Privacy information for restaurant accounts
Prepared for review under the GDPR and applicable Austrian law
01 Controller and contact
TastyBee is operated by Alpenglocke e.U. The controller responsible for the account and platform processing described here is:
- Controller
- Alpenglocke e.U.
- Postal address
- [full postal address]
- Privacy contact
- [privacy contact email]
02 Account and restaurant data
We process data needed to create, secure, and operate restaurant accounts and public pages. Depending on the features used, this can include:
- Account email addresses, one-time login records, authentication cookies, Terms acceptance version and time, and security or rate-limit data.
- Restaurant profile details, menus, opening hours, images, social links, customizations, reservations settings, and translation settings.
- Billing status and transaction references received from Paddle. We do not store complete payment-card details.
- Content submitted for optional translation, menu import, or AI-assistant configuration.
- Technical request information required to operate, diagnose, and protect the service.
We generally process this data to perform the TastyBee service contract or requested pre-contractual steps, comply with legal obligations, and pursue legitimate interests in operating a secure and reliable platform. The separate Storefront Privacy Policy describes visitor and reservation data.
03 Google Maps and Places
Authenticated restaurant owners can search for and select their restaurant using Google Maps Platform Places API features. When this feature is used, TastyBee sends the search text, a random search-session token, and the selected Google Place ID to Google through TastyBee's server. Google receives the technical information needed to process those requests.
Search suggestions and place details are provided by Google Maps. When an owner selects a result during onboarding, TastyBee stores the selected Place ID and the returned profile fields as a draft, then asks the owner to review and correct them before publishing the restaurant page. In the admin profile search, populated fields are stored only when the owner submits the profile form.
Google processes data under its own terms and privacy policy. Use of Google Maps features and content is subject to the current Google Maps End User Additional Terms of Service and Google Privacy Policy.
04 Service providers and recipients
We use service providers where necessary to host and operate TastyBee. Depending on enabled features, recipients can include hosting and database providers, email-delivery providers, Paddle for billing, Plausible for privacy-focused analytics, Google Maps Platform, configured AI providers, document-extraction providers, and object-storage providers.
Restaurant owners receive reservation data submitted to their restaurant page. We may also disclose data where required by law, to establish or defend legal claims, or to protect users and the service. Some providers may process data outside the European Economic Area; where required, we use an applicable transfer mechanism and assess supplementary safeguards.
05 Cookies and account security
TastyBee uses essential signed cookies to keep owners authenticated and protect security-sensitive flows. Administrative interface preferences and short-lived workflow state may be stored in the browser. We use access controls, input validation, request limits, and provider-access restrictions to protect account data.
06 Retention
We keep account and restaurant data while the service is active and thereafter only as needed to meet legal retention duties, resolve disputes, or protect the service. Authentication codes expire after a short period. Security and operational records are retained for limited periods appropriate to their purpose. Account, restaurant, billing, translation, and related records are deleted or anonymized when no longer required, subject to legal obligations and legitimate claims.
07 Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection to processing. You may withdraw consent without affecting earlier lawful processing. You may also lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority.
Send privacy requests to [privacy contact email]. We may need to verify your identity before acting on a request.