Privacy Policy

What Ordevia collects, why, who it reaches, and the rights you have over it.

Version 1.0 · Effective 21 July 2026

Who is responsible

Ordevia is operated by an auto-entrepreneur registered in Tunisia under the Moubadir Dhati regime (décret-loi n° 2020-33), unique identifier 1981483Y. Throughout this policy, "Ordevia", "we" and "us" mean that operator.

Ordevia provides restaurants with a digital menu that diners open by scanning a QR code at their table, together with the ordering, kitchen and service tools behind it. Questions about this policy, or any request about your data, go to support@ordevia.app.

Two different relationships are covered here. When a restaurant signs up, we hold data about that business and its team. When you scan a QR code as a diner, we hold a small amount of data about that visit — you never create an account, and we want to keep it that way.

If you scanned a QR code (diners)

Scanning a QR code opens a temporary session so the menu can remember your basket and show you the orders you placed. We collect the minimum needed for that to work and for the restaurant to spot abuse of its QR codes.

Session record
The public IP address of the device you scanned with, a coarse device marker, and the start and expiry times of the session. The IP address lets us recognise a returning device during the same visit and helps a restaurant see when its QR image has leaked outside the venue.
Location check
If you allow it, your browser gives us your coordinates so we can measure how far you are from the restaurant. We store only the result of that measurement — a flag meaning near, far, permission refused, or unavailable. Your latitude and longitude are used for that calculation and are never written to our database.
Orders and messages
The items you order, any note you attach to them, and any message you send when calling a waiter. Please do not put personal details in a free-text note — it is passed straight to the restaurant's kitchen and service screens.
A cookie
One cookie, holding the identifier of your session and nothing else. It is signed so it cannot be tampered with, and it is not readable by scripts. We use no advertising or tracking cookies.

We do not ask for your name, your phone number or your email. We do not track you across restaurants or across the web, we do not build a profile of you, and we do not sell or share your data with advertisers.

You pay the restaurant directly, at the table. No payment is ever taken through Ordevia, so we hold no card or banking details of any kind.

If you run or work at a restaurant

Your account
Your email address and a securely hashed password, held by our authentication provider, plus your role in the restaurant and when you signed in.
Your restaurant
Its name, address, coordinates, phone number, opening hours, menu, photographs and settings. For a small owner-run venue some of this identifies a person, so we treat it with the same care.
Team activity
An activity log recording who did what — publishing a menu, changing settings, inviting a colleague — with the name, email and role of the person who did it. It exists so an owner can see what happened in their own restaurant.
Invitations
The email address, and optionally the phone number, of a colleague you invite, until the invitation is accepted or revoked.
Notifications
Your notification preferences, the notifications sent to you, and — if you enable them — the browser subscription details needed to deliver push notifications, including your browser's user-agent string.
Subscription
Your plan, trial and billing period dates, and a history of the changes made to them. Invoices are issued and paid outside the platform; we hold no card details.
Security records
IP addresses of failed staff-PIN attempts, kept to block brute-force guessing of the code that unlocks kitchen and service screens.

During onboarding, if your browser cannot provide your location, you can ask us to estimate your restaurant's country and city from your IP address. That request sends your IP address to a third-party lookup service. It happens only when you are signed in and only for that purpose, and diners' IP addresses are never sent to it.

Why we process it

  • To run the service you asked for: showing the menu, taking orders, routing them to the kitchen and service screens.
  • To keep accounts and restaurants secure, and to prevent abuse — including brute-force protection and spotting QR codes that have leaked outside a venue.
  • To show a restaurant analytics about its own activity, so it can understand its menu and its service.
  • To send you notifications you have chosen to receive.
  • To manage subscriptions and issue invoices.
  • To fix faults, using error reports that tell us what broke.

We do not use your data for advertising, and we do not make automated decisions that produce legal effects about you.

Automated menu tools

When a restaurant uses our assisted menu features, the photographs and menu text it uploads are sent to Google's Gemini service to read the menu and, if asked, translate it. The restaurant always reviews and publishes the result — nothing produced this way reaches diners automatically.

A note for restaurant owners: photograph your menu somewhere quiet. If customers or staff are visible in the frame, their image is uploaded along with the menu.

Who else sees your data

We do not sell personal data and we do not share it for anyone else's marketing. We rely on a small number of service providers, each processing data only to provide their service to us:

Supabase
Database, authentication and file storage — the platform's primary data store.
Vercel
Application hosting. Handles every request to the service, and therefore sees visitors' IP addresses, and keeps short-lived server logs.
Google (Gemini)
Reading and translating menus, when a restaurant uses those features.
Sentry
Error reporting, so faults can be diagnosed. Hosted in the European Union.
An IP geolocation service
Estimating a restaurant's country and city during onboarding, at the owner's request. Diner data is never sent to it.

The orders and messages you send as a diner are, of course, shown to the restaurant you sent them to. We may also disclose data where the law requires it.

Where your data is processed

Ordevia is operated from Tunisia, but its infrastructure is not. The providers listed above host data outside Tunisia, so operating the service involves transferring personal data abroad. Tunisian law (loi organique n° 2004-63) regulates such transfers, and we are working through the required formalities with the national data-protection authority. We prefer to say so plainly rather than leave it unsaid. If this matters to you, write to support@ordevia.app.

How long we keep it

Diner sessions
A session expires shortly after your visit — the restaurant sets the window, typically thirty minutes. Expired session records are not yet deleted on an automatic schedule; we are introducing one, and until then you can ask us to delete yours.
Orders
Kept while they are useful to the restaurant for its own records and analytics.
Accounts
Kept while the account exists. Closing it removes the account and its personal details.
Restaurant data
After a subscription ends, the restaurant can export its data for thirty days, after which it is deleted.
Security and audit records
Kept only as long as they serve their purpose — short for PIN attempts, longer for activity and subscription history.

How we protect it

  • Every connection to Ordevia is encrypted in transit.
  • Each restaurant's data is isolated at the database level, so one restaurant can never read another's — this is enforced by the database itself, not only by application code, and is covered by automated tests.
  • Passwords are stored hashed, never in readable form.
  • The session cookie is signed, restricted to our own site, and not readable by scripts.
  • Access to production data is limited to the operator.

No service can promise perfect security. If a breach ever affects your data, we will tell those affected and the competent authority.

Your rights

Under loi organique n° 2004-63 you may ask us to:

  • confirm what data we hold about you, and give you a copy;
  • correct anything inaccurate or incomplete;
  • delete data we no longer have a reason to keep;
  • stop a particular processing, including where it relies on your consent;
  • withdraw consent you previously gave — the location check being the clearest example.

Write to support@ordevia.app. We answer within a reasonable time and never charge for it. As a diner you will not have an account to prove ownership with, so tell us roughly when and where you scanned, and we will find the session.

You may also complain to the Instance Nationale de Protection des Données à Caractère Personnel (INPDP) in Tunisia.

Children

Ordevia is meant for restaurant customers and staff and is not directed at children. We do not knowingly collect data from a child, and a diner session holds no identifying details in any case. If you believe a child's data reached us, tell us and we will delete it.

Changes to this policy

If this policy changes we update the version and effective date shown at the top of the page, and keep a record of what changed. Substantive changes are notified to subscribing restaurants.

Contact

Ordevia is operated by an auto-entrepreneur registered in Tunisia under the Moubadir Dhati regime (décret-loi n° 2020-33), unique identifier 1981483Y. Email: support@ordevia.app.