RestivoRestivo

Privacy Policy

Last updated 21 September 2026

The English version is the authoritative one.

This is the privacy policy for Restivo. See also our Terms of Service.

Restivo is software that hospitality businesses (restaurants, cafés, bars and similar) use to run orders, kitchen and counter tickets, staff and reports. This policy explains what personal data Restivo handles and why. It covers two kinds of people: the people who hold a Restivo account (owners, managers and staff), and — indirectly — the customers of those businesses.

For the business data an owner or manager enters (menu, tables, orders, the team list), the business is the party deciding how it is used and Restivo processes it on the business's behalf. For account and security data (sign-in, sessions, security notices) Restivo decides how it is used.

  • Account: your name, your email address, and either a hashed password (never the password itself) or the identifier of your Google account if you sign in with Google.
  • Your work in a business: which businesses you belong to, your role in each, and the actions you take that affect the business (for example creating an order or changing a role). These form the business's audit log and can include the IP address a sensitive action was made from.
  • Business records entered by the business: menu and prices, tables, orders and their items, payments recorded as Cash, Card or Other, receipts, shifts and reports. Restivo records that a customer paid; it does not process customer payments and never sees card details.
  • Staff invitations: the email address an owner or manager types in when inviting someone.
  • Table requests: when a customer scans a table's "call a waiter" QR code, we store which table it was, what they asked for (for example the bill, water or a waiter) and any note they chose to type, so staff can respond. There is no customer account, and nothing that identifies the customer — no name, email or IP address — is stored with the request. Please don't type personal details into the note; it is visible to the business's staff.
  • Signed-in devices: a short label such as "Chrome on macOS", when each session was created and last used, so you can see and end your own sessions.
  • Messages you send us: the contact form, and feedback or bug reports from inside the app (the page you were on is attached; no browser fingerprint).
  • Technical error reports: when something breaks, a scrubbed error message and stack trace. Tokens, codes, emails and card-like numbers are removed before storage.
  • Product usage: a small set of milestones (for example "created a business", "reached setup step 2", "opened a help article"). No cookies, no third-party tracker, no IP address and no browser details are stored with these.

Restivo does not set advertising or tracking cookies. To keep you signed in and remember your choices it stores a few items in your browser's local storage: your sign-in token, the business you last opened, your language, and (only while you are setting up a business) your unfinished setup answers. These are strictly necessary for the app to work, so no consent banner is shown. If we ever add analytics or marketing tools that need consent, this page and a consent choice will be added first.

  • To provide the service: sign you in, keep businesses separate from one another, show each person only what their role allows, and run orders through the kitchen and counter.
  • To keep accounts and businesses secure: rate limiting, sign-in and security notices, audit logs, and detecting and fixing errors.
  • To communicate with you: verification codes, password resets, staff invitations, security and billing notices, and replies to your messages.
  • To improve Restivo: understanding where people get stuck in setup and which help pages are used.

We do not sell personal data and we do not share it for advertising.

  • Google, only if you choose "Continue with Google" (we receive your name, email and Google account identifier).
  • Our email delivery provider, which sends the emails listed above.
  • Our hosting and database providers.
  • A billing provider, once paid subscriptions are switched on. It will handle payment details; Restivo does not store them.
  • Account data: until you delete your account. Deleting it removes your access, erases your name, email and password from the account record, and unlinks your sign-in methods.
  • Business records and audit logs: they belong to the business and are kept while the business exists, so a business's order history does not disappear when one member leaves. A deleted person appears there as "Deleted user".
  • Technical error reports: 90 days.
  • Messages you sent us: kept so we can answer and improve the product; ask us to delete them at any time.
  • See and correct your details: Profile and Security pages.
  • Get a copy: Security → "Download my data" gives you the personal data above as a file. Owners and managers can also download the business's own data from Settings.
  • See and end your sessions: Security → Signed-in devices.
  • Delete your account: Security → "Delete account". If you own a business you first transfer ownership.
  • Anything else — including a question or complaint about how your data is handled — use the Contact page. You also have the right to complain to your local data-protection authority.

Passwords are stored only as salted hashes. One-time codes are stored only as hashes and expire quickly. Access to a business is checked on the server for every request, so one business can never read another's data. Uploaded images are re-encoded before being stored. We limit sign-in and code attempts and tell you about sensitive changes to your account. No system is perfectly secure; if we learn of a breach affecting you we will tell you.

Restivo is a business tool and is not intended for anyone under 16.

If we change what we collect or why, we will update this page and its date, and tell account holders about material changes.

Questions about privacy? Use the Contact page on this website, or "Send feedback" inside the app.