Privacy Policy
Last updated: 2 June 2026
This page explains in plain language what personal data we collect, why we collect it, how long we keep it, and the rights you have under the EU GDPR and the Swedish Data Protection Act.
Section 1
Who we are
Platra is the data controller responsible for your personal data on this platform. You can contact us at any time at system@platra.se.
Section 2
Data we collect
Account data
- Name, email, phone (encrypted at rest)
- Hashed password
- Google ID (if you use Google sign-in)
- Marketing-consent flag & timestamp
Order data
- Items, prices, taxes, totals
- Delivery address & door code (encrypted)
- Payment status (cards handled by Stripe — we never see them)
Technical data
- IP address & user agent (security only)
- Session cookies (essential)
- Push token (if you opt in)
Usage data
- Menu items viewed (anonymous)
- AI-chat messages (90-day retention)
- Reviews you publish
Section 3
Legal basis
Delivering the service
Processing your order, taking payment, sending order updates.
Sharing data with the restaurant you order from
Your name, contact details, order history, loyalty balance, and delivery information are passed to the Merchant (restaurant) so they can fulfil your order, handle support, and run loyalty/cashback programmes.
Bookkeeping
Keeping order/invoice records for 7 years (Bokföringslagen 1999:1078).
Security & abuse prevention
Logging IP for fraud, rate-limiting, and account protection.
Marketing emails, analytics, AI-chat history
Only when you actively tick the relevant box.
Section 4
How long we keep it
Active customer account
Until you delete it
Order/invoice records
7 years (Swedish law)
Menu views & QR scans
90 days
AI chat logs
90 days
Checkout session data
24 hours after expiry
GDPR request artefacts
7 days after expiry
Application logs
14 days
Section 5
Sub-processors
We share strictly necessary data with the following providers. Each has signed a Data Processing Agreement (DPA). International transfers, where unavoidable, rely on the EU Standard Contractual Clauses.
Stripe
Payment processing
Brevo
Transactional & marketing email
Google Sign-In OAuth
OpenAI
AI menu assistant (zero-retention)
AWS S3 (EU)
Image & file storage
BunnyCDN
Image content-delivery
Firebase Cloud Messaging
Push notifications (opt-in)
Section 6
Data shared with Merchants (restaurants)
When you place an order with a restaurant through Platra, we share the personal data that the restaurant needs to fulfil your order, provide customer support, and manage their customer relationship with you. This is a necessary part of the contract between you and the restaurant.
What restaurants can see about you
- Your name
- Your email address and phone number
- Your order history with that specific restaurant (items, quantities, totals)
- Your loyalty points and cashback balance at that restaurant
- Your delivery address and door code for delivery orders
- Special instructions or notes included with an order
What restaurants cannot see
- Your password or any authentication credentials
- Your payment card details (handled exclusively by Stripe)
- Your orders placed at other restaurants
- Any personal data beyond what is listed above
Each restaurant may only access data of customers who have placed at least one order with them through Platra. A restaurant cannot access any information about customers who have ordered from other restaurants.
Restaurants may use your information for the following purposes only:
- Order fulfilment — preparing, dispatching, and confirming your order
- Customer support — responding to questions or complaints about your order
- Loyalty and cashback programmes — tracking and rewarding your purchases
- Customer relationship management — understanding your preferences and ordering patterns
- Compliance with Swedish food-safety and record-keeping obligations
Legal basis for this sharing
Order fulfilment
Sharing is necessary to perform the contract between you and the restaurant.
Loyalty, cashback, and CRM
The restaurant has a legitimate interest in managing its customer relationships for customers who have chosen to order from it.
By placing an order or creating an account on Platra, you acknowledge that your order-related personal data will be shared with the restaurant you order from as described above. You may exercise your GDPR rights (access, erasure, restriction, objection) at any time — see Section 7.
Section 7
Your rights
Under GDPR you have the right to:
- Access: Get a copy of your data (Art. 15).
- Rectify: Correct inaccurate data (Art. 16).
- Erase: Delete your account (Art. 17).
- Restrict: Pause certain processing (Art. 18).
- Portability: Receive your data in JSON (Art. 20).
- Object: Stop processing based on legitimate interest (Art. 21).
- Withdraw consent: At any time, without affecting prior processing.
- Complain: To the Swedish IMY supervisory authority.
Section 9
Security
- Passwords hashed with bcrypt
- Email & phone encrypted at rest (AES-256)
- All traffic over HTTPS / TLS 1.2+
- Single-use, expiring tracking tokens
Section 10
Data breaches
In the unlikely event of a personal-data breach that risks your rights and freedoms, we will notify the IMY within 72 hours and inform affected users without undue delay (GDPR Art. 33 & 34).
Section 11
Changes to this policy
We may update this policy. Material changes are communicated via email or in-app notice at least 14 days before they take effect.