Política de Privacidad

Última actualización: 19 de abril de 2026

BettterMenu OÜ takes the privacy of your data seriously. This policy explains how we process personal data under the General Data Protection Regulation (GDPR) and applicable German and Estonian data protection law. It covers this corporate website (betttermenu.com) and our product Avaara (avaara.de).

1. Data Controller

BettterMenu OÜ
Registry Code: 17401720
Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 15551, Estonia

CEO: Tushar Sood — tusharsood@betttermenu.com
CTO: Abhigyan Gogoi — abhigyangogoi@betttermenu.com
Privacy contact: contact@betttermenu.com
Phone: +49 173 936 7518

Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee. Data subjects in Germany may also lodge complaints with their competent Landesdatenschutzbeauftragte.

2. What Data We Process

A. Business Customers

When a business registers to use Avaara, we collect name, business name, email address, and billing records. This data is used for account management, subscription billing, and support. The legal basis is Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (legal obligation for invoicing).

B. Guests (visitors who scan QR codes)

When a guest accesses a digital menu via Avaara, we process the following transient technical data solely to deliver the page:

  • IP address — for HTTP routing; retained in truncated form for up to 7 days for security purposes.
  • User-agent string — browser and device type, used to optimise display.
  • Session identifier — stored client-side in the browser session only; never transmitted to BettterMenu servers.
  • Language preference — stored client-side in localStorage if the guest actively selects a language.

We do not set tracking cookies, advertising pixels, or third-party analytics on guest menu pages. There is no cross-session profiling of guests.

C. This website (betttermenu.com)

This corporate website does not use analytics or tracking tools. If you submit the contact form, we receive your name, email, and message. We use that data solely to respond to your inquiry. It is not shared with third parties.

3. Sub-processors

Sub-processor Purpose Location
Google Cloud / Firebase Hosting, authentication, database EU (Frankfurt / Netherlands) preferred
Supabase, Inc. Database hosting, user authentication, and API infrastructure EU (Frankfurt, Germany) — Standard Contractual Clauses (SCC) active
Google Vertex AI AI menu extraction, allergen suggestions EU regions where available
DeepL SE Menu translation Germany (EU)
Mollie B.V. Payment processing Netherlands (EU)
BettterMenu engineering team (India) Platform development and incident response India — EU SCCs + TIA on file

4. Cookies and Local Storage

Our website primarily uses local storage technologies (specifically your browser's localStorage) to ensure the proper functionality of our pages. We do not set cookies or tracking pixels to monitor your behaviour or for personalised advertising.

Storage technologies used:

  • Language Preference (localStorage): When you actively select a language from the selector, this preference is saved in your browser's localStorage so that the website loads in your chosen language on subsequent visits. This is technically necessary to provide a user-friendly service.
  • Session Storage (sessionStorage): We use transient session storage to manage loading states and navigation flags. This data is automatically deleted when you close your browser.

Because we do not use any non-essential tracking cookies or third-party analytics tools, a cookie consent banner is not legally required. However, we provide an information banner to ensure complete transparency regarding our storage practices.

5. Data Retention

  • Account data: retained for the duration of the subscription, then deleted within 90 days of termination.
  • Billing records: retained for 10 years per § 147 AO (Germany) and Estonian accounting law.
  • Security logs: retained for up to 7 days.
  • Contact form submissions: retained for up to 12 months, then deleted.

6. Your Rights

Under GDPR, you have the right to access, correct, erase, restrict, or port your personal data, and to object to processing based on legitimate interest. To exercise any of these rights, contact contact@betttermenu.com. We aim to respond within 30 days.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee) or, if you are in Germany, with your relevant Landesdatenschutzbeauftragte.

7. Changes to this Policy

If we make material changes, we will notify active Business Customers by email at least 30 days in advance. The "last updated" date at the top of this page reflects the current version.