GDPR & Security
Gastavo is built in Europe, for European hospitality. Privacy is not an afterthought — anonymous-by-design guest feedback is the product. This page summarizes how we comply with the General Data Protection Regulation (GDPR) and how we secure your data.
Anonymous by design
- Guests never create accounts, and we never ask them for names, emails, or phone numbers.
- Feedback pages contain no advertising trackers, no analytics cookies, and no fingerprinting.
- The only identifiers stored with feedback are the restaurant, the table, and a timestamp.
Data residency
- All customer and feedback data is stored in the European Union (Supabase, EU region).
- Where a processor operates outside the EU (OpenAI for comment categorization, Stripe for payments), transfers are safeguarded by EU Standard Contractual Clauses.
- Feedback comments sent to OpenAI are used only to generate categories and summaries — never for AI model training.
Security measures
- Every restaurant’s data is isolated with database Row Level Security — one customer can never read another’s data.
- All traffic is encrypted in transit (TLS); data is encrypted at rest.
- Authentication is handled by Supabase Auth, with Google sign-in as an option; passwords are stored as salted hashes, never in plain text.
- Payment details are handled entirely by Stripe (PCI-DSS Level 1); they never touch our servers.
- Access to production systems is restricted and logged.
Roles and agreements
For guest feedback, the restaurant is the data controller and Gastavo acts as processor. A Data Processing Agreement (DPA) covering our processing and our subprocessors is available to every customer — request it at hello@gastavo.nl.
Subprocessors
- Supabase — database & authentication (EU)
- Vercel — hosting
- OpenAI — AI categorization & summaries (US, SCCs)
- Stripe — payments
- Resend — email delivery
Data subject requests
Guests or restaurant users can exercise their GDPR rights (access, correction, deletion, portability, objection) by emailing hello@gastavo.nl. We respond within 30 days. Complaints can be lodged with the Autoriteit Persoonsgegevens.
Incident response
In the unlikely event of a personal data breach, we notify affected customers and, where required, the supervisory authority within 72 hours of becoming aware, in line with Articles 33–34 GDPR.