Privacy Policy
Last updated: 24 June 2026
This is a draft document provided for transparency. It is not legal advice and is pending professional review. Some details are still being finalised.
This policy explains what personal data Scango processes, why, and the choices you have. It covers both guests who place orders and the venues that run their menus on Scango.
1. Who we are
Scango is a QR-based food-ordering platform that lets guests scan a code, browse a venue's menu, and place an order from their phone, while giving venues a back office to manage menus, orders, and staff.
The data controller responsible for this platform is [TODO: legal entity name], registered at [TODO: registered address], company registration number [TODO: reg. no.]. For any privacy question you can reach us at [TODO: privacy contact email].
2. What data we collect
From guests placing an order, we process the contents of the order, an optional name or table number used to identify it, and any notification preference you choose. We do not require you to create an account to order.
From venue staff and owners, we process account details (name, email, hashed password) and the actions taken in the back office. We also record technical data such as request logs and approximate device information needed to operate and secure the service.
3. Legal basis for processing
Where the GDPR applies, we rely on the following legal bases (Article 6): performance of a contract, to take and fulfil your order and to provide the venue's account; our legitimate interests, to keep the service secure, prevent abuse, and improve it; and your consent, where we ask for it, such as enabling order-status notifications. You may withdraw consent at any time without affecting processing already carried out.
4. How we use your data
We use order data to pass your order to the venue, show you live status updates, and let the venue prepare and hand over what you ordered. We use account and usage data to operate the back office, calculate plan usage and billing, provide support, and keep the platform reliable and secure. We do not sell your personal data.
5. Who we share data with
We share order details with the venue you ordered from, as that is the point of the service. We use a small number of processors who act on our instructions: our hosting and database provider (Railway), and, once enabled, a payment provider to take card payments. Each processor only receives the data needed for its task. We may also disclose data where required by law.
6. How long we keep data
We keep order and account data for as long as needed to provide the service and to meet legal, accounting, and tax obligations, after which it is deleted or anonymised. Specific retention periods are being finalised [TODO: confirm retention schedule with counsel].
7. Your rights
Subject to applicable law, you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to certain processing, and to data portability. You also have the right to lodge a complaint with your local data-protection authority. To exercise any of these rights, contact us using the details below.
8. Cookies and similar technologies
We use a small number of strictly necessary cookies. These include a language-preference cookie that remembers your chosen locale and a session cookie that keeps venue staff signed in to the back office. We do not use advertising or cross-site tracking cookies.
9. Contact us
For any question about this policy or your personal data, email us at [TODO: privacy contact email] or write to [TODO: registered address]. See also our Contact page.