Privacy Policy

How TechVerdi SA collects, uses, and protects personal data across the Kappino restaurant management platform, in line with Swiss and EU data protection law.

Effective date: 29 June 2026
Last updated: 29 June 2026
Version: 1.0

Summary at a glance

  • Who we are: Kappino is a restaurant management platform operated by TechVerdi SA, based in Pully, Switzerland.
  • What we collect: account and contact details, the operational data you enter, technical and usage data, and limited payment metadata.
  • What we do not store: full card numbers and CVV codes — payments are handled by specialised payment providers.
  • Why: to provide and secure the Service, perform our contract with you, comply with the law, and improve the product.
  • Who we share with: vetted service providers under contract. We never sell your data.
  • Where it is stored: the core platform is hosted in Switzerland; some AI and integration features process data abroad with safeguards in place.
  • Your rights: access, correct, delete, export, restrict, object, withdraw consent, and complain to a regulator.
  • Contact: office@techverdi.ch
1

About this Policy

Kappino is a restaurant management platform owned and operated by TechVerdi SA. This Privacy Policy explains how TechVerdi SA collects, uses, discloses, stores, and protects personal data in connection with the Kappino platform — including the website at kappino.com, the web application at app.kappino.com, and our mobile applications.

We process personal data in accordance with the Swiss Federal Act on Data Protection of 25 September 2020, including the revised FADP, its implementing Ordinance on Data Protection, and, where applicable, the EU General Data Protection Regulation.

The Swiss supervisory authority is the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, Switzerland.

2

Definitions

To make this Policy easier to read:

  • Personal data — any information relating to an identified or identifiable natural person.
  • Processing — any operation performed on personal data, such as collecting, storing, using, disclosing, or deleting it.
  • Controller — the party that decides why and how personal data is processed.
  • Processor — a party that processes personal data on behalf of, and under the instructions of, a controller.
  • Business Client — a restaurant, café, chain, franchise, or other business that subscribes to and uses the Service.
  • End Customer — a diner or guest of a Business Client whose data is processed through the Service.
  • You — the individual whose personal data is processed, whether an account holder, staff member, End Customer, or website visitor.
3

Who is responsible

3.1 Controller details

TechVerdi SA
Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Email: office@techverdi.ch
VAT / UID: CHE-110-027.685

3.2 Controller vs. processor

Our role depends on the data in question. TechVerdi acts as the controller for website and account registration data, billing data, login and security data, support communications, and aggregate analytics about how the Service is used.

TechVerdi acts as a processor for the operational data a Business Client enters or generates within the platform about its own End Customers, staff, orders, and reservations. In that case, the Business Client is the controller and our processing is governed by a separate Data Processing Agreement.

3.3 Data Protection Contact

Data Protection Contact — TechVerdi SA
Email: office@techverdi.ch
Post: TechVerdi SA, Attn. Data Protection, Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland

4

Whose data we process and how we obtain it

We process personal data that:

  • you provide directly — when you register, configure your account, contact support, or enter data into the platform;
  • is generated automatically — log, device, and usage data created when you interact with the Service;
  • comes from a Business Client — where a restaurant enters or uploads data about its staff or End Customers; and
  • comes from third parties — for example, confirmation of payment status from a payment provider, or integrations you connect.
5

Categories of data we collect

5.1 Personal / account information

Data Examples / Notes
NameFull name of the account holder or user
Email addressLogin, notifications, billing
Phone numberContact and, where enabled, SMS notifications
Business nameThe legal / trading name of your business
Restaurant nameThe brand or venue name shown in the app
Billing addressInvoicing and tax purposes
CountryLocalisation, tax, and legal-compliance routing
LanguagePreferred interface language
User rolee.g. owner, manager, staff — determines access level

5.2 Account, login, and technical data

Data Examples / Notes
UsernameYour login identifier
PasswordStored only as a salted hash — never in plain text
Login historyTimestamps and outcomes of sign-in attempts
Device informationDevice type, model, operating system
BrowserBrowser type and version
IP addressSecurity, fraud prevention, and approximate location

5.3 Restaurant operational data

Data you create or upload while using the Service, which may include personal data of staff and End Customers: branches and locations; staff records; customer records; orders; reservations; tables and floor plans; inventory; sales reports and analytics; and menu items.

5.4 Payment data

  • We do not store full credit/debit card numbers or CVV / security codes.
  • Payments are securely processed by third-party payment providers responsible for handling card data.
  • We retain limited transaction metadata for billing, accounting, tax, dispute-handling, and fraud-prevention purposes.

5.5 Mobile device data

Permission Why it is used
GPS / locationDelivery routing and rider location for active deliveries
CameraScanning codes or capturing images / documents within the app
NotificationsOperational alerts such as orders, reservations, and status
BluetoothConnecting to receipt / kitchen printers and hardware
Internet / networkRequired to operate the Service

You can revoke any of these permissions in your device settings; some features may then be limited.

5.6 Rider location data

Where a Business Client uses delivery features, the rider mobile app periodically transmits the rider’s GPS coordinates to the platform. The tracking is real-time only — we store only the rider’s most recent location, not a continuous location history.

5.7 Uploaded documents

The Service includes a document-scanning feature. When you upload a document, such as an invoice or menu, it is processed using OCR and text parsing to extract structured data, after which the result is presented for human review and approval.

6

Why we process data

We process personal data to create and manage accounts; process orders and reservations; support payroll features; manage inventory; provide analytics and reporting; provide AI recommendations and forecasting; provide customer support; handle billing; maintain security; detect and prevent fraud and abuse; communicate with you; and comply with legal obligations.

8

Automated processing, AI, and profiling

Kappino uses artificial intelligence and statistical methods to provide features including AI copilot, administrative assistance, OCR document parsing, forecasting, recommendations, customer segmentation, and churn prediction.

Some AI features rely on third-party AI providers. Documents submitted to the OCR / AI Scanner may be processed by Google Cloud Vision and OpenAI for text extraction and parsing.

AI outputs are designed to support — not replace — business decisions. AI processing can be disabled for a specific Business Client on request, although some core platform features may be limited.

9

How we share data

We do not sell personal data. We share it only where necessary to operate the Service, with appropriate contractual and technical safeguards.

Recipient / Provider Purpose Location
Infomaniak SACloud hosting and infrastructureSwitzerland
OpenAIAI text parsing and copilot featuresUSA
Google Cloud VisionOptical character recognition for uploaded documentsUSA / global
Google Maps & Google APIsMapping, location, and delivery featuresUSA / global
Google FontsWeb fonts on our websiteUSA / global
Meta / Facebook APIs & SDKMessaging and marketing integrationsUSA / global
ShopifyE-commerce integrationOutside CH/EU
WordPress / WooCommerceWebsite and e-commerce integrationDepends on deployment
Payment providersSecurely process transactionsAs applicable
Professional advisers / auditorsLegal, accounting, and compliance supportSwitzerland / EU
AuthoritiesWhere required by law, court order, or valid legal processAs applicable
10

Cookies and consent

We use the following categories of cookies and similar technologies:

  • Essential cookies — necessary for authentication, security, session management, and load balancing.
  • Analytics cookies — help us understand how the Service is used so we can improve it. These are set only with consent.
  • Marketing cookies — used to deliver and measure relevant communications. These are set only with consent.

On your first visit, we present a cookie consent banner offering an “Accept” option and an “Essential-only” option. You can change or withdraw your choices at any time.

11

Where your data is stored and international transfers

The Service is hosted with a local Swiss hosting provider, Infomaniak SA, and the core platform infrastructure and database are physically located in Switzerland.

Some features rely on third-party providers that process data outside Switzerland and the EU/EEA, including OpenAI, Google, and Meta. These transfers are carried out in compliance with applicable Swiss and EU data protection law.

12

Your rights

Subject to the conditions and exceptions under the FADP and, where applicable, the GDPR, you have the right to access, rectify, erase, export, restrict, object, withdraw consent, and request human review in significant automated decisions.

To exercise your rights, contact our Data Protection Contact. We respond within the timeframes required by applicable law and may need to verify your identity.

13

Data retention

We keep personal data only as long as necessary for the purposes set out in this Policy or as required by law.

Data Retention period Basis
Customer account dataDeleted within 30 days after account deletionStorage limitation — subject to statutory exceptions
BackupsRetained for up to 90 days in the rolling backup cycleTechnical backup cycle
Uploaded documentsRetained until you delete themProvision of the scanning feature
Rider location dataOnly the most recent location is heldProvision of delivery features
Accounting and business records10 years from the end of the relevant financial yearArt. 958f Swiss Code of Obligations
VAT-relevant records10 years, up to 20 years for immovable property recordsSwiss VAT Act and Ordinance
Audit and access logsRetained as needed for security and fraud preventionOverriding interest
Marketing data based on consentUntil consent is withdrawn or you objectConsent — Art. 6(1)(a) GDPR
Data needed for legal claimsUntil limitation periods expire, generally up to 10 yearsOverriding interest / legal claims

How the 30-day rule interacts with statutory retention. When you delete your account, operational and profile data is deleted within 30 days. Where a specific record is subject to mandatory legal retention, we block or archive that record.

14

Children’s privacy

The Service is a business tool intended for professional users and is not directed at, marketed to, or intended for use by children.

We do not knowingly collect, process, or store personal data from children under the age of 16.

15

Security measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, disclosure, or alteration.

  • Encryption in transit via HTTPS/TLS, HSTS, and Content Security Policy.
  • Encryption of sensitive credentials and tokens at rest using AES-256-GCM.
  • Password hashing with bcrypt.
  • Token-based authentication, session management, and role-based access control.
  • Tenant isolation in our multi-tenant environment.
  • Daily backups and disaster-recovery planning.
  • Audit logging and selected system activity logs.
  • Vulnerability assessments, penetration testing, and internal security audits.
16

Data breaches

We maintain an incident-response procedure to detect, respond to, and mitigate security incidents and data breaches, including escalation workflows and post-incident reviews.

If a data security breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals.

18

Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated version with a revised “Last updated” date.

19

Contact us

Privacy Officer / Data Protection Contact
TechVerdi SA
Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Email: office@techverdi.ch

Privacy Officer / Data Protection Contact

TechVerdi SA
Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Email: office@techverdi.ch
VAT / UID: CHE-110-027.685