Privacy Policy
Last updated: September 3, 2026
1. Introduction
This Privacy Policy describes how Qartta («we») collects, uses, stores, and protects the personal information of users of our digital menu platform accessible at qartta.com. We are committed to protecting your privacy and to processing your data in accordance with the laws of the United States of America and, where applicable, the Commonwealth of Puerto Rico, as well as the principles of the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA) where those rules apply to your residence. By creating an account and accepting our terms, you consent to the processing of your data as described in this policy.
2. Information We Collect
We collect the following categories of information: (a) Account data: name, email address, and encrypted password, provided at registration. (b) Business data: business name, logo, images, description, product and service catalog, prices, locations, and hours of operation, which you voluntarily publish. (c) Usage data: information about how you interact with the Service, pages visited, actions performed, and visit statistics for your storefront (view counters without visitors' personal data). (d) Technical data: IP address, browser and device type, operating system, language, and session identifiers, collected automatically. (e) Payment data: when you subscribe to the Pro plan, processing is performed entirely through Stripe, Inc.; we do NOT store, process, or have access to your full payment card numbers. We receive from Stripe only reference identifiers (customer_id, subscription_id) and the subscription status. (f) Consent records: accepted terms version, date, time, IP address, and user agent, for legal evidence purposes.
3. How We Use Your Information
We use your information to: (a) create, operate, and maintain your account and digital storefront; (b) provide, improve, and personalize the Service; (c) process authentication and protect platform security; (d) manage the Pro plan subscription, billing, and collection through our payment processor; (e) generate aggregated and anonymous usage and visit statistics; (f) send you service communications (notifications, legal notices, terms changes); (g) comply with legal obligations and defend our rights. We do NOT sell, rent, or share your personal information with third parties for marketing purposes, and we never will without your explicit consent.
4. Legal Basis for Processing
We process your personal data on the following bases: (a) Contract performance: the data is necessary to provide the Service you subscribe to. (b) Consent: the record of your acceptance of these terms and this policy. (c) Legitimate interest: platform security, fraud prevention, and Service improvement. (d) Legal obligation: compliance with applicable laws and authority requirements. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
5. Storage and Security
Your data is stored on secure infrastructure provided by our vendors (Supabase, Inc. for database and authentication; Railway Corporation for application hosting), located in the United States. We implement technical and organizational security measures, including: multi-tenant isolation through Row Level Security (RLS) in the database, encryption in transit (TLS/HTTPS), cryptographically hashed passwords, signature verification in external integrations, role-based access control, and periodic vulnerability review. No system is infallible; we cannot guarantee absolute security, but we apply commercially reasonable industry standards. In the event of a data breach affecting your personal information, we will notify you without undue delay in accordance with applicable law.
6. Data Retention
We retain your account and business data while your account remains active. After account cancellation, your data is deleted or anonymized within a maximum of 30 days, unless the law requires longer retention periods (for example, tax or billing records, which are kept according to legal timeframes). Consent records (evidence of terms acceptance) are retained for at least 5 years from creation, for legal defense purposes. Aggregated and anonymous statistics may be retained indefinitely.
7. Sharing Data with Third Parties
We share your information only with the following essential service providers, which act as data processors: (a) Stripe, Inc. — payment processing and subscription management (United States). (b) Supabase, Inc. — database hosting, authentication, and file storage (United States). (c) Railway Corporation — application hosting (United States). (d) Cloudflare, Inc. — content delivery network and protection (United States). These providers only access the data necessary to provide their services and are bound by contractual confidentiality and security obligations. We do not share your data with any other entity, except: (i) legal requirement from a competent authority; (ii) protection of our legal rights; (iii) merger, acquisition, or sale of assets, with prior notice; or (iv) your explicit consent. Data Processing Agreements (DPAs) are maintained with subprocessors as required by applicable law; publicly available DPAs from our subprocessors can be referenced at their respective legal pages. International transfers: your data may be processed in the United States where our subprocessors operate. When data is transferred from the European Economic Area (EEA) or the United Kingdom, we rely on the legal mechanisms available under applicable data protection law, which may include Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework (DPF), or other appropriate safeguards. We ensure that any international transfer is subject to adequate protections as required by the GDPR.
8. Your Rights
You have the right to: (a) Access: request a copy of the personal data we hold about you. (b) Rectification: correct inaccurate or incomplete data. (c) Erasure: request deletion of your data («right to be forgotten»), subject to legal exceptions. (d) Portability: receive your data in a structured, commonly used format. (e) Objection: object to certain processing based on legitimate interest. (f) Restriction: request limitation of processing in certain cases. If you reside in the European Union or the European Economic Area, these rights are exercised under the GDPR, and you may file a complaint with your supervisory authority. If you reside in California, the CCPA/CPRA grants you additional rights, including the right to know, delete, and opt out of the «sale» or «sharing» of personal data; Qartta does not sell or share personal data, so no opt-out action is required. To exercise any of these rights, contact us at [email protected] — we will respond within a maximum of 30 days. To exercise your right to restriction of processing (Art. 18 GDPR) or your right to object (Art. 21 GDPR), please send a written request to [email protected] specifying the right you wish to exercise and the processing activity to which it relates. We will acknowledge receipt of your request within 5 business days and provide a substantive response within 30 days. If we are unable to fulfill your request, we will explain the reasons and inform you of your right to lodge a complaint with a supervisory authority.
9. Minors
The Service is not directed to individuals under 13 years of age (or the minimum age established by applicable law, which in no case will be lower than 13). We do not knowingly collect personal information from minors. If we become aware that we have collected data from a minor without proper parental consent, we will delete such data as soon as possible. If you are a parent or guardian and believe your child has provided us with personal data, please contact us to request its deletion.
10. Cookies and Tracking Technology
The Service uses cookies and similar technologies (local storage) to: keep you logged in, remember preferences (language, theme), and protect the platform against abuse. We do not use third-party advertising cookies or marketing trackers. We collect server-side analytics data to understand how the Service is used and to improve it. This includes: • Page views and visit duration • Referral sources (how you found us) • Device type (mobile, tablet, desktop) • QR code scan events (when you access via QR code) • Product and service engagement (views, clicks, interactions) • Time-of-day patterns (to help businesses understand peak hours) All analytics data is collected on our own infrastructure and does not involve third-party tracking cookies. Analytics data is aggregated and anonymized — we do not track individual user behavior across sessions. You can configure your browser to reject cookies, but some Service features may not work correctly.
11. Changes to This Policy
We may update this Privacy Policy periodically. The current version will be published on this page with its update date. Substantial changes will be notified by email and/or through a notice within the Service. Continued use of the Service after the changes are published constitutes your acceptance. Previous versions of the policy are kept archived for evidence purposes.
12. Contact
For any question, request, or complaint regarding this Privacy Policy or the processing of your personal data, you may contact us at: Qartta, San Juan, Puerto Rico, email: [email protected]. We will respond to all requests within a maximum of 30 days. Last updated: August 19, 2026.

