Privacy Policy.
This Privacy Policy explains how dotik (“we”, “us”, “our”) collects, uses, and protects personal data when you use our website and digital QR menu platform (the “Service”).
1. Who we are
The data controller for dotik during this demo phase is the individual operator of the Service (available at dotik.eu and dotik.sk). There is no registered company behind dotik at this time. Contact us about privacy at dotik.contactus@gmail.com.
2. Scope
This policy applies to:
- Visitors to our marketing website
- Registered account holders (restaurant owners, staff, and administrators)
- Users who sign in with email/password or Google
Public menu pages viewed by guests via QR codes generally do not require guest accounts. If you add analytics or guest-facing forms later, update this section.
3. Data we collect
Depending on how you use the Service, we may process:
- Account data: name/username, email address, password (hashed; not stored in plain text), profile image URL, Dotik ID, email verification status
- Google sign-in data: if you use Google, we receive an ID token from Google containing your Google account ID, email, name, and profile picture URL as permitted by Google
- Establishment data: business name, menu URL slug, address, contact details, Wi‑Fi info, branding, and menu content you upload
- Team and invitations: invitations sent to or received by your email address, roles, and membership in establishments
- Technical data: IP address, browser type, device information, access times, and security logs needed to operate and protect the Service
- Authentication tokens: access and refresh tokens stored in your browser to keep you signed in
4. How we collect data
- Directly from you when you register, create a menu, or contact us
- From Google when you choose “Sign in with Google”
- Automatically through cookies, local storage, and server logs
- From third-party services integrated into the platform (see section 7)
5. Why we use your data
We process personal data to:
- Provide, maintain, and improve the Service
- Create and manage your account and establishments
- Authenticate you and keep your session secure
- Send transactional emails (e.g. email verification, invitations)
- Prevent abuse, fraud, and unauthorized access (including reCAPTCHA checks)
- Respond to support requests and legal obligations
- Analyse aggregated usage to improve the product, where applicable
6. Legal basis (EEA/UK users)
Where GDPR applies, we rely on:
- Contract: to provide the Service you signed up for
- Legitimate interests: security, fraud prevention, and product improvement
- Consent: where required (e.g. non-essential cookies, if used)
- Legal obligation: where we must retain or disclose data by law
7. Third-party services
We use trusted providers to run dotik. They process data only as needed to provide their service:
- Google: Sign-in (OAuth) and reCAPTCHA v3 bot protection
- Cloudinary: image hosting and delivery for menu and store assets
- Mailgun: transactional email delivery
- Hosting and infrastructure providers: application hosting, databases, and background job processing
Each provider has its own privacy policy. We choose providers with appropriate safeguards, including standard contractual clauses where data may leave the EEA.
8. Cookies and local storage
We use:
- Strictly necessary storage: authentication tokens in local storage so you remain signed in
- Security cookies/scripts: Google reCAPTCHA on registration and similar flows
- Third-party cookies: may be set by Google when you use Google Sign-In or reCAPTCHA
If you add analytics or marketing cookies, publish a separate Cookie Policy and, where required, obtain consent before setting non-essential cookies.
9. How long we keep data
We retain personal data only as long as necessary for the purposes above, including:
- For the lifetime of your account, unless you delete it sooner
- As required for legal, tax, or dispute-resolution purposes
- In backups for a limited period after deletion, where technically unavoidable
You may request account deletion from your profile or by contacting us.
10. When we share data
We do not sell your personal data. We may share data:
- With service providers listed in section 7
- With other members of an establishment you join, as needed for collaboration
- When required by law, court order, or to protect rights and safety
- In connection with a merger, acquisition, or asset sale, with notice where required
11. Your rights
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data
- Restrict or object to certain processing
- Data portability
- Withdraw consent where processing is consent-based
- Lodge a complaint with your local supervisory authority (e.g. ÚOOÚ in Slovakia)
To exercise these rights, email dotik.contactus@gmail.com. We may need to verify your identity before responding.
12. Security
We use technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), hashed passwords, and access controls. No method of transmission or storage is 100% secure.
13. Children
The Service is intended for businesses and users aged 16 or older (or the minimum age required in your country). We do not knowingly collect data from children.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the new version on this page and update the “Last updated” date. Material changes may also be notified by email or in-app notice where appropriate.
15. Contact
Questions about this policy or your data: dotik.contactus@gmail.com
