sent, so choosing not to give one simply means not placing that order.
- How long the restaurant keeps your number
- Until it deletes it. The restaurant can see the numbers that have ordered from it, how many times each one has ordered and what it spent, so that it can recognise a regular. Ask the restaurant to erase your number and it can do so in one action: the number is removed from every order it appears on, and the orders stay without it. A restaurant can also refuse a number, in which case that number cannot place another order there — that decision belongs to that restaurant alone and means nothing at any other.
- Your name and number, when you book a table
- If you ask the restaurant for a table, it needs a name to hold the booking under and a phone number to reach you on — to confirm it, or to tell you if it cannot. Both are shown to that restaurant's own staff on the screen that holds the booking, are used for nothing else, are never used to market anything to you, and never leave the restaurant you booked with. Anything you type in the note is passed straight to the same screen, so please do not put personal details there. Each restaurant decides whether it takes bookings at all — if yours does not, the button is not shown and nothing is collected.
- How long the restaurant keeps a booking
- Until it deletes it. A restaurant keeps its past bookings so it can count how many people it seated, how much notice guests give, and how often a booked table went empty. Ask the restaurant to erase your details and it can remove them. You can cancel a booking yourself from the menu at any time before you arrive, and a booking you cancel is kept only as a cancelled entry in that restaurant's own record.
- Orders and messages
- The items you order, any note you attach to them, and any message you send when calling a waiter. Please do not put personal details in a free-text note — it is passed straight to the restaurant's kitchen and service screens.
- Three cookies
- The first holds the identifier of your ordering session, so the menu can remember your basket and your orders. The second holds a random number that stands for your device, so the restaurant's visitor count does not go up every time you reload the page — a device counts once a day, however often it looks. The third simply remembers which language you are reading the menu in, so it opens in that language next time: it holds a restaurant's short name and a language code, nothing more. None of them holds your name, your location, or anything about you. The first two are signed so they cannot be tampered with and are not readable by scripts; all three are ours alone — they are never sent to any other company and cannot follow you to any other website. We use no advertising cookies and no cross-site tracking cookies.
- A copy of the device number, kept in your browser
- The same random device number is also stored in your browser's own storage, so that a device is still recognised as itself if the cookie is removed by the browser — which happens routinely, for reasons that have nothing to do with you. It is the same number and nothing more; clearing your browsing data for this site removes both copies together.
- A fourth cookie, only on a restaurant's own devices
- If somebody who works at the restaurant opens their own menu from their dashboard, we mark that device so their visits are not counted as customer visits. The mark holds the restaurant's short name, nothing about the person, and the menu shows a small badge saying so with a one-tap way to remove it. It never appears on a guest's device.
We do not ask for your name, your phone number or your email. We do not track you across restaurants or across the web, we do not build a profile of you, and we do not sell or share your data with advertisers.
You pay the restaurant directly, at the table. No payment is ever taken through Ordevia, so we hold no card or banking details of any kind.
If you run or work at a restaurant
- Your account
- Your email address and a securely hashed password, held by our authentication provider, plus your role in the restaurant and when you signed in.
- Your restaurant
- Its name, address, coordinates, phone number, opening hours, menu, photographs and settings. For a small owner-run venue some of this identifies a person, so we treat it with the same care.
- Team activity
- An activity log recording who did what — publishing a menu, changing settings, inviting a colleague — with the name, email and role of the person who did it. It exists so an owner can see what happened in their own restaurant.
- Invitations
- The email address, and optionally the phone number, of a colleague you invite, until the invitation is accepted or revoked.
- Notifications
- Your notification preferences, the notifications sent to you, and — if you enable them — the browser subscription details needed to deliver push notifications, including your browser's user-agent string.
- Subscription
- Your plan, trial and billing period dates, and a history of the changes made to them. Invoices are issued and paid outside the platform; we hold no card details.
- Security records
- IP addresses of failed staff-PIN attempts, kept to block brute-force guessing of the code that unlocks kitchen and service screens.
During onboarding, if your browser cannot provide your location, you can ask us to estimate your restaurant's country and city from your IP address. That request sends your IP address to a third-party lookup service. It happens only when you are signed in and only for that purpose, and diners' IP addresses are never sent to it.
Why we process it
- To run the service you asked for: showing the menu, taking orders, routing them to the kitchen and service screens.
- To keep accounts and restaurants secure, and to prevent abuse — including brute-force protection and spotting QR codes that have leaked outside a venue.
- To show a restaurant analytics about its own activity, so it can understand its menu and its service.
- To send you notifications you have chosen to receive.
- To manage subscriptions and issue invoices.
- To fix faults, using error reports that tell us what broke.
We do not use your data for advertising, and we do not make automated decisions that produce legal effects about you.
Automated menu tools
When a restaurant uses our assisted menu features, the photographs and menu text it uploads are sent to Google's Gemini service to read the menu and, if asked, translate it. The restaurant always reviews and publishes the result — nothing produced this way reaches diners automatically.
A note for restaurant owners: photograph your menu somewhere quiet. If customers or staff are visible in the frame, their image is uploaded along with the menu.
Where your data is processed
Ordevia's infrastructure is not in the country the operator is registered in. The providers listed above host data abroad, so running the service involves transferring personal data across borders. The data-protection law that applies to us regulates those transfers, and we are working through the formalities it requires with the competent authority. We prefer to say so plainly rather than leave it unsaid. If this matters to you, write to support@ordevia.app.
How long we keep it
- Diner sessions
- A session expires shortly after your visit — each restaurant sets that window for itself, and you can ask us what it is. Expired session records are not yet deleted on an automatic schedule; we are introducing one, and until then you can ask us to delete yours.
- The device cookie
- The random number that stops a restaurant's visitor count rising every time you reload lasts up to 400 days on your device, and slides forward each time you visit. Clearing your browsing data for this site removes it — both the cookie and the copy your browser keeps — and the next visit simply counts as a new device. It is never linked to your name, an account, or anything you order.
- The menu-language cookie
- The language you are reading a menu in is remembered for a year, so the menu opens in it next time. Clearing your browser's cookies removes it.
- Orders
- Kept while they are useful to the restaurant for its own records and analytics.
- Accounts
- Kept while the account exists. Closing it removes the account and its personal details.
- Restaurant data
- After a subscription ends, the restaurant can export its data for thirty days, after which it is deleted.
- Security and audit records
- Kept only as long as they serve their purpose — short for PIN attempts, longer for activity and subscription history.
How we protect it
- Every connection to Ordevia is encrypted in transit.
- Each restaurant's data is isolated at the database level, so one restaurant can never read another's — this is enforced by the database itself, not only by application code, and is covered by automated tests.
- Passwords are stored hashed, never in readable form.
- The session and device cookies are signed, restricted to our own site, and not readable by scripts.
- Access to production data is limited to the operator.
No service can promise perfect security. If a breach ever affects your data, we will tell those affected and the competent authority.
Your rights
Under the data-protection law that applies to us, you may ask us to:
- confirm what data we hold about you, and give you a copy;
- correct anything inaccurate or incomplete;
- delete data we no longer have a reason to keep;
- stop a particular processing, including where it relies on your consent;
- withdraw consent you previously gave — the location check being the clearest example.
Write to support@ordevia.app. We answer within a reasonable time and never charge for it. As a diner you will not have an account to prove ownership with, so tell us roughly when and where you scanned, and we will find the session.
You may also complain to the data-protection authority that supervises us. Write to us and we will name it and tell you how to reach it.
Children
Ordevia is meant for restaurant customers and staff and is not directed at children. We do not knowingly collect data from a child. A diner session holds no identifying details unless a phone number is given for a takeaway order, and that is asked for on screen, is never required to read a menu, and can be erased by the restaurant on request. If you believe a child's data reached us, tell us and we will delete it.
Changes to this policy
If this policy changes we update the version and effective date shown at the top of the page, and keep a record of what changed. Substantive changes are notified to subscribing restaurants.
Contact
Ordevia is a digital menu and ordering service for restaurants, operated by a registered business. The operator's full registration details, country of registration included, are provided on request to any customer, data subject, or competent authority — write to support@ordevia.app. Email: support@ordevia.app.