Privacy Policy

Last updated: April 27, 2026

1. Data Controller

The Batlr application and the batlr.app website are published by Lucas Khoury, an individual. In the absence of a designated Data Protection Officer, any question about data protection can be addressed to: privacy@batlr.app.

2. Data Collected

2.1 Restaurant Operator Data (app user)

2.2 Restaurant Customer Data

2.3 Technical and Analytics Data

2.4 Data NOT Collected

The Batlr iOS application requests no broad system permissions: no access to your device location, contacts, camera, microphone, full photo library, calendar, or any other device sensor. When you upload a restaurant logo, cover image, or feedback screenshot, the iOS system photo picker (PhotosPicker) lets you choose specific items — Batlr only ever receives the images you explicitly select, never the rest of your library, and we never request "all photos" access. No advertising or third-party tracking cookies are placed on the batlr.app website.

3. Purposes of Processing

4. Legal Bases

5. Sub-processors and Data Sharing

Your data is never sold. It is processed by the following sub-processors, each bound by GDPR-compliant data-processing agreements (DPAs):

| Sub-processor | Purpose | Primary location | |---|---|---| | Supabase (Supabase Inc.) | Database, authentication, file storage, Edge Functions, realtime | Frankfurt, Germany (eu-central-1) | | Apple (Apple Inc. / Apple Distribution International Ltd) | App distribution, StoreKit in-app purchases, Sign in with Apple, App Store Server notifications | United States / Ireland | | Stripe (Stripe, Inc. / Stripe Payments Europe Ltd) | Card holds, prepayments, refunds, KYC verification for Stripe Connect | Ireland / United States | | Google (Google LLC / Google Ireland Ltd) | Sign in with Google (when used) | Ireland / United States | | Resend (Resend Inc.) | Transactional email delivery (confirmations, reminders, follow-ups, team invitations) | United States | | Twilio (Twilio Inc.) | Transactional and marketing SMS delivery | United States | | PostHog (PostHog Inc.) | Product analytics and crash/error capture (EU instance eu.i.posthog.com) | Frankfurt, Germany | | Vercel (Vercel Inc.) | Hosting of the batlr.app website and public restaurant pages | United States (global edge network) | | jsDelivr (Prospect One sp. z o.o.) | Runtime CDN for the public booking widget (Supabase JS, web fonts) | Global network |

For data transfers outside the European Union, Batlr relies on the European Commission's Standard Contractual Clauses (SCCs) and/or on the EU-U.S. Data Privacy Framework where applicable to the relevant sub-processor.

6. Retention Period

| Data category | Retention period | |---|---| | Account data (Batlr user) | For the lifetime of the account, then 3 years after the last activity | | Reservation data | 3 years from the last visit | | Billing data and invoices | 10 years (legal obligation, Art. L.123-22 of the French Commercial Code) | | Technical logs and audit logs | 12 months | | PostHog analytics data | 12 months |

When an account is deleted, certain invoices subject to legal retention may be kept in anonymized form (customer-name hash) in the legal_retention_invoices registry for the legal duration of 10 years, and then permanently deleted.

7. Your Rights

In accordance with GDPR, you have the following rights:

To exercise these rights, contact us at privacy@batlr.app. We will respond within 30 days.

You may also file a complaint with the CNIL (the French Data Protection Authority — www.cnil.fr), or with your local equivalent data-protection authority.

8. Account Deletion

You may request the deletion of your account and all your data at any time:

More details on our dedicated account deletion page.

The deletion procedure run from the application chains the following steps:

  1. Automatic Stripe refund of any unconsumed prepayments (future-dated reservations)
  2. Anonymized archival of invoices subject to legal retention (10 years)
  3. Best-effort closure of attached Stripe Connect accounts
  4. Cascade deletion of restaurants, teams, reservations, floor plans, and waitlists
  5. Revocation of Sign in with Apple tokens, where applicable
  6. Permanent deletion of the Supabase authentication account (auth.admin.deleteUser) — without backup copy

Deletion takes effect within 30 days. Data subject to legal retention is kept for the required duration and then automatically purged.

9. Security

We implement appropriate technical and organizational measures:

10. Cookies and Local Storage

The batlr.app website uses only cookies strictly necessary for its operation and for remembering your language preference. No advertising or third-party tracking cookies are used.

The public booking widget and restaurant pages may use the browser's local storage (localStorage) to temporarily remember the information entered into the form, in order to avoid losing it in the event of a network error.

11. Changes

This policy may be updated. In case of a substantial change, we will notify you by email or through the application at least 30 days before the change takes effect.

12. Contact

For any questions about this policy: privacy@batlr.app