Legal
Privacy Policy
Last updated: June 2026
1. Data controller
The data controller for personal data collected through Bookarta (bookarta.eu) is Bookarta. For any privacy-related enquiries, contact us at info@bookarta.es.
2. Data we collect
We collect the following personal data:
- Registration data: name, email address and password when creating an account.
- Payment data: processed entirely by Stripe. Bookarta does not store card details.
- Restaurant data: name, address, phone, opening hours, logo, photos and menu information that the user voluntarily provides.
- Usage data: statistics on visits to the digital menu (page views, without personally identifying visitors).
- Technical data: IP address, browser type and operating system, collected automatically for the proper functioning of the service.
- Google account data: if you sign in with "Sign in with Google", we receive your name, email address and profile picture. If you connect Google Calendar, we access only the calendar events created by Bookarta in order to sync your reservations; we do not read the rest of your calendar.
3. Purpose of processing
We use your data to:
- Provide and manage the digital menu service.
- Process payments and manage subscriptions.
- Send service-related communications (confirmations, technical notices).
- Improve and develop new features.
- Comply with legal obligations.
4. Legal basis
Processing is based on the performance of the service contract accepted upon registration (Art. 6(1)(b) GDPR), legitimate interest in improving the service (Art. 6(1)(f) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
5. Data retention
Data is retained for the duration of the contractual relationship and, once the account is cancelled, for the legally required periods (up to 6 years for accounting and tax data).
6. Third parties and transfers
Bookarta uses the following trusted providers (data processors) that may access data in order to provide the service:
- Supabase — database and authentication (servers in the EU).
- Stripe — payment processing (PCI-DSS compliant).
- Vercel — hosting infrastructure.
- Resend — transactional email delivery.
- OpenAI — artificial intelligence features (menu extraction, translation and description). See section 8.
- Google — authentication ("Sign in with Google") and optional reservation sync with Google Calendar.
All providers process data under GDPR-compliant data processing agreements (DPAs). Transfers outside the EEA (e.g., OpenAI) rely on the European Commission's Standard Contractual Clauses. We do not sell or share personal data with third parties for commercial purposes.
7. Security measures and data protection
We apply technical and organisational measures to protect your data, including sensitive data and Google user data:
- Encryption in transit via HTTPS/TLS for all communications.
- Encryption at rest of the database and of third-party access tokens (e.g., Google Calendar tokens are stored encrypted).
- Access control based on authentication and per-account data isolation (Row Level Security in Supabase), so each user can only access their own data.
- Internal access restricted to strictly necessary personnel under a duty of confidentiality.
- Infrastructure providers with recognised certifications (Supabase, Vercel) and processing preferentially on EU servers.
In the event of a security breach affecting your personal data, we will notify the supervisory authority and, where applicable, the affected individuals, in accordance with Articles 33 and 34 GDPR.
8. Artificial intelligence features
Bookarta uses the OpenAI API (GPT-4o and GPT-4o-mini models) as a third-party provider for AI features: extracting menus from images, translating menus, suggesting allergens and generating dish descriptions.
To do so, we send OpenAI the menu text or images that you provide. We do not send payment data or credentials. Under the OpenAI API terms, data submitted via the API is not used to train its models and is retained only for a limited period for security and abuse-prevention purposes.
Bookarta does not make automated decisions producing legal effects about you based on these features; AI outputs are suggestions that the user reviews and edits.
9. Google account data and Limited Use
When you sign in with Google or connect Google Calendar, Bookarta requests only the minimum necessary permissions: basic identity (name, email and profile picture) and, optionally, management of the calendar events created by the application itself (calendar.events.owned scope).
Bookarta's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Specifically: we use Google data only to authenticate you and to create, update or delete the calendar events corresponding to your reservations; we do not transfer this data to third parties except as needed to provide the service or as required by law; we do not use it for advertising; and no humans read it except with your explicit consent, for security purposes, or where required by law. You can revoke access at any time from your Google account or from the Bookarta dashboard.
10. Your rights
You may exercise the following rights at any time:
- Access: find out what data we process about you.
- Rectification: correct inaccurate data.
- Erasure: request deletion of your data.
- Portability: receive your data in a structured format.
- Objection and restriction: object to certain processing activities.
To exercise any right, email us at info@bookarta.es. You may also lodge a complaint with your local data protection authority.
11. Cookies
Bookarta uses only technical cookies necessary for the service to function (user session). We do not use tracking or third-party advertising cookies.
12. Changes to this policy
We reserve the right to update this policy. We will notify you of relevant changes by email or through a notice in the dashboard.
13. Contact
For any privacy enquiries: info@bookarta.es