Privacy information for restaurant-page visitors
Prepared for review under the GDPR and applicable Austrian law
01 Controller and contact
TastyBee is operated by Alpenglocke e.U. The controller responsible for the platform processing described here is:
- Controller
- Alpenglocke e.U.
- Postal address
- [full postal address]
- Privacy contact
- [privacy contact email]
Restaurant owners receive information submitted to their restaurant and may have their own privacy responsibilities. Contact the restaurant directly about its subsequent use of reservation information.
02 Visiting a restaurant page
When a page is requested, TastyBee and its hosting providers process the technical information required to deliver it and protect the service. This can include the requested path, timestamp, browser request metadata, network address, and security or rate-limit information.
Some restaurant themes load typefaces from Google Fonts. The browser then contacts Google directly and sends technical request information under Google's own privacy practices. Restaurant pages may also contain social or directions links; the destination provider receives data only when your browser follows or otherwise requests that external resource.
03 Reservations
If a restaurant enables reservations, TastyBee processes the details you submit, including your name, email address or telephone number, party size, requested date and time, optional notes, and the reservation's status. The restaurant owner receives this information to review, confirm, manage, and fulfill the reservation.
This processing is performed to take the steps you request before receiving the restaurant's service, to provide the reservation functionality, and to protect against misuse. Do not include unnecessary sensitive information in reservation notes.
04 AI menu assistant
If a restaurant enables the menu assistant, TastyBee sends your question, recent conversation context, and relevant restaurant menu information to the configured AI provider to generate an answer. AI answers can be inaccurate and must not replace advice from restaurant staff about allergens or dietary requirements.
TastyBee stores your questions, generated answers, menu-item recommendations shown with those answers, selected language, request status, and timestamps for up to 30 days. The restaurant owner can review these conversations to understand visitor questions and improve its menu information. Conversation records do not include your IP address, cookies, or browser identifiers.
Do not include names, contact details, health information, or other sensitive personal information in your questions.
05 Reports, analytics, and providers
If you report a restaurant page, TastyBee stores the report reason, report details, an optional contact email, and technical anti-abuse information. A short-lived essential receipt cookie confirms a successful report submission.
Where configured, TastyBee uses Plausible to measure aggregate storefront visits. Tracking is configured to avoid form values and to limit the page address sent for analytics. TastyBee also uses hosting, database, object-storage, AI, and other infrastructure providers where necessary to deliver enabled storefront features.
Some providers may process data outside the European Economic Area. Where required, we use an applicable transfer mechanism and assess supplementary safeguards.
06 Retention and security
AI-assistant conversations are automatically deleted after 30 days and restaurant owners can delete them sooner. We keep other visitor data only as long as needed to deliver the requested feature, manage a reservation or report, meet legal obligations, resolve disputes, or protect the service. Reservation and report records are deleted or anonymized when no longer required, subject to legal obligations and legitimate claims.
We use access controls, encryption in transit, input validation, rate limits, and provider-access restrictions. No internet service can guarantee absolute security.
07 Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection to processing. You may withdraw consent without affecting earlier lawful processing. You may also lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority.
Send privacy requests to [privacy contact email]. We may need to verify your identity before acting on a request. Restaurant owners can read the separate Restaurant Owner Privacy Policy.