Privacy

Privacy Policy

In force since 07.09.2026.

In force since: 07.09.2026Published: 07.09.2026

This is a translation from Ukrainian, provided for convenience and for information only. Only the Ukrainian version is legally binding: in case of any discrepancy, the Ukrainian text prevails. Open the Ukrainian version.

All versions of this document

Translation from Ukrainian. Provided for information only. In case of any discrepancy, the Ukrainian text prevails.

1. Who processes your data

1.1. Personal data in the “Stolik POS” Service (stolik.top) is processed by Vitalii Mykolaiovych Sipitin, individual entrepreneur (record number in the Unified State Register: 2004800010007048993, taxpayer registration card number: 2605412174), referred to below as “we” or “the Provider”. Contact details are given in section 15 of this Policy and in section 15 of the Offer.

1.2. This Policy explains what data we process, on what grounds, who we share it with and what rights you have. It forms an integral part of the Public Offer Agreement published at stolik.top/legal/offer/en.

1.3. This Policy covers three different categories of people, and our role is different for each of them:

  • The Customer: the owner or manager of the venue who has registered in the Service;
  • Venue staff: the Customer's employees to whom the Customer has given access to the Service;
  • Venue guests: visitors whose data reaches the Service through the guest portal or when an order is placed.

1.4. We process data under the Law of Ukraine “On Personal Data Protection” No. 2297-VI of 01.06.2010.

1.5. The use of cookies on the public website is governed by a separate document — the Cookie Policy (stolik.top/legal/cookie/en). Section 9 of this Policy summarises its provisions.

2. Who is responsible for what

2.1. For the Customer's data (registration and payment data, login logs), the Provider is the controller of personal data.

2.2. For the data of venue staff and venue guests that the Customer collects and enters into the Service itself, the Customer is the controller of that data, and the Provider is the processor, which processes that data on the Customer's instructions and within the limits of those instructions.

2.3. This means that the venue, not us, determines the purpose, scope and grounds for collecting staff and guest data. The venue is responsible for obtaining consent from those people and for the lawfulness of the processing. The terms of the instruction — purpose, scope, list of permitted operations, term of processing and our obligations as processor — are set by clause 10.6 of the Offer.

2.4. If you are a venue guest or a member of venue staff and want to find out where the venue got your data, or to change or delete it, contact the venue — it is the controller of that data and takes decisions about it. You may also send such a request to us at support@stolik.top: we do not take decisions about that data ourselves, but within 5 (five) working days we will pass your request to the venue, tell you that we have done so, and technically implement its decision. If the venue has stopped using the Service and its data has already been deleted, we will tell you so in reply.

3. What data we process

3.1. Data about the Customer: e-mail address, Google or Telegram account identifier (depending on how you log in), the venue's name and address, the chosen Subscription Plan, payment history.

3.2. Venue staff data: name, role in the Service, contact details chosen by the Customer (telephone, Telegram, e-mail), actions in the Service within work duties.

3.3. Venue guest data: name, telephone number, Telegram identifier, order history, depending on which fields the venue uses.

3.4. The venue's operational data: the menu (dishes, prices, images), orders (contents, payment method, tips), shifts, reports.

3.5. Technical data: the login log (IP address, time, login method), device and browser type, technical error logs.

3.6. Payment data: we do not receive or store payment card numbers. Online payment is handled by the LiqPay (JSC CB “PrivatBank”) and monobank (JSC “Universal Bank”) payment services, certified under the PCI DSS security standard: card details are entered on a secure page of the payment service and do not reach us. We see only the amount, the currency, the payment status and the order identifier.

4. On what grounds we process data

4.1. Performance of the Agreement (paragraph 3 of part one of Article 11 of the Law) — processing of the Customer's data needed to give access to the Service, to provide support and to handle payments.

4.2. Consent (paragraph 1 of part one of Article 11 of the Law) — processing that goes beyond what is needed for the Agreement: information mailings about how the Service works, and optional cookies. You can withdraw your consent at any time.

4.3. Compliance with a legal obligation (paragraph 5 of part one of Article 11 of the Law) — keeping the documents needed for tax and accounting records.

4.4. Instructions from the controller — processing of staff and guest data on the venue's instructions under section 2 of this Policy and clause 10.6 of the Offer.

4.5. Protection of legitimate interests (paragraph 6 of part one of Article 11 of the Law) — processing needed to establish, exercise or defend our rights in the event of a dispute, for the duration of the general limitation period, and to keep the Service secure and prevent abuse. On this basis we keep the archive of consents (clause 10.6) and the technical logs (clause 10.5).

5. Why we process data

5.1. We process data only to run the Service: to provide features under the Subscription Plan, to produce analytics and reports for the Customer, to give technical support, to send receipts and notifications to guests in Telegram, to issue invoices and keep records, to keep the Service secure and to prevent abuse.

5.2. We do not sell your data. We do not pass it to advertising networks or data brokers, and we do not use it for third-party advertising.

5.3. To improve the Service, we may use statistics in anonymised and aggregated form, from which no particular person or individual venue can be identified.

6. Who we share data with

6.1. We engage contractors without which the Service cannot work. Each one receives only the minimum data needed for its function and acts on our instructions — it has no right to dispose of that data on its own.

Infrastructure: where data is stored and processed

Contractor What for What data Where it is located
Supabase, Inc. database and file storage (dish photos, logos, avatars) all Service data: Customer, staff and guest data, the venue's operational data EU (Frankfurt, Germany)
Railway Corp. back-end hosting — computation and operational logs data processed while the Service is running USA
Vercel, Inc. hosting and delivery of the web interface and the website IP address, technical request logs USA and a global delivery network
Backblaze, Inc. (B2 Cloud Storage) automatic backups copies of Service data EU (EU Central region, the Netherlands)

Communication with users

Contractor What for What data Where it is located
Resend, Inc. sending e-mails: address confirmation, password recovery, confirmation codes, service notifications e-mail address, content of the e-mail USA
Telegram Messenger FZ-LLC login through Telegram, notifications and receipts for guests and staff, support requests Telegram identifier and username, message text outside Ukraine (UAE)
The push notification services of your browser's vendor (Google, Mozilla, Apple) delivering push notifications to the device the device's technical subscription address, notification text USA, EU

Payments and exchange rates

Contractor What for What data Where it is located
LiqPay (JSC CB “PrivatBank”) accepting online subscription payments amount, currency, payment status, order identifier; payment card details are entered on LiqPay's side and are not passed to us Ukraine
monobank (JSC “Universal Bank”) accepting online subscription payments amount, currency, payment status, order identifier; payment card details are entered on monobank's side and are not passed to us Ukraine
JSC CB “PrivatBank”, public exchange rate reference converting menu prices into another currency no personal data is transferred: the request contains no user data Ukraine

AI-based features

Contractor What for What data Where it is located
OpenRouter, Inc. routing queries to the language model the text of the query to the assistant USA
Google LLC (the Gemini model through Google AI Studio) generating the assistant's reply, recognising a voice query the text of the query, the audio recording of a voice query USA

Login, abuse protection and fonts

Contractor What for What data Where it is located
Google LLC (sign-in with a Google account) Customer registration and login e-mail address, name, Google account identifier USA
Cloudflare, Inc. (Turnstile) protecting registration and forms from automated abuse IP address, technical browser signals USA and a global network
Google LLC (Google Fonts) loading the fonts of the interface and the website IP address, browser type USA and a global delivery network

Analytics — on the public website only, and only with your consent

Contractor What for What data Where it is located
Google LLC (Google Analytics 4, Google Ads) anonymised visit statistics and measurement of advertising performance on the public website truncated IP address, cookie identifier, page view events USA
Vercel, Inc. (Vercel Analytics) anonymised page view counting without cookies page address, device and browser type USA

6.2. We engage no contractors to which personal data is transferred other than those listed in clause 6.1. The current list is always contained in the effective version of this Policy; we give notice of engaging a new contractor in the manner set out in section 14, at least 14 calendar days before processing begins.

6.3. Division of responsibility. For the Customer's data, where the Provider is the controller (clause 2.1), the contractors in clause 6.1 are our processors and handle the data on our instructions. For the data of venue staff and guests, where the Customer is the controller (clause 2.2), the Provider acts as the processor and the contractors in clause 6.1 are engaged by us as sub-processors — with the Customer's consent given under clause 10.6.6 of the Offer. Each contractor performs only the technical function stated in the table and has no right to use the data for its own purposes, including advertising or training its own models.

6.4. Accepting online payment and the status of the payment services. Accepting online subscription payments through LiqPay and monobank is implemented in the Service. Each method works only if its payment keys are set; the Service shows the available methods on the payment method screen. As long as the keys for a service are not set, payment through it is not accepted and no data is transferred to it. The corresponding row of the table in clause 6.1 takes effect once payment through that service is switched on; we give notice of switching it on in the manner set out in section 14. As at the date of publication of this version, the payment keys are not set for either method.

6.5. The contractors to which we transfer personal data are engaged under contracts concluded with us and process the data solely on our instructions. Each of them has its own privacy policy.

6.6. Public technical services to which no personal data is transferred. Separately, we use services for the automatic translation of dish names and menu notes (Google Translate, Lingva, MyMemory) and for generating a QR code with a link to the venue's public menu (goQR.me). Only the text being translated, or the public menu link, is sent to those services; Customer, staff and guest data does not reach them. Those services are used on the basis of their public terms of use and may be replaced by us without changing this Policy.

6.7. We may also disclose data at the request of state authorities, if the request is lawful and properly made.

7. Cross-border data transfers

7.1. The equipment of some contractors listed in section 6 is located outside Ukraine. The country or region of each contractor is stated in the table in clause 6.1. The Service's primary data storage — the database and the files — is located in the European Union (the Federal Republic of Germany).

7.2. Transfers to member states of the European Economic Area, and to states party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, are made under part three of Article 29 of the Law of Ukraine “On Personal Data Protection”, because those states ensure adequate protection of personal data.

7.3. Transfers to states not listed in clause 7.2 (in particular to the United States of America) are made:

  • for the Customer's data — on the basis that it is necessary to conclude and perform a transaction for the benefit of the data subject (paragraph 2 of part four of Article 29 of the Law), because without engaging those contractors it is technically impossible to provide access to the Service, and also on the basis of the Customer's consent given under clause 10.2 of the Offer;
  • for the technical data of website visitors (IP address, browser signals) — on the basis of guarantees provided by the Provider against interference with the data subject's private life (paragraph 5 of part four of Article 29 of the Law); those guarantees are secured by data processing agreements with the relevant contractors that include standard contractual clauses on data protection;
  • for the data of venue staff and guests — on the basis of consent obtained by the Customer as the controller of that data, under clause 10.7.1 of the Offer.

7.4. Every contractor located outside the states listed in clause 7.2 is engaged under a contract containing standard contractual clauses on data protection or equivalent contractual guarantees.

7.5. We do not transfer personal data to the aggressor state, or to states subject to sanctions prohibiting such transfers.

8. AI-based features

8.1. The Service and the website run an assistant based on the Google Gemini language model. The text of your query is passed through the OpenRouter routing service to Google AI Studio, where the model generates a reply; a voice query travels the same path as an audio recording for recognition.

8.2. We do not pass guests' personal data to the AI assistant, and we do not use it for automated decision-making that has legal consequences for anyone.

8.3. We keep query metadata for statistics and to protect the Service: the time, the number of queries and signs of abuse, without the content.

8.4. Answers generated by artificial intelligence are for reference only and may be inaccurate.

8.5. We have configured these services so that the content of your queries is not retained by the providers for longer than is needed to generate the reply, and is not used to train or improve their models. The audio recording of a voice query is used solely for speech recognition, is not used to identify a person by voice, and is not retained by us after the reply is generated.

9. Cookies

9.1. In the Service — in the Personal Account, on the kitchen screen, in the POS terminal, in the bar terminal and in the guest portal — we use browser local storage to keep your login session and your language and interface settings. Without it the Service will not work. Analytics and advertising cookies are not set in those parts of the Service.

9.2. On the public stolik.top website we use Google Analytics and Google Ads analytics and advertising cookies only after you have given consent in the consent banner. Until consent is given, those services are not loaded and no cookies are set. You can change or withdraw your consent at any time through the “Cookie settings” link at the bottom of the website.

9.3. The ground for processing is your consent (paragraph 1 of part one of Article 11 of the Law of Ukraine “On Personal Data Protection”).

9.4. You can block or delete cookies using your browser. This does not restrict access to any feature of the website or of the Service.

9.5. The full list of cookies, their purpose and retention periods is given in the Cookie Policy (stolik.top/legal/cookie/en).

10. How long we keep data

10.1. The venue's data is kept for the whole time the subscription is in effect.

10.2. How long data is kept after you stop using the Service depends on who initiated it:

  • deletion of the account or of an individual venue by the Customer through the Personal Account — data is kept for 7 calendar days from the moment the deletion request is confirmed. During that period the Customer can cancel the deletion with a single action in the Personal Account and export their data. After that period expires, the data is deleted in full — all of the venue's tables, staff data and files in storage — with no possibility of recovery. The 90-day period set out below does not apply in this case;
  • the Agreement ends on other grounds, or access is blocked for non-payment — data is kept for 90 calendar days, during which the Customer can export it. After that, the data is deleted.

We notify the Customer by e-mail when a deletion request is accepted, that it can be cancelled, and when deletion is complete — within no more than ten working days from the relevant action (Article 21 of the Law of Ukraine “On Personal Data Protection”).

There are four exceptions to this rule, and all of them are set out below in this section: backups (clause 10.3), accounting documents (clause 10.4), technical logs (clause 10.5) and the archive of consents (clause 10.6). We keep no other data once the periods above expire.

10.3. Backups are kept for up to 180 days, after which they are overwritten. Data deleted from the active system may remain in backups until that period expires. Backups are stored encrypted, are used solely to restore the Service after a failure, and are not used to restore deleted accounts, for analytics or for any other purpose. If a backup is used to restore the Service after a failure, data deleted before the failure is deleted again without delay after the restore.

10.4. Documents needed for tax and accounting records (payment information, data for issuing invoices and certificates) are kept for the period set by paragraph 44.3 of Article 44 of the Tax Code of Ukraine — not less than 1,095 days from the day the tax return for which they were used was filed — regardless of whether the account is deleted.

10.5. Technical logs (the login log, error and request logs) are kept for up to 12 months. The ground for processing is the need to protect our legitimate interests (paragraph 6 of part one of Article 11 of the Law): detecting and investigating unauthorised access, abuse and technical failures. The logs are not used to assess the Customer or its employees and are not passed to third parties, except in the cases provided by law.

10.6. Archive of consents. Once the data has been finally deleted under clause 10.2, we keep for 3 (three) years a separate record of consents containing: the internal account identifier, the Customer's e-mail address, information on which versions of our documents they accepted and when, together with the checksum of the text of each such version, and information about the confirmation of deletion — the confirmation method, the time the one-time code was sent and entered and its cryptographic hash, the time of each confirmation and the time of final deletion. The record contains no other data: no name, no telephone number, no IP address, no browser information, no venue data, no staff or guest data. The record is stored separately from the working database, with restricted access.

The ground for keeping it is the need to protect the Provider's legitimate interests as the controller of the personal data (paragraph 6 of part one of Article 11 of the Law of Ukraine “On Personal Data Protection”). The retention period equals the three-year general limitation period set by Article 257 of the Civil Code of Ukraine: this is the period during which a claim may be brought against us in which we would have to confirm which versions of the documents the Customer accepted and when, and that the data was deleted on their confirmed request. The period runs from the day the data is finally deleted; once it expires, the record is deleted without any separate request.

We have weighed that interest against your rights: the record is kept in the minimum composition needed to prove those facts; it is not used for any other purpose, is not passed to third parties except as provided by law, and is not used to contact you. You may object to this retention by sending a reasoned request to support@stolik.top; we will consider it and, if your arguments outweigh our interest, delete the record early.

11. Security

11.1. We take organisational and technical measures to protect data: data transfers are encrypted, access to the database is restricted, passwords are stored as cryptographic hashes, and backups are made regularly.

11.2. No service can guarantee absolute security. A large part of the risk depends on your own behaviour: do not give your password to third parties, and use a unique password.

11.3. If an incident occurs that threatens people's rights, we will notify the affected Customers without undue delay and in any event no later than 72 hours after the incident is detected, describing what data was affected and what to do.

12. Your rights

12.1. Under Article 8 of the Law of Ukraine “On Personal Data Protection”, you have the right to:

  • know the sources from which your data was collected and where it is held, the purpose of processing it, and information about us as the controller;
  • receive information about the terms on which access to your data is given;
  • get access to your data and a copy of it (export is available in the Service settings);
  • receive a reply to a request about processing within 30 calendar days;
  • demand the correction of inaccurate or incomplete data;
  • make a reasoned demand to change or destroy your data;
  • object to processing and limit its scope;
  • withdraw consent you gave earlier;
  • complain about the processing of your data to the Ukrainian Parliament Commissioner for Human Rights or to a court.

12.2. To exercise these rights, write to us at support@stolik.top. We will reply within 30 calendar days.

12.3. If you are a venue guest or a member of venue staff, send your request to the venue, because it is the controller of that data; the procedure for contacting us is described in clause 2.4.

12.4. A request concerning a deletion request that is pending (clause 10.2) is handled without delay and in any event before the seven-day period expires. If you send such a request during the seven-day period, we will handle it ahead of the general thirty-day reply period: a demand for immediate deletion is carried out early, and a demand to cancel the deletion is carried out before the data is actually erased. If it is technically impossible to handle the request before the period expires, we suspend the deletion until it has been considered.

13. Minors

13.1. The Service is not addressed to people under 18. We do not knowingly collect data about minors. If you learn that a minor's data has reached the Service without proper grounds, tell us and we will delete it.

14. Changes to this Policy

14.1. We may change this Policy. We will give notice of changes at least 14 calendar days before they take effect, through the Personal Account, by e-mail or through the Telegram bot. The notice separately lists the changes.

14.2. Each version is published at a permanent address and kept in the archive at stolik.top/legal/en together with its SHA-256 checksum; previously published versions are never edited, so you can always look up the version in force on any given date.

14.3. Changes have no retroactive effect and do not apply to relations that arose before they took effect.

15. Contacts

Questions about this Policy and about exercising your rights: support@stolik.top Official correspondence: through the Personal Account or using the contact details given in section 15 of the Offer. Website: stolik.top


This Policy was drawn up in Ukrainian. The Russian and English versions are provided for convenience; in case of any discrepancy, the Ukrainian text prevails.

Questions about this document: support@stolik.top
SHA-256 checksum of the text of this version:
b446dd8f6599e69be20a7f29d3d3fc0cf526c0f5e5e8fe5b35da050e4eef278c