Privacy Policy
Version 2.4 · Last updated 5 October 2026
Who we are
Amusebit is a service of it Kwaks OÜ, a company registered in Estonia under registry code 16835586, at Tornimäe tn 5, 10145 Tallinn, Estonia. For the data described here we are the controller: we decide what is collected and why.
You can reach us about anything in this policy at hello@amusebit.com. We aren’t required to appoint a data protection officer, so that address reaches the people who actually run the service.
What this policy covers
This policy is about you: anyone with an Amusebit account, whether you signed up yourself or were invited into a venue by a colleague. It covers this website and the Amusebit application.
It does not cover the content of your published menus. There, you are the controller and we act on your instructions as a processor. The terms of that arrangement are in our data processing agreement.
What we collect, and why
Rather than one long list, here is each purpose with the specific data it uses and the lawful basis we rely on under Article 6 of the GDPR.
Your account
- What
- Your name, email address, and the password you set (stored only as a hash we can't reverse).
- Why
- To create your account, sign you in, and contact you about the service.
- Legal basis
- Performance of our contract with you (Art. 6(1)(b) GDPR).
Record of your agreement to our terms
- What
- Which version of the Terms of Service and Data Processing Agreement you accepted, which version of this policy was current, the email address you used, and when.
- Why
- So that both of us can show what was agreed, and when.
- Legal basis
- Our legitimate interest in being able to prove the terms of our contract (Art. 6(1)(f)).
Billing details
- What
- Company legal name, billing address, VAT number where you give one, your Stripe customer reference, and the invoices we issue. We never see or store your card number.
- Why
- To charge you, issue correct invoices, and apply the right VAT treatment.
- Legal basis
- Performance of our contract (Art. 6(1)(b)), and our legal obligations under Estonian accounting and tax law (Art. 6(1)(c)).
Your menu content
- What
- Everything you put into a menu: sections, dishes, descriptions, prices, allergen and nutrition information, photos, your logo, opening hours, and contact details.
- Why
- To build, host, and publish your menus. That's the service itself.
- Legal basis
- Performance of our contract (Art. 6(1)(b)).
- Note
- This is your content, and it's usually about food rather than people. If you do put personal data in it, such as a chef's name or a photo with a face in it, we handle that as your processor under our data processing agreement.
AI translation
- What
- The menu text you ask us to translate, sent to a machine-translation model along with the target language.
- Why
- To produce the translation you requested.
- Legal basis
- Performance of our contract (Art. 6(1)(b)). It only runs when you ask it to.
- Where
- Amazon Bedrock, in EU regions only. Your text isn't used to train any model.
Trial eligibility
- What
- Your email address and two one-way hashes of it, one of which ignores dots and plus-addressing so that alias variants of the same address group together.
- Why
- So that one business gets one free trial. Without it, a new alias every 60 days would give unlimited free service.
- Legal basis
- Our legitimate interest in preventing abuse of the free trial (Art. 6(1)(f)). We think this is a fair use of the data because it's limited to checking whether an address has been seen before, and it isn't used for anything else. You can object; see your rights below.
Referrals
- What
- Your own referral code, the code of whoever referred you, and the resulting reward or commission.
- Why
- To run the referral programme and pay the rewards it promises.
- Legal basis
- Performance of our contract (Art. 6(1)(b)).
- Before signup
- On this website, remembering a referral code between visits needs your consent (Art. 6(1)(a)). That's the one optional cookie described in our cookie policy.
Newsletter
- What
- Your email address and whether you opted in, if you tick the box at signup.
- Why
- To send you product news. We don't send it unless you opted in.
- Legal basis
- Your consent (Art. 6(1)(a)). Withdraw it any time, from your account settings or the link in any newsletter.
Website analytics (Google Analytics)
- What
- The pages you view, how you reached them, a random ID for your browser, your approximate location (derived from your IP address), your device and browser type, and when you click through to sign up. If you then sign up, our servers also report when your trial starts and when you first pay, with the amount before VAT, linked to that browser ID and a random ID for your account.
- Why
- Counts visits and shows us which pages people read and where they came from, so we can tell what is working on this website.
- Legal basis
- Your consent (Art. 6(1)(a)), asked for in the cookie banner, for everything above. You can withdraw it at any time with “Cookie settings” in the footer.
- Without your consent
- Google Analytics runs in a limited mode: no cookies, and only basic technical information about each page view.
- Legal basis without consent
- Our legitimate interest in understanding how this website is used (Art. 6(1)(f)).
- Where
- Google Ireland Limited, with processing by Google LLC in the United States. Google LLC is certified under the EU–US Data Privacy Framework.
- Their own use
- Google Ireland Limited and Google LLC also handles this data under its own privacy policy.
Advertising measurement (Meta Pixel)
- What
- The pages you view, a random ID for your browser, the ad click ID if you arrived from a Meta ad, your IP address and browser details, and when you click through to sign up. If you arrived from a Meta ad and sign up, our servers also report when your trial starts and when you first pay, with your email address in hashed form.
- Why
- Measures whether our adverts on Facebook and Instagram lead people to this website and to sign up, so we can see which adverts work and show them to people likely to be interested.
- Legal basis
- Your consent (Art. 6(1)(a)), asked for in the cookie banner, for everything above. You can withdraw it at any time with “Cookie settings” in the footer.
- Without your consent
- The Meta Pixel loads but stays paused: no cookies and no events. Loading it gives Meta basic technical information, such as your IP address.
- Legal basis without consent
- Our legitimate interest in running this website and its tools smoothly (Art. 6(1)(f)).
- Where
- Meta Platforms Ireland Limited, with transfer to Meta Platforms, Inc. in the United States. Meta Platforms, Inc. is certified under the EU–US Data Privacy Framework.
- Their own use
- Meta Platforms Ireland Limited also handles this data under its own privacy policy.
Advertising measurement (ChatGPT Ads pixel)
- What
- The pages you view, a random ID for your browser, the ad click reference if you arrived from a ChatGPT advert, your IP address and browser details, and when you click through to sign up. If you arrived from a ChatGPT advert and sign up, our servers also report when your trial starts and when you first pay, with your email address in hashed form.
- Why
- Measures whether our adverts in ChatGPT lead people to this website and to sign up, so we can see which adverts work.
- Legal basis
- Your consent (Art. 6(1)(a)), asked for in the cookie banner. Nothing is collected before you give it, and you can withdraw it at any time with “Cookie settings” in the footer.
- Where
- OpenAI in the United States. OpenAI is not certified under the EU–US Data Privacy Framework.
- Their own use
- OpenAI also handles this data under its own privacy policy.
Ad click IDs and signup reporting
- What
- If you arrive by clicking an advert, the click ID in the link (gclid, gbraid, wbraid, fbclid, or oppref). If you then sign up, we also keep the IP address and browser details of your signup, and report two events: when your trial starts, and when you first pay, with the amount before VAT. Each report carries the click ID and your email address in hashed form, never in plain text.
- Why
- So we can see which adverts lead to real signups and customers, and so the advertiser can show our adverts to people likely to be interested.
- Who receives it
- Only the advertiser whose advert you clicked: Google Ireland Limited (Google Ads, for gclid, gbraid, and wbraid), Meta Platforms Ireland Limited (fbclid), or OpenAI (oppref). Each also handles it under its own privacy policy.
- Legal basis
- Your consent (Art. 6(1)(a)), as part of the advertising category in the cookie banner. Without it, click IDs are ignored and nothing is reported.
- Kept
- In your browser tab's session storage until you close the tab. If you sign up, we keep the click ID, IP address, and browser details for 90 days, then delete them automatically.
Support conversations
- What
- The emails you send us and our replies.
- Why
- To answer you, and to keep a record of what was agreed.
- Legal basis
- Our legitimate interest in supporting our customers (Art. 6(1)(f)).
Technical logs
- What
- IP address, browser user-agent, timestamps, and which requests were made, recorded automatically by our servers.
- Why
- To keep the service running, investigate faults, and detect abuse.
- Legal basis
- Our legitimate interest in the security and reliability of the service (Art. 6(1)(f)).
What you have to give us
To open an account we need your name, an email address, and a password. For a paid plan we also need your company’s legal name and billing address, because the law requires them on an invoice. Without these we can’t provide the service. Everything else, including the newsletter, is up to you.
Your guests and published menus
Today, published menus set no cookies and load no analytics or tracking scripts. Menus do load their typefaces from Google Fonts, which means Google receives the guest’s IP address, as any web request would. Details are below. If we change how published menus work in a way that affects this, we’ll update this policy and tell you before it takes effect.
What we deliberately don’t do
- We don’t sell or rent personal data. Not to anyone, in any form.
- We don’t use your content to train AI models, and neither does our translation provider.
- We make no automated decisions that produce legal or similarly significant effects about you.
- This website loads no third-party fonts, and its analytics and advertising tools run in full only with your consent. Its typefaces are served from our own servers.
Where your data lives
Everything we store is stored in Amazon Web Services’ eu-central-1 (Frankfurt, Germany) region. Data is encrypted in transit and at rest.
Menu pages and images are delivered through a content delivery network, which caches copies briefly at a location near the guest opening your menu. If they’re outside the EU, that cached copy can be outside the EU too. The stored data stays in Frankfurt, and menu pages are public content in any case.
Who else receives your data
These are our sub-processors, the companies that handle personal data on our behalf. We keep the list as short as we can while still running a platform.
Amazon Web Services EMEA SARL
Luxembourg, part of the Amazon group
- What it does
- Hosting, database, file storage, content delivery, sign-in and account email. Effectively the whole platform runs here.
- Data location
- eu-central-1 (Frankfurt, Germany). Stored data stays in the EU.
- Delivery
- Pages and images are delivered through a content delivery network, which caches copies briefly at edge locations near the reader. For a reader outside the EU, that edge location can be outside the EU too.
- Safeguards
- AWS Data Processing Addendum, incorporating the EU Standard Contractual Clauses.
Amazon Bedrock
An AWS service, listed separately because it's the only place your content meets a machine-learning model
- What it does
- Translates menu text when you use the AI translation feature. Only the text you ask to translate is sent.
- Data location
- EU regions only, via an EU inference profile. Requests don't leave the EU.
- Who sees it
- Nobody outside AWS. The model runs inside AWS infrastructure. Anthropic, whose model it is, receives nothing and has no contract with us.
- Training
- AWS doesn't use Bedrock inputs or outputs to train models, and doesn't share them with the model provider.
Microsoft Ireland Operations Limited
Dublin, Ireland
- What it does
- Hosts our email, including hello@amusebit.com, so it holds the support conversations you have with us.
- Data location
- Microsoft data centres, with possible transfer to Microsoft Corporation in the United States.
- Safeguards
- Microsoft's Data Protection Addendum with the EU Standard Contractual Clauses; Microsoft Corporation is certified under the EU–US Data Privacy Framework.
If we add a sub-processor, customers get notice in advance under the data processing agreement, which is where the current list is formally maintained.
Two more companies receive personal data, in different roles:
Stripe Payments Europe, Limited
Dublin, Ireland
- What it does
- Takes payments, runs subscriptions, issues invoices and checks VAT numbers. Card details go straight to Stripe and never touch our systems.
- Its own role
- Stripe also uses some of this data as a controller in its own right, for fraud prevention and to meet its own legal obligations. The Stripe privacy policy covers that part.
- Data location
- European Union, with onward transfer to Stripe, Inc. in the United States.
- Safeguards
- Stripe's Data Processing Agreement with the EU Standard Contractual Clauses; Stripe, Inc. is certified under the EU–US Data Privacy Framework.
Google LLC (Google Fonts)
United States
- What it does
- Delivers the typefaces used on published menus and in the Amusebit app. This website serves its own fonts and doesn't use it.
- What it receives
- The reader's IP address and browser details, which any web request carries. Google Fonts sets no cookies, and Google says it collects only what it needs to serve the fonts.
- Why
- Our legitimate interest in showing menus in the typefaces a venue chose, quickly and consistently (Art. 6(1)(f) GDPR).
- Safeguards
- Google LLC is certified under the EU–US Data Privacy Framework.
International transfers
What we store, we store in the EU. Personal data does leave it in three places: Stripe’s Irish company is supported by Stripe, Inc. in the United States; Microsoft may process email in the United States; and Google Fonts is operated by Google LLC in the United States. All three US companies are certified under the EU–US Data Privacy Framework, and the Stripe and Microsoft transfers are also covered by the EU Standard Contractual Clauses.
If you switch on the optional tools in the cookie banner, data also goes to Google Ireland Limited, with processing by Google LLC in the United States (Google Analytics); to Meta Platforms Ireland Limited, with transfer to Meta Platforms, Inc. in the United States (the Meta Pixel); and to OpenAI in the United States (the ChatGPT Ads pixel). If you arrived from an advert and sign up, the report of your signup goes to the same company that showed you the advert, including Google Ireland Limited for Google Ads, with processing by Google LLC. Google LLC and Meta Platforms, Inc. are certified under the EU–US Data Privacy Framework. OpenAI is not. Without your consent, Google and Meta receive only the limited information described above.
To get a copy of the Standard Contractual Clauses that apply, write to hello@amusebit.com.
How long we keep it
Account, menus, and images
- Kept
- For as long as your account is open. When you delete it, we schedule everything for deletion 30 days later. Our database backups roll over within a further 35 days, after which no copy remains.
- Why 30 days
- A grace period, so an accidental deletion or a disputed cancellation can be undone. After it passes, we can't restore your account.
- Unpaid trials
- If your trial ends and you don't subscribe, we keep your account for 90 days in case you come back, then delete it as above.
Invoices, accounting records, and paid commissions
- Kept
- Seven years from the end of the financial year.
- Why
- Required by the Estonian Accounting Act. We can't delete these on request.
Record of your agreement to our terms
- Kept
- For as long as your account is open, and three years after it closes, which is the general limitation period for contract claims under Estonian law.
Trial eligibility record
- Kept
- Six months after the account is deleted, then removed automatically.
- Why
- Long enough to stop an immediate delete-and-resignup loop, short enough that it doesn't become a permanent record of you.
Technical logs
- Kept
- 90 days, then deleted automatically.
Support emails
- Kept
- Up to two years after the conversation ends.
Cookies
This website sets one cookie to remember your cookie choices. Everything else is optional and off until you agree to it: analytics and advertising cookies, and a cookie that remembers a referral code. Until then, some tools run in a limited mode without cookies. The cookie policy lists every cookie, and you can change your mind at any time using “Cookie settings” in the footer.
The Amusebit application itself uses no cookies at all. Your session is held in your browser’s session storage and disappears when you close the tab.
Security
Access to your venue is controlled by role, sign-in is protected by a password policy and account verification, and every request is authorised against your membership of that venue before it returns anything. Data is encrypted in transit and at rest, and access to production systems is limited to the people who operate them.
No system is perfect. If a breach ever affects your personal data and is likely to result in a risk to you, we’ll notify the Estonian Data Protection Inspectorate within 72 hours and tell you directly where the law requires it.
Your rights
Under the GDPR you can ask us to:
- Give you a copy of the personal data we hold about you, and tell you what we do with it.
- Correct anything that is wrong or incomplete.
- Delete your data. You can delete your account yourself from the app. Where we’re legally required to keep something, such as an invoice, we’ll tell you.
- Export your data. Ask us and we’ll send it to you in a portable, machine-readable format.
- Restrict what we do with it while a dispute is being resolved.
- Withdraw consent at any time, where we asked for it. That won’t affect anything done before you withdrew it.
Your right to object. Where we rely on legitimate interests (the trial-eligibility check, the record of your agreement to our terms, technical logs, support records, and font delivery), you can object on grounds relating to your particular situation. We’ll then stop, unless we have compelling legitimate grounds that override your interests, or we need the data to establish or defend a legal claim.
Write to hello@amusebit.com and we’ll respond within one month. We don’t charge for this. We may ask you to confirm your identity first, so that we don’t hand your data to someone else.
If you’re not happy with how we handle it, you can complain to your local data protection authority, or to ours: Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), Tatari 39, 10134 Tallinn, Estonia, info@aki.ee, https://www.aki.ee.
Children
Amusebit is a tool for businesses and isn’t directed at children. We don’t knowingly collect personal data from anyone under 16.
Changes to this policy
When we change something that matters, such as a new sub-processor, a new purpose, or a longer retention period, we’ll email you before it takes effect and raise the version number at the top of this page. Smaller clarifications are made without notice, and the date always tells you when we last touched it.
Contact
it Kwaks OÜ (Amusebit)
Tornimäe tn 5, 10145 Tallinn, Estonia
Registry code: 16835586
hello@amusebit.com