Privacy Policy
Last updated: August 31, 2026
1. Who controls your data
The data controller is PMFOR, a sole proprietorship registered in Poland's CEIDG register, with its registered address at ul. Dębowa 11 lok. 10, 43-225 Wola, Poland, tax ID (NIP) 6381756205 ("we", "us"). For anything related to your personal data, contact contact@vuplate.com.
2. What this policy covers
This policy describes three separate places where we process data, each covered on its own below: the marketing site vuplate.com, which you're visiting and where you can submit the contact form; the restaurant panel at app.vuplate.com together with the iOS app, used by a restaurant owner or staff member; and the dish page that opens when a guest scans a QR code on the menu, used by a restaurant guest.
3. Data from vuplate.com visitors
The contact form on vuplate.com collects an email address (required), a phone number (required), message text (optional), and consent to marketing emails (optional, a separate checkbox). We process your email and phone number to respond to your inquiry and present an offer, on the basis of Art. 6(1)(b) GDPR, steps taken at your request prior to a possible contract. If you check the marketing consent box, we also send you emails about VuPlate on the basis of your consent, Art. 6(1)(a) GDPR, which you can withdraw at any time with one click in the footer of any email. The form is protected by rate limiting per IP address and a hidden field that catches bots. The legal basis for these mechanisms is our legitimate interest in protecting the site from abuse, Art. 6(1)(f) GDPR; they don't collect any extra data about you beyond what we see on every request to our server anyway.
4. Restaurant account data (app.vuplate.com and the iOS app)
A restaurant creating an account in the app.vuplate.com web panel provides: a restaurant name, contact person details (first and last name, phone number), a city, optionally a website address, an email address, and a password (stored hashed, never in plain text). When you accept the terms of service, we also record a hashed IP address, as proof of acceptance of the contract template, on the basis of our legitimate interest, Art. 6(1)(f) GDPR. In the panel, before the first paid plan purchase, the restaurant fills in the data needed to issue an invoice: the invoice name, tax ID (NIP) or EU VAT number, address, country, and optionally a separate invoice email address; the legal basis for this data is, alongside contract performance, also a tax obligation, Art. 6(1)(c) GDPR. The restaurant may also upload its own logo, shown on the branded QR code. The iOS app is not used to create an account or to make payments. Scanning a dish, building the 3D model on your phone, and browsing your saved scan library all work without signing in and without an account — the whole process happens locally on the phone (Apple's PhotogrammetrySession technology), and without signing in the app sends nothing to our servers, including no photos or models, and uses no external analytics libraries or external AI provider: the 3D reconstruction happens entirely on your device. Signing in is optional and only needed when you want to send a finished model to the restaurant panel: only then does the app connect to our server and upload 3D dish models in USDZ and GLB format along with dish photos to an account created earlier in the web panel; these materials show only the scanned product, the dish on the plate, and contain no personal data. Subscription billing is handled by Stripe in the web panel; we don't store payment card numbers on our own servers. The legal basis for processing the remaining account and model data is performance of the contract for the VuPlate service, Art. 6(1)(b) GDPR.
If you use VuPlate, we publish the fact that we work together: your restaurant's name, logo, and city on vuplate.com and in our marketing materials, and we tag your restaurant's profiles in VuPlate social media posts. We never publish the commercial terms of our agreement, your plan, your price, or any billing data. To the extent such a publication involves personal data (for example, where the restaurant's registered business name contains the owner's first and last name), the legal basis is our legitimate interest in promoting the service and building market credibility, Art. 6(1)(f) GDPR. You can object at any time by writing to contact@vuplate.com; we then stop publishing new material and remove you from the client list on our site within 30 days. The detailed rules are set out in section 8 of the VuPlate Terms of Service.
5. Data from guests scanning a QR code
When a restaurant guest scans a QR code next to a dish and views the 3D model, we record three things: the platform type (iOS, Android, or other), the full User-Agent header sent by the browser, and a hashed IP address. That last item is an irreversible cryptographic digest (SHA-256), not a raw IP address, but it isn't anonymous data under GDPR: the salt key used for hashing stays in our possession, so we could technically match it back to a specific IP address. We therefore treat it as pseudonymous data, not anonymous data, and give it the same protection as any other personal data. We collect it only for dish popularity statistics, on the basis of our legitimate interest in improving the service, Art. 6(1)(f) GDPR. Guests don't create an account and don't submit any data directly; the dish page also stores nothing in the guest's browser, see section 7.
6. Site visit statistics (Umami)
We measure traffic on vuplate.com with Umami, which we run on our own server; it's not a third-party analytics service like Google Analytics. Umami sets no cookies and doesn't use browser storage (localStorage, sessionStorage); each measurement is a standalone event, not linked to a given visitor's previous visits. We collect: the page visited, the referring page, a country (derived from the IP address, which we don't store in plain form), browser and operating system type, and screen resolution. None of this makes it possible to identify a specific person. The legal basis is our legitimate interest in understanding where traffic comes from and which content works, Art. 6(1)(f) GDPR. You can turn this off at any time with one click, see the notice bar at the bottom of the page or the "Privacy settings" link in the footer.
7. Cookies and browser storage
vuplate.com sets no cookies at all. The only thing we store in browser storage (localStorage) is a single key holding your choice from the statistics notice bar, in other words whether you've dismissed it and which option you picked. That entry is strictly necessary for the bar itself to work (so it doesn't reappear on every visit) and needs no consent. The dish page opened after scanning a QR code (URLs shaped like /m/[id]) stores absolutely nothing in the guest's browser, no cookie, no localStorage. The app.vuplate.com panel uses one strictly necessary session cookie to keep you logged in; without it the panel wouldn't work, so it likewise needs no separate consent.
8. Who we share data with
We use subprocessors that handle data on our behalf: Railway (application and database hosting, EU region), Stripe (payment and subscription processing), ING Usługi dla Biznesu S.A. / ING Księgowość (invoice issuance and archiving), LH.pl Sp. z o.o. (hosting for the mailbox we send the invoice PDF from), Cloudflare (CDN and DNS for the site), Apple (iOS app distribution through the App Store). We host the model-viewer library that renders 3D models in the guest's browser ourselves (since August 12, 2026) — it no longer loads from an external CDN. Once issued, invoices are also sent to the National e-Invoice System (KSeF), run by Poland's Head of the National Revenue Administration — this is a statutory recipient, not our subprocessor, and the transfer follows directly from Polish VAT law, Art. 6(1)(c) GDPR. Telegram is also on this list, covered separately in section 9 because it involves a transfer of data outside the European Economic Area. We don't sell or share your data with any third party for marketing purposes.
9. International data transfers
Railway stores our main database in the EU region, so that data never leaves the European Economic Area. Stripe, Cloudflare, and Apple are based in the United States; we rely on EU standard contractual clauses or on those companies' participation in the EU-U.S. Data Privacy Framework, depending on what each provider uses at a given time.
Telegram (Telegram FZ LLC, United Arab Emirates): we use Telegram for internal operational notifications to the business owner, for example about a new restaurant registration or invoicing events — these may include a limited amount of data (e.g. the restaurant name, contact details, or invoice buyer data). Contact form submissions are NOT sent to Telegram (changed August 12, 2026) — a new submission is only visible in the admin panel. The United Arab Emirates does not have a European Commission adequacy decision. For questions about these notifications, email contact@vuplate.com.
10. How long we keep data
Retention periods depend on the type of data:
- form submissions that didn't lead to a working relationship: 12 months from the last contact, then permanently deleted;
- the email address of someone with an active marketing consent: until that consent is withdrawn;
- restaurant account data and 3D dish models: for the subscription duration plus 30 days after cancellation, as described in section 11, then permanently deleted;
- invoices and accounting records: 5 years, as required by Polish accounting law (an invoice is additionally retained in KSeF for the period required by law, independent of us);
- QR scan statistics (platform, User-Agent, hashed IP): 12 months from when they were recorded.
11. What happens when a subscription ends
When a restaurant's subscription stops being active (cancellation, a failed payment, or a trial ending without moving to a paid plan), the dish page shown to guests stops displaying the 3D model and shows the message "This dish is temporarily unavailable. Check back soon." The QR code printed on the menu itself never changes, so nothing needs reprinting, resuming the subscription is enough. During that time the restaurant panel is restricted to the billing and reactivation section, the rest of its features are locked. For 30 days after the subscription ends, resuming it restores everything exactly as it was, with no rescanning of dishes and no reprinting of the menu. After 30 days we permanently delete the account data, 3D models, and dish photos. Before deletion you can request an export of your 3D model files in USDZ and GLB format by writing to contact@vuplate.com.
12. Your rights
Under GDPR, you have the right to:
- access your data and get a copy of it,
- have inaccurate data corrected,
- request erasure ("right to be forgotten"),
- restrict processing,
- data portability,
- object to processing based on our legitimate interest,
- withdraw marketing consent at any time, without affecting the lawfulness of processing before withdrawal,
- lodge a complaint with the Polish data protection authority (UODO), ul. Stawki 2, 00-193 Warszawa, Poland, if you believe we're processing your data unlawfully.
To exercise any of these rights, write to contact@vuplate.com.
13. Children, automated decisions, and security
VuPlate isn't directed at children and we don't knowingly collect data from anyone under 16. We don't make any automated decisions about you with legal effects, and we don't build profiles from your data. All traffic between your browser and our servers is encrypted over HTTPS. Account passwords are stored only in hashed form using bcrypt, and access tokens (for example, for logging into the iOS app) are stored hashed with SHA-256; we never store the plain-text value in either case.
14. Changes to this policy
If we make a material change to this policy, we'll update the date at the top of this page. The current version is always available at vuplate.com/en/privacy-policy.
15. Contact
For anything about this policy or your data, write to contact@vuplate.com.