NexlyGO

Bozza / Draft — à faire valider par un avocat

This text is a draft: it describes what the platform does with data today, but it has not yet been reviewed by a lawyer and may change before its final version. The passages in square brackets are choices that have yet to be made: they do not amount to a commitment.

Privacy policy — NexlyGO, restaurants and their customers

What data the NexlyGO platform processes when a restaurant uses it and when you order from, book with or write to a restaurant on its website, via WhatsApp or via Telegram: why, where it goes, for how long, and your rights.

Version 2026-10-06-draft of 6 October 2026

1. Who processes your data

The NexlyGO platform (restaurant websites, online ordering and booking, ordering via WhatsApp and Telegram, chat and voice assistants, the dashboard and the NexlyGO Manager app) is operated by Nexly GO [legal form, registered office, registration number — to be confirmed] (“Nexly GO”, “we”).

For any question about your data or to exercise your rights: info@ngo.travel. [Postal address, data protection officer and, where necessary, representative in the European Union or in Switzerland — to be confirmed.]

The NGO app (ordering dishes from several restaurants, travel) has its own privacy policy, at nexlygo.pro/ngo/privacy: this text does not replace it.

2. Who this text is for

It concerns three groups of people:

  • partner restaurants and the people who work there (owner, manager, team) and use the platform;
  • restaurants' customers: people who order, book a table, leave a review, or write to or call a restaurant through the platform;
  • visitors to the restaurants' websites and to nexlygo.pro.

3. Who decides what: Nexly GO and the restaurant

Nexly GO is the controller of the processing it alone decides on: restaurant accounts, the operation and security of the platform, online payment (collected in Nexly GO's Stripe account, then paid over to the restaurant), the verification of restaurants, the WhatsApp number and the Telegram bot shared by all restaurants, the loyalty points and the customer profile shared by all restaurants (section 5), and messages sent on behalf of the platform.

The restaurant decides what it does with the orders and bookings it receives: it prepares your order, welcomes you, contacts you if need be, and it is responsible for the tools it adds to its website itself (section 6). For orders and bookings placed with a restaurant, Nexly GO acts [as the restaurant's processor (Article 28 of the GDPR), with a data processing agreement annexed to the partner terms, or as joint controller with it (Article 26) — characterisation to be validated].

You may contact either of them: we pass on to the restaurant the requests that concern it, and vice versa.

4. Partner restaurants' data

  • The account: name, email address, telephone number, password (never stored as such: our authentication service keeps only a hash of it, unreadable even by us) or sign-in with Google; the team members you invite (email address, name, role).
  • The establishment: name, address, country, cuisine, opening hours, menu and prices, photos, public contact details. If you import your Google listing, we reuse its public information (rating, number of reviews, telephone number, website, opening hours, photos) and copy the photos to our storage.
  • The business and payouts: company name, business number or tax number, account holder, IBAN and BIC of the bank account into which your sales are paid. For subscriptions and paid services, Stripe receives the establishment's email address and name.
  • Sign-up: the display language, the country inferred from the connection (never the IP address itself), the originating campaign (utm parameters), and the date and version of the partner terms accepted.
  • Verification before payments are enabled: we compare the IBAN, telephone number and name with those of other restaurants, we look at the type of email address and whether the country of the connection matches the declared country, and we search for the establishment on Google (name and city).
  • Communications with us: messages to support, emails, and conversations with the dashboard assistant, which, in order to help you, sees the day's orders with the customers' names.
  • Notifications: the technical identifiers of your devices (Google Firebase, Apple, browser) and your number for the automated calls that alert you to a pending order. These calls are not recorded and you can turn them off.
  • The till in France: for the till's certificate of compliance, the signatory's name, the company name, the SIRET number, and the IP address and browser at the time of signing.

5. Restaurant customers' data

  • Online ordering: first name, surname, email address, telephone number, delivery address and its location on the map, instructions and notes, items, time slot, promo code, amount, page language, and your choice whether or not to receive the newsletter. For a delivery, the address is sent to the courier as soon as the price is calculated, before payment.
  • Payment: your card details are entered in Stripe's form; we never see the card number, only the payment identifier and the last four digits.
  • Table booking: name, telephone number, email address, number of people, date, time and notes.
  • Reviews: the display name, the rating and the text; for reviews imported from Google, the name, photo and profile link of their author.
  • Contact form: name, email address, telephone number and message.
  • WhatsApp and Telegram: your number or user ID, your profile name, your messages (voice messages are transcribed into text), your basket, and what the assistant remembers for your next orders: favourite dishes, last delivery address, allergies and dietary requirements if you mention them, and a short summary written by artificial intelligence.
  • Chat on a restaurant's website: name, email address and telephone number if you provide them, your messages and your basket.
  • Calls: if you call a restaurant's voice assistant, your number and the transcript and summary of the call, anonymised after 90 days. If an item in your order is unavailable, we may call you to offer you the choice of keeping the rest or cancelling; your choice (a key pressed on the keypad) is recorded.
  • Loyalty points: linked to your telephone number and valid at every restaurant on the platform; a shared profile (number, name, last delivery address) is used to recognise you from one restaurant to the next [legal basis, and how customers are informed, for this data shared by all restaurants — to be validated].
  • Delivery tracking: the tracking link shows the name, telephone number and location of the delivery driver.

Allergies and dietary requirements may reveal information about your health. Only mention them if you wish to: they are used to prepare your order [explicit consent to be obtained before they are remembered for future orders — to be validated].

Orders received from delivery platforms (Deliveroo, and Uber Eats once the connection is live) reach us with the customer's name and telephone number, in accordance with those platforms' rules.

6. Website visitors

The platform's audience measurement: two cookies, one for the visit (30 minutes), the other to recognise a returning visitor (365 days). They are used to count page views and to record the referring page, the campaign, the device, the browser, the language, and the country and city inferred from the IP address, which is not kept [prior consent or exemption for audience measurement — to be validated].

If you arrive via Google's “Order online” feature, we record the identifier of that click, the browser, the country and the referring page, so that a restaurant knows which orders come from Google.

On your device, the website also keeps your basket, your contact details from your last order (to fill in the form next time) and the language you chose.

If a restaurant has added Google Analytics or the Meta pixel to its website, these Google and Meta tools are loaded on its pages, under its responsibility [obtaining consent before they load — to be put in place before publication].

Some pages display content from third parties, who receive your IP address: maps from Google Maps, videos from YouTube or Vimeo, fonts from Google Fonts, and the Stripe payment form. Vercel measures how quickly pages are displayed, without cookies.

7. Why we use this data

  • Taking, collecting payment for, preparing and delivering your order, managing your booking and keeping you informed about them (performance of the contract).
  • Service messages: confirmation, progress updates, delivery tracking, a payment reminder for an order started by message, a basket left in a conversation, a request for a review after the order [legitimate interest or consent, depending on the message and the country — to be validated].
  • Newsletter and offers by email: only if you ticked the box when ordering (consent), with an unsubscribe link in every mailing.
  • Promotional messages via WhatsApp or Telegram (a restaurant's offers, a follow-up message a few days after a first order) [legal basis to be validated: these messages do not yet check for consent to direct marketing].
  • Loyalty: crediting and using your points (performance of the programme).
  • Managing restaurants' accounts, verifying sign-ups, paying out sales, invoicing and keeping the accounts (contract and legal obligations).
  • Preventing fraud, securing the platform, answering support requests and improving the service (legitimate interest).
  • Artificial intelligence: replying to your messages and calls, remembering your preferences, importing a restaurant's menu from a PDF, a photo or its website, and assisting support [performance of the contract and legitimate interest — to be validated]. No decision producing legal effects concerning you is taken by automated means.

We do not sell your data.

8. Who receives your data

  • The restaurant you order from or book with.
  • Hosting: Supabase (database, accounts and files, in Paris, in the European Union) and Vercel (application servers, in Paris, and the network that delivers the pages).
  • Payment: Stripe.
  • Delivery: the courier chosen by the restaurant (Uber Direct or, depending on the restaurant, Stuart, Shipday, DoorDash, Deliveroo or Pikup) receives your name, your telephone number, and the delivery address and instructions.
  • Tills and software that a restaurant has connected to the platform (HubRise, Deliverect, RusHour, NexlyHUB, Square, SumUp): the order details and, depending on the software, your name, telephone number, email address and the delivery address.
  • Messages and calls: Resend (emails), Twilio (SMS and calls), Telnyx (calls), Meta (WhatsApp), Telegram, Vapi (voice assistant, with Deepgram for speech recognition and Microsoft Azure for the voice).
  • Newsletter: Brevo, when a restaurant's subscriber list is sent to it for a campaign.
  • Artificial intelligence: Anthropic (Claude) and OpenAI (GPT, transcription of voice messages).
  • Google: notifications (Firebase), restaurant search and addresses, maps, restaurant listings for Google's “Order online” feature, and Google Analytics if a restaurant has enabled it. Apple: notifications on iPhone.
  • Addresses and postcodes: the public address services of France (data.gouv.fr) and Switzerland (geo.admin.ch), and Zippopotam for Swiss postcodes.
  • Importing a menu from a website: ScraperAPI or ScrapingBee reads the page for us.
  • The authorities, where required by law.

9. Data sent outside the European Union and Switzerland

The database is in Paris. Several providers are established in the United States or process data there, in particular Stripe, Twilio, Resend, Meta, Anthropic, OpenAI, Google, Uber and Vapi.

These transfers are based on [the European Commission's standard contractual clauses, the Data Privacy Framework or another safeguard — to be checked for each provider and listed here].

10. How long we keep your data

  • Call transcripts and summaries: 90 days, then anonymised.
  • Orders and accounting records: [10 years for accounting records; customers' contact details: period to be set].
  • WhatsApp, Telegram and website conversations, and preferences remembered by the assistant: [period to be set].
  • Bookings, reviews and contact form messages: [period to be set].
  • Audience measurement: visit cookie 30 minutes, visitor cookie 365 days; visit data [period to be set].
  • Restaurant accounts: for the duration of the relationship, then [period to be set, subject to accounting obligations].
  • Newsletter: until you unsubscribe.

[To be implemented before publication: apart from call transcripts, no automatic deletion is in place yet.]

11. Your rights

You may request access to your data, its rectification, its erasure, the restriction of its use or its portability, and object to its use, in particular for direct marketing, at any time. Where processing is based on your consent, you may withdraw that consent at any time.

Write to info@ngo.travel: we reply within one month [verification of the requester's identity — procedure to be specified]. For an order or a booking, you can also contact the restaurant.

To stop receiving the newsletter: use the unsubscribe link in each email. To stop receiving promotional messages via WhatsApp or Telegram: write to us [unsubscribing directly in the conversation — to be put in place].

You may lodge a complaint with a data protection authority: in France the CNIL, in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in Italy the Garante per la protezione dei dati personali, in Spain the Agencia Española de Protección de Datos (AEPD), in Portugal the Comissão Nacional de Proteção de Dados (CNPD).

12. Cookies and storage on your device

  • Strictly necessary: signing in to the restaurants' dashboard (session cookies from our authentication service) and the choice of active establishment (7 days); payment (Stripe's anti-fraud cookies).
  • The platform's audience measurement: visit (30 minutes) and visitor (365 days); see section 6.
  • Local storage: basket, contact details from the last order, language, visit identifier and, for the duration of the visit, the identifier of a click coming from Google.
  • Tools added by a restaurant (Google Analytics, Meta pixel) and third-party content (Google Maps, YouTube, Vimeo): their own cookies, under their own rules.

[Consent banner for cookies that are not strictly necessary — to be put in place and described here.]

13. Security

Communications are encrypted (HTTPS), access to data is restricted to the people who need it, passwords are never stored in plain text, card data stays with Stripe and restaurants' WhatsApp access credentials are encrypted. No measure is infallible: in the event of a data breach presenting a risk, we notify the competent authority and, where necessary, the individuals concerned.

14. Minors

The platform is not intended for children [minimum age for ordering or creating an account — to be set country by country].

15. Changes

Each version of this text is dated. If we change it significantly, we notify restaurants by email or in the dashboard, and we update this page.

16. Contact

Nexly GO [legal form, registered office, registration number — to be confirmed] — info@ngo.travel.