Privacy Policy
Last updated: August 1, 2026
1. Data We Collect
At Restomas, we collect the following personal data to provide and improve our services:
- Identity: Name, surname, email address, phone number
- Business: Restaurant name, branch addresses, tax ID
- Account: Username, password (hashed), login records
- Usage Data: IP address, browser info, page views, session durations
- Site Analytics: Pages viewed, time on page, scroll depth, referring source and campaign tags, device type, browser, language, and country. Your IP address is shortened before it is stored, so it identifies a network area rather than a person.
- Order Data: Menu interactions, order details, payment amounts
- Cookie Data: Session cookies, preference cookies, analytics cookies
2. How We Use Your Data
Collected data is processed for the following purposes:
- Providing, managing, and improving our services
- Creating and securing user accounts
- Managing and reporting order processes
- Handling customer support requests
- Fulfilling legal obligations
- Marketing communications (with consent)
- Statistical analyses and improving service quality
Our roles: controller and processor
Restomas handles data in two distinct roles, and your rights depend on which one applies.
- As data controller: for your own account, billing and website usage data. We decide why and how these are processed.
- As data processor: for data about your own customers that you enter or that reaches us through the platform, such as orders, phone numbers and message content. We process these only on your instructions.
When Restomas acts as processor, the business remains the controller: informing its own customers and collecting any required consent is the business’s responsibility.
3. Third-Party Sharing
Your data may only be shared in the following cases:
- Payment Processors: PCI-DSS compliant providers (Stripe etc.)
- Infrastructure: Server hosting and cloud service partners
- Legal Requirement: Court orders or authorized public authority requests
- AI providers: Anthropic, OpenAI and ElevenLabs, for assistant replies, transcription and speech synthesis.
- Messaging and calls: Meta (WhatsApp Business Platform), Telnyx, Twilio and NetGSM, to deliver messages and calls.
- Payments: Stripe for platform subscriptions, plus the provider you choose for your own checkout (Iyzico, PayTR, Param, PayTabs, Checkout.com or Authorize.Net). Card details never reach our servers.
- Hosting and backups: Microsoft Azure, for servers, databases and encrypted backup storage.
- Sign in and maps: Google, Microsoft and Apple if you sign in with them, and Google Maps for address and location features.
Your data is never sold or rented for advertising purposes.
Data we receive from Meta (WhatsApp)
When a business connects its own WhatsApp Business Account to Restomas, Meta shares data with us so that we can run the service for that business. This section explains what we receive and what we do with it.
- What we receive: the WhatsApp Business Account and phone numbers the business has authorised, their status and settings, and the messages guests send to those numbers, including the sender’s WhatsApp number and profile name.
- How we use it: only to operate the service for that business: showing its conversations in its own inbox, letting its staff reply, routing each number to the right branch, and producing assistant replies when the business has switched the assistant on.
- What we never do: we do not sell this data, we do not use it for advertising or audience building, we do not pass it to data brokers, and we never combine one business’s data with another’s. Each business is stored in its own separate database.
- Deletion: when a business disconnects its WhatsApp account or asks for deletion, the stored access credentials are deleted immediately and the related conversations within 30 days. If our access is withdrawn by Meta or by the business, we stop processing and delete the data we hold.
Our use of this data also follows Meta’s Platform Terms and the WhatsApp Business Messaging Policy.
International data transfers
Restomas serves ten countries and some of our providers operate outside your own. Message content sent to AI providers, payment records and hosting infrastructure may therefore be processed in the United States or the European Union.
These transfers are covered by written agreements with each provider that require confidentiality, purpose limitation and comparable security measures.
Only the data needed for the specific feature is sent. Your customer database as a whole is never transferred to these providers.
Processing by artificial intelligence
Some features answer messages and calls automatically. This requires sending the relevant content to an AI provider.
- What is sent: the message or call content being answered, the business profile you have written, and the recent conversation history needed for context.
Our agreements with these providers prohibit using your content to train their models.
A member of your staff can take over any conversation at any time, and automatic replies can be switched off per branch.
Calls may be recorded and transcribed where the branch has enabled it and local law allows. Callers are notified before recording starts, and recordings follow the retention periods above.
4. Cookie Policy
- Essential: Required for session management and security
- Preference: Remembers settings like language and theme
- Analytics: Collects anonymous usage statistics
- Our own analytics: We keep two of our own cookies (rms_vid and rms_sid) that hold only random numbers, never your name or email. They let us tell one visit apart from the next so we can measure which pages help and which do not. The data stays on our own servers and is not sold or shared for advertising.
You can disable cookies through your browser settings.
If your browser sends a "Do Not Track" signal, our own analytics turns itself off for that visit.
5. Data Retention
- Account Data: While account active + 30 days after deletion
- Order Data: Legal accounting requirements: 10 years
- Usage Logs: 12 months
- Site Analytics: 6 months for visit records; after that only daily totals remain, and those carry no visitor identifier.
- Marketing Data: Until consent is withdrawn
Deleting your data
You can have your data deleted at any time, in one of the following ways.
- From the application: records such as products, customers and connections can be deleted from their own screens. Disconnecting a WhatsApp connection deletes the stored access credentials immediately.
- By request: write to support@restomas.com from your registered email address and ask for your account and its data to be deleted. We verify the request before acting on it.
- Timing: verified requests are completed within 30 days. Encrypted backups are rotated out within 90 days, after which no copy remains.
Records we are legally required to keep, such as invoices and payment history, are retained for the statutory period and then deleted. Nothing else is kept.
6. Data Security
- SSL/TLS encryption for all data transfers
- Integration credentials and two factor secrets stored encrypted with AES-256-GCM
- Regular security audits and penetration testing
- Access control and authorization mechanisms
- Backup and disaster recovery procedures
7. Your Rights (KVKK & GDPR)
- Right to know whether your data is being processed
- Right to request information about processing
- Right to learn the purpose of processing
- Right to know third parties data is transferred to
- Right to request correction of inaccurate data
- Right to request deletion when conditions are met
- Right to object to automated analysis outcomes
- Right to data portability (GDPR)
- Lodge a complaint with your local data protection authority if you believe your rights have been breached.
Children's privacy
Restomas is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has provided us data, write to support@restomas.com and we will delete it.
Communications and SMS
When you create an account, verify your phone number or sign in, Restomas may contact you by email and SMS. This section explains what we process for those messages and how you can stop them.
- Communication data: phone number, email address, language preference, consent and opt-out records, and the delivery status of the messages we send you.
- Purpose: we use SMS to deliver one-time verification codes for account login and phone number verification, and to send security notices about your account. We do not send marketing SMS.
- Messaging providers: SMS messages are delivered through Telnyx LLC and email through our email infrastructure provider. These providers process the data only to deliver the message on our behalf.
SMS opt-in data and consent records are never sold, rented or shared with third parties for marketing purposes. They are shared only with the service providers needed to deliver the message, and where the law requires it.
We will not share or sell your mobile information with third parties for promotional purposes.
You can withdraw your consent at any time by removing your phone number in your account settings, by replying STOP to a message received from our US number, or by writing to support@restomas.com. Once the number is removed, we stop sending SMS to it.
Message and data rates may apply. Message frequency varies and depends on your own activity, such as how often you sign in.
Changes to this policy
When this policy changes we update the date at the top of the page. For changes that materially affect your rights we also notify you by email or inside the application before they take effect.
8. Contact
Restomas is operated by Evert, LLC, a company registered in Delaware, United States.
For questions about our privacy policy or to exercise your rights: