Privacy Policy
LocalX Gastro — Restaurant Management Platform
Last updated: 5 September 2026
This Privacy Policy explains how we collect, use, and protect personal data across the LocalX Gastro platform (the “Platform”), including all applications, web panels, and services.
This policy applies to all Platform users: restaurant owners, managers, accountants, employees (waiters, cooks, bartenders), and restaurant guests.
CHE-334.936.697 MWST (“LocalX”, “we”, “us”)
1. What data the Platform collects
Restaurant owner and manager data
| Category | Examples |
|---|---|
| Identity | Name, email address, phone number |
| Business | Restaurant name, address, CHE/UID numbers, opening hours |
| Account | Login credentials, role, permissions |
| Activity | Admin actions, settings changes, approvals |
Employee data (collected on behalf of the restaurant)
| Category | Examples |
|---|---|
| Identity | Name, email address, profile photo (optional) |
| Employment | Role, location, contract type, vacation balance |
| Working time | Clock-in/out times, break records, GPS coordinates at clock-in (if enabled by the owner) |
| Shifts | Scheduled shifts, swap requests, availability preferences |
| Requests | Time-off requests (vacation, sick, unpaid, other) |
| Documents | Employment contracts, work permits, certificates, payslips |
| Financial | Hourly rate, tip share (visible only to owner and accountant) |
Guest data (QR ordering)
| Category | Examples |
|---|---|
| Session | Table number, order contents, session duration |
| Technical | IP address, device type, browser information |
No guest account or personal information is required. Guest sessions are anonymous and expire automatically.
Technical data (all users)
| Category | Examples |
|---|---|
| Device | Push notification tokens, app version, operating system |
| Language | Preferred language setting |
| Usage | Feature interactions for reliability monitoring |
Data we do NOT collect
- Biometric data (fingerprint, face recognition)
- Continuous location tracking — GPS is captured only at clock-in/out
- Personal contacts, photos, or files not voluntarily uploaded
- Payment card numbers or banking details — payment processing is handled by the restaurant’s own provider
- Guest personal identity — QR ordering is anonymous
- Advertising identifiers or browsing history
2. How we use data
| Purpose | Legal basis |
|---|---|
| Provide the Platform (ordering, workforce, operations) | Performance of contract |
| Send push notifications | Legitimate interest |
| Verify employee clock-in location | Legitimate interest of the restaurant owner |
| Process and display orders | Performance of contract |
| Stock tracking and alerts | Performance of contract |
| Generate operational reports | Legitimate interest |
| Maintain and improve the Platform | Legitimate interest |
| Comply with legal obligations | Legal obligation |
We do not use data for advertising, profiling, automated decision-making, or selling to third parties.
3. Who sees data
Within the restaurant
Access is role-based. Not every user sees everything:
| Data | Owner | Manager | Accountant | Employee | Guest |
|---|---|---|---|---|---|
| All employee records | ✓ | ✓ (their location) | Read-only | Own only | ✗ |
| Hourly rates, financial | ✓ | ✗ | ✓ | ✗ | ✗ |
| Time entries | ✓ | ✓ (their location) | ✓ | Own only | ✗ |
| Orders | ✓ | ✓ | ✗ | Own tables | Own order |
| Stock | ✓ | ✓ | ✗ | Cook/bar only | ✗ |
| Menu | ✓ | ✓ | ✗ | ✓ | ✓ |
With service providers
We use the following providers, all under data processing agreements:
- Supabase — database hosting (EU servers)
- Vercel — web application hosting
- Expo — mobile app distribution and push notifications
- Worldline — payment processing (restaurant’s own agreement)
Legal requirements
We may disclose data to comply with a court order, regulatory request, or legal obligation.
We do not sell, rent, or trade personal data.
4. How long data is kept
| Data type | Retention |
|---|---|
| Employee working-time records | Retained as long as the restaurant owner requires. The restaurant is responsible for Swiss retention law compliance. |
| Payslips | Retained as long as the restaurant owner requires. |
| Orders and revenue data | Retained as long as the restaurant owner requires. |
| Stock movements | Retained as long as the restaurant owner requires. |
| Guest session data | Automatically deleted 90 days after the session ends. |
| Push notification tokens | Until the user uninstalls the App or revokes permission. |
| Employee accounts | Until the restaurant owner deactivates the account. Data deleted within a reasonable period unless the owner instructs otherwise. |
| Restaurant accounts | Until the subscription ends. Data export available upon request before deletion. |
LocalX stores data on behalf of the restaurant owner. The owner determines what is kept and for how long. If the owner instructs LocalX to delete data, LocalX will comply unless prohibited by law.
5. Where data is stored
Data is hosted on servers in the European Union (Supabase infrastructure). If data is transferred outside the EU/EEA, we ensure adequate safeguards are in place as required by the Swiss Federal Act on Data Protection (revDSG).
6. Your rights
Under the Swiss Federal Act on Data Protection (revDSG) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (subject to legal retention requirements)
- Export your data in a portable format
- Object to certain processing activities
For employees: contact your employer (as data controller) for employment data requests. For requests concerning LocalX’s processing, contact us at contact@localx.world.
For restaurant owners: contact us directly at contact@localx.world.
For guests: guest sessions are anonymous. No personal data is stored beyond what is listed above.
We respond to requests within 30 days.
7. Location data
If the restaurant owner enables location verification:
- GPS coordinates are captured only at the moment of clock-in and clock-out
- Location is not tracked continuously between clock events
- Location data is not shared outside the Platform
- Data is retained as part of the time entry record
The restaurant owner decides whether location verification is enabled and configures the geofence area. Employees can manage location permissions in their device settings.
Android may display notifications about background location access. This is required by the operating system for the automatic clock-in feature and does not mean location is continuously tracked.
8. Push notifications
The Platform sends push notifications to employees for:
- Shift changes, new shifts, cancellations
- Time-off approvals or declines
- New payslips and documents
- Manager announcements
- Low-stock alerts (cook and bartender roles)
Notifications are sent in the user’s preferred language (German, French, Italian, or English). Users can disable notifications in device settings without affecting other functionality.
9. Guest ordering and anonymity
Guest ordering via QR code is designed to be anonymous:
- No account creation or login required
- No personal information collected
- Order data is associated with a table, not a person
- Session data expires automatically
The restaurant may see what was ordered at a table but cannot identify the individual guest through the Platform.
10. Children
The Platform is not intended for individuals under the age of 16. We do not knowingly collect data from children under 16.
In Switzerland, employment of minors aged 15–18 is permitted under certain conditions (ArG Art. 29–32). If a restaurant owner creates an account for a minor employee, the owner ensures appropriate consent.
Guest ordering has no age restriction as it collects no personal data.
11. Data security
We implement appropriate technical and organisational measures:
- Encryption in transit (TLS/HTTPS) and at rest
- Row-level security ensuring each restaurant’s data is isolated
- Role-based access controls per user
- Tenant isolation — no restaurant can access another’s data
- Regular security reviews
No system is completely secure. In the event of a data breach that poses a risk to rights, we notify affected parties and relevant authorities as required by law.
12. Changes to this policy
We may update this Privacy Policy as the Platform or applicable law evolves. Material changes will be announced through the Platform. The “Last updated” date at the top indicates the most recent revision.
13. Contact
Handelsregister-Nr.: CH-600.1.019.575-8
UID: CHE-334.936.697 MWST
contact@localx.world