Good2Order Privacy Policy
Last updated: 23.07.2026
The Polish version (Polityka prywatności) is the binding version; this English text is provided for convenience.
§1. Data controller
The controller of personal data is Dominik Myszkowski, conducting business activity under the name Knight Software Dominik Myszkowski, ul. Tadeusza 24, 05-420 Józefów, Poland, entered in the Polish Central Registration and Information on Business (CEIDG), tax ID (NIP): 5252291057 (the Controller).
Contact for data protection matters: contact@good2order.com.
§2. What data we process
We process only the data necessary to provide the service:
- Restaurant data: name, tax ID, address, phone number, contact details.
- Owner and team data: first name, last name, email address, password (stored hashed), role and preferences.
- Guest data: email address and first name (if an account was created), order history, reviews, favourite venues, reservations.
- Technical data: server logs, IP address, device identifier and push notification token (for session handling and notifications).
- Location data: the Guest’s approximate device location — only with their consent and for finding nearby restaurants.
§3. Purposes and legal bases of processing
We process data for the following purposes:
- Providing the service and performing the agreement (Art. 6(1)(b) GDPR).
- Issuing invoices and fulfilling legal obligations, including tax obligations (Art. 6(1)(c) GDPR).
- Marketing of our own services, including the newsletter — only with consent (Art. 6(1)(a) GDPR).
- Establishing, pursuing or defending against claims and ensuring the security of the service (Art. 6(1)(f) GDPR).
§4. Recipients and processors
Data may be entrusted to trusted processors, only to the extent necessary to provide the service, including:
- the infrastructure and hosting provider — OVH,
- the payment operator — PayPro S.A. (Przelewy24), ul. Pastelowa 8, 60-198 Poznań, Poland, a national payment institution supervised by the Polish Financial Supervision Authority (KNF),
- the transactional email provider — Google (SMTP service),
- push notification providers (Apple, Google) and privacy-friendly analytics (Plausible).
We make the current list of processors available on request. We do not sell personal data.
§5. Transfers outside the EEA
We aim to process data within the European Economic Area. Where data is transferred outside the EEA, it takes place on the basis of appropriate safeguards (e.g. standard contractual clauses approved by the European Commission).
§6. Retention periods
- Account data is stored for the duration of the agreement and until the account is deleted.
- Billing data and invoices — for the period required by law (generally 5 years from the end of the tax year).
- Order and visit data linked to a venue — as the restaurant’s records, whereby data identifying the Guest is anonymised after the account is deleted.
- Marketing consents — until consent is withdrawn.
- Technical logs — typically up to 12 months.
After a Guest’s account is deleted, identifying data is irreversibly anonymised or removed, and records retained by the restaurant lose their link to the Guest’s identity.
§7. Rights of data subjects
You have the right to: access your data, rectify it, erase it, restrict processing, data portability, object, and withdraw consent at any time (without affecting the lawfulness of processing before withdrawal).
You may delete your account and data at any time in the application (Profile → Delete account) or by contacting us. You may also download a copy of your data (export).
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO).
§8. Cookies and analytics
The Service may use necessary cookies and privacy-friendly analytics that does not profile users and, where possible, does not use identifiers enabling cross-site tracking. You can change cookie settings in your browser.
§9. Security
We apply technical and organisational measures appropriate to the risk, including transmission encryption (HTTPS), password hashing and access control. We follow the data minimisation principle.
§10. Automated decision-making
We do not make decisions based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you. We do not carry out profiling for marketing purposes.
§11. Changes to this policy
We may update this policy; we will announce material changes on the Service or by email. The date of the last update is indicated at the top of the document.
§12. Contact
For matters relating to personal data, please contact us: contact@good2order.com.