Data Protection & Privacy

Privacy Policy

Last Updated: February 2026 · Compliant with GDPR (Regulation (EU) 2016/679), CCPA & Global Standards

1. Data Controller Identification

Sofija Potocka Software Development IT Consulting Services (SP Dev), NIP: 7343675273 | REGON: 545555664, located at ul. Romana Żulińskiego 15 lok. 6, 33-300 Nowy Sącz, Poland ("SP Dev", "Company", "we", "our", "us") is the Data Controller responsible for the processing of personal data on this website and across the SP Dev restaurant software platform.

For any questions regarding these terms, data privacy, or billing inquiries, please contact us at sofijapotocka@getdadigital.com or call +48 575 514 320.

2. Information We Process

We process information in two main contexts:

A. Restaurant Merchant Information:

When you create an account, request a demo, or subscribe to a software plan, we collect your name, business email, telephone number, restaurant business name, physical store address, and billing configuration.

B. End-Diner Order Data (Processed as Data Processor for Merchants):

When diners order food via a merchant's custom website or branded mobile app, we process customer names, delivery addresses, phone numbers (for SMS tracking), email receipts, and ordered menu items. This data belongs strictly to the merchant.

C. Technical & Telemetry Data:

IP address, browser type, device operating system, session tokens, and performance telemetry to detect fraud and ensure 99.9% system stability.

3. Payment Security & Certified Processing (Stripe & Mollie)

All payment transactions for subscriptions and food orders are processed securely through our certified payment partners, Stripe, Inc. and Mollie B.V., both PCI-DSS Level 1 certified payment service providers supporting Visa, Mastercard, iDEAL, Apple Pay, and Google Pay.

We do not store complete credit or debit card numbers, CVVs, or bank credentials on our servers. Stripe and Mollie tokenize and securely store payment details using 256-bit AES encryption.

4. Legal Basis & Purpose of Data Processing

We process personal data on the following legal bases under the GDPR (EU) and applicable privacy laws:

  • Performance of a Contract (Art. 6(1)(b) GDPR): To provision software, process orders, enable driver dispatch, and deliver receipts.
  • Legitimate Interests (Art. 6(1)(f) GDPR): To prevent fraud, troubleshoot bugs, ensure system reliability, and provide support.
  • Compliance with Legal Obligations (Art. 6(1)(c) GDPR): For tax reporting, billing records, and audit compliance.

5. Third-Party Sub-processors

We work with trusted infrastructure providers that adhere to rigorous data protection standards:

  • Stripe, Inc. & Mollie B.V. (EU / USA / Netherlands) — Certified payment gateways, card processing (Visa, Mastercard), local payment methods (iDEAL), digital wallets (Apple Pay, Google Pay), and merchant payouts;
  • Vercel, Inc. & AWS (EU / USA) — Edge cloud hosting and secure database infrastructure;
  • Twilio / SendGrid (EU / USA) — Transactional SMS dispatch and email order confirmations;
  • Apple Inc. & Google LLC (EU / USA) — Mobile application distribution and push notification gateways.

6. Your Rights Under GDPR & CCPA

Under the GDPR (Articles 15–22), you have the right to access, rectify, erase, restrict processing of, and export your personal data. We do not sell personal data.

To exercise any privacy rights, email sofijapotocka@getdadigital.com with your request. We respond within 30 days.

7. Contact Us Regarding Privacy

For any questions regarding these terms, data privacy, or billing inquiries, please contact us at sofijapotocka@getdadigital.com or call +48 575 514 320.

Sofija Potocka Software Development IT Consulting Services (SP Dev)

ul. Romana Żulińskiego 15 lok. 6, 33-300 Nowy Sącz, Poland

NIP: 7343675273 | REGON: 545555664