Legal · Privacy
Privacy Policy
How Cevor handles personal data across the website, waitlist, demo requests, and the experience we build around a restaurant's existing menu.
Last updated · 5 July 2026
Cevor is an experience built around existing restaurant menus. We do not replace menus. We add photos, translations, culinary explanations and menu understanding on top of what a restaurant already serves. This policy explains what personal data we collect to do that, why, and the rights you have under the EU General Data Protection Regulation (GDPR, Regulation 2016/679).
1. Who we are
Cevor ("we", "us", "our") is the controller of the personal data described in this policy when collected through cevor.app, the waitlist, demo requests and pilot conversations.
When a restaurant uses Cevor to enhance its own menu, the restaurant remains the owner of the menu content and the controller of any guest information it chooses to collect through the experience. Cevor acts as a processor for that restaurant under a written arrangement.
2. What we collect and why
Website visitors
- Your preferred language (EN / FR / NL), stored locally in your browser so we do not ask again.
- Your browser's preferred language, read once on first visit to choose the initial display language.
- Anonymised usage analytics (page views, referrer, device class) when analytics are enabled. No advertising identifiers.
Waitlist and early partner requests
- Your email address, so we can reply and, if you opted in, keep you updated.
- Any information you add voluntarily in a form (name, role, restaurant name, city).
Demo requests and pilot conversations
- Contact details you share (name, work email, restaurant name, location).
- Notes on what you are looking to solve, so we can prepare a useful conversation.
Pilot / demo restaurants
- Information about the restaurant taking part (name, location, cuisine, languages served).
- Menu content shared with us (dish names, descriptions, prices, sections).
- Photos of dishes provided by the restaurant or produced with the restaurant's agreement.
- Aggregate guest-side usage of the experience (views per language, popular dishes). No individual guest identifiers.
Operational information
- Basic technical logs required to keep the service secure and reliable (timestamps, error traces, IP address at the time of the request).
3. Why we collect this information
We collect only what is needed to run the website, respond to your messages, prepare and deliver a Cevor experience for a partner restaurant, and keep the service safe and working.
We do not sell personal data. We do not build advertising profiles. We do not enrich our data with third-party sources.
4. Where data is stored
Cevor relies on a small number of trusted providers to run the service:
- Supabase — our database, authentication and file storage provider. Data is hosted on European infrastructure and protected in transit and at rest.
- Resend — our transactional email provider, used to send confirmations, demo replies and pilot communications.
These providers process data only on our instructions and under contracts aligned with the GDPR.
5. Legal basis for processing
Contract (Art. 6(1)(b) GDPR)
- Responding to a waitlist entry, demo request or pilot conversation you initiated, and delivering the Cevor experience to partner restaurants.
Legitimate interest (Art. 6(1)(f) GDPR)
- Basic, non-identifying product analytics and security monitoring so the service stays fast, safe and useful.
- Limited follow-up after a request you sent us.
Consent (Art. 6(1)(a) GDPR)
- Any optional analytics cookies, and any newsletter or update emails you actively opt into.
Legal obligation (Art. 6(1)(c) GDPR)
- Accounting, tax and lawful requests from competent authorities.
6. How long we keep data
- Waitlist and contact requests: up to 18 months after the last interaction, then deleted or anonymised.
- Demo and pilot conversations that do not become an active partnership: up to 12 months, then deleted.
- Active pilot / partner restaurants: for the duration of the collaboration plus 6 months for handover and backup rotation.
- Menu files and photos shared with us: kept as long as needed for the active experience; removed on request or when the collaboration ends.
- Aggregated, non-identifying analytics: retained without a defined limit.
- Accounting and legal records: retained as required by applicable EU law (typically 7 years).
7. Your rights under the GDPR
You have the right to access the personal data we hold about you, to ask for correction or deletion, to restrict or object to processing, to receive a copy of the data you provided, and to withdraw consent at any time without affecting the lawfulness of earlier processing.
You can exercise any of these rights by writing to hello.cevor@gmail.com. We respond within one month. You also have the right to lodge a complaint with your national data protection authority (for example the Autorité de protection des données in Belgium, the CNIL in France, or the Autoriteit Persoonsgegevens in the Netherlands).
8. How to request deletion
Send an email to hello.cevor@gmail.com from the address concerned, or from an address clearly linked to the restaurant if you are asking on behalf of a venue. We confirm receipt, verify identity where needed, and complete the request within one month. Some information may be retained for a limited period when the law requires it (for example accounting records); we tell you when that is the case.
9. Cookies, analytics and browser language
Cevor uses only the cookies and local storage entries needed to run the site and remember your preferences (such as the language you select). We do not run advertising trackers.
Your browser's preferred language is read once on first visit to pick between English, French and Dutch. The result is stored locally in your browser.
Full details are in our Cookie Policy.
10. Security
- Encrypted connections (TLS) for all traffic and encryption at rest on our storage.
- Access to production data is restricted to people who need it, with role-based controls.
- Automated monitoring, logging and dependency scanning.
- Separated environments for development and production.
- Regular backups with documented restore procedures.
11. International processing
Cevor prefers European infrastructure and the providers listed above operate primarily inside the European Economic Area. Where a processor operates from outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses and, where required, by additional safeguards in line with the Schrems II ruling.
12. Children
Cevor is a service for restaurants and their guests and is not directed at children under 16. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy as the product evolves or as legal requirements change. Material changes are announced on this page with a new "last updated" date. Where we already have an ongoing relationship with you, we let you know by email.
Contact
For any privacy question or data request, write to hello.cevor@gmail.com. We reply within 48 hours in most cases and always within one month for formal GDPR requests.
See also