About this Policy
Kappino is a restaurant management platform owned and operated by TechVerdi SA. This Privacy Policy explains how TechVerdi SA collects, uses, discloses, stores, and protects personal data in connection with the Kappino platform — including the website at kappino.com, the web application at app.kappino.com, and our mobile applications.
We process personal data in accordance with the Swiss Federal Act on Data Protection of 25 September 2020, including the revised FADP, its implementing Ordinance on Data Protection, and, where applicable, the EU General Data Protection Regulation.
The Swiss supervisory authority is the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, Switzerland.
Definitions
To make this Policy easier to read:
- Personal data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data, such as collecting, storing, using, disclosing, or deleting it.
- Controller — the party that decides why and how personal data is processed.
- Processor — a party that processes personal data on behalf of, and under the instructions of, a controller.
- Business Client — a restaurant, café, chain, franchise, or other business that subscribes to and uses the Service.
- End Customer — a diner or guest of a Business Client whose data is processed through the Service.
- You — the individual whose personal data is processed, whether an account holder, staff member, End Customer, or website visitor.
Who is responsible
3.1 Controller details
TechVerdi SA
Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Email: office@techverdi.ch
VAT / UID: CHE-110-027.685
3.2 Controller vs. processor
Our role depends on the data in question. TechVerdi acts as the controller for website and account registration data, billing data, login and security data, support communications, and aggregate analytics about how the Service is used.
TechVerdi acts as a processor for the operational data a Business Client enters or generates within the platform about its own End Customers, staff, orders, and reservations. In that case, the Business Client is the controller and our processing is governed by a separate Data Processing Agreement.
3.3 Data Protection Contact
Data Protection Contact — TechVerdi SA
Email: office@techverdi.ch
Post: TechVerdi SA, Attn. Data Protection, Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Whose data we process and how we obtain it
We process personal data that:
- you provide directly — when you register, configure your account, contact support, or enter data into the platform;
- is generated automatically — log, device, and usage data created when you interact with the Service;
- comes from a Business Client — where a restaurant enters or uploads data about its staff or End Customers; and
- comes from third parties — for example, confirmation of payment status from a payment provider, or integrations you connect.
Categories of data we collect
5.1 Personal / account information
| Data | Examples / Notes |
|---|---|
| Name | Full name of the account holder or user |
| Email address | Login, notifications, billing |
| Phone number | Contact and, where enabled, SMS notifications |
| Business name | The legal / trading name of your business |
| Restaurant name | The brand or venue name shown in the app |
| Billing address | Invoicing and tax purposes |
| Country | Localisation, tax, and legal-compliance routing |
| Language | Preferred interface language |
| User role | e.g. owner, manager, staff — determines access level |
5.2 Account, login, and technical data
| Data | Examples / Notes |
|---|---|
| Username | Your login identifier |
| Password | Stored only as a salted hash — never in plain text |
| Login history | Timestamps and outcomes of sign-in attempts |
| Device information | Device type, model, operating system |
| Browser | Browser type and version |
| IP address | Security, fraud prevention, and approximate location |
5.3 Restaurant operational data
Data you create or upload while using the Service, which may include personal data of staff and End Customers: branches and locations; staff records; customer records; orders; reservations; tables and floor plans; inventory; sales reports and analytics; and menu items.
5.4 Payment data
- We do not store full credit/debit card numbers or CVV / security codes.
- Payments are securely processed by third-party payment providers responsible for handling card data.
- We retain limited transaction metadata for billing, accounting, tax, dispute-handling, and fraud-prevention purposes.
5.5 Mobile device data
| Permission | Why it is used |
|---|---|
| GPS / location | Delivery routing and rider location for active deliveries |
| Camera | Scanning codes or capturing images / documents within the app |
| Notifications | Operational alerts such as orders, reservations, and status |
| Bluetooth | Connecting to receipt / kitchen printers and hardware |
| Internet / network | Required to operate the Service |
You can revoke any of these permissions in your device settings; some features may then be limited.
5.6 Rider location data
Where a Business Client uses delivery features, the rider mobile app periodically transmits the rider’s GPS coordinates to the platform. The tracking is real-time only — we store only the rider’s most recent location, not a continuous location history.
5.7 Uploaded documents
The Service includes a document-scanning feature. When you upload a document, such as an invoice or menu, it is processed using OCR and text parsing to extract structured data, after which the result is presented for human review and approval.
Why we process data
We process personal data to create and manage accounts; process orders and reservations; support payroll features; manage inventory; provide analytics and reporting; provide AI recommendations and forecasting; provide customer support; handle billing; maintain security; detect and prevent fraud and abuse; communicate with you; and comply with legal obligations.
Legal basis for processing
7.1 Under Swiss law
As a Swiss controller, we process personal data in line with the FADP’s core principles. Where a justification is required, we rely on consent, overriding private or public interest, performance of contract, security of the Service, fraud prevention, legal claims, or a basis provided by law.
7.2 Under the GDPR
| Purpose | GDPR legal basis |
|---|---|
| Account creation and provision of the Service | Contract — Art. 6(1)(b) |
| Order processing, inventory, reporting | Contract — Art. 6(1)(b) |
| Billing, accounting, tax records | Legal obligation — Art. 6(1)(c); Contract — Art. 6(1)(b) |
| Security, fraud prevention, product improvement | Legitimate interests — Art. 6(1)(f) |
| AI recommendations and forecasting | Legitimate interests — Art. 6(1)(f); Contract — Art. 6(1)(b) |
| Non-essential cookies, marketing communications | Consent — Art. 6(1)(a) |
| Responding to legal requests | Legal obligation — Art. 6(1)(c) |
Automated processing, AI, and profiling
Kappino uses artificial intelligence and statistical methods to provide features including AI copilot, administrative assistance, OCR document parsing, forecasting, recommendations, customer segmentation, and churn prediction.
Some AI features rely on third-party AI providers. Documents submitted to the OCR / AI Scanner may be processed by Google Cloud Vision and OpenAI for text extraction and parsing.
AI outputs are designed to support — not replace — business decisions. AI processing can be disabled for a specific Business Client on request, although some core platform features may be limited.
How we share data
We do not sell personal data. We share it only where necessary to operate the Service, with appropriate contractual and technical safeguards.
| Recipient / Provider | Purpose | Location |
|---|---|---|
| Infomaniak SA | Cloud hosting and infrastructure | Switzerland |
| OpenAI | AI text parsing and copilot features | USA |
| Google Cloud Vision | Optical character recognition for uploaded documents | USA / global |
| Google Maps & Google APIs | Mapping, location, and delivery features | USA / global |
| Google Fonts | Web fonts on our website | USA / global |
| Meta / Facebook APIs & SDK | Messaging and marketing integrations | USA / global |
| Shopify | E-commerce integration | Outside CH/EU |
| WordPress / WooCommerce | Website and e-commerce integration | Depends on deployment |
| Payment providers | Securely process transactions | As applicable |
| Professional advisers / auditors | Legal, accounting, and compliance support | Switzerland / EU |
| Authorities | Where required by law, court order, or valid legal process | As applicable |
Cookies and consent
We use the following categories of cookies and similar technologies:
- Essential cookies — necessary for authentication, security, session management, and load balancing.
- Analytics cookies — help us understand how the Service is used so we can improve it. These are set only with consent.
- Marketing cookies — used to deliver and measure relevant communications. These are set only with consent.
On your first visit, we present a cookie consent banner offering an “Accept” option and an “Essential-only” option. You can change or withdraw your choices at any time.
Where your data is stored and international transfers
The Service is hosted with a local Swiss hosting provider, Infomaniak SA, and the core platform infrastructure and database are physically located in Switzerland.
Some features rely on third-party providers that process data outside Switzerland and the EU/EEA, including OpenAI, Google, and Meta. These transfers are carried out in compliance with applicable Swiss and EU data protection law.
Your rights
Subject to the conditions and exceptions under the FADP and, where applicable, the GDPR, you have the right to access, rectify, erase, export, restrict, object, withdraw consent, and request human review in significant automated decisions.
To exercise your rights, contact our Data Protection Contact. We respond within the timeframes required by applicable law and may need to verify your identity.
Data retention
We keep personal data only as long as necessary for the purposes set out in this Policy or as required by law.
| Data | Retention period | Basis |
|---|---|---|
| Customer account data | Deleted within 30 days after account deletion | Storage limitation — subject to statutory exceptions |
| Backups | Retained for up to 90 days in the rolling backup cycle | Technical backup cycle |
| Uploaded documents | Retained until you delete them | Provision of the scanning feature |
| Rider location data | Only the most recent location is held | Provision of delivery features |
| Accounting and business records | 10 years from the end of the relevant financial year | Art. 958f Swiss Code of Obligations |
| VAT-relevant records | 10 years, up to 20 years for immovable property records | Swiss VAT Act and Ordinance |
| Audit and access logs | Retained as needed for security and fraud prevention | Overriding interest |
| Marketing data based on consent | Until consent is withdrawn or you object | Consent — Art. 6(1)(a) GDPR |
| Data needed for legal claims | Until limitation periods expire, generally up to 10 years | Overriding interest / legal claims |
How the 30-day rule interacts with statutory retention. When you delete your account, operational and profile data is deleted within 30 days. Where a specific record is subject to mandatory legal retention, we block or archive that record.
Children’s privacy
The Service is a business tool intended for professional users and is not directed at, marketed to, or intended for use by children.
We do not knowingly collect, process, or store personal data from children under the age of 16.
Security measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, disclosure, or alteration.
- Encryption in transit via HTTPS/TLS, HSTS, and Content Security Policy.
- Encryption of sensitive credentials and tokens at rest using AES-256-GCM.
- Password hashing with bcrypt.
- Token-based authentication, session management, and role-based access control.
- Tenant isolation in our multi-tenant environment.
- Daily backups and disaster-recovery planning.
- Audit logging and selected system activity logs.
- Vulnerability assessments, penetration testing, and internal security audits.
Data breaches
We maintain an incident-response procedure to detect, respond to, and mitigate security incidents and data breaches, including escalation workflows and post-incident reviews.
If a data security breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals.
Third-party links and services
The Service may link to or integrate with third-party websites and services. This Policy does not cover those third parties, and we are not responsible for their privacy practices.
Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated version with a revised “Last updated” date.
Contact us
Privacy Officer / Data Protection Contact
TechVerdi SA
Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Email: office@techverdi.ch