Privacy Policy
Effective Date: 31.12.2026
Last Updated: 16.09.2025
This Privacy Policy explains how nom-nom (“we”, “us”, or “our”) collects, uses, discloses,
and protects personal information when restaurants and their staff use the nom-nom
бизнес (the “App”) distributed on Google Play. It also describes your choices and rights.
Where applicable, this Policy addresses regional requirements, including the UK/EU GDPR
and U.S. state privacy laws.
Transparency on Google Play. The disclosures below are aligned with Google
Play’s User Data policy and the Data safety section requirements. Your Play
Console answers must stay accurate and up to date.
1) Who We Are & How to Contact Us
Controller: nom-nom
Email: info@nom-nom.by
B2B notice. For data that restaurants enter about their guests/customers (e.g.,
guest name, phone, visits), we generally act as a processor/service provider to that
restaurant; for restaurant account, usage, and diagnostics data, we act as controller.
2) What Data We Collect
We collect the minimum data needed to register restaurant accounts, manage staff and
reservations, operate loyalty features, and maintain the App.
A) Restaurant Account & Onboarding
Registration request (on landing site): representative name, restaurant name,
address, phone, email.
Account signup & login: email verification with one-time code, password creation
(stored hashed); password reset by emailed link.
Venue profile: name, address, venue type, cuisine type(s), average check
(food/drinks), working phone, work schedule, detailed info, venue photos.
B) Staff Management
Employee profiles: name, email, phone, role (manager/admin/host/waiter);
password-set link sent by email; ability to edit/delete employees; broadcast
messages to all staff.
C) Reservations & Hall Map
Reservations: guest name, phone, party size, date/time, pre-order flag,
comments, expected duration, table number, status
(upcoming/active/closed/no-show), edits/cancellations with reasons.
Hall map & timeline: table state, transfers between tables, active bookings,
delay/overdue markers.
D) Loyalty & Customer Base (entered by restaurants)
Customer base: name, phone, rating, number of visits, average check, top
dishes, order history with amounts, birthday (day/month), notes, discount
level, blacklist flag; search and filtering.
Guest QR scans: scanning to retrieve visit count, discount %, name, phone, past
orders and to apply benefits; optional adding to customer base.
E) Menu & Media
Menu items: names, ingredients/composition, portions/volume, price, categories,
service type; item photos uploaded from photo library or captured with camera.
Venue photos likewise added.
F) Device, Diagnostics & Usage
Device & App info (device identifiers, OS, app version), crash logs/performance
data, and feature-usage analytics to improve stability and UX.
We do not access device Contacts and do not collect precise device location
for the Restaurant App; address details are provided manually by the restaurant.
3) How We Collect Data
Directly from you during registration, profile setup, staff/guest management,
reservations, loyalty configuration, and when you upload photos.
Automatically via in-app technologies/SDKs for analytics and crash diagnostics.
From service providers (email gateway) solely to deliver verification and reset links.
4) Purposes & Legal Bases
We process personal data to:
Create and secure restaurant accounts; authenticate users; handle password
resets. (Contract; legitimate interests; legal obligations.)
Operate core features: reservations, hall map, loyalty, customer base, menu/media,
staff management, staff messaging. (Contract; legitimate interests.)
Scan guest QR codes to retrieve loyalty/visit data and apply benefits. (Contract;
legitimate interests.)
Improve and secure the App via analytics and diagnostics; prevent fraud/abuse.
(Legitimate interests; legal obligations.)
Provide support and service communications. (Contract; legitimate interests.)
Controller/Processor roles (GDPR/CPRA). For Business Customer Data (guest records),
we act as processor/service provider and process on the restaurant’s instructions; for
restaurant account, usage, and diagnostic data, we are controller.
5) Google Play “Data safety” Summary (for Play
Console)
Use the mapping below to help complete the Data safety form. Ensure your final answers
reflect your actual implementation and SDKs, including any third-party SDK data handling.
Data types (Google Play categories) → Collected / Shared / Purposes / Optional?
Personal info → Email; Phone (restaurant user & staff)Collected / Not
shared / Account creation, authentication, support, staff management / Required.
Personal info → Name (staff & guest, entered by restaurant)Collected / Not
shared / Staff/guest management, reservations, loyalty / Required for these
features.
User IDs/Device IDsCollected / Not shared / Security, fraud prevention,
analytics / Required.
User-generated content → Photos/Images (menu & venue)Collected
(optional) / Not shared / Menu/venue profile / Optional.
App activity → Interactions (e.g., feature usage)Collected / Not shared /
Analytics, product improvement / Required for quality.
Diagnostics → Crash/performanceCollected / Not shared / Stability and
quality / Required.
Other data → Reservations & Guest QR contentCollected / Not shared /
Loyalty and reservations management / Required for these features.
Security practices (for Data safety):
Data is encrypted in transit;
Users can request data deletion (see Section 10);
We do not sell personal data;
We do not use data for advertising or cross-app tracking.
Google Play requires that your Data safety disclosures are truthful and kept up
to date; misrepresentations may lead to enforcement.
6) App Permissions (Android)
Camera: to scan guest QR codes and to capture photos for menu/venue images.
Photos and media / Storage: to select and save photos for menu items and venue
profile.
Требования к продукту
Notifications (optional): service and account/security alerts.
You can manage permissions in Android Settings → Apps → nom-nom бизнес →
Permissions. Certain permissions may require a Permissions Declaration in Play Console
during release.
7) Do We Share Personal Data?
We do not sell personal data and do not share it with third parties for their independent
advertising or marketing. We share data only with processors/service providers bound by
contracts to act on our instructions, such as hosting/databases, email delivery,
analytics/crash reporting, and support tooling.
8) International Transfers
If data is transferred outside your jurisdiction (e.g., UK/EU), we use safeguards such as
Standard Contractual Clauses or rely on adequacy decisions. We maintain technical and
organizational measures to protect data in transit and at rest.
9) Data Retention
Restaurant account & staff data: retained for the life of the account; deleted within
[30] days after account deletion or [24] months of inactivity.
Reservations & hall data: retained to provide history and resolve disputes;
archived/anonymized after [24] months.
Loyalty & customer base (Business Customer Data): retained per restaurant
settings and contract; we delete or return this data upon account termination or per
the restaurant’s instructions.
Menu & media assets: retained while published; you can delete items/photos at any
time.
Diagnostics & analytics: up to [13] months.
We may keep minimal records to comply with legal obligations and enforce our
terms.
10) Your Rights & Choices
Depending on your location, you may have rights to access, rectify, delete, restrict, or
object to processing; to data portability; and to withdraw consent. UK/EU residents may
contact their Supervisory Authority. California residents may exercise rights under the
CCPA/CPRA.
Controls in the App
Update venue info, staff, menu, photos, loyalty settings in the App.
Manage Camera/Photos/Notifications in device settings.
Opt out of analytics where available (if provided in settings).
Account & Data Deletion (Google Play requirement)
In-app: Profile → Settings → Delete account (removes account and associated
personal data we aren’t legally required to keep).
Web request (required): Provide a public web link where users can request
account and data deletion without reinstalling or signing in (e.g., a simple form).
Include this URL in Play Console’s Data safety → Data deletion section.
11) Children’s Privacy
The App is for use by restaurant staff and is not intended for children below the age
defined by local law (typically 13–16). We do not knowingly collect data from children.
12) Security
We implement technical and organizational measures designed to protect personal data,
including encryption in transit, hashed passwords, access controls, and regular reviews.
No method of transmission or storage is completely secure.
13) Third-Party Links & Integrations
The App may contain links you enter (e.g., Instagram, Telegram, Facebook, website, Twitter)
for your venue profile; your use of those services is governed by their own privacy policies.
14) Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated in the
App or by email, and the “Last Updated” date will be revised. Your continued use of the App
after changes take effect means you accept the revised Policy.
15) Region-Specific Notices
UK/EU GDPR: Legal bases as listed in Section 4; we rely on SCCs or adequacy
decisions for international transfers; you may contact our DPO (if appointed).
California (CCPA/CPRA): We do not “sell” or “share” personal information as
defined by the CPRA. You may exercise access and deletion rights via Section 10.
16) Developer Notes (not part of user-facing policy; for
your Play Console configuration)
Keep Data safety answers synchronized with this Policy and with all SDKs in use (be
aware of SDK data practices and versions).
Complete the Data deletion questions and include the web resource URL;
enforcement and deadlines are documented by Google Play.
Declare permissions accurately; complete any required Permissions Declaration
Form for restricted permissions.
Before submission, ensure Play Console’s App content sections (Ads, Data safety,
Privacy Policy URL, etc.) are complete.
17) Contact
Questions about this Policy or our data practices: info@nom-nom.by.