This policy describes how ARDOIZA processes personal data in connection with the ardoiza.fr website, the app.ardoiza.fr customer area, the ARDOIZA WordPress plugins, the automated assistant, the menu pages published at an address on the carte.ardoiza.fr domain and the websites that ARDOIZA hosts for its customers at an address on the my-ardoiza.fr domain (together, “the Service”). A mobile app for restaurant owners, the ARDOIZA Pro app, complements the customer area (article 9). This policy is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and French Law No. 78-17 of 6 January 1978 as amended, the loi Informatique et Libertés (French Data Protection Act).
1. Who is responsible for your data
1.1 Controller
The controller of the processing described in article 3 is the publisher of the Service:
Mr Hamar Azzi, sole trader (entrepreneur individuel, EI), trading as ARDOIZA, SIREN 511 435 885, SIRET 511 435 885 00021, registered with the Registre national des entreprises (French National Business Register) since 27 March 2009, whose registered office is at 4 place Victor Basch, 30400 Villeneuve-lès-Avignon, France. In this policy, “ARDOIZA” and “we” refer to this business. The development and technical operation of the platform are entrusted to JOUCLA CYBERDÉFENSE, a technical service provider which acts on ARDOIZA's instructions as a processor (article 5). The point of contact for exercising your rights is [email protected].
Personal data contact: [email protected]. ARDOIZA has not appointed a data protection officer, as such an appointment is not mandatory given its activity; an internal contact person handles requests.
1.2 Three different situations
- You are a restaurant owner (or integrator) and you use the Service: for the data relating to your account, your billing, your exchanges with support and your browsing, ARDOIZA is the controller. This is what this policy covers.
- You visit the website of a restaurant hosted by ARDOIZA (an address on my-ardoiza.fr, or the restaurant's domain name connected to that website): the restaurant is the publisher of that website and the controller of your data. ARDOIZA is its hosting provider and acts on the restaurant's behalf, as a processor. The server's technical logs (IP address, date and time, page requested, browser) are kept for twelve (12) months at most, for security purposes and under the legal obligations of hosting providers. They are rotated every night and deleted no later than twelve (12) months after they are written.
- You are a customer of a restaurant (you view a menu, book a table, order, or buy or receive a gift card through the Service): the restaurant is the controller of your data. When its website is hosted by ARDOIZA, when you send it a booking request from its menu page (an address on the carte.ardoiza.fr domain), when you buy or receive a gift card that it sells through the Service, or when you answer its request for feedback after a meal, ARDOIZA acts on its behalf, as a processor, under the Data Processing Agreement entered into with it; when the restaurant uses our plugins on its own website, your data stays with its hosting provider and ARDOIZA has no access to it. To exercise your rights, please contact the restaurant first; you can also write to [email protected], and we will forward your request to the restaurant concerned and help it respond. Article 8 explains what ARDOIZA does with this data.
2. Data we collect
Depending on how you use the Service, we process the following categories of data.
| Category | Data | Source |
|---|---|---|
| Identity and account | First name, surname, email address, password (hashed, never readable), language, name of the venue, preferences, subscription status, licence key, Gift Cards Module settings | You |
| Billing | Name of the legal entity, address, SIRET, intra-EU VAT number, website address, time zone, invoices, payment history, brand and last four digits of the payment method (never the full number) | You, payment provider |
| Websites and licence | Address of the hosted website, website status (being created, online, suspended, deleted), visibility, log of operations carried out on the website (creation, login by link, suspension, reactivation, deletion), domain names of the WordPress websites on which the licence is activated, plugin version, date of the last check. Your email address is also used to create your access to the dashboard of your hosted website | You, plugins, automatic |
| Support | Content of your requests, attachments, the team's replies, dates | You |
| Automated assistant | Questions asked, answers, conversation identifier, hashed IP address (irreversible), audience (prospect or logged-in customer) | You |
| Login and security | IP address, timestamp, browser (user agent), session identifier, trusted devices (two-factor authentication), country of the last login and changes of country from one login to the next, including a login through a network that hides the country (derived from the IP address by Cloudflare), shortened fingerprint, computed with a secret server key, of the email address entered in a failed login attempt, log of sensitive actions (change of password, email address or plan, key regeneration) | Automatic |
| Prospecting | Email address and messages if you write to us from the website, name of the venue; if you ask to be called back using the “Get some help” form in the customer area: name of the venue, first name, surname, telephone number, email address, town or city, preferred way of being called back (phone or video call), availability, current solution, address of your website, whether it is built with WordPress, message, language of the form, date on which you agreed to be called back and version of this policy then in force; for the restaurants we canvass (since 29 September 2026): name of the venue, professional contact email address and telephone number, website, canvassing status and follow-up notes | You; for canvassed restaurants, the restaurants' public websites and business directories |
| Technical alerts | Address of the website or reference of the account concerned, nature and date of the incident (failure to create a website, disk space, security release to apply), with no order or booking content | Automatic |
| Mobile app | See article 9: connected devices (name, model, operating system and version, app version), notification token, dates of login and last use, hashed IP address, result of the latest notifications | You, automatic |
ARDOIZA collects no bank card data: this data is entered directly with the payment provider (see article 5). ARDOIZA collects no so-called sensitive data. No telephone number is requested for the account itself; the telephone number you enter in your venue's details is intended for your end customers and displayed under your control.
Canvassed restaurants. Since 29 September 2026, ARDOIZA has kept, in its internal console accessible to the founders only, a record of the restaurants it canvasses: name of the venue, professional contact email address and telephone number, website, canvassing status and follow-up notes. This information comes from the restaurants' public websites and from business directories, never from your accounts or from your customers' data. This record is based on ARDOIZA's legitimate interest in offering its services to food service professionals (article 3); you may object at any time by writing to [email protected], and a refusal is kept, so that we no longer contact you, then deleted no later than twelve (12) months later (article 4). Where you yourself ask to be called back using the “Get some help” form in the customer area, the information you enter is sent by email to the founders and added to this record, with the status “To call back”; this processing is then based on pre-contractual measures taken at your request (article 3).
Licence key and plugins. When you subscribe to a plan that includes the plugins, we send you by email your licence key and a link to download the plugins, valid for thirty (30) days. When someone downloads a plugin through this link, we record the date, IP address and browser used, linked to your account, for the security of the service and as proof of the downloads; this information is kept in the same way as the other download logs (article 4). When a new website activates your key, we let you know by email.
Reminder after sign-up. If you create an account without choosing a plan, we send you a single reminder, twenty-four (24) hours after sign-up. There is no other.
Assisted linking of your Stripe account. If you ask our team to prepare the link to your Stripe account and to fill in the Stripe sign-up with you, we record in your account's log the date of the preparation, the email address and IP address of the team member who prepared it and the reason they give (how and when your request came in, without your contact details), then, when the preparation link is opened, the date, the IP address of the device used and the identifier of the Stripe account created or resumed, and finally the date this account is activated. The other administrators of the team are notified by email of the preparation, of the opening of the link and of the activation; these alerts never carry the IP address itself, only its fingerprint and the country when they are known. The information you give Stripe during the sign-up (identity, contact details, bank details, documents) is entered on Stripe's pages: ARDOIZA keeps none of it. You are notified by email of each preparation. These records are kept under the conditions of article 4.
3. Why and on what basis we process your data
| Purpose | Legal basis (Art. 6 GDPR) | Data concerned |
|---|---|---|
| Create and manage your account, provide the Service, check the plugins' licence | Performance of the contract (Terms of Sale) | Identity and account, websites and licence |
| Create, host, update, suspend and delete your hosted website; log you in to its dashboard with a single-use link | Performance of the contract (Terms of Sale) | Identity and account, websites and licence |
| Alert the team to a technical incident so that it can be fixed | Legitimate interest (continuity and security of the Service) | Technical alerts |
| Invoice the subscription, collect payments, manage unpaid invoices | Performance of the contract; legal obligation (accounting, tax) | Billing |
| Respond to your support requests | Performance of the contract | Support, identity |
| Run the automated assistant | Legitimate interest (offering immediate help) and, for logged-in customers, performance of the contract | Assistant |
| Secure the Service: authentication, two-factor authentication, abuse detection, rate limiting, audit log | Legitimate interest (security of the Service and of data); legal obligation (retention of connection data) | Login and security |
| Prepare with you, at your request, the link to your Stripe account, and keep evidence of your request and of what was done | Performance of the contract, at your request; legitimate interest (security of the Service and evidence) | Identity and account, login and security |
| Send you the emails and customer area announcements relating to the Service: address verification, password, login code and alert, end of free trial, invoices, payment failure, cancellation, new versions of the contractual documents, price changes, maintenance, incidents | Performance of the contract; legal obligation | Identity, billing |
| Respond to a contact, demo or call-back request (“Get some help” form) | Pre-contractual measures taken at your request | Prospecting |
| Inform you about new ARDOIZA features or plans | Legitimate interest (B2B prospecting for similar services), with the option to object at any time | Identity |
| Canvass restaurants that do not yet use the Service (prospect tracking) | Legitimate interest (B2B prospecting), with the option to object at any time | Prospecting |
| Protect the sign-up form, the “Get some help” form, the menu pages' booking request form and gift card purchase form and, when a restaurant has switched on the Reviews module, the feedback form of this module against bots, by means of the Cloudflare Turnstile check, switched on since 1 October 2026 (article 5) | Legitimate interest (security of the Service) | Login and security |
| Produce aggregated usage statistics (number of accounts, free trials, websites) | Legitimate interest (managing the Service) | Aggregated, non-identifying data |
| Respond to requests from the authorities, establish or defend our rights | Legal obligation; legitimate interest | All, depending on the request |
We do not take any decision producing legal effects concerning you based solely on automated processing. We do not sell your data and do not use it for advertising purposes.
4. Retention periods
| Data | Duration |
|---|---|
| Account and identity data | Duration of the contractual relationship, then three (3) years after the account is closed or after the last activity (B2B prospecting and handling of complaints), then deletion or anonymisation |
| Invoices and accounting records | Ten (10) years from the end of the financial year (Article L123-22 of the Code de commerce, French Commercial Code), in an isolated archive |
| Billing details | Duration of the contract, then kept with the invoices |
| Support requests | Closed fourteen (14) days after resolution, then deleted automatically twelve (12) months after closure, attachments included; also deleted on request and when the account is deleted |
| Conversations with the automated assistant | Thirty (30) days, then automatic deletion; the current conversation is only kept in your browser for the duration of the session |
| Login logs and audit log | Twelve (12) months at most, then automatic deletion. Only the audit log entries that serve as evidence for longer are kept for their own period: handling of a report of illegal content (views, decision and the date it was sent to the notifier, reviews), three (3) years after the decision and for as long as the report is kept; sign-up and acceptance of a new version of the contractual documents, term of the contract then five (5) years; preparation, opening of the link, cancellation and activation of an assisted linking of your Stripe account (article 2), at least twelve (12) months, and for as long as your Stripe account remains linked to ARDOIZA, then twelve (12) months after it is disconnected. The hosted websites' access logs are deleted no later than twelve (12) months after they are written; the customer area's technical logs (access and errors) are rotated by volume, their deletion by age being a commitment not yet fulfilled (Annex 2 of the Data Processing Agreement) |
| Verification, reset and address change tokens | One (1) to twenty-four (24) hours, then invalidated |
| Trusted devices (two-factor authentication) | Thirty (30) days |
| Login codes sent by email (hashed) | Ten (10) minutes, then deleted one (1) day later at the latest |
| Login links to the hosted website dashboard | Two (2) minutes, single use |
| Log of operations on your hosted website | Duration of the contract, then deleted with the account |
| Download logs of the plugins and of their updates (date, plugin, version, IP address, browser) | For as long as the account exists; the IP address and browser are erased when the account is closed |
| Full copy of a hosted website | Made before its deletion: thirty (30) days after the website is deleted; requested from the Copies of my website page: seven (7) days |
| Proof of acceptance of contractual documents (document, version, date, IP address, browser), including acceptance of the Gift Cards Module terms (version, date, author) | Duration of the contract, then five (5) years (limitation period) |
| Technical alerts | Seven (7) days for event details |
| Announcements received in the customer area (date the email was sent, date read) | Same periods as the account |
| Contact requests (website form) | Three (3) years after the last exchange, then automatic deletion |
| Record of canvassed restaurants | Until an account is opened or a refusal is received; a refusal is kept, then deleted no later than twelve (12) months later |
| Call-back requests (“Get some help” form) | Until an account is opened; a request that is not followed up is archived, then deleted no later than twelve (12) months later; a request that could not be added to the record is deleted twelve (12) months after it was sent |
| Backups | Backups are overwritten on rotation within a maximum of ninety (90) days |
Free Menu plan. When the limits of the Menu plan apply to your account (article 4.7 of the Terms of Sale) and nobody has logged in to this account for six (6) months, we use the date of the last login to send you two reminders by email, then to stop displaying your menu page publicly. No data is deleted on that occasion: the periods in the table above apply. To apply these limits, we also count, each month, the number of booking requests received by your menu page, without any data on the people who send them; these counters are deleted after thirteen (13) months.
When your account is closed (request made from My profile, handled by the team), your account data, your support requests and the related attachments are deleted or anonymised, subject to the continued access to the Gift cards section provided for in article 23.8 of the Terms of Sale: if a gift card you sold still has a balance and has not expired, your identity and login means (email address, hashed password, two-factor authentication), your venues and the identifier of your linked Stripe account are kept, the rest of the customer area being closed, until the latest of the expiry dates of those cards, then for the thirty (30) days of the export period; your account is anonymised at the end of that period; invoices are kept as they are to meet accounting obligations.
5. Recipients and processors
Your data is accessible only to authorised ARDOIZA staff (the founders and, where applicable, the support team), each according to their needs, and to the following providers, which act on ARDOIZA's instructions and are bound by a contract that complies with Article 28 of the GDPR.
| Provider | Role | Data location | Safeguards |
|---|---|---|---|
| JOUCLA CYBERDÉFENSE, Mr Hugo Joucla, sole trader, SIREN 938 064 714, 84 chemin du Rabet et du Ramplan, 13670 Saint-Andiol, France | Development, technical operation and maintenance of the platform (customer area, console, hosted websites cluster, menu pages, backups): administrative access to the servers and databases, on ARDOIZA's instructions and only to the extent these operations require | France (European Union) | Processing contract that complies with Article 28 of the GDPR; confidentiality obligation; access by individual keys, logged (article 7) |
| OVH SAS, 2 rue Kellermann, 59100 Roubaix, Lille Métropole RCS 424 761 419 | Hosting of the servers, hosted websites, databases, backups and email service; registration of the my-ardoiza.fr domain name | France (European Union), Gravelines data centre | OVHcloud contract and data processing terms |
| Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States | Content delivery network (CDN), DNS resolution for the ardoiza.fr and my-ardoiza.fr domains, issuing and presenting the security certificate for Customers' domain names connected to their Hosted Website, protection against denial-of-service attacks, traffic filtering. Cloudflare decrypts traffic at its edge to filter it, then re-encrypts it towards our server: it sees IP addresses and connection metadata and can technically access the content of requests, without storing it. Turnstile anti-bot check, switched on since 1 October 2026 for the sign-up form, for the “Get some help” form, for the menu pages' booking request form and gift card purchase form and, when a restaurant has switched on the Reviews module, for the feedback form of this module: the widget is loaded from challenges.cloudflare.com, and Cloudflare receives the verification token, the visitor's IP address and technical signals from their browser, for which it is the controller; ARDOIZA keeps nothing from this check | Global network; processing possible outside the European Union | Cloudflare's data processing agreement and the European Commission's standard contractual clauses (Decision 2021/914), including for the Turnstile check |
| Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland, and affiliated companies) | Payment service provider: collection of the subscription, management of the payment method, billing portal. Where the restaurant offers it, payment of its customers' orders, booking deposits and gift cards into the restaurant's Stripe account (article 8) | European Union; transfers to the United States possible | Stripe acts as an independent controller for its own obligations (fraud prevention, regulatory obligations) and as a processor for the rest; standard contractual clauses. Since 23 September 2026, Stripe has been connected in live mode, for subscriptions and for online payment of orders and booking deposits, and since 1 October 2026 for gift cards |
| Anthropic, PBC, San Francisco, United States | Provider of the language model (Claude) used by the automated assistant for some answers. Only the text of the current conversation and the documentation extracts needed for the answer are sent to it. We add no name, email address, account identifier or IP address; the text you write is sent as it is, so please avoid including personal data in it | United States | Anthropic's commercial terms and data processing agreement including the standard contractual clauses; Anthropic does not use data sent through the API to train its models |
The automated assistant first works from a local base of answers. Use of the Anthropic API is optional, switched on by ARDOIZA for some answers and capped daily; if it is unavailable or the cap is reached, the assistant falls back on local answers only. You can avoid any processing by Anthropic by not using the assistant and writing directly to [email protected] or from the My requests section.
Your data may also be disclosed to judicial or administrative authorities where required by law, and to our advisers (chartered accountant, lawyer) to the extent necessary.
Mobile app providers (Expo, Apple, Google): see article 9.
The up-to-date list of processors is available from [email protected]. Any addition or replacement of a processor handling personal data is announced in the customer area at least thirty (30) days before it takes effect.
6. Transfers outside the European Union
The Service's servers are located in France, with OVH SAS (Gravelines data centre). Six providers may nevertheless process data outside the European Union: Cloudflare (network traffic and IP addresses and, for the Turnstile anti-bot check of the public forms, verification token, IP address and browser signals), Stripe (payment data), Anthropic (text of conversations with the assistant, with no identifier), and, for the mobile app, Expo, Apple and Google (notification token and notification content; for Expo, also the installation identifier and, after a crash, the error message, article 9). These transfers are governed by the standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) or, for Expo, by the EU-U.S. Data Privacy Framework (article 9), and are supplemented by technical measures (encryption in transit, minimisation of the data sent) and, for Stripe, by the provider's role as an independent controller for its own obligations. A copy of the applicable safeguards can be requested from [email protected].
7. Security
ARDOIZA implements appropriate technical and organisational measures, including:
- encryption of communications (TLS) and HSTS;
- passwords hashed with the Argon2id algorithm, never stored in plain text or viewable by the team;
- server-side sessions of thirty (30) days at most, with HttpOnly and Secure cookies, all sessions closed after a password change, and closure from the Security section of any session open on another browser;
- two-factor authentication (TOTP app and backup codes) available on accounts;
- refusal, when a password is created or changed, of common passwords and of passwords found in public data leaks: only the first five characters of the SHA-1 fingerprint of the password are sent to the Have I Been Pwned service (the so-called k-anonymity method), never the password or its full fingerprint;
- without two-factor authentication, a one-time code sent by email for a login from an unusual address and browser, and an alert message for each login from a new browser;
- single-use, time-limited verification and reset tokens, stored in hashed form;
- protection against cross-site request forgery (CSRF), rate limiting on sensitive endpoints, security headers (CSP, X-Content-Type-Options, Referrer-Policy);
- strict separation of data between accounts, checked by automated tests;
- no bank card data held by ARDOIZA;
- audit log of sensitive actions, with no password, token or key in the logs;
- encrypted daily backups, which the server itself cannot read back;
- hosted websites: read-only code, non-executable media folder, restaurant owner login by signed single-use link, security updates handled by ARDOIZA;
- automated assistant: IP addresses hashed with a secret, conversations deleted after thirty (30) days.
Annex 2 of the Data Processing Agreement details these measures, including production hosting in France and the copy of backups off the server, and lists, each with its deadline, the commitments not yet fulfilled as at the date of this version, including the penetration test by a third party and professional liability insurance. In the event of a data breach likely to result in a risk to your rights and freedoms, ARDOIZA will inform you as soon as possible and notify the CNIL (Commission nationale de l'informatique et des libertés, the French data protection authority) in accordance with Articles 33 and 34 of the GDPR.
8. Data of restaurants’ end customers
When you order from or book with a restaurant through the Service, the restaurant collects the data needed for your order or booking: surname, first name, email address, telephone number, content of the order and collection time, date and number of guests, preferred seating (indoors or on the terrace, optional), comments, consents. When the restaurant's website is hosted by ARDOIZA (an address on my-ardoiza.fr), this data is hosted by ARDOIZA on behalf of the restaurant, which is its controller, under the location conditions described in article 6; when the restaurant uses our plugins on its own website, it is hosted with the restaurant's hosting provider and ARDOIZA has no access to it. ARDOIZA uses it only to provide the Service (sending it to the restaurant, sending confirmations and reminders, history, export). ARDOIZA never uses it for its own purposes, does not transfer it to anyone and never sends you any marketing communication. The restaurant decides on retention periods and responds to your requests for access, rectification, erasure or objection; the Data Processing Agreement gives it the tools it needs. Depending on the restaurant's choice, an order is paid on site at collection or online. Where the restaurant offers online payment, payment for an order or a booking deposit is made through Stripe directly between you and the restaurant, into the restaurant's Stripe account; your email address is sent to Stripe for the receipt and for fraud prevention; ARDOIZA receives the payment identifier and status, never your card data, and does not collect the funds. If the restaurant declines or cancels your order or booking, or if you cancel your booking within the period shown, a full refund is initiated automatically from the restaurant's Stripe account.
Free plugin. When a restaurant uses the free ARDOIZA PRO plugin, offered to the wordpress.org directory, on its website, the booking requests you send it stay in its website's database: this plugin sends no data to ARDOIZA.
Customers imported by a restaurant. A restaurant using the Ardoiza Clients plugin may import its customer list into it from a file, for example the export of the booking or online ordering tool it used before: name, email address, phone number and, if the file states it, your answer about receiving offers from it. The restaurant is the controller of this processing and is responsible for the origin of this file; it informs you of it. A “yes” coming from a file is shown to the restaurant but never counts as your agreement to receive offers from it: only the box you tick yourself on its website counts. When the restaurant's website is hosted by ARDOIZA, this data is hosted by ARDOIZA on its behalf, as a processor; when the restaurant uses our plugins on its own website, it stays with its hosting provider and ARDOIZA has no access to it. If the restaurant erases your record, at your request or at the end of its retention period, the plugin only keeps a fingerprint of your email address (or, failing that, of your phone number), protected by a key specific to the website, which does not allow your address to be retrieved, and the date of erasure, so that a new import does not add you again. This fingerprint is deleted three (3) years after your record was erased, and at the latest when the plugin is deleted from the website, unless its administrator chose to keep its data; the list keeps at most the last ten thousand (10,000) erasures. You exercise your rights with the restaurant.
A restaurant's menu page. A restaurant can publish its menu on a page hosted by ARDOIZA, at an address of the form carte.ardoiza.fr/restaurantname, with a booking request form. If you send a request, your name, telephone number, email address, requested date and time, number of guests, preferred seating (indoors or on the terrace, if you state it) and message are sent to the restaurant, the sole recipient, which is their controller; ARDOIZA hosts them on its behalf, sends you an acknowledgement by email with a link to cancel your request, then the restaurant's reply. Your IP address is not recorded with the request. As the Cloudflare Turnstile anti-bot check has been switched on for this form since 1 October 2026 (article 5), Cloudflare receives the verification token, your IP address and technical signals from your browser; ARDOIZA keeps nothing from it. Requests are deleted automatically ninety (90) days after the requested date. Your rights of access, rectification and erasure are exercised with the restaurant; you can also lodge a complaint with the CNIL.
Feedback after a booking. A restaurant subscribed to a paid plan may switch on the Reviews module. After a confirmed booking request sent from its menu page, once the meal time has passed, ARDOIZA sends you on its behalf a single “How was your meal?” email. The restaurant is the controller of this processing, based on its legitimate interest in knowing how satisfied its customers are; ARDOIZA processes it on its behalf, as a processor. Your name and email address, received with your booking, the date of your meal and, if you answer, your rating (from 1 to 5) and your comment are processed. Your answer is sent to the restaurant only: it is never published, neither by ARDOIZA nor on the menu page. The same email invites you, like every customer and whatever your rating, to leave a public review on the restaurant's Google listing if you wish; that review is then subject to Google and its rules. You may object to this email when you send your booking request (tick box), then at any time through the link in every email; your objection is kept as a fingerprint computed with a secret key, without your address in clear text. You never receive more than one such email from the same restaurant within thirty (30) days. The link in the email is valid for thirty (30) days; without an answer, your name and email address are erased when it expires; if you answer, your email address is erased ninety (90) days after your answer, and your answer and your name thirteen (13) months after the email was sent. The restaurant may reply to you once by email. Emails are sent through OVH's email service (article 5). Your IP address is not recorded with your answer. As the Cloudflare Turnstile anti-bot check is switched on for this form (article 5), Cloudflare receives the verification token, your IP address and technical signals from your browser; ARDOIZA keeps nothing from it. You exercise your rights with the restaurant; you may also write to [email protected], which will pass your request on, or lodge a complaint with the CNIL.
A restaurant's gift cards. Since 1 October 2026, a restaurant subscribed to a paid plan can sell gift cards on a page hosted by ARDOIZA, at an address of the form carte.ardoiza.fr/restaurantname/cadeau. The restaurant is the seller of the card and the controller of the data relating to it; ARDOIZA processes this data on its behalf, as a processor, under the Data Processing Agreement entered into with it. If you buy a card, the following are processed: your name and email address, the amount, the language chosen, the name and email address of the recipient, to whom the card is sent (required; to hand the card over yourself, you may give your own), your message (three hundred (300) characters at most) and the sending date chosen; for the card itself, its code, its balance, its expiry date and the history of its uses (amount, date, venue, any note from the restaurant). This data is used to issue the card, to send you the receipt, to send the card to the recipient on the date chosen, with your name and your message, to inform the recipient of the remaining balance after each use and thirty (30) days before the expiry date, to allow the restaurant to redeem, refund or cancel the card, to handle any withdrawal on your part and to keep the restaurant's accounts. Payment is made by Stripe directly between you and the restaurant, into the restaurant's Stripe account; your email address is sent to Stripe for the receipt and fraud prevention, but not the recipient's name or your message; ARDOIZA receives the payment identifier and status, never your bank card data, and does not collect the funds. Emails are sent by OVH's email service (article 5). The card's code is only kept in encrypted form and in the form of a fingerprint; it never appears in any log. Your IP address is not recorded with the card. As the Cloudflare Turnstile anti-bot check has been switched on for the purchase form since 1 October 2026 (article 5), Cloudflare receives the verification token, your IP address and technical signals from your browser; ARDOIZA keeps nothing from it. A purchase abandoned before the payment is confirmed is deleted thirty (30) days later. The message is deleted on the card's expiry date, or as soon as the card is refunded or cancelled; the names and email addresses of the buyer and the recipient are deleted three (3) years after the expiry date, or after the card is refunded or cancelled, so that any complaint can be handled; the history of the card's movements (amounts, dates, venue), without any name or address, is kept for the restaurant's accounts for as long as its account exists, for ten (10) years at most, the retention period for accounting records (Article L123-22 of the French Commercial Code), and is then handed over to the restaurant with its data at the end of its contract. No address collected when a gift card is sold is added to the restaurant's customer file by the Service or used for marketing purposes by ARDOIZA. Your rights are exercised with the restaurant, whose contact details appear on the purchase page and in the emails; you can also write to [email protected], which will forward your request to the restaurant, or lodge a complaint with the CNIL.
The content published on a restaurant's website (menu, prices, allergens, photographs, legal notice) is the responsibility of the restaurant, which is its publisher. To report unlawful content: form at https://app.ardoiza.fr/signaler or [email protected].
9. ARDOIZA Pro app
The ARDOIZA Pro app, for iPhone, iPad and Android, lets you receive and handle your orders and bookings from your phone or tablet. It is included in the Basic, Essential and Pro plans. It has been available on Apple's App Store since 28 September 2026 and on Google Play since 5 October 2026, from which you download it, and signs in with the email address and password of your customer area; we neither receive nor keep any data relating to your Apple ID or your Google account. Apple and Google process your download and usage data for their app store (App Store, Google Play) as independent controllers, each under its own privacy policy.
Login. You log in with the email address and password of your customer area, then a verification code (authenticator app if you have switched it on, otherwise a code sent to your email address). The app then receives a token specific to the device, kept in the device's secure storage, which lets it stay logged in without asking for your password again.
Data processed, on the basis of performance of the contract (article 3):
| Data | Use | Duration |
|---|---|---|
| Connected device: the name you gave it, model, operating system and version, app version | Show you, in the customer area, the devices linked to your account and let you log one out | For as long as the device is connected: four hundred (400) days at most, or ninety (90) days without use; then deleted ninety (90) days after logout or expiry |
| Device notification token, chosen sound, date and result of the latest notifications | Tell you about a new order or a new booking request, then remind you of those awaiting a reply | Same duration as the device; the token is removed as soon as you log the device out or switch off notifications |
| Verification codes at login (hashed) | Check that it really is you | Ten (10) minutes, then deleted one (1) day later at the latest |
| Dates of login and last use, hashed IP address (irreversible), address of the last website viewed | Security: detect unusual use, help you recognise a device | Same duration as the device |
| Audit log: login, logout, sending and acknowledgement of notifications | Security and proof | Twelve (12) months at most (article 4) |
Content of notifications. A notification states the type of event (new order, booking request, item already handled), the order or booking number assigned by your website and its technical identifier, the date and time of collection or of the table, the number of items or guests, the number of items pending, and the address of your website. It never contains your customer's name, contact details or order details: this information is only shown in the app, once you are logged in.
Providers. Notifications are delivered by Expo's notification service (650 Industries, Inc., United States), which receives the notification token and the content described above, then, depending on your device, by Apple's notification service (Apple Inc., United States) on an iPhone or iPad, or by Firebase Cloud Messaging, Google's notification service (Google LLC, United States), on an Android device; Apple and Google receive the device's notification token and the same content. Expo participates in the EU-U.S. Data Privacy Framework; Apple and Google govern their transfers from the European Economic Area with the European Commission's standard contractual clauses; these transfers are moreover limited to the content described above (article 6). Each time it opens, the app also asks Expo's update service whether a fix is available. This request carries the device's operating system, the app version and a random installation identifier, specific to the app on that device; after the app has crashed, it also carries the technical message of the error. We add no data from your account. To obtain the notification token, the app likewise sends Expo an installation identifier. No other provider receives data from the app. Google is added to these providers on 5 October 2026, the day the app was published on Google Play: it receives nothing until you have connected an Android device to your account. If your account existed before that date, we inform you of it by email and in your customer area, and you have thirty (30) days from that information to object by writing to [email protected] (article 13).
On your device. The app stores your preferences locally (sound, volume, lock), a note that the first-launch introduction has been seen, and the device token in the secure storage. Locking with the device's passcode or biometrics is handled by the device's operating system: ARDOIZA receives no biometric data. You delete this data by logging the device out from the app or the customer area, or by uninstalling the app.
10. Your rights
You have the following rights over your data: access, rectification, erasure, restriction of processing, portability of the data you have provided to us, objection on grounds relating to your particular situation to processing based on legitimate interest, and objection without giving reasons to prospecting. You can also set instructions on what happens to your data after your death.
To exercise your rights, write to [email protected] from the email address linked to your account, or from the My requests section of the customer area. If we have reasonable doubts about your identity, we may ask you for proof. We respond within one (1) month, which may be extended by two (2) months for a complex request, in which case you will be informed.
From your customer area, you can directly update your information (My profile, Billing), download your invoices, download a copy of your account data (My profile, My data section: an archive in JSON and CSV formats, provided after confirmation with a two-factor authentication code) and request the deletion of your account. The content of the websites we host for you is downloaded from the Copies of my website page. To obtain a copy of data that is not in these archives, or if you would rather not enable two-factor authentication, write to [email protected]: we will send it to you within one (1) month.
If, after contacting us, you consider that your rights have not been respected, you can lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
11. Cookies
The Service only uses cookies and storage that are strictly necessary for its operation (session, security, two-factor authentication, language, assistant), which are exempt from consent. No advertising, third-party audience measurement or tracking cookie is set. Full details are given in the Cookie Policy.
12. Minors
The Service is reserved for professionals. ARDOIZA does not knowingly collect data from minors for accounts. Orders, bookings and gift card purchases made with restaurants are the responsibility of those restaurants.
13. Changes
This policy may be updated to reflect changes to the Service or to the regulations. The version in force, with its date, is published on ardoiza.fr and in the customer area. In the event of a substantial change (new purpose, new processor, new transfer), you will be informed by email or in your customer area at least thirty (30) days before it comes into force.
14. Contact
For any question about this policy or your data: [email protected].