Privacy policy
Last updated:
This policy explains what personal data we process when you use the Gusto Raffinato app (for restaurant guests), the GR Sala app (for the staff of restaurants that use Gusto Raffinato) and the gustoraffinato.com website: why we process it, who we share it with, how long we keep it and what you can do. It is written to be read, not just signed.
1. Who processes your data
The data controller is RIGHELLO S.r.l., Via Pio X 21, Mestre (VE), Italy, VAT no. 01979970934. Email: [email protected]. Certified email (PEC): «[DA COMPLETARE: PEC]».
We have not appointed a data protection officer (DPO): for any privacy request, write to [email protected].
For the GR Sala app the roles are different: the customer and staff data processed in a restaurant's management system belong to the restaurant, which is the controller; we process them on its behalf as a processor (Art. 28 GDPR). Section 3 explains this.
2. The Gusto Raffinato app (for guests)
Account
You can sign in with Sign in with Apple, with Google, or with email and password. Sign-in is handled by Firebase Authentication (Google). We process your name, email, account identifier and sign-in method; a profile with your name is stored in Google Cloud Firestore. If you use Sign in with Apple and choose to hide your email, we receive the anonymous relay address created by Apple.
Reservations
You can only book at venues that use Gusto Raffinato. For each reservation we process: venue, day, time, party size, seating preference, the notes you write, your optional consent to receive communications from the venue, and the status of the reservation. The venue sees the request on its iPad together with your account name, so it can recognise you, and confirms or declines it.
Diets and allergies are health data (Art. 9 GDPR). The diet and allergen preferences you set in the app stay on your phone: they reach the venue only if you write or add them in the reservation request, that is with your explicit consent, for the sole purpose of serving you safely. When you delete your account, notes are also removed from past reservations.
Once the request reaches the venue, the venue uses it to organise service: for the data it keeps in its management system, the restaurant is the controller (see section 3).
Loyalty cards and Apple Wallet
The app shows the venues' loyalty cards, with stamps and rewards. Stamps are based on what you were served at the table. To collect stamps you show the waiter a personal code (QR). If you wish, you can add the card to Apple Wallet: our server then updates the pass through Apple Wallet notifications, and to do so it registers the device on which the pass is installed.
Notifications
If you turn them on, we use the Apple Push Notification service to tell you when a reservation is confirmed or declined and about your loyalty cards. To do so we store the device token linked to your account. These are service messages, not advertising. We ask at the right moment, they are optional, and you can turn them off at any time in iOS Settings.
Location
The app uses your location only if you tap “use my location” when choosing your town, and only while you are using the app. The nearest town is worked out on your phone; our server receives only an approximate point (about 1 km) to look up nearby venues, and it is not stored.
Preferences and favourite venues
Your town, usual party size, diets and allergens to avoid, and favourite venues stay on your phone: we do not receive them.
“I'd like it too”
If you ask for a venue to adopt Gusto Raffinato, the request is linked to your account. The venue only sees how many people asked, not who.
Venues and maps
The list of venues comes from public OpenStreetMap data (© OpenStreetMap contributors, ODbL licence). On a venue's page we show photos and a rating from Google Places: requests to Google are sent from our server, without your data. Maps are provided by Apple (Apple Maps).
What we don't do
The app has no advertising, we don't track you across other companies' apps and websites, we don't sell your data, we don't build advertising profiles and we don't use analytics tools (SDKs).
3. The GR Sala app (for restaurant staff)
GR Sala is the management system for restaurants that use Gusto Raffinato: on the restaurant's iPad and as a handheld on the phone. There is no public sign-up: the device is linked to the restaurant with a room code or a QR code, and staff sign in with a PIN.
The restaurant is the controller of the data of its customers and staff processed in the management system. RIGHELLO S.r.l. acts as a processor on behalf of the restaurant (Art. 28 GDPR); the data processing agreement is part of the contract with the restaurant. If you are a customer or an employee of a restaurant and want to exercise your rights over this data, contact the restaurant; if you write to us, we will forward the request to the restaurant and help it reply.
What the management system processes
- Staff: name, role (waiter or manager), PIN, shifts and which device they use. The PIN is stored only as a cryptographic hash, never in clear text.
- Devices: device name, type (iPad or phone), last access, push notification token.
- Floor and service: tables, orders, bills, service times, customer reservations (name, party size, notes), waiting list (name and phone number), loyalty cards of seated customers (first name and stamps only). Staff can mark an allergy on a table to alert the kitchen: this is health data, processed on behalf of the restaurant for the sole purpose of serving the customer safely.
- Camera and LiDAR: used to map the room and the tables. The view of the room is sent to the Gusto Raffinato server to recognise the tables and their status; frames are not stored, they stay in memory only for the time of the analysis. If the restaurant connects its room cameras, they are used to follow the status of the tables, with views framed on the tables.
- Coloured room (“Colora la sala” in GR Sala): only if the restaurant uses it, an iPad or a restaurant manager's iPhone with the room-measuring sensor (LiDAR) films the empty room, before service, to give the 3D model of the room its real colours. The images stay on the device that films them: they are not sent, not saved, and they are deleted as soon as the model is coloured; there is no recognition of people. Only the coloured 3D model (shapes and colours of walls, floor and furniture) reaches the Gusto Raffinato server, and only the restaurant's management devices can see it, not the staff's handhelds. The restaurant can remove it at any time.
- Purchase documents: photos and PDFs of supplier invoices, delivery notes and receipts, XML e-invoices. Only if the restaurant turns this on, they can be read by an artificial intelligence service (Qwen by Alibaba Cloud, international endpoint) to suggest stock entries, which the manager checks and confirms.
- WhatsApp messages: only if the restaurant connects WhatsApp, the conversations and phone numbers of customers who message the restaurant. No message is sent without staff approval.
- Push notifications on the restaurant's devices.
What the restaurant must do
The restaurant must inform its customers and staff about the use of the camera, the room cameras and the other processing in the management system: for example with signs in the room and, for staff, with the agreements or authorisations required by Article 4 of the Italian Workers' Statute (Law 300/1970).
4. The gustoraffinato.com website
- Demo request: name of the venue or person, phone number, email (optional) and number of tables. We use them only to get back to you about that request.
- Restaurant area: sign-in with the room code and the manager's PIN, read-only. The GR Sala rules in section 3 apply.
- The website is hosted on Cloudflare Pages. We use no profiling cookies and no analytics tools, and fonts are self-hosted, with no requests to external services.
5. Why we process it (legal bases)
- To provide the service you ask for (Art. 6(1)(b) GDPR): account, reservations, loyalty cards, service notifications, account deletion, replies to demo and support requests.
- With your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time: location and push notifications (iOS permissions), Apple Wallet pass, optional consent to receive communications from the venue. Diets and allergies written or added in a reservation request: your explicit consent (Art. 9(2)(a) GDPR), given by entering them, for the sole purpose of serving you safely. Allergies marked on a table in GR Sala are processed by the restaurant, which is their controller.
- Our legitimate interest (Art. 6(1)(f) GDPR): service security, limits on PIN and code attempts, abuse prevention, short-lived technical logs.
- Legal obligations (Art. 6(1)(c) GDPR): for the restaurant, keeping accounting records.
6. Who we share it with
To run the service we use these providers, which process data on our behalf (processors or sub-processors) or give us public data:
- Google (Firebase Authentication, Cloud Firestore)Sign-in to the Gusto Raffinato app account and the user profile.Data: Name, email, account identifier, sign-in method, app data linked to the account. The Firebase libraries also collect technical diagnostic data about their own operation.
- Google (Google Places)Venue photos and ratings shown on the venue page.Data: No user data: requests are sent from our server.
- AppleSign in with Apple, push notifications (APNs), Apple Wallet, maps (Apple Maps / MapKit).Data: Sign in with Apple identifier, notification tokens, device registration for pass updates.
- HostingerServer (VPS) hosting the Gusto Raffinato gateway. Data centre country: Germany (Frankfurt).Data: The service data described in this policy, including demo requests sent from the website.
- CloudflareHosts the gustoraffinato.com website.Data: Technical connection data needed to serve the pages.
- Alibaba Cloud (Qwen, endpoint internazionale)Reading purchase documents with artificial intelligence.Data: Photos and PDFs of the restaurant's supplier invoices, delivery notes and receipts.When: Only if the restaurant turns this feature on in GR Sala.
- Meta (WhatsApp)WhatsApp messages between the restaurant and its customers.Data: Conversations and phone numbers of people who message the restaurant.When: Only if the restaurant connects WhatsApp.
- OpenStreetMapSource of public venue data (© OpenStreetMap contributors, ODbL licence).Data: No user data.
The venue where you book, or whose loyalty card you hold, receives the data needed for that reservation or card. We do not sell or hand over data to anyone else.
7. Transfers outside the European Union
Google, Apple, Cloudflare and Alibaba Cloud may also process data outside the European Economic Area. In those cases the transfer is protected, where applicable, by the European Commission's standard contractual clauses or by the EU-US Data Privacy Framework.
8. How long we keep it
- Account and linked data: as long as the account exists.
- When you delete your account, data is erased immediately as described on the Delete your account page. The venue keeps past reservations only in anonymous form (party size, day and time) for its floor statistics.
- Notification tokens: removed when you sign out or delete the account.
- Room frames (GR Sala): not stored.
- Demo requests: «[DA DECIDERE: es. 12 mesi]».
- Server technical logs: «[DA COMPLETARE: durata dei log del server]».
- A restaurant's management data: for the period the restaurant decides, within the limits of the contract and of the law.
9. Your rights
You can ask us at any time to access your data, correct it, erase it, restrict its processing, receive it in a portable format, and object to processing. You can withdraw consent whenever you want: permissions in iOS Settings, the pass by removing it from Wallet, the rest by writing to us. Withdrawal does not affect what was done before.
Write to [email protected]: we reply within 30 days. If you think your data is not being processed correctly, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali).
10. Children
The Gusto Raffinato app is not intended for anyone under 14, the age of digital consent in Italy.
11. Security
Staff PINs are stored only as cryptographic hashes, PIN and room code attempts are limited, and room frames are not stored. No system is one hundred percent secure: if you notice something wrong, write to us.
12. Changes
If we change this policy we update the date at the top of the page; important changes are announced in the app or on the website. If the Italian and English versions differ, the Italian version prevails.