Legal
Effective date: December 20, 2025
This Privacy Policy describes how Nicklas SARL, trading as The New Software Company ("Verjus", "we", "us"), collects, uses, and shares personal data when you use the Verjus platform (verjus.io) and related services.
Nicklas SARL — SIRET 91339724600012 — 31 Perspective de la Côte des Basques, 64200 Biarritz, France. Privacy contact: nicklasmenschel@gmail.com.
Verjus acts in two capacities depending on the data involved.
For restaurant owner account data (name, email, authentication credentials, billing information), Verjus is the data controller. For guest personal data (names, emails, phone numbers, booking history, preferences, notes) entered by restaurants or their guests through the platform, each restaurant is the data controller and Verjus is the data processor acting on the restaurant’s instructions.
When a guest makes a reservation or is added by a restaurant, the following data may be stored:
When a restaurant owner creates an account, we collect:
We process personal data to: provide the reservation and restaurant management platform; send transactional communications (booking confirmations, reminders, follow-ups); process payments via Stripe (guest deposits) and Mollie (restaurant subscriptions); send marketing communications to guests who have opted in (with one-click unsubscribe via RFC 8058 compliant links); maintain guest marketing profiles for restaurants; generate analytics and reports; detect fraud and enforce security; comply with legal obligations. We do not sell personal data.
We share personal data only with service providers who need it to deliver our platform. Each processor handles only the minimum data required for its function.
Guest payments (deposits, no-show charges) are processed by Stripe (US). Restaurant subscription billing is handled by Mollie (Netherlands). EU-to-US transfers are covered by Standard Contractual Clauses. Mollie operates within the EU.
We use third-party providers to send transactional emails (booking confirmations, reminders) and SMS notifications. These providers receive only the recipient's contact details and message content.
We use industry-standard cloud services for hosting, file storage, error monitoring, and performance optimization. These providers may process anonymized technical data such as IP addresses and error logs.
A complete list of sub-processors is available upon request.
Restaurant owner data is retained for the duration of the account and deleted upon account closure or request. Guest data retention is configurable per restaurant, with a default of 365 days. Restaurants can configure anonymization of guest data after 730 days. Payment audit logs are retained as required for PCI-DSS compliance and legal accounting obligations. Email logs and webhook records are retained for operational debugging and compliance.
We implement appropriate technical and organizational measures to protect personal data. These include: hashed storage of email addresses and phone numbers (HMAC-SHA256); encrypted sensitive fields (dietary restrictions, allergies); immutable payment audit logs with actor tracking; rate limiting on API endpoints and webhooks; HTTPS for all data in transit. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Under the General Data Protection Regulation, you have the following rights:
Right of access
Right to rectification
Right to erasure
Right to restrict processing
Right to data portability
Right to object
To exercise any of these rights, contact us at nicklasmenschel@gmail.com
You also have the right to lodge a complaint with the CNIL (Commission Nationale de l’Informatique et des Libertés), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
Most data processing occurs within the European Union. Where data is transferred to the United States (Stripe, Sentry), transfers are governed by Standard Contractual Clauses (SCCs) as approved by the European Commission. We do not transfer data to countries without adequate data protection guarantees unless appropriate safeguards are in place.
We may update this Privacy Policy. Changes will be posted on this page with an updated effective date. For material changes, we will notify registered users by email.