Privacy Policy
1. Who we are
GICATI (“we”, “us”, or “GICATI”) operates the Pay4 restaurant platform at gicatipos.com. We are based in Erbil, Iraq.
This Privacy Policy explains what personal data we collect from three groups: restaurant owners and their staff (our direct customers), restaurant guests (people who scan a QR code at a table), and website visitors (people browsing gicatipos.com or whatsoninerbil.com).
2. Data we collect
From restaurant owners & staff
- Business name, business address, business phone number
- Owner/manager name, personal phone number, email address
- Login email and hashed password (never stored in plain text)
- Waiter names, PINs (hashed), optional email + phone
- Employee names, salaries, contact details (if the account owner adds them)
- Menu content, floor layouts, sales records, cash-drawer records
From restaurant guests (QR ordering)
- Optional: name and phone number (only if the guest chooses to enter them at checkout)
- Order history: what was ordered, table number, timestamp, total
- Anonymous device data: IP address (used only for rate limiting and abuse prevention)
From website visitors
- Basic request logs (IP address, browser type, page visited) — kept for 30 days for security
- Demo requests submitted through /for-restaurants: business name, contact name, phone, city, message, and any UTM parameters that identify the marketing source
3. How we use this data
- To provide the service: take orders, sync tickets to the kitchen, process cash, generate sales reports.
- To communicate: respond to your demo request or support enquiries (usually via WhatsApp).
- To send marketing messages — only if you (or the restaurant guest) explicitly opted in. Every message includes an opt-out link.
- To secure the platform: detect abuse, rate-limit login attempts, comply with legal obligations.
- To improve GICATI: aggregate analytics (never at individual level for guests).
4. Who we share data with
We do not sell your data. We only share it with:
- Supabase (database, authentication) — hosted in the EU/US, industry-standard security.
- Vercel (application hosting) — the servers that run gicatipos.com.
- Cloudinary (image and video hosting) — for menu photos and event videos.
- WhatsApp Business API — only when you or a restaurant explicitly sends a marketing message.
- Law enforcement — only when legally required by valid Iraqi legal process.
The restaurant guest’s data (phone, order history) belongs to the restaurant they visited, not to GICATI. We store it on the restaurant’s behalf and act as a data processor. The restaurant is the data controller.
5. Cookies
We use only strictly necessary cookies for keeping you logged in and remembering your language preference. We do not use advertising or third-party tracking cookies. See /cookies for the full list.
6. How long we keep data
- Restaurant account data: as long as your account is active, plus 90 days after cancellation for compliance.
- Guest data (phone, order history): the restaurant chooses. They can delete individual customers or wipe their marketing list from their /admin.
- Server logs: 30 days.
- Financial records: 5 years (Iraqi tax law requirement — TEMPLATE, verify with a lawyer).
7. Your rights
You can request a copy of your data, correct it, or delete it by emailing hello@gicatipos.com. Restaurant guests should contact the restaurant directly. Restaurant owners can export or wipe their data from /admin.
8. Security
Passwords are hashed with bcrypt. All connections use HTTPS. Access to production data is limited to authorized GICATI staff, logged, and requires 2FA. Payment card details are never touched by our servers — payment integrations (when live) route through certified processors.
9. Contact
Questions? Email hello@gicatipos.com or WhatsApp us at [REPLACE WITH YOUR NUMBER].