Last updated: 25 September 2026. This policy explains what the DishDraw app and
website (“DishDraw”, “we”) process and why. Controller: Antiochia Software, owner Ibrahim
Gazaloglu, Prenzlauer Promenade 9, 13086 Berlin (see Impressum),
contact legal@dishdraw.de.
What we process
Location (approximate & precise) — when you use “near me”, to find
restaurants around you; when you order at a table, to confirm you are at the
restaurant (we keep only how far away you were, never where you were); and when you
apply for a job whose advert only accepts people living in certain countries, to
confirm which country your phone is in (we keep only the country — see
DishDraw Jobs). The app asks before it first uses your location,
and says so again before a job application checks it. Processed on request; your
position is not stored.
Camera / photos / video — when you scan a menu page, or submit a photo or a
short video of a dish. Submitted media is stored and, once approved by us, shown
publicly.
Contributor name — if you add it when submitting content.
Reservations: name & phone number — when you request a table, so the
restaurant can reach you about your booking. Visible to that restaurant only;
deleted automatically no later than 30 days after the reservation date. If you
book through a restaurant's own website (the booking form we host for it) you
may also give an email address, used only to send you the confirmation
and a link to view or cancel that booking; it is stored with the booking and
deleted with it.
Pickup orders: name & phone number — when you order ahead for
collection, so the restaurant can reach you about your order (for example if a
dish has run out). Visible to that restaurant only; deleted automatically no
later than 30 days after the order. We take no payment for pickup orders — you
pay the restaurant directly at the counter, so we never see payment details.
Email address — for restaurant owners signing in to the owner portal
(the login code is sent to it), for people who sign in to DishDraw Jobs and for
staffing companies with a recruiter account (see DishDraw
Jobs), for listing requests you send us, and when you start a live demo of the
restaurant tools (your email becomes your demo sign-in, and we may contact you once
about listing your restaurant).
Device identifier & IP address — to prevent automated scraping/abuse
and to keep the service available (security; rate-limiting).
Push token — only if you enable notifications: a device token so we can
tell you when your table order, pickup order or reservation is confirmed. You
can disable
notifications in the app at any time, which deletes the token.
Crash diagnostics — if the app crashes, it sends us a report so we can fix
it: what went wrong and where in our code, your device model, its operating
system version, the language you had set, and how much memory and storage were
free at that moment. No menu content, no location, no name, email or phone
number, and nothing that identifies you. It carries an identifier generated by
the crash reporter itself, which is not connected to your DishDraw device
identifier or to any account.
Restaurant & menu data — factual business information compiled from
public sources and community contributions.
Website usage statistics — on this website only (not in the app),
we count visits with Umami, a privacy-friendly analytics tool we host on
our own server. It sets no cookies and stores nothing on your device.
Per page view it records the page address, the referring site, and your browser,
operating system, device type, screen size and country. Your IP address is used
only to derive the country and to generate a daily-changing, non-reversible
identifier for counting unique visitors — it is not stored, and the
identifier cannot be linked to you or traced across days or websites. The pages
used to open a table or accept a staff invite are excluded from counting
entirely. We also record when the App Store / Google Play buttons are clicked,
together with which store and which page — no other data is attached to this
event.
DishDraw Jobs
Restaurants and approved staffing companies (“hirers”) advertise work in the app, and
people looking for work can keep a profile and apply. Browsing job adverts needs no
account.
Your job account — your email address, to which we send a one-time sign-in
code. No password.
Your profile — the name hirers see, your full name, phone number, the city
you live in (and the country it is in), the roles you do, your languages, years of
experience, a few words about yourself, the days you are free, optionally a link
to your CV, and optionally your work history: for each job, the role, the
workplace, its city if you give one, the months you started and finished (or that
you still work there), and a note on what you did if you add one. A profile is shown
to hirers only while you have switched it to visible, and to staffing agencies only
if you separately allowed that.
What a hirer sees, and when — your display name, roles, languages,
experience, city, free days and the words about yourself, and for each job in your
work history the role and how long you did it. This is also what hirers see when
they browse profiles. Your full name, phone number and CV link, and the
workplace, city, dates and note of each job, reach a hirer only after you
accept their request to share your contact; nothing else — not an application, not
a message — releases them.
Your public profile link — if you choose, you can create a link to a page
with your profile that anyone who has the link can open, without an account.
The page shows your display name (never your full name), roles, city, years of
experience, languages, the words about yourself, your free days, your full work
history including workplaces, and your CV link. Your phone number appears on
it only if you switch that on. We tell search engines not to list the page. This is
separate from making your profile visible to hirers: the page works for as long as
you share the link. When you stop sharing, the link stops working at once,
for everyone who has it; sharing again creates a new link at a different address,
and the old one never works again. The link also stops working if your account is
deleted or we suspend your profile after a review.
Applying — the advert you answer, your optional message, and when you applied
go to that hirer.
Location check for some adverts — a hirer may accept applicants only from
certain countries (for example “living in the EU, the EEA or Switzerland”). For such
an advert the app reads your phone's position when you tap “I'm interested”,
so that you are told at once if the advert cannot take your application, and
again when you send it — each time after telling you it will. Our server works
out which country that position is in using a map stored on our own server — the
position is not sent to any other service — and then discards it. The first check
keeps nothing at all; with an application we keep only the country and the time
of the check, and show that country to the hirer. If you
do not allow location, the application cannot be sent; everything else in the app
works without it. This check is about where you are, never about your
nationality, which we do not ask for.
Safety — hirers can report a profile, and we review reports. To limit fake
accounts we note which install created an account and compare phone numbers
between accounts; a match is only a flag for our review.
Notifications — if you allow them, we tell you when a hirer wants to contact
you (see push tokens above), and we email you about it.
Recruiter accounts — a staffing company signing up on
jobs.dishdraw.de gives us its company name, a contact person, a work
email, its website and the country it hires in. We review each account before it
can see anyone.
How long we keep it. A profile nobody has opened for 45 days is taken off the
board until you open the app again. Thirty days after a request or application is
settled (answered, declined or expired) we delete the message on it and the country
from any location check; the record that it happened remains. When your job account is
deleted, your full name, phone number, CV link, the words about yourself, your free
days and your work history are removed at once, any public profile link stops working
at once, your profile leaves the board, and the account with all its requests and
applications is deleted 30 days later (so an accidental deletion can be undone by
signing in again). An account unused for a year is deleted the same way.
Recruiter accounts are deleted on request, and 30 days after that nothing of them
remains.
Legal bases (GDPR Art. 6)
Consent (Art. 6(1)(a)) for camera/location access and push notifications, for
making your job profile visible to hirers (and separately to staffing agencies), for
sharing your contact details with a hirer, and for a public profile link you create
(and the phone number on it, if you switch that on); performance of a contract /
pre-contractual steps (Art. 6(1)(b)) for table reservations and for your job account
and applications, including the location check an advert asks for; legitimate
interests (Art. 6(1)(f)) for security/abuse-prevention, reviewing reported profiles,
operating a menu directory, diagnosing crashes so the app keeps working, and
measuring website traffic in aggregate. We rely on
legitimate interests for the website statistics rather than asking for consent
because the tool stores no information on your device and produces no personal
profile; you can object at any time using the contact address below.
Sharing
We do not sell your data and show no ads. Hosting is provided by our server
provider (in the EU). Approved restaurant/menu content is shown publicly. Sign-in codes
and notification emails are sent through our email delivery provider. What a hirer
sees of a job profile or application is described under
DishDraw Jobs; a hirer is the restaurant or staffing company you
apply to or that asks you, and is responsible for what it does with your details once
you have shared them. A public profile link you create lets anyone who has the link
open your profile page, until you stop sharing it.
The app also calls the following third-party services directly from your device, so
they receive your IP address and — where noted — the coordinates or place name you are
searching for. We use them only to turn places into coordinates and to draw maps and
routes; none of them receive your submitted content:
OpenStreetMap (map tiles, tile.openstreetmap.org) and
Nominatim / Overpass (address and venue lookup) — receive the map area
or search area you are looking at.
Photon (komoot, photon.komoot.io) — receives the place text you
type when searching for an address or a venue.
OSRM (router.project-osrm.org) — receives the start and
destination when you ask for restaurants along a route.
On this website, the coverage map on the home page and on
/for-restaurants loads its map tiles from
OpenStreetMap (tile.openstreetmap.org), which therefore receives
your IP address and the area of the map being drawn. The map software itself is
served from our own server, not from a third party, and the tiles are requested only
once the map itself comes into view — near the top of
/for-restaurants, and only after scrolling on the home
page, where a visitor who never scrolls that far causes no request at all. No cookies
are set, on our side or theirs, and nothing about you is sent beyond the request for
the tile images themselves.
If you enable notifications, your device's push token is processed by
Google Firebase Cloud Messaging (and, on iPhones, Apple Push Notification
service) to deliver the message. We send only order/reservation status updates —
no marketing. Disabling notifications in the app deletes the token from our systems.
If the app crashes, the report described above is processed by Google Firebase
Crashlytics. It exists because the app stores tell us only that a crash
happened and never what caused it, which leaves a fault we cannot find and cannot
fix. The reports are kept for at most 90 days and are used for nothing else.
We do not use advertising SDKs and we do not track you across apps or websites.
The DishDraw app contains no analytics SDK — a crash reporter is not one: it
sends something only when the app breaks, and never records what you look at or do. The website statistics described
above stay on our own server and are never shared with an analytics company.
Retention
Security logs are kept only as long as needed to prevent abuse. Submitted content
remains until removed by you/the restaurant or by us. Reservation details (name,
phone, email if given, party, time) are deleted automatically no later than 30 days after the
reservation date. Pickup order details (name, phone, the items ordered) are deleted
automatically no later than 30 days after the order. Activity in the shared demo restaurant (test orders,
reservations, photos) is wiped automatically every night. Website usage statistics
are kept in aggregate only; because no IP address or reusable identifier is stored,
they cannot be traced back to a visitor.
Your rights
You may request access, correction, deletion, restriction, or object to
processing, and lodge a complaint with a supervisory authority. Contact
legal@dishdraw.de. To delete a job account
or a recruiter account, write to that address from the email you sign in with (see
how to delete your account). Restaurants can also
use the “For restaurants” section on the home page.