Last Updated: July 24, 2026
This Privacy Policy explains how StartApp collects, uses, shares, and protects personal data when you visit our website, create an account, or use our platform. It also explains the role StartApp plays when we process the personal data of your own customers on your behalf. We are committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
For personal data relating to StartApp account holders and website visitors, the data controller is:
STARTAPP SOLUTIONS LIMITEDAI-assisted setup: if you use our AI menu import or AI website setup features, the menu photos, documents, and business details you provide for that purpose are sent to our AI sub-processor (Anthropic) to generate the result. This content is processed only to produce your output and is not used to train third-party models.
We process your personal data for the following purposes, each with a legal basis under Article 6 GDPR:
When your diners interact with your StartApp website or app — placing an order, booking a table, or creating an account — you are the data controller of that personal data and StartApp acts as your data processor, processing it only on your documented instructions to provide the service. Our responsibilities in that role are set out in our Data Processing Agreement, which forms part of our agreement with you. You remain responsible for informing your own customers about how you use their data.
We do not sell your personal data. We share it only with the sub-processors below, who help us run the platform and are bound by contract to protect it and use it solely to provide their service to us:
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing (you connect your own Stripe account; payouts go directly to you) | EU / USA |
| Anthropic (Claude) | AI menu import and website setup assistant | USA |
| Zoho Mail | Transactional and support email delivery | EU |
| DigitalOcean | Cloud hosting and file storage | EU (Amsterdam) |
| Google Firebase | Push notifications and authentication infrastructure | USA |
| Apple & Google | Publishing and distributing your mobile app | USA |
Some of our sub-processors are located outside the European Economic Area (notably in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards — primarily the European Commission's Standard Contractual Clauses — to ensure your data receives an equivalent level of protection.
We keep personal data only for as long as it is needed for the purposes above:
We use administrative, technical, and physical safeguards — including encryption in transit, encrypted storage of sensitive credentials, and access controls — to protect personal data. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the relevant authority of any qualifying breach without undue delay.
Subject to the conditions in the GDPR, you have the right to:
To exercise any of these rights, contact us at support@startapp.solutions. If you believe we have not handled your data properly, you also have the right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie) or your local supervisory authority.
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last Updated” date above; where changes are significant, we will take reasonable steps to notify you.
If you have any questions about this Privacy Policy or your data, please contact us at support@startapp.solutions.