LEGAL DOCUMENT

Privacy Policy

LAST UPDATED

December 14, 2025

VERSION 1.0

Introduction

This Privacy Policy for Voicu Octavian-Mihai PERSOANA FIZICA AUTORIZATA (doing business as TASTEEM) ("we", "us", or "our") describes how and why we collect, store, use, and share ("process") your personal information when you use our Services.

COMPANY DETAILS

LEGAL NAME

Voicu Octavian-Mihai PERSOANA FIZICA AUTORIZATA

VAT NUMBER

51944577

ADDRESS

Str. Cerealelor, Nr 13, Baneasa, Constanta, Romania

EMAIL

octavianvoicu0@gmail.com

PHONE

+40 768 004 329

TASTEEM provides an AI-powered restaurant recommendation and analytics platform that helps restaurants deliver intelligent dish suggestions to customers while providing owners with detailed performance insights.

We are committed to protecting your privacy and complying with GDPR (EU), CCPA (California), PIPEDA (Canada), UK Data Protection Act 2018, and other applicable data protection laws.

PRIVACY CONTACT

octavianvoicu0@gmail.com

Quick Summary

Before diving into details, here's what matters most:

WE COLLECT

Your account info (name, email), restaurant/menu data, usage analytics, and billing information

WE USE IT FOR

Providing AI recommendations, analytics, billing, service improvement, and security

WE SHARE WITH

Stripe (payments), cloud hosting providers, AI services (OpenAI) - that's it

WE DON'T

Sell your data, use it for unrelated advertising, share it with competitors, or use tracking cookies

YOUR RIGHTS

Access, correct, delete, export your data anytime

SECURITY

Industry-standard encryption, access controls, regular audits

RETENTION

Active account data kept while you use the service. Analytics retained based on plan: 30/60/120 days. Immediate deletion upon account closure

Information We Collect

Information We Collect

Account & Authentication Data

What We Collect:

Name and email address (required for account creation)

Password hash (encrypted - we never store plain passwords)

Google OAuth data if you sign in with Google (we receive your Google profile info but don't store your Google password)

User role (member, admin) within teams

Consent records: Whether you've given consent, Timestamp when you consented, Privacy policy version you agreed to, Marketing consent preferences (optional)

Account timestamps: Creation date, last updated, deletion date (if applicable)

Authenticate you securely

Communicate service updates

Manage team permissions

Comply with GDPR consent requirements

Send marketing emails (only if you opt-in)

Contract performance (account management), Consent (marketing), Legal obligation (consent tracking)

Team & Business Information

What We Collect:

Team names and member lists

Team member roles and permissions

Join dates and invitation history

Invitation records: email, role, who invited them, status (pending/accepted/rejected)

Manage multi-user restaurant teams

Control access based on roles

Track team activity for security

Contract performance, Legitimate interests (security)

Billing & Subscription Data

What We Collect:

Stripe identifiers: Customer ID, Subscription ID, Product ID

Plan information: Plan name, subscription status

Token usage tracking: Daily counts per team/restaurant for billing

Billing history and payment status

What We DON'T Collect:

❌ Credit card numbers

❌ CVV codes

❌ Full payment details

All payment card information is handled directly by Stripe (PCI DSS compliant). We never see or store your card details.

Process payments and manage subscriptions

Track usage against plan limits

Generate invoices

Comply with tax regulations

Contract performance, Legal obligation (tax records)

Restaurant & Menu Data

What We Collect:

Restaurant names, addresses, cities, countries

Opening hours and contact information

Logos you upload (stored as image URLs)

Branding settings: colors, fonts, welcome messages, background images

Chatbot personality: Tone (friendly, professional, humorous, etc.), formality level (1-10)

Embed codes generated for your websites

Dish names, descriptions, categories

Prices and currency

Ingredients and toppings

Allergens (critical for customer safety)

Dietary flags (vegetarian, vegan, gluten-free, etc.)

Nutritional information: Calories, protein, carbs, fat, weight

Spice levels (0-5)

Availability status

Vector embeddings (1536-dimensional) for AI semantic search

Generate AI-powered recommendations

Match customer preferences to dishes

Provide accurate allergen warnings

Calculate nutritional information

Enable semantic menu search

Display recommendations on your website

Contract performance (core service functionality)

⚠️ Important: You are responsible for ensuring this data (especially allergens and nutrition) is accurate and compliant with food safety regulations.

Usage Analytics & Performance Data

What We Collect:

Daily and hourly recommendation session counts

Session durations (in milliseconds)

Timestamps of interactions

Which dishes were recommended

Customer feedback (positive/negative ratings)

Recommendation success rates

Conversion metrics (views to engagement)

Time-based patterns (which hours/days perform best)

Menu section popularity and view counts

Monthly dish insights (total recommendations, views, conversion rates)

Peak performance days and times

Trending dishes and declining items

Provide you with business intelligence dashboards

Improve AI recommendation algorithms

Optimize menu performance suggestions

Help you identify trending dishes

Calculate ROI of recommendations

Contract performance (analytics features), Legitimate interests (service improvement)

We analyze this data at the restaurant level (not individual customer tracking). We don't create customer profiles or track individual diners across restaurants. All analytics are collected server-side without using tracking cookies.

Security & Technical Data

What We Collect:

Activity logs: User actions and timestamps

Login attempts and authentication events

API usage: Which API keys are used, when, and how often

Embed tracking: Which websites use your embed codes

Error logs and system performance metrics

Security incidents and threat detection data

What We DON'T Collect:

❌ IP addresses

❌ Browser fingerprints

❌ Device identifiers

Detect and prevent fraud

Investigate security incidents

Monitor for unauthorized access

Troubleshoot technical issues

Ensure service reliability

Legitimate interests (security, fraud prevention), Legal obligation (security incident reporting)

Security logs kept for 1 year for incident investigation.

GDPR Compliance Records

What We Collect When You Request Data Deletion:

Original user ID (before deletion)

Email hash (SHA-256) - provable but not readable

Request timestamp and completion timestamp

Verification method used to confirm your identity

What was deleted (detailed list of data removed)

What was retained and the legal basis for retention

Who processed the request (automated system or staff member)

Prove GDPR compliance if audited by data protection authorities

Demonstrate we honored your deletion request

Prevent fraud (can't claim "you never deleted my data")

Legal obligation (GDPR Article 17 compliance)

Permanent (required for audit trail)

After deletion, we cannot identify you from these records (email is hashed), but we can prove deletion occurred.

How We Use Information

How We Use Your Information

Core Service Delivery

✅ Provide AI-powered dish recommendations to your restaurant customers

✅ Generate analytics dashboards and business insights

✅ Manage your restaurant profile, menus, and team members

✅ Process payments and manage subscriptions via Stripe

✅ Enable website embed functionality with your custom branding

✅ Track token usage and enforce plan limits

Service Improvement

✅ Analyze usage patterns to improve recommendation accuracy

✅ Train and optimize AI algorithms (using anonymized data)

✅ Develop new features based on aggregate usage trends

✅ A/B test recommendation strategies

✅ Research restaurant industry trends

Communication

✅ Send essential service notifications (account changes, security alerts, billing issues)

✅ Provide customer support and technical assistance

✅ Send marketing emails about new features and tips (only if you opt-in)

✅ Notify you of Terms/Privacy Policy changes

Unsubscribe from marketing emails anytime using the link in every email or in account settings. You cannot opt-out of essential service emails.

Security & Legal Compliance

✅ Detect and prevent fraud, abuse, and unauthorized access

✅ Investigate security incidents and suspicious activity

✅ Comply with tax obligations (7-year retention of financial records)

✅ Respond to law enforcement requests with proper legal authority

✅ Protect our legal rights and user safety

✅ Maintain GDPR deletion audit trail

How We Share Information

How We Share Your Information

Service Providers We Use

Stripe - Handles all payment card processing

Name, email, billing amounts

Process subscriptions and payments securely

Stripe Privacy Policy

Vercel - Hosts our platform

Platform application and data

Reliable, secure hosting with global CDN

Data processing agreements, encryption at rest and in transit

Cloudinary - Stores uploaded images

Restaurant logos, branding images, background images

Optimized image delivery and storage

Secure storage with access controls

OpenAI (or your AI provider) - Powers recommendation engine

Menu data, customer preferences (for recommendation generation)

AI recommendation generation

Subject to OpenAI's privacy policy

We do not send personally identifiable customer information to AI services

Resend - Email delivery service

Email addresses, names, message content

Deliver transactional and marketing emails

Data processing agreements

What We DON'T Do

❌ We DO NOT sell your data to third parties

❌ We DO NOT share data with competitors

❌ We DO NOT use your data for unrelated advertising

❌ We DO NOT share individual customer dining data (analytics are restaurant-level only)

❌ We DO NOT share your data with data brokers

Legal Requirements

We may disclose information when required by:

✅ Law enforcement with proper legal authority (court order, subpoena)

✅ Regulatory investigations or audits

✅ Court orders or legal processes

✅ Protection of our legal rights or user safety

✅ Prevention of fraud or illegal activity

✅ Emergency situations (immediate harm prevention)

We will notify you of legal requests unless prohibited by law.

Business Transfers

If TASTEEM is acquired or merged:

Your data may transfer to the acquiring company

Same privacy protections will apply

You'll be notified of any ownership change

Data Security

Data Security

We take security seriously and implement:

Encryption

In transit: TLS 1.2+ encryption for all data transfers

At rest: Industry-standard encryption for stored data

Passwords: Never stored in plain text (bcrypt hashing)

Access Controls

Role-based access: Team members only see what they need

Multi-factor authentication: Optional for extra security

Principle of least privilege: Staff access limited to job requirements

API keys: Secure tokens for embed/integration authentication

Monitoring & Response

24/7 security monitoring for threats

Intrusion detection systems

Regular security audits and penetration testing

Incident response procedures

Automated threat alerts

Infrastructure Security

Regular software updates and patches

Firewall protection

DDoS mitigation

Secure backup procedures with encryption

Database access logging

Staff Training

Regular privacy and security training

Background checks for employees with data access

Confidentiality agreements

⚠️ No System is 100% Secure: While we implement strong safeguards, no internet-based service is completely invulnerable. We will notify you promptly of any data breach affecting your account.

Data Retention

Data Retention Periods Summary

Data TypeRetention PeriodReason
Active Account DataWhile account existsProvide service
After Account Deletion RequestImmediate permanent deletionHonor your deletion request
Analytics & Usage Data (Plan-Based Retention)Starter Bite: 30 days, Main Course: 60 days, Chef's Special: 120 daysProvide analytics dashboards and performance insights based on your subscription tier
Financial/Billing Records7 yearsRomanian tax law compliance
Security/Activity Logs1 year (anonymized immediately upon account deletion)Fraud prevention, incident investigation
GDPR Deletion RecordsPermanentProve compliance if audited
Marketing Consent RecordsUntil withdrawn + 2 yearsGDPR compliance proof

What Happens After Deletion?

Your account, menu data, and personal information are permanently deleted

All analytics data is permanently deleted (no retention after account deletion)

Billing records kept for tax compliance (7 years, anonymized)

GDPR deletion proof kept permanently (hashed email only, cannot identify you)

Your Privacy Rights

Depending on your location (EU, California, Canada, etc.), you have various rights:

Universal Rights (Available to All Users)

Right to Access 📄

Request copies of your personal data. Learn how we process your information.

How: Email octavianvoicu0@gmail.com or use account dashboard export

Right to Correction ✏️

Correct inaccurate or incomplete data. Update your profile, menu, and restaurant info.

How: Edit directly in account settings or contact support

Right to Deletion 🗑️

Request immediate account deletion ("right to be forgotten"). Deletion is permanent and irreversible.

How: Account settings > Delete Account, or email us

Note: We retain GDPR deletion proof (but cannot identify you from it)

Right to Data Portability 📦

Export your data in machine-readable format (JSON/CSV). Transfer to another service provider.

How: Account dashboard > Export Data

Additional Rights (GDPR - EU/UK Users)

Right to Restrict Processing ⏸️

Limit how we use your data in certain situations

How: Email octavianvoicu0@gmail.com with specific request

Right to Object ⛔

Object to processing based on legitimate interests. Object to direct marketing (always honored immediately).

How: Use unsubscribe link or email us

Right to Withdraw Consent 🚫

Revoke marketing consent anytime

How: Account settings or unsubscribe link

Right to Lodge a Complaint 📢

Complain to your local Data Protection Authority

California Privacy Rights (CCPA)

If you're a California resident:

Right to Know 📋

Categories of personal information collected. Sources and purposes of collection. Third parties we share with.

Right to Delete 🗑️

Same as GDPR deletion

Right to Opt-Out of Sale 🚫

We do not sell personal information, so this doesn't apply

Right to Non-Discrimination ⚖️

Equal service regardless of privacy choices

**CCPA Contact:** octavianvoicu0@gmail.com

How to Exercise Your Rights

Account Dashboard: Many rights (correction, export, deletion) available directly

Email Request: octavianvoicu0@gmail.com

Identity Verification: We may ask for proof of identity to protect your privacy

Response Time: Within 30 days (GDPR), 45 days (CCPA)

No Fee: Rights requests are free (except excessive or repetitive requests)

International Transfers

International Data Transfers

Your data may be processed in countries outside Romania/EU.

Where We Process Data

EU (Romania) - Primary location

US (Vercel hosting, OpenAI, Stripe, Cloudinary, Resend)

How We Protect Your Data

Standard Contractual Clauses (SCCs): For EU → non-EU transfers

Adequacy Decisions: Where EU Commission approves country's data protection

Encryption: Data encrypted in transit and at rest regardless of location

Data Processing Agreements: With all international service providers

EU-US Data Transfers

If using US providers:

Compliant with EU-US Data Privacy Framework (if applicable)

Or using Standard Contractual Clauses (SCCs)

Same security standards apply everywhere

Cookies & Tracking

Cookies & Tracking

Essential Cookies (Always Active)

We use necessary cookies for:

Authentication: Keep you logged in securely

Security: CSRF protection, session management

Functionality: Remember your dashboard preferences

Legitimate interests (site functionality)

No - these are required for the service to work

Analytics (No Cookies Used)

We collect analytics data to understand platform usage, but we do this server-side without using tracking cookies:

Feature usage and interaction patterns

Popular dashboard sections and tools

User flows and navigation paths

Performance metrics and error rates

All analytics are collected server-side through your authenticated session. No third-party tracking cookies or scripts are used.

Legitimate interests (service improvement)

Because we don't use cookies for analytics, no cookie consent is required for this tracking.

What We DON'T Use

❌ Third-party analytics cookies (Google Analytics, Facebook Pixel, etc.)

❌ Advertising cookies or retargeting pixels

❌ Cross-site tracking cookies

❌ Social media tracking pixels (beyond Google Sign-In button)

Your Choices

Browser Settings: You can block/delete essential cookies, but this will prevent login

Google Sign-In: Uses Google cookies per Google's privacy policy (only if you choose this login method)

Do Not Track: We respect browser DNT signals where feasible

Children's Privacy

Children's Privacy

Our service is designed for business use by adults (18+) operating restaurants.

❌ We do not knowingly collect information from children under 13 (or 16 in EU)

❌ Our service is not intended for children

If you believe we've collected child data:

Contact us immediately: octavianvoicu0@gmail.com

We will delete it promptly upon verification

If you discover your child created an account, contact us for immediate deletion.

Changes to Policy

Changes to This Privacy Policy

We may update this policy to reflect:

Changes in our practices or technology

New features or services

Legal or regulatory requirements

User feedback

How We Notify You:

Email to all registered users (for material changes)

In-app notification when you log in

Version tracking in your account (shows which version you reviewed)

Posted notice on website with effective date

For significant changes (e.g., new data collection, sharing practices), we may:

Require renewed consent

Provide opt-out option

Give advance notice (30+ days when possible)

Continued Use = Acceptance: Using Services after changes means you accept the new policy.

Don't Agree? You may delete your account before changes take effect.

Legal Basis Summary

This section summarizes the legal bases under the General Data Protection Regulation (GDPR) we rely upon for processing different categories of your personal data.

GDPR Legal Basis Mapping

PurposeData ProcessedLegal Basis (GDPR)
Account managementName, email, passwordContract performance
Payment processingStripe IDs, billing dataContract performance
AI recommendationsMenu data, preferencesContract performance
Analytics dashboardUsage data, performanceContract performance
Security monitoringActivity logs (no IP addresses)Legitimate interests
Service improvementAnonymized usage dataLegitimate interests
Marketing emailsEmail (opt-in only)Consent
Tax complianceBilling recordsLegal obligation
GDPR deletion trackingDeletion recordsLegal obligation

Data Protection Officer

Data Protection Officer

For a company our size, we do not have a dedicated Data Protection Officer (DPO). However, all privacy inquiries are handled by:

octavianvoicu0@gmail.com

Voicu Octavian-Mihai

Within 30 days of inquiry

Contact Us

Contact Us

octavianvoicu0@gmail.com

Voicu Octavian-Mihai PERSOANA FIZICA AUTORIZATA, Str. Cerealelor, Nr 13, Baneasa, Constanta, Romania

+40 768 004 329

octavianvoicu0@gmail.com (subject: "Security Issue")

octavianvoicu0@gmail.com (subject: "GDPR Deletion Request")

Delete Account button

Regulatory Authorities

Regulatory Authorities

If you're unhappy with our response, you can lodge a complaint with:

ANSPDCP (Romanian Data Protection Authority)

https://www.dataprotection.ro/

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București

Your local Data Protection Authority

https://edpb.europa.eu/about-edpb/board/members_en

ICO (Information Commissioner's Office)

https://ico.org.uk/

California Attorney General

https://oag.ca.gov/privacy/ccpa

Your Consent

Your Consent & Acknowledgment

By creating an account and using TASTEEM, you confirm that you:

✅ Have read and understood this Privacy Policy

✅ Understand how we collect, use, and protect your information

✅ Provide explicit consent for data processing as described

✅ Understand your rights and how to exercise them

✅ Agree to international data transfers with appropriate safeguards

✅ Are at least 18 years old

Consent Recording: Your acceptance is recorded in our database with:

Timestamp of consent

Privacy policy version number

Consent given status (true/false)

Withdrawing Consent: You can withdraw consent for optional processing (e.g., marketing) anytime without affecting your account status. Core service processing continues under contract performance basis.

Effective Date

Effective Date

This Privacy Policy is effective as of December 14, 2025 and applies to all data collected from that date forward.

Previous versions available upon request: octavianvoicu0@gmail.com

Thank you for trusting TASTEEM with your restaurant data. We take that responsibility seriously and are committed to protecting your privacy.

December 14, 2025

PRIVACY CONTACT

octavianvoicu0@gmail.com

PHONE

+40 768 004 329

TIME-AWARE AI

with nutrition intelligence

ALL RIGHTS RESERVED © 2026.

Designed & Developed by Octavian Voicu

Privacy Policy | How TASTEEM Protects Restaurant Data | TASTEEM