Banak

Privacy Policy

Last updated: July 14, 2026 · Version 2026-07-14

This policy explains how Banak processes personal data when you visit our website, register a restaurant, or use the dashboard, guest QR pages, orders, payments, support, and related features.

For privacy questions or requests, contact info@banak.app.

1. Who uses Banak

We process data about restaurant owners and administrators, staff using the dashboard or KDS, guests using table QR pages, and people contacting us. Banak is controller for account, billing, security, support, and its own communications. Restaurants generally control guest and staff data processed through the service, while Banak acts as processor.

2. Data we collect

Depending on use, this may include account and restaurant details; tables, spaces, QR tokens, menu, availability, orders and requests; guest notes, feedback, contact or receipt email; IP address, user agent, device identifiers, security and error logs; and payment status, amounts, tips, refunds, and provider identifiers. Banak does not store full card numbers.

3. How we use data

We use data to provide authentication and QR, ordering, staff-request, dashboard, KDS, billing, support, security, abuse prevention, audit, and restaurant analytics features, and to meet legal, tax, and accounting obligations.

4. Legal bases

Processing may be necessary to perform a contract, comply with law, pursue legitimate interests in security and service improvement, or act on consent where required. Restaurants must establish an appropriate legal basis for their guest and employee data.

5. Service providers and transfers

Vetted providers such as Supabase, Stripe, Resend, and Vercel may support hosting, data, authentication, email, payment, analytics, and security. International transfers use an applicable adequacy decision or safeguards such as standard contractual clauses.

6. Cookies and local storage

Banak uses necessary cookies and local storage for sign-in, security, QR-table validation, language selection, cart state, payments, and interface preferences. We do not use advertising or profiling cookies. Optional analytics or marketing storage will require separate consent if introduced.

7. Retention

We retain data while an account is active and as needed for service, support, security, abuse prevention, tax, accounting, disputes, and legal duties. We delete, anonymize, or restrict data when the applicable purpose and retention period end.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection, and withdraw consent for future processing. We may verify identity. You may also complain to the Croatian Personal Data Protection Agency or another competent EU/EEA authority.

9. Security

We use reasonable technical and organizational measures, including access controls, password and PIN hashing, rate limits, separated keys, and security checks. No system is entirely risk-free, so users must protect their credentials and devices.

10. Policy changes

We may update this policy and will publish the current version and update date here. Material changes may also be announced through the application or by email.