Back to the site

Reprehendo (RH)

Security and data custody

Version 1.2 · in force since 23/09/2026

How your venue's data is protected, written so it can be understood. If anything here does not add up, write to us before starting a trial.

1. Your venue's data is yours alone

  • ·Each business has its own separate archives: menu, tables, orders, takings and staff of one venue cannot be reached from another venue.
  • ·Separation is not left to individual queries: it is enforced at a single control point that travels with every request. A coding mistake on one page cannot leak data outside the venue.
  • ·The connection is always encrypted (HTTPS) on the service domain.

2. Passwords, codes and PINs

  • ·Your venue code and staff PINs are never stored in clear text: only an encrypted fingerprint (bcrypt) is kept, from which the original cannot be recovered. Not even we can read them.
  • ·After five wrong attempts access locks automatically for a few minutes, per originating address: anyone trying to guess codes in bulk is stopped.
  • ·Access to the vendor console requires a long password plus a one-time code sent by email: knowing the password alone is not enough.
  • ·We never ask for passwords or card details by email. If you get such a request, it is not from us.

3. Backups

  • ·Every night a copy of each venue's data is created and encrypted at rest (AES-GCM) before being stored.
  • ·The owner can download a file with all their data at any time, from the Backup section of the app.
  • ·Download links expire and every download is counted.

4. Who can do what, and it is recorded

  • ·Everyone signs in with their own PIN and operations stay in their name: cancellations, discounts, takings and cash handovers are attributed to whoever made them.
  • ·Vendor operations (activations, plan changes, suspensions, deletions) go into an append-only log that no page can erase.

5. Deletion and retention

  • ·You can request permanent deletion of your venue from the app: the request is confirmed by email and nothing is touched until you confirm.
  • ·Trials that are not converted: data is kept for 30 days after expiry, with an email warning three days before deletion and a link to download everything.
  • ·On deletion, backups and open sessions are removed too.

6. What we do not promise

  • ·Reprehendo is in beta: we would rather say what is missing than let you find out later.
  • ·We do not (yet) hold formal security certifications, nor certified fiscal storage of electronic receipts.
  • ·Infrastructure is provided by third parties: processing takes place in the United States, the European Union and India, with the safeguards required by the GDPR.
  • ·If an incident affecting data occurs, affected customers are notified without delay and in writing.