1. Who we are
ListoQ is a B2B SaaS platform for food-service venues to create, publish, and manage digital menus that guests can open from a QR code or link.
For privacy requests, contact [email protected].
2. Our privacy roles
We act as a controller for personal data we collect for our own business purposes, including account administration, authentication, billing and commercial communication, support, security, website analytics, and marketing.
We may act as a processor for personal data that a customer uploads, configures, or otherwise processes through the ListoQ service on behalf of its own business, such as venue contact details or any guest-related information a venue chooses to include in the platform.
3. Personal data we collect
The categories of data depend on how you use ListoQ, whether you are a website visitor, an account user, a venue owner, or a business contact.
- Identity and contact data: name, email address, phone number, company or venue name, business role, and preferred language.
- Account data: login credentials, authentication status, venue access, account settings, and security events.
- Venue and menu data: venue profile, contact details, digital menu structure, categories, items, prices, descriptions, images, allergens, tags, availability, styling choices, QR and publishing metadata.
- Billing and commercial data: plan, subscription status, invoices, payment references from payment providers or merchants of record, tax information, commercial requests, and contract-related correspondence.
- Technical data: IP address, device and browser information, operating system, approximate location inferred from technical data, logs, request metadata, cookies, and similar identifiers.
- Usage and analytics data: page views, admin actions, feature usage, performance events, and aggregated or anonymized product analytics.
- Support and communication data: messages sent through forms, support requests, implementation notes, feedback, and related attachments.
4. Why we process data and legal bases
We process personal data only when we have a legal basis under applicable law. Depending on the context, this may include contract necessity, legitimate interests, consent, or legal obligation.
- Account creation, authentication, and service delivery: contract necessity.
- Publishing and hosting customer-facing menu pages, QR links, media, and venue content: contract necessity and, where relevant, customer instructions as processor.
- Billing, tax, accounting, subscription management, and payment-related administration: contract necessity and legal obligation.
- Customer support, onboarding, troubleshooting, service notices, and operational communication: contract necessity and legitimate interests.
- Security monitoring, fraud prevention, abuse detection, rate limiting, audit logs, and platform reliability: legitimate interests and legal obligation where applicable.
- Product analytics, performance measurement, and service improvement: legitimate interests or consent where required for cookies or tracking.
- Marketing communication, newsletters, retargeting, or optional promotional messages: consent where required or legitimate interests for limited B2B communication, with an opt-out option.
7. International transfers
Some providers or infrastructure may process data outside the European Union or the European Economic Area. This can happen when hosting, analytics, payment, email, support, CDN, or security providers operate internationally.
Where required, we rely on appropriate transfer safeguards such as adequacy decisions, Standard Contractual Clauses, data processing agreements, or other lawful mechanisms recognized by applicable data protection law.
8. Data retention
We keep personal data only for as long as reasonably necessary for the purposes described in this notice, unless a longer period is required by law, tax rules, accounting duties, dispute handling, fraud prevention, security, or backup integrity.
- Account and venue workspace data is generally retained while the account is active.
- Menu content and media are retained while needed to provide the service or until removed by the customer, subject to backups and legal requirements.
- Support and business correspondence may be retained for a reasonable period after resolution to maintain service history and defend legal rights.
- Billing, invoice, payment, and tax records are retained for the period required by applicable financial and tax laws.
- Security logs, technical logs, and backup copies are retained for limited operational periods unless needed for investigation, security, or legal reasons.
9. Security
We use administrative, technical, and organizational measures designed to protect personal data, including access controls, encrypted transport, secure infrastructure practices, backups, monitoring, and restricted administrative access.
No online service can guarantee absolute security. Customers are responsible for using strong passwords, protecting credentials, keeping account access current, and notifying us promptly about suspected unauthorized access.
10. Your rights
Depending on your location and the context of processing, you may have the following rights. We may need to verify your identity and, where we act as processor, redirect the request to the customer that controls the relevant data.
- Access your personal data and receive information about how it is processed.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of personal data where the law allows it.
- Request restriction of processing in certain circumstances.
- Request data portability where technically feasible and legally required.
- Object to processing based on legitimate interests.
- Withdraw consent where processing is based on consent, without affecting earlier lawful processing.
- Complain to a competent data protection authority if you believe your rights have been violated.
11. Customer responsibilities
Customers decide what venue, menu, image, allergen, price, and customer-facing information they upload or publish through ListoQ. Customers must ensure they have a lawful basis and any required notices or permissions for personal data they add to the platform.
If a venue uses ListoQ together with third-party tools, printed QR codes, websites, social profiles, ordering flows, reservation systems, or analytics outside ListoQ, the venue remains responsible for explaining those separate processing activities to its own users where required.
12. Changes and contact
We may update this Privacy Policy when the service, legal requirements, providers, or processing activities change. The updated version will be posted on this page with a revised date.
For privacy, data access, correction, deletion, portability, or other data protection requests, contact [email protected].