Back to home

Privacy Policy

This policy explains what personal data KindGuest collects, why we collect it, who we share it with, and the rights you have over it.

Last updated: 18 July 2026

1. Who we are

KindGuestis a feedback platform for restaurants. Restaurant operators (“managers”) use it to collect guest feedback through QR codes placed on their tables.

For manager accounts, Costan Călin-George PFA is the data controller. For guest feedback submitted in a venue, the restaurant is the controller and Costan Călin-George PFA acts as a data processor on its behalf.

2. What we collect and why

Manager accounts (via Google Sign-In). When you sign in we receive your name, email address and profile picture from Google. We use these to create your account, identify you in the dashboard and send you service emails. We never receive your Google password.

Restaurant data. Venue name, city, country, contact email, table numbers and your chosen feedback questions — needed to operate the service and generate your QR codes.

Guest feedback.A star rating and free-text answers to the venue’s two questions. Guests are not asked to identify themselves and no account is required.

Guest IP addresses. When feedback is submitted we store the submitting IP address. This is used solely to rate-limit submissions (one review per IP per venue per 10 minutes) and prevent spam and ballot-stuffing. It is not used to profile or track guests.

Billing data. Subscription status, trial end date and Stripe customer / subscription identifiers. We never receive, process or store card numbers — card data is entered directly with Stripe, which is PCI-DSS compliant.

3. Legal bases for processing

We process manager account data to perform our contract with you, billing data to comply with legal obligations and perform the contract, and guest IP addresses under our legitimate interest in preventing abuse of the service. Guest feedback is processed on behalf of the restaurant under its own legal basis.

4. Who we share data with

We use the following sub-processors. We do not sell personal data to anyone.

  • Google (Sign-In)Authentication — we receive your name, email and profile picture.
  • StripePayment processing and subscription billing. Stripe handles card data directly; we never receive or store card numbers.
  • Turso (libSQL)Database hosting for restaurant, table and review records.
  • Google Cloud RunApplication hosting.
  • ResendTransactional email delivery (review alerts).
  • Gmail SMTPFallback transactional email delivery.
  • Serper.devPrint-shop search during onboarding (a search query containing your city/country is sent).

Where data is stored. The database holding restaurant, table and guest feedback records is hosted in the European Union (AWS eu-west-1, Ireland). Application hosting is in the United States (Google Cloud Run).

International transfers.Stripe, Google, Resend and Serper.dev are US-based and processing by them involves a transfer outside the EEA. Those transfers rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework, together with the safeguards in each provider’s own data-processing terms.

5. How long we keep it

Account and restaurant data is kept for as long as the account is active. Guest feedback is kept for as long as the restaurant’s account is active, since it is the restaurant’s operational record. When an account is deleted, its data is removed as described below.

Guest IP addresses are deleted after 30 days. They exist only to stop repeat submissions, which is a short-lived purpose, so a scheduled job clears the IP from older reviews automatically. The review itself is kept — only the IP is removed.

Billing records are kept for 10 years from the end of the financial year, as required of Romanian businesses by accounting legislation (Law 82/1991). This applies to invoices and payment records, not to guest feedback.

6. Your rights

Depending on your jurisdiction you may have the right to access, correct, export or delete your personal data, and to object to or restrict processing.

Deletion is genuinely implemented.When an account is deleted by an administrator, we permanently remove the user account, its restaurant, and all of that restaurant’s reviews, tables and cached search results, and we cancel any active Stripe subscription. This is a real deletion, not a flag.

Guests who wish to have a specific review removed should contact the restaurant, which can request removal through us.

7. Security

Sessions use signed, httpOnly cookies. Traffic is served over HTTPS. Secrets and API keys are stored in a managed secret store, not in source code. Access to production data is limited to the operator of the service.

8. Contact

For any privacy question or to exercise your rights, contact us at ccalin.webdesign@gmail.com.

We are established in Romania and our lead supervisory authority is the ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal). If you believe we have handled your personal data unlawfully you have the right to lodge a complaint with it at dataprotection.ro, or with the authority in your own country.

We have not appointed a Data Protection Officer: our processing is not large-scale systematic monitoring nor large-scale processing of special categories, so art. 37 GDPR does not require one. Privacy questions go to the address above.