Privacy Policy
Last updated: 9/2/2026
Last updated: replace with a real date before launch.
STAFFMA ("we", "us") helps restaurants collect verified guest feedback and recognise their staff. This policy explains what personal data we process and why.
What we collect
- Restaurant owners and staff: name, email, phone (owners), and the account details you provide. Staff photos and display preferences are set by the staff member.
- Guests leaving feedback: the star ratings you submit, and — only if you create an optional account — your email and saved favourites. Basic anonymous feedback needs no account and stores no personal identifiers beyond a one-time session token.
- Technical: we set essential cookies to keep you signed in and to remember your language and cookie choices. With your consent we also use analytics cookies (see the Cookie Policy).
Why we process it
To operate the service (contract), to keep it secure and prevent abuse (legitimate interests), and, for analytics, on the basis of your consent.
Sharing
We use Supabase (hosting, database, authentication) and, where configured, Stripe (payments) and an email provider. Google ratings shown on restaurant pages come from Google and are never mixed into STAFFMA scores. We never sell personal data.
Retention
Feedback is kept as immutable evidence for the restaurant's recognition record. Account data is kept while your account is active. Contact us to close an account.
Your rights
You can request access, correction, deletion, restriction, portability, and you can object to processing. See "Your data rights" for how. You may also complain to your local data protection authority.
Contact
Replace with a real contact email and postal address before launch.
