Privacy policy
Last updated: 27 August 2026
This policy applies to https://carta.so, https://app.carta.so, customer accounts, public menus and communications with Carta.
1. Controller
Luca Huerse, Karl-Schurz-Straße 13, 70190 Stuttgart, Germany, hey@carta.so, +49 152 23373152
No data protection officer has currently been appointed.
2. Roles
Carta is controller for the website, account and contract administration, billing, support, security and its own communications. For personal data and usage statistics processed on a restaurant’s instructions, the restaurant will generally be controller and Carta processor. The DPA applies.
3. Website access and logs
When a page is accessed, IP address, time, URL, HTTP and status data, referrer, browser and device information are processed. Purposes are secure delivery, troubleshooting and abuse prevention. The legal basis is Article 6(1)(f) GDPR and, where contract-related, point (b). The internal standard period for application logs is 30 days; security incidents or provider requirements may require a different period.
Hosting is provided by Vercel Inc. The exact execution region and log retention must be confirmed before production launch. Third-country transfers are protected by an adequacy decision, valid EU-US DPF certification or Standard Contractual Clauses.
5. Account and authentication
We process email address, optional name, user ID, roles, session and security data and accepted document versions. Legal bases are Article 6(1)(b), (c) and (f) GDPR. Authentication, database and storage are provided by Supabase, Inc.; the currently expected but not yet verified project region is Zürich, Schweiz (eu-central-2). One-time codes are sent by Resend, Inc. Optional Google login is provided by Google Ireland Limited.
7. AI features
When import, assistant or translation features are used, selected images, PDF files, menu and restaurant text, chat messages and configuration are sent to Anthropic, PBC. Under the current design, the Wi-Fi password is not sent. The purpose is the requested extraction, translation or editing. According to current provider information, the commercial API does not use inputs or outputs for training by default and generally deletes them within 30 days. Zero Data Retention has not been agreed; abuse or legal cases may be retained longer.
AI output may be incorrect. Prices, allergens, additives and translations are published only after express review and approval by the restaurant operator.
9. Communications, accounting and domain
Support data are processed under Article 6(1)(b) and (f) GDPR. Billing and tax data are processed under points (b) and (c) and managed through Haufe-Lexware GmbH & Co. KG (Lexware Office). The domain is administered through Namecheap, Inc. No payment provider is currently integrated; this policy will be updated before one is introduced.
10. Recipients and third-country transfers
Recipients are the named hosting, database, authentication, email, AI, OAuth, accounting and domain providers, authorised team members, advisers and authorities where legally required. Third-country transfers take place only under an adequacy decision or appropriate safeguards, particularly Standard Contractual Clauses and a supplementary assessment.
11. Retention and exit
Accounts and product data are stored during the contract. After termination, a transition period of no more than 30 calendar days is followed by a retrieval period of at least 30 calendar days. Production data are then deleted unless a legal basis requires retention. Once the documented backup system is in place, backup copies are overwritten or deleted within no more than a further 90 days. Statutory retention duties remain unaffected.
12. Security
Carta uses encrypted transmission, role-based access, database tenant isolation, private file storage, secret management, logged publishing and deletion processes. Regular backups, restoration tests and a documented incident process will be established before public production launch.
13. Rights
Subject to the GDPR, data subjects have rights of access, rectification, erasure, restriction, portability and objection. Requests should be sent to hey@carta.so. For restaurant content, the identified restaurant operator is primarily responsible.
14. Complaints
Complaints may be submitted to the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, or any other competent supervisory authority.