Privacy Policy
Last updated: 6 October 2026
Who we are
OrderGate (https://ordergate.dev) is operated by Arsen Tsntsgoukian, Cyprus. Contact: hello@ordergate.dev.
Our role
OrderGate processes order data on behalf of the restaurants that use it. For customer data contained in orders, the restaurant is the data controller and OrderGate acts as a data processor under the EU General Data Protection Regulation (GDPR). For restaurant account data (such as staff logins), OrderGate is the controller.
What we process
- Order data received from delivery platforms (such as Wolt, Foody, efood and Bolt Food): order contents, prices, timing, and, where the platform provides it, the customer's name, phone number, delivery address and order notes.
- Restaurant data: venue details, menus, platform connection identifiers and access tokens, and staff account details.
- Technical data: server logs, IP addresses and device information, used for security and troubleshooting.
Why we process it
- To show orders to the restaurant and pass status updates back to the platform (performance of our contract with the restaurant).
- To keep the service secure and working (legitimate interest).
- To meet legal obligations, such as tax and accounting records.
We do not sell personal data or use customer data for advertising.
How long we keep it
Customer contact and address details are kept only as long as needed to fulfil the order and handle related issues, then deleted or anonymised. Order records without customer contact details may be kept longer for the restaurant's reporting and accounting. Account data is kept while the account is active.
Who we share it with
We share data only with the delivery platforms the restaurant has connected, a POS or ERP system the restaurant chooses to connect, and the infrastructure providers that host the service (hosting, database and email providers), under data processing agreements. Data is stored within the EU/EEA where possible. Where a provider is outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.
Security
Data is encrypted in transit. Platform access tokens are encrypted at rest. Access is limited to what is needed to run the service.
Your rights
You can ask for access to, correction of, or deletion of your personal data, or object to or restrict its processing. If you ordered through a delivery platform, the restaurant or the platform is usually the right first contact, and we will help them respond. You can also contact us at hello@ordergate.dev. You may complain to your data protection authority. In Cyprus, this is the Commissioner for Personal Data Protection.
Changes
We will update this page when our practices change and change the date above.