Privacy Policy
Last updated: 10 October 2026
Draft — company details are placeholders until the company is registered.
This Privacy Policy explains how [COMPANY NAME] (“we”, “us”) processes personal data in connection with Total-It, an online dashboard for bars and restaurants that use the Total-It point-of-sale system, and the website at [WEBSITE URL] (together, the “Service”). It is provided in accordance with the EU General Data Protection Regulation (“GDPR”) and applicable national data protection law.
1. Who is responsible
For the personal data described in section 3, the controller is [COMPANY NAME], [LEGAL FORM], registered office [REGISTERED ADDRESS], company number [COMPANY NUMBER]. For any privacy question or to exercise your rights, contact us at [PRIVACY EMAIL].
2. Our two roles: controller and processor
- Controller. We are the controller for personal data we process for our own purposes: user accounts, team invitations, billing, customer support, security and the operation of our website.
- Processor. Our customers’ tills send sales data (closed orders) to the Service. This data is primarily about transactions, but it may indirectly relate to identifiable people — for example, a staff member linked to a device, shift or table. For this sales data (“Customer Data”), the business using the Service is the controller and we act only as its processor, on its instructions, under our Data Processing Agreement. If you are a staff member or guest of one of our customers and have a question about such data, please contact that business directly; we will assist it in responding.
3. Personal data we process as controller
| Category | Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Account data | Email address, password (stored only in hashed form by our authentication provider), business name, venue names, time zone, role (owner, admin, viewer), language preference | Creating and managing your account, authenticating you, providing the Service | Performance of a contract (Art. 6(1)(b)) with the business you represent; where you act as an employee or team member of a customer, our and our customer’s legitimate interest in providing the Service to its team (Art. 6(1)(f)) |
| Team invitations | Invitee email address, assigned role, invitation status | Sending the invitation and linking the invitee to the right business | Legitimate interest of the inviting customer and us in enabling team access (Art. 6(1)(f)) |
| Billing data | Business name, billing address, VAT number, billing email, subscription plan and status, invoices, payment status. Card details are collected directly by Stripe and never reach our systems. | Billing, collecting payment, accounting, tax compliance | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for accounting and tax records |
| Support and communications | Name, email address, content of your messages, related account information | Responding to requests, service notices (e.g. changes to terms, prices, security notices) | Performance of a contract (Art. 6(1)(b)); legitimate interest in running our business (Art. 6(1)(f)) |
| Technical and security data | IP address, browser and device information, timestamps, login events, request logs, device identifiers of tills, error logs | Keeping the Service secure and available, preventing fraud and abuse, debugging, enforcing our Terms of Service | Legitimate interest in security and service integrity (Art. 6(1)(f)) |
| Legal matters | Data relevant to a dispute, claim or request from authorities | Establishing, exercising or defending legal claims; complying with lawful requests | Legal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f)) |
We do not use your personal data for advertising, we do not sell it, and we do not use analytics or tracking cookies (see our Cookie Policy). We may produce aggregated, anonymised statistics about use of the Service to operate and improve it; these statistics cannot identify you or any other individual.
Providing account data is necessary to use the Service; without it we cannot create an account. Billing data is necessary for paid plans.
4. Customer Data processed as processor
On behalf of our customers we process the data their tills send: product names, quantities, prices, VAT rates and amounts, table identifiers, number of covers, payment method identifiers, amounts, tips, timestamps and device identifiers. We do not receive or store card numbers or any card data (payments are semi-integrated and card data never enters our systems), and we do not collect guest names. We process this data only to provide the Service to the customer and as described in the Data Processing Agreement.
5. Recipients and sub-processors
We share personal data only with service providers that help us run the Service, under contracts that require them to protect it and use it only on our instructions:
- Supabase — database, authentication and data hosting. Data is hosted in [HOSTING REGION].
- Stripe — payment processing and subscription billing. Stripe collects card details directly and acts as an independent controller for certain processing (for example fraud prevention and its own legal obligations), as described in Stripe’s privacy policy.
- [WEB HOSTING PROVIDER] — hosting and delivery of the web application and website.
- [EMAIL PROVIDER] — sending transactional emails (sign-up confirmation, password reset, team invitations, billing and service notices).
We may also disclose personal data:
- to our professional advisers (lawyers, accountants, auditors) under duties of confidentiality;
- to authorities, courts or other third parties where required by law or to establish, exercise or defend legal claims;
- to a successor or acquirer in the context of a merger, acquisition or sale of all or part of our business, subject to equivalent protection;
- within a customer’s account: other team members of the same business can see your name or email address and role.
6. International transfers
We aim to store and process personal data within the European Economic Area (EEA). Some of our providers (for example Stripe, or our web hosting and email providers) may process data outside the EEA, including in the United States. Where personal data is transferred to a country that does not benefit from an adequacy decision of the European Commission, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, or on the provider’s certification under the EU-U.S. Data Privacy Framework where applicable, together with supplementary measures where necessary. You may request a copy of the relevant safeguards at [PRIVACY EMAIL].
7. Retention
- Account data is kept for as long as the account exists. After the account is closed or the contract ends, the customer has 30 days to export its data; we then delete account data and Customer Data from our live systems. Backups are purged within a further [BACKUP RETENTION PERIOD, e.g. 30] days.
- Team invitations are deleted when they are accepted (the data then becomes account data), revoked or expired, or together with the account.
- Billing records and invoices are kept for [LEGAL RETENTION PERIOD FOR INVOICES] as required by accounting and tax law.
- Support communications are kept for as long as needed to handle the request and for up to [SUPPORT RETENTION PERIOD, e.g. 2 years] afterwards, unless longer retention is needed for a legal claim.
- Security and technical logs are kept for a limited period of up to [LOG RETENTION PERIOD, e.g. 90 days], unless needed to investigate an incident.
- Data needed for a pending legal claim or investigation may be kept until it is resolved.
8. Security
We implement appropriate technical and organisational measures to protect personal data, including:
- encryption of data in transit using TLS (HTTPS) for the website, dashboard and till API;
- tenant isolation enforced at database level with row-level security, so that each business can access only its own data;
- passwords stored only in hashed form by our authentication provider; device keys stored only in hashed form;
- role-based access within each business (owner, admin, viewer);
- least-privilege access for our own staff and systems, limited to what is needed for operations and support;
- encryption at rest and regular backups provided by our hosting infrastructure;
- no storage of card data.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, you, in accordance with the GDPR.
9. Your rights
Subject to the conditions of the GDPR, you have the right to:
- access the personal data we hold about you and obtain a copy;
- have inaccurate data rectified;
- have your data erased;
- restrict processing;
- receive your data in a structured, commonly used, machine-readable format (data portability);
- object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests;
- withdraw any consent you have given, without affecting the lawfulness of processing before withdrawal.
To exercise your rights, email [PRIVACY EMAIL]. We may need to verify your identity. We will respond within one month, which may be extended by two further months where necessary. For Customer Data processed on behalf of a business, please contact that business; we will forward any request we receive to it.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement. Our lead supervisory authority is [SUPERVISORY AUTHORITY, e.g. the Belgian Data Protection Authority]. We would appreciate the chance to address your concerns first.
10. Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
11. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data of anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Cookies
We use only strictly necessary cookies (for login sessions, remembering the business you are viewing and your language). Details are in our Cookie Policy.
13. Changes to this policy
We may update this Privacy Policy from time to time. The date of the current version is shown at the top of this page. If we make material changes, we will inform account holders by email or in the Service before they take effect.
14. Contact
[COMPANY NAME], [REGISTERED ADDRESS]. Privacy questions: [PRIVACY EMAIL].