Last updated: 1 July 2026
Privacy Policy
This privacy policy informs you about how we process personal data when you visit our website or use Onboard as software-as-a-service.
1. Controller
Responsible for the data processing within the meaning of Art. 4 No. 7 GDPR: Jeremy Meya, Meya Business Solutions (MBS) Walczer Straße 21 59368 Werne Germany Email: [email protected] Onboard is operated as a sole proprietorship. A data protection officer has not been appointed under Art. 37 GDPR in conjunction with § 38 BDSG, as neither the number of employees nor the type of processing requires this. Please address privacy requests directly to the email above.
2. Purposes and legal bases of processing
We process your personal data exclusively on the basis of statutory provisions. Legal bases are in particular Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal obligations) and Art. 6(1)(f) GDPR (legitimate interests).
3. Hosting and sub-processors
The application and the primary database are hosted in the EU (Frankfurt). We use the following sub-processors, which process personal data on our behalf: • Supabase – database, authentication, storage (EU, Frankfurt) • Vercel – hosting of the web application (EU / global edge network) • Stripe – billing and voucher sales (Ireland/EU · USA) • Resend – delivery of transactional email (EU · USA) • Anthropic – AI assistant and help chat (Claude) (USA) • OpenAI – voice input (Whisper), optional (USA) • Vapi – phone assistant, voice AI for inbound calls (USA) • Twilio – phone numbers and call routing for the phone assistant (USA · EU) • Cloudflare – Turnstile bot protection and DDoS defence (global) • Google – Reserve with Google (EU · USA) • Google Firebase (FCM) – push notifications to the mobile staff app (EU · USA) • Apple (APNs) – push notifications to the iOS staff app (USA) • Expo / EAS – build and delivery of the mobile staff app (USA) An always-current overview with purpose and region is additionally available on the Security page. We have a data processing agreement pursuant to Art. 28 GDPR in place with each of these providers.
4. Cookies
We use only technically necessary cookies on the website and — with active consent — cookies for reach measurement. Details and consent withdrawal via the cookie banner.
5. Server logs
When you visit the website, technically necessary server logs are recorded (IP address, timestamp, user agent, requested URL). These are deleted after a short period.
6. Contact form
If you send us a message via the contact form, we process your inputs to handle your request. Delivery is via Resend; bot defence is via Cloudflare Turnstile.
7. Accounts and billing
When you create an Onboard account, we process master data (name, email) and — on paid subscription — the data required for billing via Stripe.
8. Signing in with Google (Google Sign-In)
Onboard lets you sign in with a Google account ("Continue with Google" or Google One Tap). If you use this option, we process only the following user data provided by Google: • Your name • Your email address • Your Google profile picture • Your unique Google account identifier (Google Account ID) For this we request only the standard sign-in permissions (the OpenID Connect scopes openid, email and profile). We do not access any other Google services such as Gmail, Google Calendar, Google Drive or your contacts. Purpose and use: this data is used solely to create your Onboard account or sign you in and to pre-fill your profile (name, email, profile picture). It is stored with our processor Supabase (EU, Frankfurt). We do not share this Google user data with third parties (other than the processors required to operate the service listed above), do not sell it, and do not use it for advertising or to train AI models. The legal basis is Art. 6(1)(b) GDPR (performance of the usage relationship) and Art. 6(1)(a) GDPR (consent to sign in with Google). Limited Use: Onboard's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Revocation: you can revoke the connection to your Google account at any time — in your Onboard account settings or via myaccount.google.com under "Third-party apps & services".
9. Menu, reservation and guest data
In operations we process data you enter as a customer under a data processing relationship — e.g. guest profiles and employee data. The legal basis is the data processing agreement.
10. Recipients of the data
Data recipients are the services listed under ‘sub-processors’ and authorities to the extent a legal obligation applies.
11. Data subject rights
You have the right to information, correction, deletion, restriction of processing, data portability, objection and complaint to a supervisory authority.
12. AI-assisted help chat and transfers to third countries
On our documentation pages we offer an AI-assisted help chat. The questions you enter are sent to Anthropic (Claude) in order to generate the answer. Anthropic processes the content solely to respond to your request and does not use it to train its models. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in efficient user support). The bot protection on our public forms via Cloudflare Turnstile is likewise based on Art. 6(1)(f) GDPR (legitimate interest in abuse and spam prevention). Some of the service providers we use also process data in the USA — in particular Anthropic, OpenAI, Cloudflare, Resend, Stripe, Vapi, Twilio, Apple (APNs), Google (Firebase/FCM) and Expo, as well as Vercel’s global edge network. Such transfers are based on the EU Standard Contractual Clauses pursuant to Art. 46 GDPR and, where the respective provider is certified, the EU-US Data Privacy Framework. The primary database and application run in the EU (Frankfurt). AI answers may contain errors; for binding information please contact our support.
13. Consumer account and retention periods
For restaurant discovery ("Entdecken") and managing your own reservations, you can create a guest account. We process your email address and session data via our provider Supabase (EU, Frankfurt). The legal basis is Art. 6(1)(a) GDPR (registration) or Art. 6(1)(f) GDPR (provision of the search and management features). You can delete your account at any time. Retention: we delete contact enquiries no later than twelve months after final processing; server logs after a few days; accounts until you delete them, plus statutory retention periods for billing-relevant data.
14. Updates
We update this privacy policy when our processing activities change. The latest version applies.