Privacy Policy
Last updated: 2026-10-05
This is a first draft, written to be accurate about how the system actually works today. It has not been legally reviewed yet, it should be before it's the final version shown to real customers.
Matvy (RI Norby AB) runs a platform for restaurants – table bookings, online ordering and related services. This page explains what guest data we handle on a restaurant's behalf, and why.
What data we handle
A guest's name, phone number and email address at the time of booking, plus any note the guest or restaurant adds. The email address is required so we can send the confirmation and the link a guest uses to change or cancel it. We act as a data processor for the restaurant, which is the data controller for its own guests' information.
How long we keep data
Each restaurant sets its own retention window in settings. Once a booking passes that window, it's automatically anonymised, name, phone, email and note are removed, while party size, time and status remain for reporting. If a restaurant hasn't set a window, data is kept indefinitely.
Your rights
To correct or delete your information, contact the restaurant you booked with directly, they are the data controller. Questions about how Matvy itself handles data can go to the contact address below.
Cookies
Matvy sets a small number of cookies, all of them either necessary to keep you signed in or to remember your language and country. There are no analytics and no advertising trackers. Each one is listed, with its purpose and lifetime, on the cookies page. See the full list
The Matvy Staff app
Matvy Staff is the app restaurant staff use during service (Android, package name com.matvy.staff). It is a window onto matvy.com and keeps no copy of a restaurant's bookings or orders on the phone. The restaurant is the data controller for its guests' information and Matvy is its processor, as described above. What follows covers the staff members' own sign-in and use of the app.
What is stored on the phone
After sign-in the app keeps a session token that identifies that phone to Matvy, together with the staff member's email address and role and the restaurant's name and time zone. It also keeps the device's own choices: language, light or dark theme, whether sound is on and, if the restaurant uses a kitchen-ticket printer, that printer's network address. Nothing else is stored: no bookings, orders, menu or guest details are saved on the phone, and the session token is removed when the staff member signs out. The app does not ask for access to the phone's contacts, location, camera, microphone or photos.
What is sent
When a staff member signs in, the app sends their email address and password to matvy.com, together with the type of phone (Android) and the phone's model name, so the restaurant's manager can recognise and revoke the device in the dashboard. After that the app sends the session token with each request, and what staff do in the app: marking a booking arrived or seated, assigning a table, adding a walk-in or phone booking (guest name, phone number, optional email address and note), accepting or advancing an order, or marking a dish sold out. It receives the day's bookings and orders, including guest names, phone numbers and notes. All traffic uses an encrypted connection. If the restaurant's server has asked for them, the app also sends a short technical error report (the error message and its technical trace, the app version and the language) when something breaks. It never contains what is on the screen.
Notifications and Google (Firebase)
If the staff member allows it, the app registers the phone for notifications. The phone's notification token, a random identifier issued by Google's Firebase Cloud Messaging, is sent to Matvy and stored for that device so Matvy can reach it. When a new booking request or order arrives, Matvy sends a notification through Firebase Cloud Messaging. Its text contains the guest's name, party size and time for a booking, or the guest's name, total and requested time for an order. Google (Firebase) processes this on Matvy's behalf as a processor, only to deliver the notification to the phone. When a device is signed out or revoked, its notification token is deleted at Matvy.
No ads, no analytics
The app shows no advertising and contains no advertising or analytics software. It does not follow staff across other apps or websites. Data is not sold and is not shared with anyone other than the processors needed to run Matvy.
Deleting data
Signing out removes the session from the phone, and a restaurant's manager can revoke any device in the dashboard. To have a staff account, device records or other data about you deleted, or to ask what we hold, email support@matvy.com, or ask the restaurant's manager to. Guest data belongs to the restaurant: guests should contact the restaurant, as set out under Your rights above.
Contact
Questions about this policy or how we handle data can be sent to the contact address in the footer. support@matvy.com