This Privacy Policy details how Sosene Digital QR Menu Platform ("Sosene", "we", "us", or "our") collects, protects, processes, and manages personal data and venue information when you interact with our website at https://sosene.com, use our restaurant management panel, or view digital QR menus.
We collect several categories of information to provide seamless digital menu rendering, account management, and payment processing services:
When a restaurant owner or vendor registers an account, we collect:
BCRYPT encryption algorithms. We never store plain-text passwords.To construct and display public QR menus, vendors upload and provide:
/menu/gourmet-bistro), telephone numbers, physical address, and operating hours.Subscription payments are handled securely through our payment provider, Stripe. Sosene records non-sensitive payment transaction metadata including transaction IDs, plan names, billing intervals, currency symbols, and expiration dates. Raw credit card numbers and CVV codes are processed directly by Stripe under strict PCI-DSS Level 1 compliance.
When customers scan a table QR code to view a digital menu:
We process your personal and business data strictly for legal and legitimate operational purposes:
| Processing Purpose | Categories of Data Used | Legal Basis |
|---|---|---|
| Digital Menu Service Delivery | Venue info, menu categories, dish items, prices | Contract Performance |
| Subscription Billing & Access Control | Email address, subscription ID, payment transaction log | Contractual Requirement |
| Table Service & Order Request Relay | Table number, waiter call status, timestamp | Legitimate Interest |
| Platform Security & Fraud Prevention | IP address, CSRF session tokens, login attempt logs | Legal Obligation & Security |
Sosene prioritizes state-of-the-art security measures to safeguard all stored records and network communications:
All data transferred between your browser, QR guests, and our servers is encrypted in transit using SSL certificates.
Database interactions utilize parameterized PDO queries to neutralize SQL injection vulnerabilities completely.
Passwords are cryptographically hashed using PASSWORD_BCRYPT algorithms with one-way salting.
Form submissions require unique cryptographic CSRF tokens to block cross-site forgery attacks.
To deliver advanced capabilities, Sosene integrates with trusted third-party providers under strict data privacy obligations:
We retain your account information for as long as your subscription or user account remains active. Upon account termination or written request, all associated restaurant records, categories, dish images, and waiter call history will be permanently deleted from our primary databases within 30 days.
Under international privacy regulations (including General Data Protection Regulation GDPR and KVKK), users possess explicit data protection rights:
Sosene utilizes essential session cookies and preference cookies to maintain control panel login sessions and remember language choices. For complete details, please inspect our dedicated Cookie Policy.
For privacy inquiries, data access requests, or regulatory questions, please contact our Data Protection Officer:
Email: info@sosene.com
Phone: +905306853691