Provisional version: we are completing the service owner's details, marked as pending. The rest of this page already applies.
GastroPilot is a service for running a restaurant's back office (delivery notes, inventory, recipe costing, point-of-sale sales and orders to suppliers) through WhatsApp and a web dashboard at www.getgastropilot.com. This policy explains what personal data we process, why, who we share it with and how you can exercise your rights. The Spanish version is available at /privacidad.
1. Who is responsible for your data
We are the controller of the data of the people who use GastroPilot (restaurant owners and staff) and of anyone who writes to us through the website. The business data a restaurant enters into GastroPilot, including its suppliers' data, is processed on behalf of the restaurant, which is its controller (see section 8).
2. What data we process
- Account data: name, email, password (stored hashed, we never see it), WhatsApp phone number and role of each person with access to the bot or the dashboard, the restaurants they can access and each restaurant's name.
- Google account data, if you sign in with Google: see section 5.
- Messages and files you send to the bot: text, photos of delivery notes and invoices, and documents you send us to load inventory or recipes.
- Business data: ingredients, stock, prices, recipes, sales and waste you record, and the orders you send.
- Point-of-sale data, if you connect it: sales (dishes, units, amounts and refunds) and the menu your POS provides, and the access permission you grant us, stored encrypted. We do not receive card data or data about your customers.
- Supplier data: name, WhatsApp number and email of the suppliers the restaurant adds, the orders we send them on its behalf and their replies. If the restaurant asks us to place orders through a supplier's website, also the username and password for that website, stored encrypted.
- Technical data: access and error logs. Error logs are stripped of emails, phone numbers and free text before being stored, and are deleted after 30 days.
- Website contact form: whatever you write in it.
3. Why we use it and on what legal basis
- Providing the service (replying in the bot, reading delivery notes, updating inventory, sending orders and telling you about replies): performance of a contract.
- Keeping the service secure (preventing abuse, applying the daily message quota, detecting and fixing errors): legitimate interest.
- Service emails (dashboard access, invitations, notices about your orders): performance of a contract.
- Answering people who contact us through the website: legitimate interest or pre-contractual steps.
We do not sell data, use it for advertising or build marketing profiles. We do not use your data to train artificial intelligence models.
4. Who we share it with
We use these providers, which process data only to provide their service to us:
- Meta (WhatsApp Business): carries messages with the bot and the orders we send to suppliers over WhatsApp.
- Anthropic (USA): the artificial intelligence that understands messages and reads photos of delivery notes and invoices. Under its commercial terms, data sent through its API is not used to train its models.
- Supabase: database and file storage, in the European Union (Ireland).
- Vercel: hosts the website and the API (servers in Dublin) and counts website visits without cookies.
- Resend: sends orders to suppliers by email and the messages from the website contact form.
- Google: sends dashboard access emails (account confirmation, password recovery, invitations) and runs our support mailbox. If you choose to sign in with Google, it also verifies your identity (section 5).
- Slack: notifies us internally of each order sent (restaurant, supplier, channel and destination phone or email) so we can help if something fails.
- Sentry: records technical errors so we can fix them, without message content or contact details.
- Square or SumUp: only if you connect your POS; we read sales and the menu from it.
- Browserless: only if an order is placed through a supplier's website; it opens that website and fills in the order on your behalf.
If we later enable payments or connecting your own WhatsApp or email to send orders, we will add those providers here before doing so.
Some of these providers are US companies or may access data from the US. Those transfers rely on the safeguards provided by the GDPR: the EU-US Data Privacy Framework or standard contractual clauses approved by the European Commission.
5. Google user data (Sign in with Google)
You can sign in to the dashboard with the "Continue with Google" button. If you do, Google shares only these details from your Google account with us: your name, your email address, your profile picture and your Google account identifier. We do not request access to your Gmail, contacts, calendar, files or any other Google data or service.
- How we use it: only to create your GastroPilot account, identify you when you sign in and show your name in the dashboard.
- How we share it: it is stored in our database (Supabase, in the EU) with the rest of your account data. We do not sell it, share it with third parties, use it for advertising or use it to train artificial intelligence models.
- How long we keep it: for as long as you have an account; when the account is closed it is deleted along with the rest of your data (section 6).
- How to revoke it: you can remove GastroPilot's access to your Google account at any time at myaccount.google.com/permissions, and ask us to delete this data by writing to soporte@getgastropilot.com.
GastroPilot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. How long we keep it
- While your account is active, we keep the data that makes up the restaurant's history (delivery notes, orders, inventory).
- Messages received by the bot are held briefly so they can be processed in order; their content is cleared as soon as processing finishes.
- The owner can download the restaurant's data and close it from the dashboard (Plan y uso → Tus datos), or ask us by writing to soporte@getgastropilot.com. When it is closed, the bot stops serving it immediately and we delete the account and restaurant data within 30 days, except what the law requires us to keep.
7. Your rights
You can ask to access, correct or delete your data, object to or restrict its processing, or take it with you (portability), by writing to soporte@getgastropilot.com. We will reply within one month. If you think we have not handled your request properly, you can complain to the Spanish Data Protection Agency (www.aepd.es).
8. If you are a supplier of a restaurant that uses GastroPilot
The restaurant has given us your name and contact details so that its orders reach you by WhatsApp or email. We process that data on the restaurant's behalf: we deliver its orders and pass your replies back to it. We do not use it for anything else or give it to anyone else. To exercise your rights you can contact the restaurant or write to us at soporte@getgastropilot.com and we will forward your request.
9. Cookies and browser storage
We do not use advertising or tracking cookies. The dashboard stores in your browser only what it needs to work: your session, the restaurant you have selected and whether you prefer the light or dark theme (in local storage), and a technical cookie that remembers whether the side menu is open or closed. Website visits are counted without cookies.
On the sign-in page, the "Continue with Google" button is served by Google, which may use its own cookies to show your account and, if you click it, sign you in. It only loads on that page; you can sign in with your email without using it. More information in Google's cookie policy.
10. Security
Data is encrypted in transit, POS credentials and supplier website credentials are stored encrypted, each restaurant can only see its own data and, within a restaurant, each person can only see and do what their role allows (for example, kitchen staff do not see costs). Access to our systems is limited to the people who need it to provide the service.
11. Changes
If we change this policy in a meaningful way, we will tell you by email or in the dashboard before it applies. If the service is taken over by a company, that company will become the new controller of the data; we will tell you in advance, with its details, and you can close your account if you disagree. See also the terms of service and the legal notice (in Spanish).