Sosene Logo Sosene.
  • 🇬🇧 English
  • 🇩🇪 Deutsch
  • 🇫🇷 Français
  • 🇮🇹 Italiano
  • 🇹🇷 Türkçe
Back to Home
Data Protection & Compliance

Privacy Policy

Effective Date: January 01, 2026
Last Updated: September 11, 2026

This Privacy Policy details how Sosene Digital QR Menu Platform ("Sosene", "we", "us", or "our") collects, protects, processes, and manages personal data and venue information when you interact with our website at https://sosene.com, use our restaurant management panel, or view digital QR menus.

Table of Contents
  • 1. Information We Collect
  • 2. How We Use Collected Data
  • 3. Technical Security & Encryption
  • 4. Third-Party Service Integrations
  • 5. Data Retention & Deletion Rights
  • 6. International Compliance (GDPR / KVKK)
  • 7. Cookies & Tracking Technologies
  • 8. Contact Information & Support

1. Information We Collect

We collect several categories of information to provide seamless digital menu rendering, account management, and payment processing services:

A. Restaurant Member & Account Data

When a restaurant owner or vendor registers an account, we collect:

  • Full Name & Email Address: Used for account creation, login identification, and security notifications.
  • Cryptographic Password Hash: Stored securely using salted BCRYPT encryption algorithms. We never store plain-text passwords.
  • Account Role & Status: Assigning system permissions (Vendor or Administrator).
B. Venue Branding & Menu Content Data

To construct and display public QR menus, vendors upload and provide:

  • Venue Profile Information: Restaurant name, custom URL slug (e.g. /menu/gourmet-bistro), telephone numbers, physical address, and operating hours.
  • Social Media Handles: WhatsApp ordering numbers, Instagram, and Facebook profile URLs.
  • Menu Items & Photography: Category names, food/beverage descriptions, price amounts, allergen tags, dietary badges, and high-resolution food images.
C. Payment & Subscription Billing Data

Subscription payments are handled securely through our payment provider, Stripe. Sosene records non-sensitive payment transaction metadata including transaction IDs, plan names, billing intervals, currency symbols, and expiration dates. Raw credit card numbers and CVV codes are processed directly by Stripe under strict PCI-DSS Level 1 compliance.

D. Guest & Visitor Usage Data

When customers scan a table QR code to view a digital menu:

  • Waiter Calls & Requests: Table numbers and service call timestamps (e.g. "Table 5 requests waiter").
  • Server Logs & Analytics: IP addresses, browser user-agent strings, device screen dimensions, and page request timestamps to optimize image rendering and server responsiveness.

2. How We Use Collected Data

We process your personal and business data strictly for legal and legitimate operational purposes:

Processing Purpose Categories of Data Used Legal Basis
Digital Menu Service Delivery Venue info, menu categories, dish items, prices Contract Performance
Subscription Billing & Access Control Email address, subscription ID, payment transaction log Contractual Requirement
Table Service & Order Request Relay Table number, waiter call status, timestamp Legitimate Interest
Platform Security & Fraud Prevention IP address, CSRF session tokens, login attempt logs Legal Obligation & Security

3. Technical Security & Encryption

Sosene prioritizes state-of-the-art security measures to safeguard all stored records and network communications:

256-Bit SSL/TLS Transport Encryption

All data transferred between your browser, QR guests, and our servers is encrypted in transit using SSL certificates.

PDO Prepared Statement Security

Database interactions utilize parameterized PDO queries to neutralize SQL injection vulnerabilities completely.

Salting & Password Hashing

Passwords are cryptographically hashed using PASSWORD_BCRYPT algorithms with one-way salting.

CSRF & Session Hijacking Guards

Form submissions require unique cryptographic CSRF tokens to block cross-site forgery attacks.

4. Third-Party Service Integrations

To deliver advanced capabilities, Sosene integrates with trusted third-party providers under strict data privacy obligations:

  • Stripe Payment Gateway: Handles credit card verification and subscription renewals. (Read Stripe Privacy Policy).
  • Google Translate API: Renders multi-language translations for global restaurant guests.
  • Google Fonts & FontAwesome CDN: Delivers optimized typography and UI icons.
No Data Selling Guarantee: Sosene strictly refrains from selling, leasing, or trading personal or restaurant data to ad networks or data brokers under any circumstances.

5. Data Retention & Deletion Rights

We retain your account information for as long as your subscription or user account remains active. Upon account termination or written request, all associated restaurant records, categories, dish images, and waiter call history will be permanently deleted from our primary databases within 30 days.

6. International Compliance (GDPR / KVKK / CCPA)

Under international privacy regulations (including General Data Protection Regulation GDPR and KVKK), users possess explicit data protection rights:

  • Right of Access: Request copies of your personal data records stored in our system.
  • Right to Rectification: Request correction of inaccurate account or business information.
  • Right to Erasure ("Right to be Forgotten"): Request complete erasure of your data under statutory conditions.
  • Right to Data Portability: Request export of your menu listings and restaurant configuration.

7. Cookies & Tracking Technologies

Sosene utilizes essential session cookies and preference cookies to maintain control panel login sessions and remember language choices. For complete details, please inspect our dedicated Cookie Policy.

8. Contact Information & Support

For privacy inquiries, data access requests, or regulatory questions, please contact our Data Protection Officer:

Sosene Data Privacy Officer

Email: info@sosene.com

Phone: +905306853691

Send Data Request
© 2026 Sosene Digital QR Menu Platform. All rights reserved. | Privacy Policy | Terms of Service | Cookie Policy