Privacy Policy
Effective date: 2026-08-12
1. Who we are and when this applies
EXCUSEME DOO, Stanoja Bunuševca 73, Niš, Serbia, company number 22310968, PIB 115748813 (ExcuseMe) operates the Service. Privacy contact: privacy@excuseme.pro.
This notice covers visitors, Venue staff and guests using ExcuseMe. A Venue remains responsible for information it collects outside the Service.
2. Our roles
ExcuseMe is a controller for its website, Venue/admin accounts, subscription billing, support, security and fraud prevention, legal acceptance records, and service administration.
For guest orders, venue-directed AI conversations and loyalty records, the Venue determines the purpose and is normally the controller; ExcuseMe is its processor under the DPA. ExcuseMe may separately act as controller for narrowly defined platform-security records and its own legal obligations. Guests may exercise rights through either the Venue or privacy@excuseme.pro; we will route a request to the correct controller.
3. Information we process
- Venue/admin data: name, email, authentication identifier, role, venue/location assignments, account actions, billing status and support communications.
- Prospect menu-preview data: venue name, a menu file or public menu-page content supplied before signup, the extracted draft and corrections, broad campaign/referrer attribution, and a keyed one-way network identifier used for abuse limits. Raw network addresses are not stored on the preview record.
- Guest/order data: ordered items, modifiers, price, payment/fulfilment choice, table/zone, notes, timestamps, order status and an optional signed-in customer link.
- Loyalty data after explicit opt-in: account identifier, name/email returned by Google, venue-scoped promotional points total, spend/transaction history, consent version/hash, language, time, IP and user-agent. Withdrawal stops future earning and redemption.
- QR security data: a random first-party fraud identifier and, only when the device grants permission, latitude/longitude at QR/NFC session creation, distance and fraud result. Raw coordinates are kept in the QR session and are not copied to the order.
- AI data: typed messages, relevant menu/order context, model output and tool calls. Voice audio is streamed to the active voice provider; ExcuseMe does not store raw audio. Text transcripts may be stored as chat messages.
- Technical data: IP, user-agent, request/security logs, cookies, session identifiers, approximate timestamps and diagnostic data.
- Legal evidence: exact document version/hash and language, acceptance or acknowledgement action, account, time, IP and user-agent.
We do not collect payment-card numbers. Venue subscriptions are invoiced by us and settled by bank transfer, so card data never reaches the Service. We do not sell personal data or use it for third-party behavioural advertising.
4. Purposes and legal bases
Where ExcuseMe is controller, we use data to:
| Purpose | Main basis |
|---|---|
| Create and operate Venue/admin accounts and supply paid features | contract / steps requested before contract |
| Create a requested private menu preview before signup and prevent automated abuse | steps requested before contract and legitimate interests in service security and cost control |
| Bill, invoice and keep mandatory business records | contract and legal obligation |
| Secure accounts, prevent order abuse and diagnose failures | legitimate interests in a safe, reliable service |
| Record contractual acceptance and privacy acknowledgement | contract and legal obligation / legitimate interests in evidence |
| Respond to support and rights requests | contract, legal obligation and legitimate interests |
| Send essential service messages | contract and legitimate interests |
The Venue selects its basis for guest ordering and instructs ExcuseMe as processor. The product requires consent before creating or using venue loyalty history. Consent can be withdrawn without affecting earlier lawful processing. A Venue may also have mandatory fiscal/transaction retention duties after withdrawal.
We do not make decisions with legal or similarly significant effects solely from AI. Fraud signals may pause or flag an order; staff can review or take the order in person.
5. Sharing and providers
We disclose data to authorised Venue staff; vendors needed to run the Service; professional advisers; authorities where law requires; and a successor in a properly protected corporate transaction. Vendors are limited by contract and access controls. Current providers and purposes are in the Subprocessor List.
6. International transfers
Our main database is configured in the EEA, but hosting edge services and AI, identity, email or support providers may process data outside Serbia, the EEA or UK. Where required for such a transfer, we rely on an adequacy decision or the EU Standard Contractual Clauses with the UK transfer addendum/IDTA, together with supplementary technical and organisational safeguards.
7. Retention
We keep data only as long as needed, then delete or anonymise it, subject to holds and mandatory law.
| Data | Normal period |
|---|---|
| Chat sessions, messages and voice transcripts (conversation content) | 30 days |
| Voice session telemetry (session metadata — timing and minutes metered, not transcript content) | 90 days |
| AI call metering metadata (usage events used for billing) | about 3 months |
| Admin audit log (staff actions on the venue's admin) | 12 months active; archived up to 10 years for fiscal/legal purposes |
| QR raw coordinates, distance, fraud result and random fraud identifier | 90 days |
| Browser fraud cookie | fixed 90 days; not refreshed when read |
| Authentication cookies | up to 30 days, rolling while used |
| Unclaimed menu-preview source and full extracted draft | up to 24 hours |
| Claimed menu-preview source | deleted after import processing; claimed full draft cleared after 7 days |
| Content-free menu-preview conversion, cost and campaign metrics | the documented product-analytics period, normally up to 12 months |
| Server/application logs | normally 30 days, unless a security incident requires a limited hold |
| Loyalty consent and current promotional points total | while enrolled; withdrawal recorded until deletion/limitation needs end |
| Orders and transaction ledgers | for the Venue's fiscal/legal period; may be up to 10 years, then deleted/anonymised |
| B2B agreement and billing evidence | contract term plus applicable limitation, accounting and tax periods |
| Backups | overwritten on the documented backup cycle; isolated copies are not restored for ordinary use |
Orders do not retain raw GPS coordinates; the derived distance and fraud result copied onto an order for abuse-prevention follow that order's retention period above, not the 90-day QR-session window. A legal hold may temporarily override deletion for the affected records only.
8. Security
Measures include separation of each venue's data, role-based access, encryption in transit, managed encryption at rest, service-key separation, audit trails, backups, rate limits, validation and incident procedures. No system is risk-free. Report suspected incidents to security@excuseme.pro.
9. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection, and information about processing; withdraw consent; and complain to a supervisory authority. You may leave a Venue loyalty programme in the account panel. You may refuse location permission; the Venue must provide a practical staff ordering option if online fraud controls cannot complete.
Send requests to privacy@excuseme.pro and identify the account/Venue. We may verify identity and will respond within the legally required period. Some transaction records may be retained in anonymised or legally required form.
Serbian users may complain to the Commissioner for Information of Public Importance and Personal Data Protection. EEA and UK individuals may complain to their local authority or the ICO as applicable.
10. Representatives and DPO
Where ExcuseMe offers the Service to, or monitors, individuals in the EEA or the UK and a representative under GDPR Article 27 is required, ExcuseMe appoints one and publishes its identity and contact details here. Such a representative is a contact point under Article 27 and is not automatically ExcuseMe's Data Protection Officer or its Digital Services Act representative.
privacy@excuseme.pro is ExcuseMe's privacy contact. Where a Data Protection Officer is legally required, ExcuseMe designates one and publishes and notifies the appointment as required; the privacy contact above is not a DPO unless one is formally designated.
11. Children and regulated products
Admin accounts are for adults acting for businesses. The Service is not directed to children. Venues remain responsible for age checks and lawful sale of alcohol or other restricted products; the platform is not an age-verification service. Contact us to remove data submitted by a child without valid authority.
12. Cookies, language and changes
See the Cookie Policy. Legal documents are provided in English; the ordering interface and menus may be shown in other languages provided by the Venue or the Service.
We will post material changes with a new effective date and request renewed acceptance/acknowledgement where appropriate. Previous versions are available from privacy@excuseme.pro.