LEGAL DOCUMENT
Privacy Policy
LAST UPDATED
December 14, 2025
VERSION 1.0
Introduction
This Privacy Policy for Voicu Octavian-Mihai PERSOANA FIZICA AUTORIZATA (doing business as TASTEEM) ("we", "us", or "our") describes how and why we collect, store, use, and share ("process") your personal information when you use our Services.
COMPANY DETAILS
LEGAL NAME
Voicu Octavian-Mihai PERSOANA FIZICA AUTORIZATA
VAT NUMBER
51944577
ADDRESS
Str. Cerealelor, Nr 13, Baneasa, Constanta, Romania
octavianvoicu0@gmail.com
PHONE
+40 768 004 329
TASTEEM provides an AI-powered restaurant recommendation and analytics platform that helps restaurants deliver intelligent dish suggestions to customers while providing owners with detailed performance insights.
We are committed to protecting your privacy and complying with GDPR (EU), CCPA (California), PIPEDA (Canada), UK Data Protection Act 2018, and other applicable data protection laws.
PRIVACY CONTACT
octavianvoicu0@gmail.com
Quick Summary
Before diving into details, here's what matters most:
WE COLLECT
Your account info (name, email), restaurant/menu data, usage analytics, and billing information
WE USE IT FOR
Providing AI recommendations, analytics, billing, service improvement, and security
WE SHARE WITH
Stripe (payments), cloud hosting providers, AI services (OpenAI) - that's it
WE DON'T
Sell your data, use it for unrelated advertising, share it with competitors, or use tracking cookies
YOUR RIGHTS
Access, correct, delete, export your data anytime
SECURITY
Industry-standard encryption, access controls, regular audits
RETENTION
Active account data kept while you use the service. Analytics retained based on plan: 30/60/120 days. Immediate deletion upon account closure
Information We Collect
Information We Collect
Account & Authentication Data
What We Collect:
Name and email address (required for account creation)
Password hash (encrypted - we never store plain passwords)
Google OAuth data if you sign in with Google (we receive your Google profile info but don't store your Google password)
User role (member, admin) within teams
Consent records: Whether you've given consent, Timestamp when you consented, Privacy policy version you agreed to, Marketing consent preferences (optional)
Account timestamps: Creation date, last updated, deletion date (if applicable)
Authenticate you securely
Communicate service updates
Manage team permissions
Comply with GDPR consent requirements
Send marketing emails (only if you opt-in)
Contract performance (account management), Consent (marketing), Legal obligation (consent tracking)
Team & Business Information
What We Collect:
Team names and member lists
Team member roles and permissions
Join dates and invitation history
Invitation records: email, role, who invited them, status (pending/accepted/rejected)
Manage multi-user restaurant teams
Control access based on roles
Track team activity for security
Contract performance, Legitimate interests (security)
Billing & Subscription Data
What We Collect:
Stripe identifiers: Customer ID, Subscription ID, Product ID
Plan information: Plan name, subscription status
Token usage tracking: Daily counts per team/restaurant for billing
Billing history and payment status
What We DON'T Collect:
❌ Credit card numbers
❌ CVV codes
❌ Full payment details
All payment card information is handled directly by Stripe (PCI DSS compliant). We never see or store your card details.
Process payments and manage subscriptions
Track usage against plan limits
Generate invoices
Comply with tax regulations
Contract performance, Legal obligation (tax records)
Restaurant & Menu Data
What We Collect:
Restaurant names, addresses, cities, countries
Opening hours and contact information
Logos you upload (stored as image URLs)
Branding settings: colors, fonts, welcome messages, background images
Chatbot personality: Tone (friendly, professional, humorous, etc.), formality level (1-10)
Embed codes generated for your websites
Dish names, descriptions, categories
Prices and currency
Ingredients and toppings
Allergens (critical for customer safety)
Dietary flags (vegetarian, vegan, gluten-free, etc.)
Nutritional information: Calories, protein, carbs, fat, weight
Spice levels (0-5)
Availability status
Vector embeddings (1536-dimensional) for AI semantic search
Generate AI-powered recommendations
Match customer preferences to dishes
Provide accurate allergen warnings
Calculate nutritional information
Enable semantic menu search
Display recommendations on your website
Contract performance (core service functionality)
⚠️ Important: You are responsible for ensuring this data (especially allergens and nutrition) is accurate and compliant with food safety regulations.
Usage Analytics & Performance Data
What We Collect:
Daily and hourly recommendation session counts
Session durations (in milliseconds)
Timestamps of interactions
Which dishes were recommended
Customer feedback (positive/negative ratings)
Recommendation success rates
Conversion metrics (views to engagement)
Time-based patterns (which hours/days perform best)
Menu section popularity and view counts
Monthly dish insights (total recommendations, views, conversion rates)
Peak performance days and times
Trending dishes and declining items
Provide you with business intelligence dashboards
Improve AI recommendation algorithms
Optimize menu performance suggestions
Help you identify trending dishes
Calculate ROI of recommendations
Contract performance (analytics features), Legitimate interests (service improvement)
We analyze this data at the restaurant level (not individual customer tracking). We don't create customer profiles or track individual diners across restaurants. All analytics are collected server-side without using tracking cookies.
Security & Technical Data
What We Collect:
Activity logs: User actions and timestamps
Login attempts and authentication events
API usage: Which API keys are used, when, and how often
Embed tracking: Which websites use your embed codes
Error logs and system performance metrics
Security incidents and threat detection data
What We DON'T Collect:
❌ IP addresses
❌ Browser fingerprints
❌ Device identifiers
Detect and prevent fraud
Investigate security incidents
Monitor for unauthorized access
Troubleshoot technical issues
Ensure service reliability
Legitimate interests (security, fraud prevention), Legal obligation (security incident reporting)
Security logs kept for 1 year for incident investigation.
GDPR Compliance Records
What We Collect When You Request Data Deletion:
Original user ID (before deletion)
Email hash (SHA-256) - provable but not readable
Request timestamp and completion timestamp
Verification method used to confirm your identity
What was deleted (detailed list of data removed)
What was retained and the legal basis for retention
Who processed the request (automated system or staff member)
Prove GDPR compliance if audited by data protection authorities
Demonstrate we honored your deletion request
Prevent fraud (can't claim "you never deleted my data")
Legal obligation (GDPR Article 17 compliance)
Permanent (required for audit trail)
After deletion, we cannot identify you from these records (email is hashed), but we can prove deletion occurred.
How We Use Information
How We Use Your Information
Core Service Delivery
✅ Provide AI-powered dish recommendations to your restaurant customers
✅ Generate analytics dashboards and business insights
✅ Manage your restaurant profile, menus, and team members
✅ Process payments and manage subscriptions via Stripe
✅ Enable website embed functionality with your custom branding
✅ Track token usage and enforce plan limits
Service Improvement
✅ Analyze usage patterns to improve recommendation accuracy
✅ Train and optimize AI algorithms (using anonymized data)
✅ Develop new features based on aggregate usage trends
✅ A/B test recommendation strategies
✅ Research restaurant industry trends
Communication
✅ Send essential service notifications (account changes, security alerts, billing issues)
✅ Provide customer support and technical assistance
✅ Send marketing emails about new features and tips (only if you opt-in)
✅ Notify you of Terms/Privacy Policy changes
Unsubscribe from marketing emails anytime using the link in every email or in account settings. You cannot opt-out of essential service emails.
Security & Legal Compliance
✅ Detect and prevent fraud, abuse, and unauthorized access
✅ Investigate security incidents and suspicious activity
✅ Comply with tax obligations (7-year retention of financial records)
✅ Respond to law enforcement requests with proper legal authority
✅ Protect our legal rights and user safety
✅ Maintain GDPR deletion audit trail
How We Share Information
How We Share Your Information
Service Providers We Use
Stripe - Handles all payment card processing
Name, email, billing amounts
Process subscriptions and payments securely
Stripe Privacy Policy
Vercel - Hosts our platform
Platform application and data
Reliable, secure hosting with global CDN
Data processing agreements, encryption at rest and in transit
Cloudinary - Stores uploaded images
Restaurant logos, branding images, background images
Optimized image delivery and storage
Secure storage with access controls
OpenAI (or your AI provider) - Powers recommendation engine
Menu data, customer preferences (for recommendation generation)
AI recommendation generation
Subject to OpenAI's privacy policy
We do not send personally identifiable customer information to AI services
Resend - Email delivery service
Email addresses, names, message content
Deliver transactional and marketing emails
Data processing agreements
What We DON'T Do
❌ We DO NOT sell your data to third parties
❌ We DO NOT share data with competitors
❌ We DO NOT use your data for unrelated advertising
❌ We DO NOT share individual customer dining data (analytics are restaurant-level only)
❌ We DO NOT share your data with data brokers
Legal Requirements
We may disclose information when required by:
✅ Law enforcement with proper legal authority (court order, subpoena)
✅ Regulatory investigations or audits
✅ Court orders or legal processes
✅ Protection of our legal rights or user safety
✅ Prevention of fraud or illegal activity
✅ Emergency situations (immediate harm prevention)
We will notify you of legal requests unless prohibited by law.
Business Transfers
If TASTEEM is acquired or merged:
Your data may transfer to the acquiring company
Same privacy protections will apply
You'll be notified of any ownership change
Data Security
Data Security
We take security seriously and implement:
Encryption
In transit: TLS 1.2+ encryption for all data transfers
At rest: Industry-standard encryption for stored data
Passwords: Never stored in plain text (bcrypt hashing)
Access Controls
Role-based access: Team members only see what they need
Multi-factor authentication: Optional for extra security
Principle of least privilege: Staff access limited to job requirements
API keys: Secure tokens for embed/integration authentication
Monitoring & Response
24/7 security monitoring for threats
Intrusion detection systems
Regular security audits and penetration testing
Incident response procedures
Automated threat alerts
Infrastructure Security
Regular software updates and patches
Firewall protection
DDoS mitigation
Secure backup procedures with encryption
Database access logging
Staff Training
Regular privacy and security training
Background checks for employees with data access
Confidentiality agreements
⚠️ No System is 100% Secure: While we implement strong safeguards, no internet-based service is completely invulnerable. We will notify you promptly of any data breach affecting your account.
Data Retention
Data Retention Periods Summary
| Data Type | Retention Period | Reason |
|---|---|---|
| Active Account Data | While account exists | Provide service |
| After Account Deletion Request | Immediate permanent deletion | Honor your deletion request |
| Analytics & Usage Data (Plan-Based Retention) | Starter Bite: 30 days, Main Course: 60 days, Chef's Special: 120 days | Provide analytics dashboards and performance insights based on your subscription tier |
| Financial/Billing Records | 7 years | Romanian tax law compliance |
| Security/Activity Logs | 1 year (anonymized immediately upon account deletion) | Fraud prevention, incident investigation |
| GDPR Deletion Records | Permanent | Prove compliance if audited |
| Marketing Consent Records | Until withdrawn + 2 years | GDPR compliance proof |
What Happens After Deletion?
Your account, menu data, and personal information are permanently deleted
All analytics data is permanently deleted (no retention after account deletion)
Billing records kept for tax compliance (7 years, anonymized)
GDPR deletion proof kept permanently (hashed email only, cannot identify you)
Your Privacy Rights
Depending on your location (EU, California, Canada, etc.), you have various rights:
Universal Rights (Available to All Users)
Right to Access 📄
Request copies of your personal data. Learn how we process your information.
How: Email octavianvoicu0@gmail.com or use account dashboard export
Right to Correction ✏️
Correct inaccurate or incomplete data. Update your profile, menu, and restaurant info.
How: Edit directly in account settings or contact support
Right to Deletion 🗑️
Request immediate account deletion ("right to be forgotten"). Deletion is permanent and irreversible.
How: Account settings > Delete Account, or email us
Note: We retain GDPR deletion proof (but cannot identify you from it)
Right to Data Portability 📦
Export your data in machine-readable format (JSON/CSV). Transfer to another service provider.
How: Account dashboard > Export Data
Additional Rights (GDPR - EU/UK Users)
Right to Restrict Processing ⏸️
Limit how we use your data in certain situations
How: Email octavianvoicu0@gmail.com with specific request
Right to Object ⛔
Object to processing based on legitimate interests. Object to direct marketing (always honored immediately).
How: Use unsubscribe link or email us
Right to Withdraw Consent 🚫
Revoke marketing consent anytime
How: Account settings or unsubscribe link
Right to Lodge a Complaint 📢
Complain to your local Data Protection Authority
California Privacy Rights (CCPA)
If you're a California resident:
Right to Know 📋
Categories of personal information collected. Sources and purposes of collection. Third parties we share with.
Right to Delete 🗑️
Same as GDPR deletion
Right to Opt-Out of Sale 🚫
We do not sell personal information, so this doesn't apply
Right to Non-Discrimination ⚖️
Equal service regardless of privacy choices
**CCPA Contact:** octavianvoicu0@gmail.com
How to Exercise Your Rights
Account Dashboard: Many rights (correction, export, deletion) available directly
Email Request: octavianvoicu0@gmail.com
Identity Verification: We may ask for proof of identity to protect your privacy
Response Time: Within 30 days (GDPR), 45 days (CCPA)
No Fee: Rights requests are free (except excessive or repetitive requests)
International Transfers
International Data Transfers
Your data may be processed in countries outside Romania/EU.
Where We Process Data
EU (Romania) - Primary location
US (Vercel hosting, OpenAI, Stripe, Cloudinary, Resend)
How We Protect Your Data
Standard Contractual Clauses (SCCs): For EU → non-EU transfers
Adequacy Decisions: Where EU Commission approves country's data protection
Encryption: Data encrypted in transit and at rest regardless of location
Data Processing Agreements: With all international service providers
EU-US Data Transfers
If using US providers:
Compliant with EU-US Data Privacy Framework (if applicable)
Or using Standard Contractual Clauses (SCCs)
Same security standards apply everywhere
Cookies & Tracking
Cookies & Tracking
Essential Cookies (Always Active)
We use necessary cookies for:
Authentication: Keep you logged in securely
Security: CSRF protection, session management
Functionality: Remember your dashboard preferences
Legitimate interests (site functionality)
No - these are required for the service to work
Analytics (No Cookies Used)
We collect analytics data to understand platform usage, but we do this server-side without using tracking cookies:
Feature usage and interaction patterns
Popular dashboard sections and tools
User flows and navigation paths
Performance metrics and error rates
All analytics are collected server-side through your authenticated session. No third-party tracking cookies or scripts are used.
Legitimate interests (service improvement)
Because we don't use cookies for analytics, no cookie consent is required for this tracking.
What We DON'T Use
❌ Third-party analytics cookies (Google Analytics, Facebook Pixel, etc.)
❌ Advertising cookies or retargeting pixels
❌ Cross-site tracking cookies
❌ Social media tracking pixels (beyond Google Sign-In button)
Your Choices
Browser Settings: You can block/delete essential cookies, but this will prevent login
Google Sign-In: Uses Google cookies per Google's privacy policy (only if you choose this login method)
Do Not Track: We respect browser DNT signals where feasible
Children's Privacy
Children's Privacy
Our service is designed for business use by adults (18+) operating restaurants.
❌ We do not knowingly collect information from children under 13 (or 16 in EU)
❌ Our service is not intended for children
If you believe we've collected child data:
Contact us immediately: octavianvoicu0@gmail.com
We will delete it promptly upon verification
If you discover your child created an account, contact us for immediate deletion.
Changes to Policy
Changes to This Privacy Policy
We may update this policy to reflect:
Changes in our practices or technology
New features or services
Legal or regulatory requirements
User feedback
How We Notify You:
Email to all registered users (for material changes)
In-app notification when you log in
Version tracking in your account (shows which version you reviewed)
Posted notice on website with effective date
For significant changes (e.g., new data collection, sharing practices), we may:
Require renewed consent
Provide opt-out option
Give advance notice (30+ days when possible)
Continued Use = Acceptance: Using Services after changes means you accept the new policy.
Don't Agree? You may delete your account before changes take effect.
Legal Basis Summary
This section summarizes the legal bases under the General Data Protection Regulation (GDPR) we rely upon for processing different categories of your personal data.
GDPR Legal Basis Mapping
| Purpose | Data Processed | Legal Basis (GDPR) |
|---|---|---|
| Account management | Name, email, password | Contract performance |
| Payment processing | Stripe IDs, billing data | Contract performance |
| AI recommendations | Menu data, preferences | Contract performance |
| Analytics dashboard | Usage data, performance | Contract performance |
| Security monitoring | Activity logs (no IP addresses) | Legitimate interests |
| Service improvement | Anonymized usage data | Legitimate interests |
| Marketing emails | Email (opt-in only) | Consent |
| Tax compliance | Billing records | Legal obligation |
| GDPR deletion tracking | Deletion records | Legal obligation |
Data Protection Officer
Data Protection Officer
For a company our size, we do not have a dedicated Data Protection Officer (DPO). However, all privacy inquiries are handled by:
octavianvoicu0@gmail.com
Voicu Octavian-Mihai
Within 30 days of inquiry
Contact Us
Contact Us
octavianvoicu0@gmail.com
Voicu Octavian-Mihai PERSOANA FIZICA AUTORIZATA, Str. Cerealelor, Nr 13, Baneasa, Constanta, Romania
+40 768 004 329
octavianvoicu0@gmail.com (subject: "Security Issue")
octavianvoicu0@gmail.com (subject: "GDPR Deletion Request")
Delete Account button
Regulatory Authorities
Regulatory Authorities
If you're unhappy with our response, you can lodge a complaint with:
ANSPDCP (Romanian Data Protection Authority)
https://www.dataprotection.ro/
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București
Your local Data Protection Authority
https://edpb.europa.eu/about-edpb/board/members_en
ICO (Information Commissioner's Office)
https://ico.org.uk/
California Attorney General
https://oag.ca.gov/privacy/ccpa
Your Consent
Your Consent & Acknowledgment
By creating an account and using TASTEEM, you confirm that you:
✅ Have read and understood this Privacy Policy
✅ Understand how we collect, use, and protect your information
✅ Provide explicit consent for data processing as described
✅ Understand your rights and how to exercise them
✅ Agree to international data transfers with appropriate safeguards
✅ Are at least 18 years old
Consent Recording: Your acceptance is recorded in our database with:
Timestamp of consent
Privacy policy version number
Consent given status (true/false)
Withdrawing Consent: You can withdraw consent for optional processing (e.g., marketing) anytime without affecting your account status. Core service processing continues under contract performance basis.
Effective Date
Effective Date
This Privacy Policy is effective as of December 14, 2025 and applies to all data collected from that date forward.
Previous versions available upon request: octavianvoicu0@gmail.com
Thank you for trusting TASTEEM with your restaurant data. We take that responsibility seriously and are committed to protecting your privacy.
December 14, 2025