Privacy Policy
Last updated: July 2026
1. Data controller
The data controller is Vezzoly (hereinafter, «Vezzoly», «we» or «us»).
Contact email: hola@vezzoly.com
[Tax ID and registered address pending legal constitution — to be updated before activating paid plans.]
2. Data we collect
- Registration data: name, email address and password (hashed) when you create an account.
- Restaurant data: name, logo, slug, brand color and other settings you configure.
- Operational data: orders, products, categories, tables and modifier groups created within the platform.
- Usage data: access logs, IP address, browser type and interaction events for security and performance purposes.
3. Purpose and legal basis
- Providing the service: execution of the contract (Art. 6.1.b GDPR).
- Security and fraud prevention: legitimate interest (Art. 6.1.f GDPR).
- Legal obligations: compliance with applicable law (Art. 6.1.c GDPR).
4. Data retention
We retain your data for as long as your account is active. If you delete your account, your data will be permanently erased within 30 days, except where retention is required by law.
5. Data transfers
All data is hosted within the European Union. We use the following sub-processors:
- Vercel — frontend hosting (EU region).
- Stripe — payment processing (when the Premium plan is active), PCI-DSS Level 1 certified.
6. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict processing, data portability and object to processing. To exercise these rights, contact us at hola@vezzoly.com.
You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es.
7. Changes to this policy
We may update this policy. We will notify you of material changes by email or via an in-app notice. Continued use of the service after the effective date constitutes acceptance.