How your venue's data is protected, written so it can be understood. If anything here does not add up, write to us before starting a trial.
1. Your venue's data is yours alone
·Each business has its own separate archives: menu, tables, orders, takings and staff of one venue cannot be reached from another venue.
·Separation is not left to individual queries: it is enforced at a single control point that travels with every request. A coding mistake on one page cannot leak data outside the venue.
·The connection is always encrypted (HTTPS) on the service domain.
2. Passwords, codes and PINs
·Your venue code and staff PINs are never stored in clear text: only an encrypted fingerprint (bcrypt) is kept, from which the original cannot be recovered. Not even we can read them.
·After five wrong attempts access locks automatically for a few minutes, per originating address: anyone trying to guess codes in bulk is stopped.
·Access to the vendor console requires a long password plus a one-time code sent by email: knowing the password alone is not enough.
·We never ask for passwords or card details by email. If you get such a request, it is not from us.
3. Backups
·Every night a copy of each venue's data is created and encrypted at rest (AES-GCM) before being stored.
·The owner can download a file with all their data at any time, from the Backup section of the app.
·Download links expire and every download is counted.
4. Who can do what, and it is recorded
·Everyone signs in with their own PIN and operations stay in their name: cancellations, discounts, takings and cash handovers are attributed to whoever made them.
·Vendor operations (activations, plan changes, suspensions, deletions) go into an append-only log that no page can erase.
5. Deletion and retention
·You can request permanent deletion of your venue from the app: the request is confirmed by email and nothing is touched until you confirm.
·Trials that are not converted: data is kept for 30 days after expiry, with an email warning three days before deletion and a link to download everything.
·On deletion, backups and open sessions are removed too.
6. What we do not promise
·Reprehendo is in beta: we would rather say what is missing than let you find out later.
·We do not (yet) hold formal security certifications, nor certified fiscal storage of electronic receipts.
·Infrastructure is provided by third parties: processing takes place in the United States, the European Union and India, with the safeguards required by the GDPR.
·If an incident affecting data occurs, affected customers are notified without delay and in writing.