← Home

Privacy Policy

Last updated: 21.09.2026
Draft — have it reviewed by a lawyer before launch.

This page explains, in plain language, what data Callbell processes, why, and how it is protected. Our principle: don't collect what we don't need.

Whose data?

We have two kinds of users: (1) owners and staff of restaurants, cafés and similar businesses who create an account, and (2) guests who scan a QR code to view a menu. We never ask guests for their identity, phone number or email.

Business accounts

Email address, name (optional), a one-way hash of the password, business name, menu content, table names, contact details the business enters itself (phone, address, social media), opening hours, Wi-Fi details (only if the business chooses to show them), language preference and session records (sign-in time, device information).

Guests

Menu pages do not ask for personal data and use no tracking cookies. To deliver waiter calls and prevent abuse, we keep a salted, one-way device hash derived from the IP address and browser information. The "My list" feature is stored only in the guest's own browser and is never sent to us. If a guest chooses to leave contact details with feedback, they are shared only with that business.

Statistics

Menu views, QR scans and calls are stored as daily and hourly totals, not per person.

Cookies

The website and menu pages use no advertising or tracking cookies. Browser storage is used only for functional purposes such as dismissing the language suggestion, the guest's list and the status of a waiter call.

Purposes and legal bases

Providing the service and managing the account (performance of a contract), security and abuse prevention (legitimate interest), and legal obligations. Marketing emails are sent only with your explicit consent.

Service providers

Data is stored on our hosting provider's servers. Paid plans are sold through the Apple App Store and Google Play; we never see payment details. When paid features such as push notifications or AI are enabled, the related providers will be listed here. We do not sell data.

Retention

Data is kept while the account is active. When an account is deleted, its businesses, menus, tables, statistics and staff links are permanently deleted. Technical security logs are kept for up to 90 days, or longer where the law requires.

Security

All connections use HTTPS. Passwords are stored as one-way hashes, session keys rotate and theft attempts are detected. Administrative access is protected by two-factor authentication.

Your rights

You can access, correct, delete, object to the processing of, and export your data. You can export your menu at any time and delete your account from within the app. For other requests, write to the address on the contact page.