Privacy policy

Last updated: 27 August 2026

This policy applies to https://carta.so, https://app.carta.so, customer accounts, public menus and communications with Carta.

1. Controller

Luca Huerse, Karl-Schurz-Straße 13, 70190 Stuttgart, Germany, hey@carta.so, +49 152 23373152

No data protection officer has currently been appointed.

2. Roles

Carta is controller for the website, account and contract administration, billing, support, security and its own communications. For personal data and usage statistics processed on a restaurant’s instructions, the restaurant will generally be controller and Carta processor. The DPA applies.

3. Website access and logs

When a page is accessed, IP address, time, URL, HTTP and status data, referrer, browser and device information are processed. Purposes are secure delivery, troubleshooting and abuse prevention. The legal basis is Article 6(1)(f) GDPR and, where contract-related, point (b). The internal standard period for application logs is 30 days; security incidents or provider requirements may require a different period.

Hosting is provided by Vercel Inc. The exact execution region and log retention must be confirmed before production launch. Third-country transfers are protected by an adequacy decision, valid EU-US DPF certification or Standard Contractual Clauses.

4. Cookies and local storage

Carta does not use advertising or cross-site tracking cookies.

  • Session cookies for login and security
  • Language and restaurant selection, generally for up to one year
  • Display, sidebar and preview preferences
  • Guest favourites stored locally without account synchronisation

5. Account and authentication

We process email address, optional name, user ID, roles, session and security data and accepted document versions. Legal bases are Article 6(1)(b), (c) and (f) GDPR. Authentication, database and storage are provided by Supabase, Inc.; the currently expected but not yet verified project region is Zürich, Schweiz (eu-central-2). One-time codes are sent by Resend, Inc. Optional Google login is provided by Google Ireland Limited.

6. Restaurant and menu data

Customers store restaurant, operator and contact details, logos, images, menu text, prices, allergens, additives, dietary labels, languages, design and other restaurant information. Carta processes these data to edit, translate and publish menus. Special-category data under Article 9 GDPR and criminal-offence data under Article 10 GDPR may not be submitted without a separate agreement.

7. AI features

When import, assistant or translation features are used, selected images, PDF files, menu and restaurant text, chat messages and configuration are sent to Anthropic, PBC. Under the current design, the Wi-Fi password is not sent. The purpose is the requested extraction, translation or editing. According to current provider information, the commercial API does not use inputs or outputs for training by default and generally deletes them within 30 days. Zero Data Retention has not been agreed; abuse or legal cases may be retained longer.

AI output may be incorrect. Prices, allergens, additives and translations are published only after express review and approval by the restaurant operator.

8. Public menus and analytics

Published menus are accessible without login. When a dish is opened, Carta stores the internal dish ID and time. The product database currently does not store a persistent IP address, user agent or referrer for this event. Click events are deleted or permanently aggregated after no more than 24 months.

9. Communications, accounting and domain

Support data are processed under Article 6(1)(b) and (f) GDPR. Billing and tax data are processed under points (b) and (c) and managed through Haufe-Lexware GmbH & Co. KG (Lexware Office). The domain is administered through Namecheap, Inc. No payment provider is currently integrated; this policy will be updated before one is introduced.

10. Recipients and third-country transfers

Recipients are the named hosting, database, authentication, email, AI, OAuth, accounting and domain providers, authorised team members, advisers and authorities where legally required. Third-country transfers take place only under an adequacy decision or appropriate safeguards, particularly Standard Contractual Clauses and a supplementary assessment.

11. Retention and exit

Accounts and product data are stored during the contract. After termination, a transition period of no more than 30 calendar days is followed by a retrieval period of at least 30 calendar days. Production data are then deleted unless a legal basis requires retention. Once the documented backup system is in place, backup copies are overwritten or deleted within no more than a further 90 days. Statutory retention duties remain unaffected.

12. Security

Carta uses encrypted transmission, role-based access, database tenant isolation, private file storage, secret management, logged publishing and deletion processes. Regular backups, restoration tests and a documented incident process will be established before public production launch.

13. Rights

Subject to the GDPR, data subjects have rights of access, rectification, erasure, restriction, portability and objection. Requests should be sent to hey@carta.so. For restaurant content, the identified restaurant operator is primarily responsible.

14. Complaints

Complaints may be submitted to the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, or any other competent supervisory authority.