Legal

Privacy Policy

Last updated: June 1, 2025

This policy describes how GrazieChef collects, uses and protects users' personal data under Regulation (EU) 2016/679 ("GDPR") and applicable Italian data protection law.

1. Data controller

The data controller is Alexix Capurro, an individual operating under an occasional professional service arrangement (no VAT registration), reachable at: hello@graziechef.com

For any privacy-related request you can write to this address. We will reply within 30 days of receipt.

2. Data we collect

2.1 Data provided directly by the user

Registration data: email address and password (hashed with bcrypt) needed to create an account.

Venue data: venue name, table count and layout, menu (categories, items, prices), opening hours, supplier information.

Operational data: orders, table sessions, reservations, internal notes, staff clock-ins. This data belongs to the venue that generates it — GrazieChef stores it solely on the operator's behalf.

Staff data: name and role of staff members added by the operator. We do not collect additional personal data about employees without their consent.

Payment data: handled directly by Stripe (see §5). GrazieChef never stores credit card numbers.

2.2 Data collected automatically

Access logs: IP address, browser type, pages visited and access times. Kept for 90 days for security and diagnostic purposes.

Technical cookies: session tokens needed to keep the user authenticated. We do not use profiling or advertising cookies.

3. Purposes and legal basis of processing

PurposeLegal basis
Service delivery (account, app features)Performance of a contract (GDPR art. 6.1.b)
Payment and subscription managementPerformance of a contract (GDPR art. 6.1.b)
Security, fraud and abuse preventionLegitimate interest (GDPR art. 6.1.f)
Customer supportPerformance of a contract (GDPR art. 6.1.b)
Service communications (e.g. subscription expiry)Performance of a contract (GDPR art. 6.1.b)
Product improvement (aggregated, anonymous data)Legitimate interest (GDPR art. 6.1.f)
Legal and tax complianceLegal obligation (GDPR art. 6.1.c)

We do not use data for direct marketing without explicit consent, and we never sell personal data to third parties.

4. Data retention

Account and venue data are kept for the duration of the contractual relationship and for the 12 months following account closure, to allow for restoration and to meet accounting/tax obligations.

Historical orders, sessions and operational data are kept for 24 months from creation. Access logs are deleted after 90 days.

You can request early deletion of your data at any time (see §7).

5. Data recipients

Data is processed by GrazieChef and shared only with the service providers necessary to run the platform:

Supabase (infrastructure and database)

The database is hosted on Supabase (Supabase Inc.) on servers in the Frankfurt, EU region (AWS eu-central-1). Data never leaves the European Union without adequate safeguards. DPA signed.
supabase.com/privacy

Stripe (payments)

Payments are handled by Stripe (Stripe, Inc.). GrazieChef never stores payment card data: everything happens directly between the user and Stripe over an encrypted TLS connection. Stripe is PCI DSS Level 1 certified.
stripe.com/privacy

No data is ever transferred to advertising platforms, social networks or data brokers.

6. Cookies

GrazieChef only uses strictly necessary technical cookies:

  • Session cookies: keep the user authenticated while browsing. Duration: 7 days (or until explicit sign-out).
  • Preference cookies: store local preferences (e.g. theme). Duration: 1 year.

We do not use third-party cookies, advertising cookies or tracking tools like Google Analytics. A cookie banner is not required because we only use technical cookies exempt from consent under applicable guidance.

7. Your rights

Under GDPR articles 15-22, you have the right to:

  • Access: confirm whether data concerning you is being processed and obtain a copy.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure ("right to be forgotten"): request deletion of your personal data.
  • Restriction: request restriction of processing in certain cases.
  • Portability: receive your data in a structured, machine-readable format (JSON/CSV).
  • Objection: object to processing based on legitimate interest.
  • Complaint: lodge a complaint with the competent data protection authority (garanteprivacy.it).

To exercise any of these rights, write to hello@graziechef.com. We will reply within 30 days, extendable by a further 60 days for complex requests.

8. Security

We adopt adequate technical and organizational measures to protect personal data against unauthorized access, loss or alteration:

  • Encryption in transit: TLS 1.2/1.3 on all connections.
  • Encryption at rest: AES-256 on the database (managed by Supabase/AWS).
  • Authentication: bcrypt password hashing, JWT sessions with automatic expiry.
  • Multi-tenant isolation: database RLS (Row Level Security) — each venue sees only its own data.
  • Employee access: limited to the minimum necessary (least privilege principle).

9. Minors

GrazieChef is a B2B service aimed at venue and restaurant operators. We do not knowingly collect personal data of persons under 18. If you believe we have mistakenly received data about a minor, please contact us immediately.

10. Changes to this policy

We may update this policy periodically. In case of material changes, we will notify users by email with at least 15 days' notice. The updated version will always be available at this address.

Continued use of the service after the effective date of the changes constitutes acceptance of the updated policy.