Back to home

Privacy policy

Last updated: 25/05/2026

Data controller

The data controller is PariSéville. For any question regarding the processing of your data, please contact us at .

Data collected

We only collect data strictly necessary for the operation of the service.

Restaurateur account

  • Email address (login identifier and communication).
  • Password stored in encrypted form (bcrypt algorithm); never in plain text.
  • Restaurant name, default language, technical slug.

Subscription and billing data

  • Stripe identifiers (customer ID, subscription ID) allowing us to retrieve your subscription with our payment provider.
  • Subscription status (trial, active, canceled), chosen plan (monthly or yearly).
  • Trial end date, next renewal date.

Content you publish

  • Dishes, categories, prices, photos, descriptions, allergens.
  • Blog articles, titles, content, images.
  • Comments left by your customers on your articles (name and message).

Technical data

  • Session cookie (PHPSESSID), strictly necessary for authentication and storing preferences.
  • Technical logs (IP address, user agent, dates) automatically generated by the web server; kept for security and debugging purposes.

Purpose of processing

  • Creating and managing your restaurateur account.
  • Providing the MyRezto service (back office, public menu, blog, statistics).
  • Subscription management, invoicing and dunning in case of payment failure.
  • Automatic translation of your menu if you activate this feature (sent to the Anthropic API).
  • Service security, fraud prevention, logging.
  • Compliance with our legal obligations (accounting retention, authority requests, etc.).

Legal basis for processing

Processing of your data is based on the performance of the contract between us (GDPR article 6.1.b) for data necessary for the service and billing, on compliance with our legal obligations (article 6.1.c) for accounting retention, and on our legitimate interest (article 6.1.f) for security and fraud prevention.

Sub-processors and data transfers

To deliver the service, we rely on the following sub-processors:

  • Stripe Payments Europe Limited (Irlande) : payment processing and subscription management. Stripe is PCI DSS Level 1 certified. Payment data (card number, CVV) never transits through our servers.
  • Anthropic PBC (États-Unis) : automatic translation service for the menu (only if you enable this feature). Dish names and descriptions you entrust to us are sent to Anthropic for translation. Anthropic commits not to use this data to train its models.
  • o2switch (France) : hosting of the application server and database. Data stored in France.

Retention periods

  • Account data: kept as long as your account is active. Deleted on request or after 3 years of inactivity.
  • Billing data: kept for 10 years after the end of the contractual relationship (accounting obligation).
  • Published content (menu, blog, comments): deleted when the account is closed.
  • Technical logs: kept for a maximum of 12 months, then automatically purged.

Cookies and local storage

We exclusively use cookies strictly necessary for the operation of the service. No advertising, analytics or tracking cookies. No prior consent is therefore required.

  • PHPSESSID : technical session cookie for authentication and basket persistence.
  • menu_locale_* : language preference cookie to remember the visitor's language choice.
  • when entering a payment, the Stripe Checkout tunnel may drop its own cookies on its subdomain. See Stripe's policy.

Your rights

In accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the following rights:

  • right of access to your data.
  • right to rectify inaccurate data.
  • right to erasure (right to be forgotten).
  • right to data portability in a structured format.
  • right to object to processing.
  • right to restrict processing.

To exercise these rights, write to us at . We respond within 30 days maximum.

You also have the right to lodge a complaint with the French data protection authority (CNIL, www.cnil.fr).

Security

We implement appropriate technical and organisational measures: password hashing, HTTPS transit, regular backups, restricted database access, hosting in France.

Policy changes

This policy may be updated to reflect legal or technical changes. The version in force is always the one published on this page. Substantial changes will be notified by email to active accounts.