← Back to Scan55Privacy Policy
Last updated: 24 July 2026
1. Who We Are
Scan55 ("Scan55", "we", "us", "our") operates the Scan55 digital QR menu platform at scan55.com. Scan55 is a registered business in England and Wales.
For the purposes of UK GDPR:
- Scan55 is the Data Controller for data it collects about restaurant owners and operators who use the platform.
- Scan55 acts as Data Processor on behalf of restaurants (Data Controllers) for data collected about their customers (diners).
- The restaurant operator is the Data Controller for all customer/diner data collected through their QR menu pages.
Contact: support@scan55.com
2. Data We Collect
Restaurant owners: Name, email address, business name, payment information (processed by Stripe), usage data.
Diners (customers of restaurants): We collect the following only where applicable:
- Name (if voluntarily provided at the menu page)
- Device information (browser type, hashed device identifier) — only if consent is given
- Table number and visit timestamps — linked to your session only
- Order history — linked to your session for order tracking purposes
- Email address or phone number — only if you voluntarily provide it for order confirmations
- Marketing consent status — only if you explicitly opt in to marketing from the restaurant
We do NOT collect: Government IDs, payment card details, passwords, or sensitive personal data.
3. Legal Basis for Processing
We process personal data under the following legal bases (UK GDPR Article 6):
- Contract (Art. 6(1)(b)): Processing necessary to provide our service to restaurant operators.
- Consent (Art. 6(1)(a)): Device tracking and marketing communications — only with explicit opt-in.
- Legitimate Interests (Art. 6(1)(f)): Security, fraud prevention, service improvement.
For marketing communications sent by restaurants to diners: The legal basis is explicit consent (Art. 6(1)(a)), obtained separately via an opt-in checkbox on the menu page. This consent may be withdrawn at any time.
4. Marketing Communications
Scan55 provides restaurants with tools to send marketing offers to customers who have opted in.
Important:
- Marketing is sent by the restaurant, not by Scan55.
- The restaurant is the Data Controller and sole legal entity responsible for the content and lawfulness of all marketing messages sent through this platform.
- Scan55 acts solely as Data Processor providing the technical infrastructure.
- Opt-in is always explicit: customers must actively tick a checkbox. Pre-ticked boxes are never used.
- Every marketing message contains a mandatory unsubscribe link.
- Unsubscribes are processed immediately and permanently, and logged with timestamp for compliance.
- Scan55 is not responsible for, and is fully indemnified against, any claims arising from marketing messages sent by restaurants to their customers.
5. How We Share Data
We do not sell personal data. We share data only with:
- Supabase (database and authentication) — EU/UK hosting
- Stripe (payment processing) — PCI DSS compliant
- Resend (transactional email)
- Twilio (SMS/WhatsApp) — where configured by the restaurant operator
- Vonage (SMS) — where configured by the restaurant operator
Restaurant operators who configure SMS or WhatsApp providers do so under their own account and are solely responsible for compliance with those providers' terms and data processing requirements.
6. Data Retention
• Restaurant account data: Retained for the duration of the subscription plus 6 years (UK statutory requirement).
- Diner device data (consented): 24 months from last scan, then automatically deleted.
- Order data: 7 years (UK financial record-keeping requirement).
- Marketing consent records: Retained indefinitely as evidence of consent, including unsubscribe logs.
- Data subject requests processed within 30 days.
7. Your Rights (UK GDPR)
You have the right to:
- Access your personal data (Subject Access Request)
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time (without affecting lawfulness of prior processing)
For diners: Exercise your rights by contacting the restaurant directly (as Data Controller) or emailing support@scan55.com. For marketing unsubscribes, use the unsubscribe link in any marketing email or message.
For restaurant operators: Manage your data via the dashboard or email support@scan55.com.
8. Cookies
We use minimal cookies:
- Session cookies: Required for dashboard authentication. Cannot be disabled.
- Consent cookies (diner): Stored in browser localStorage to remember your consent preference per restaurant. No tracking cookies are set without your consent.
We do not use advertising cookies, third-party tracking pixels, or profiling cookies.
9. International Transfers
Data is stored on UK and EU-based servers. Any international transfers are made only with appropriate safeguards (Standard Contractual Clauses or UK International Data Transfer Agreements) in place.
10. Data Processor Agreements
Restaurants using Scan55 to process diner data do so under a Data Processing Agreement incorporated into the Scan55 Terms of Service. By using Scan55, restaurant operators confirm they are the Data Controller and accept responsibility for lawful processing of all diner data collected through their menu pages.
11. Complaints
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
We would appreciate the opportunity to address your concerns first: support@scan55.com
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify restaurant operators of material changes via email. The current version is always available at scan55.com/privacy.