How TechVerdi SA collects, uses, and protects personal data across the Kappino restaurant management platform, in line with Swiss and EU data protection law.
Last updated: 3 October 2026
Summary at a glance
- Who we are: Kappino is a restaurant management platform operated by TechVerdi SA, based in Pully, Switzerland.
- What we collect: account and contact details, the operational data you enter, technical and usage data, and limited payment metadata.
- What we do not store: full card numbers and CVV codes — payments are handled by specialised payment providers.
- Why: to provide and secure the Service, perform our contract with you, comply with the law, and improve the product.
- Who we share with: vetted service providers under contract. We never sell your data.
- Where it is stored: the core platform is hosted in Switzerland; some AI and integration features process data abroad with safeguards in place.
- Your rights: access, correct, delete, export, restrict, object, withdraw consent, and complain to a regulator.
- Contact: office@techverdi.ch
About this Policy
Kappino is a restaurant management platform owned and operated by TechVerdi SA. This Privacy Policy explains how TechVerdi SA collects, uses, discloses, stores, and protects personal data in connection with the Kappino platform — including the website at kappino.com, the web application at app.kappino.com, and our mobile applications.
We process personal data in accordance with the Swiss Federal Act on Data Protection of 25 September 2020 (FADP, in force since 1 September 2023) and its Ordinance on Data Protection and, where they apply, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
The Swiss supervisory authority is the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Bern, Switzerland.
Definitions
To make this Policy easier to read:
- Personal data — any information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data, such as collecting, storing, using, disclosing, or deleting it.
- Controller — the party that decides why and how personal data is processed.
- Processor — a party that processes personal data on behalf of, and under the instructions of, a controller.
- Business Client — a restaurant, café, chain, franchise, or other business that subscribes to and uses the Service.
- End Customer — a diner or guest of a Business Client whose data is processed through the Service.
- You — the individual whose personal data is processed, whether an account holder, staff member, End Customer, or website visitor.
Who is responsible
3.1 Controller details
TechVerdi SA
Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Email: office@techverdi.ch
VAT / UID: CHE-110-027.685
3.2 Controller vs. processor
Our role depends on the data in question. TechVerdi acts as the controller for website and account registration data, billing data, login and security data, support communications, and aggregate analytics about how the Service is used.
TechVerdi acts as a processor for the operational data a Business Client enters or generates within the platform about its own End Customers, staff, orders, and reservations. In that case, the Business Client is the controller and our processing is governed by a separate Data Processing Agreement.
3.3 Data Protection Contact
Data Protection Contact — TechVerdi SA
Email: office@techverdi.ch
Post: TechVerdi SA, Attn. Data Protection, Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
3.4 Requests from the EU and the UK
If you are in the EU/EEA or the UK, you can send any data-protection request directly to TechVerdi SA using the contact details above. We have not appointed a separate representative in the EU or the UK; TechVerdi SA handles requests from every country.
Whose data we process and how we obtain it
We process personal data that:
- you provide directly — when you register, configure your account, contact support, or enter data into the platform;
- is generated automatically — log, device, and usage data created when you interact with the Service;
- comes from a Business Client — where a restaurant enters or uploads data about its staff or End Customers; and
- comes from third parties — for example, confirmation of payment status from a payment provider, or integrations you connect.
Categories of data we collect
5.1 Personal / account information
| Data | Examples / Notes |
|---|---|
| Name | Full name of the account holder or user |
| Email address | Login, notifications, billing |
| Phone number | Contact and account notifications |
| Business name | The legal / trading name of your business |
| Restaurant name | The brand or venue name shown in the app |
| Billing address | Invoicing and tax purposes |
| Country | Localisation, tax, and legal-compliance routing |
| Language | Preferred interface language |
| User role | e.g. owner, manager, staff — determines access level |
5.2 Account, login, and technical data
| Data | Examples / Notes |
|---|---|
| Username | Your login identifier |
| Password | Stored only as a salted hash — never in plain text |
| Login history | Timestamps and outcomes of sign-in attempts |
| Device information | Device type, model, operating system |
| Browser | Browser type and version |
| IP address | Security, fraud prevention, and approximate location |
5.3 Restaurant operational data
Data you create or upload while using the Service, which may include personal data of staff and End Customers: branches and locations; staff records; customer records; orders; reservations; tables and floor plans; inventory; sales reports and analytics; and menu items.
5.4 Payment data
- We do not store full credit/debit card numbers or CVV / security codes.
- Payments are securely processed by third-party payment providers responsible for handling card data.
- We retain limited transaction metadata for billing, accounting, tax, dispute-handling, and fraud-prevention purposes.
5.5 Mobile device data
| Permission | Why it is used |
|---|---|
| GPS / location | Delivery routing and rider location for active deliveries |
| Camera | Scanning codes or capturing images / documents within the app |
| Notifications | Operational alerts such as orders, reservations, and status |
| Bluetooth | Connecting to receipt / kitchen printers and hardware |
| Internet / network | Required to operate the Service |
You can revoke any of these permissions in your device settings; some features may then be limited.
5.6 Rider location data
Where a Business Client uses delivery features, the rider mobile app periodically transmits the rider’s GPS coordinates to the platform. The tracking is real-time only — we store only the rider’s most recent location, not a continuous location history.
5.7 Uploaded documents
The Service includes a document-scanning feature. When you upload a document, such as an invoice or menu, it is processed using OCR and text parsing to extract structured data, after which the result is presented for human review and approval.
5.8 Visiting kappino.com and contacting us
- Server logs. When you open kappino.com, our web hosting provider processes your IP address, the date and time, the page requested, the referring page and your browser type. We use this to deliver the website, keep it secure and apply regional access restrictions. Logs are deleted after [number of days — to be confirmed by TechVerdi SA].
- Contact, demo and quote forms. When you send a form, we receive the details you enter (name, email, phone, job title, restaurant name, city, country, type of restaurant, number of locations, reason and message, and for quotes the product and quantity). We use them only to answer your request and to arrange a demo or quote. Your form is sent to our team by email (hello@kappino.com) through Google’s Gmail service. We do not add you to any newsletter.
- The Pino assistant on our website. Quick questions are answered with prepared text in your browser. When you type a question, it is sent, with the earlier messages of the conversation and the page language, to our server and to OpenAI, which generates the answer. We do not store chat messages. Please do not enter personal or payment details in the chat.
- Browser storage. We keep your cookie choice (for 12 months) and, once you choose one, your preferred language in your browser’s local storage. A service worker keeps a copy of website files on your device so pages load faster and work offline. These are strictly necessary for the features you use and do not identify you.
- No tracking. We currently use no analytics tools, advertising cookies, tracking pixels, or third-party embedded videos or maps on kappino.com, and our fonts are hosted on our own server. If we add such tools, we will ask for your consent first and update this Policy.
Why we process data
We process personal data to create and manage accounts; process orders and reservations; plan staff schedules; manage inventory; provide analytics and reporting; provide AI features such as recommendations and forecasting; provide customer support; answer enquiries sent through our website; handle billing; maintain security; detect and prevent fraud and abuse; communicate with you; and comply with legal obligations.
Legal basis for processing
7.1 Under Swiss law
As a Swiss controller, we process personal data in line with the FADP’s core principles. Where a justification is required, we rely on consent, overriding private or public interest, performance of contract, security of the Service, fraud prevention, legal claims, or a basis provided by law.
7.2 Under the GDPR
| Purpose | GDPR legal basis |
|---|---|
| Account creation and provision of the Service | Contract — Art. 6(1)(b) |
| Order processing, inventory, reporting | Contract — Art. 6(1)(b) |
| Billing, accounting, tax records | Legal obligation — Art. 6(1)(c); Contract — Art. 6(1)(b) |
| Security, fraud prevention, product improvement | Legitimate interests — Art. 6(1)(f) |
| AI recommendations and forecasting | Legitimate interests — Art. 6(1)(f); Contract — Art. 6(1)(b) |
| Answering website enquiries, demo and quote requests | Steps prior to a contract — Art. 6(1)(b); Legitimate interests — Art. 6(1)(f) |
| Delivering and securing the website (server logs, regional access restrictions) | Legitimate interests — Art. 6(1)(f) |
| Non-essential cookies, marketing communications | Consent — Art. 6(1)(a) |
| Responding to legal requests | Legal obligation — Art. 6(1)(c) |
Automated processing, AI, and profiling
Kappino uses artificial intelligence and statistical methods to provide features including the Pino AI copilot, OCR document parsing (AI Inventory and expense scans), sales and demand forecasting, the AI staff shift planner, recommendations, AI-suggested replies to social media comments, the WhatsApp AI order taker, the AI Poster Generator and AI menu translation.
Some AI features rely on third-party AI providers. Documents submitted to the OCR / AI Scanner may be processed by Google Cloud Vision and OpenAI for text extraction and parsing. Other AI features, such as the Pino AI copilot and AI-generated text and images, use the third-party AI providers listed in the table in the next section.
AI outputs are designed to support — not replace — business decisions. AI processing can be disabled for a specific Business Client on request, although some core platform features may be limited.
How we share data
We do not sell personal data. We share it only where necessary to operate the Service, with appropriate contractual and technical safeguards.
| Recipient / Provider | Purpose | Location |
|---|---|---|
| Infomaniak Network SA | Cloud hosting and infrastructure for the platform and database | Switzerland |
| Infomaniak Network SA | Hosting of kappino.com | Switzerland |
| Google (Gmail) | Delivery of contact form submissions by email | USA / global |
| OpenAI (API) | Answers in the Pino chat on kappino.com (your chat messages and the page language) | USA |
| OpenAI | AI text parsing, copilot and content generation features | USA |
| Google Cloud Vision | Optical character recognition for uploaded documents | USA / global |
| Google Maps & Google APIs | Mapping, location, and delivery features | USA / global |
| Meta Platforms (Facebook, Instagram, WhatsApp Business) | Social media, messaging and WhatsApp ordering integrations you connect | EU / USA / global |
| Shopify | E-commerce integration | Outside CH/EU |
| WordPress / WooCommerce | Website and e-commerce integration | Depends on deployment |
| Payment providers | Securely process transactions | As applicable |
| Professional advisers / auditors | Legal, accounting, and compliance support | Switzerland / EU |
| Authorities | Where required by law, court order, or valid legal process | As applicable |
Cookies and consent
We use the following categories of cookies and similar technologies:
- Strictly necessary — needed for the website and the Service to work. On kappino.com: your cookie choice and, once you choose one, your language (both kept in your browser’s local storage), and the service worker cache. In the web app: authentication, security and session management. These do not require consent.
- Analytics — would help us understand how the website is used. Used only with your consent. We do not use any analytics tools on kappino.com at the moment.
- Marketing — would measure our advertising. Used only with your consent. We do not use any marketing cookies or pixels on kappino.com at the moment.
On your first visit, a cookie banner lets you accept all, reject all or choose by category; nothing optional is switched on in advance. Your choice is kept in your browser for 12 months. You can change or withdraw it at any time with the “Cookie settings” link at the bottom of every page; withdrawing consent does not affect processing that took place before.
Where your data is stored and international transfers
The Service is hosted with a Swiss hosting provider, Infomaniak Network SA, and the core platform infrastructure and database are physically located in Switzerland. The European Commission recognises Switzerland as providing an adequate level of data protection, so personal data can be transferred from the EU/EEA to us without additional safeguards.
Some features rely on providers that process data outside Switzerland and the EU/EEA, mainly in the United States (OpenAI, Google and Meta). For these transfers we rely on one of the following safeguards:
- the EU-U.S. Data Privacy Framework (with its UK Extension and the Swiss-U.S. Data Privacy Framework), where the recipient is certified under it; or
- the European Commission’s Standard Contractual Clauses, with the amendments required for transfers from Switzerland and the United Kingdom, supplemented by additional measures where necessary.
You can ask us for more information about the safeguards used for a specific provider at office@techverdi.ch.
Your rights
Subject to the conditions and exceptions of the FADP and, where they apply, the GDPR and the UK GDPR, you have the right to: access your personal data; have it corrected; have it erased; restrict its processing; object to processing based on legitimate interests, and to direct marketing at any time; receive your data in a portable format; withdraw your consent at any time, without affecting processing before the withdrawal; and obtain human review of significant automated decisions.
To exercise your rights, contact our Data Protection Contact. We respond within the timeframes required by applicable law and may need to verify your identity.
Right to lodge a complaint. You can complain to a data protection supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch); in the EU/EEA, the authority of the country where you live, work or where the alleged infringement took place; in the United Kingdom, the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to deal with your concern first.
Data retention
We keep personal data only as long as necessary for the purposes set out in this Policy or as required by law.
| Data | Retention period | Basis |
|---|---|---|
| Customer account data | Deleted within 30 days after account deletion | Storage limitation — subject to statutory exceptions |
| Backups | Retained for up to 90 days in the rolling backup cycle | Technical backup cycle |
| Uploaded documents | Retained until you delete them | Provision of the scanning feature |
| Rider location data | Only the most recent location is held | Provision of delivery features |
| Accounting and business records | 10 years from the end of the relevant financial year | Art. 958f Swiss Code of Obligations |
| VAT-relevant records | 10 years, up to 20 years for immovable property records | Swiss VAT Act and Ordinance |
| Audit and access logs | Retained as needed for security and fraud prevention | Overriding interest |
| Website enquiries (contact, demo and quote forms) | [Period — to be confirmed by TechVerdi SA], unless a contract follows | Steps prior to a contract / legitimate interests |
| Website server logs | [Number of days — to be confirmed by TechVerdi SA] | Legitimate interests (security) |
| Cookie choice in your browser | 12 months | Strictly necessary |
| Marketing data based on consent | Until consent is withdrawn or you object | Consent — Art. 6(1)(a) GDPR |
| Data needed for legal claims | Until limitation periods expire, generally up to 10 years | Overriding interest / legal claims |
How the 30-day rule interacts with statutory retention. When you delete your account, operational and profile data is deleted within 30 days. Where a specific record is subject to mandatory legal retention, we block or archive that record.
Children’s privacy
The Service is a business tool intended for professional users and is not directed at, marketed to, or intended for use by children.
We do not knowingly collect, process, or store personal data from children under the age of 16.
Security measures
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, disclosure, or alteration.
- Encryption in transit via HTTPS/TLS, HSTS, and Content Security Policy.
- Encryption of sensitive credentials and tokens at rest using AES-256-GCM.
- Password hashing with bcrypt.
- Token-based authentication, session management, and role-based access control.
- Tenant isolation in our multi-tenant environment.
- Daily backups and disaster-recovery planning.
- Audit logging and selected system activity logs.
- Vulnerability assessments, penetration testing, and internal security audits.
Data breaches
We maintain an incident-response procedure to detect, respond to, and mitigate security incidents and data breaches, including escalation workflows and post-incident reviews.
If a data security breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, affected individuals.
Third-party links and services
The Service may link to or integrate with third-party websites and services. This Policy does not cover those third parties, and we are not responsible for their privacy practices.
Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated version with a revised “Last updated” date.
Contact us
Privacy Officer / Data Protection Contact
TechVerdi SA
Av. Charles-Ferdinand Ramuz 60, 1009 Pully, Switzerland
Email: office@techverdi.ch
VAT / UID: CHE-110-027.685

