Privacy Policy
Last updated: August 13, 2026
This Privacy Policy explains how Springlink OÜ, registry code 17416182, processes personal data and uses cookies and similar technologies when you visit Springlink websites, use the manager platform, communicate with us, or use a Springlink-powered restaurant service.
1. Our roles
- Springlink is the controller for its website visitors, prospects, manager accounts, billing contacts, security records, support communications, and platform usage data.
- A restaurant is normally the controller for its loyalty members, offers, referrals, and restaurant website interactions. Springlink processes that data on the restaurant's behalf.
- Springlink is the controller for the global account and authentication needed to let a restaurant client use one session across restaurant pages.
2. Data we collect
- Identity and contact data, such as name, email, phone number, language, and login details.
- Business data, including restaurant identity, manager role, locations, and billing information.
- Loyalty data, such as memberships, points, rewards, referrals, offers, consent, and Wallet passes.
- Content supplied for restaurant websites, menus, marketing rules, and communications.
- Technical data, including IP address, device, browser, cookies, identifiers, and activity logs.
- Support, sales, payment-status, and other communications with Springlink.
3. Why we use data
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, websites, loyalty, Wallet passes, offers, support, and billing | Contract or steps requested before contract |
| Secure, diagnose, prevent abuse, and improve the Services | Legitimate interests and legal obligations |
| Measure use and marketing performance | Consent where required; otherwise legitimate interests |
| Send restaurant marketing by email, SMS, or push notification | Consent or another basis available to the restaurant under applicable law |
| Comply with tax, accounting, privacy, and law-enforcement duties | Legal obligation |
4. Automated communications and AI
Springlink AI can generate and automatically send restaurant communications according to rules selected by the restaurant. The restaurant can change or pause those rules. These marketing operations do not make decisions that produce legal or similarly significant effects. Springlink does not use restaurant-client personal data to train its own general-purpose AI models.
5. Sharing and processors
We share data only where needed with the restaurant concerned, authorised managers, payment, hosting, security, analytics, communications, wallet, mapping, social-media, AI, professional-adviser, and public authority recipients. Our main service providers are listed in the Subprocessor List. We do not sell personal data.
6. International transfers
Springlink hosts its main service and database in Frankfurt, Germany. Some providers can process data outside the European Economic Area. Where required, we use an adequacy decision, EU Standard Contractual Clauses, and supplementary safeguards.
7. Retention
- Active-account data is retained while needed to provide the Services.
- After an ordinary paid-account closure, account data is scheduled for permanent deletion, typically within 180 days.
- After a trial-account closure, account data is scheduled for permanent deletion within 60 days.
- An authorised manager can request accelerated deletion from [email protected]. After verification, the manual process can take up to 48 hours and is irreversible.
- Restaurant clients can request deletion through [email protected]. We verify identity and involve the restaurant where it is the controller.
- Tax, payment, contract, consent, security, and dispute records remain as long as legally necessary.
- Inaccessible backup copies expire under the protected backup cycle.
8. Restaurant separation
A restaurant client can use one session to visit several restaurants, but must join each restaurant separately. Springlink does not expose one restaurant's membership, loyalty, or marketing data to another restaurant.
9. Cookies and similar technologies
A cookie is a small text file stored by your browser. Similar technologies include local storage, pixels, tags, and software identifiers. Springlink uses them on springlink.io, the Springlink manager application, Springlink subdomains, and custom restaurant domains powered by Springlink. A restaurant can also be a controller for technologies used for its loyalty, website, and marketing purposes.
| Type | Purpose | Examples |
|---|---|---|
| Required | Authentication, security, language, referrals, sessions, and service operation | Springlink authentication, language, and referral cookies |
| Analytics | Understand visits, navigation, errors, feature use, and performance | PostHog and Google Analytics |
| Marketing | Measure advertising and campaign effectiveness | Google Ads and related measurement tags |
| External media | Display content provided by another service | Instagram feeds, maps, videos, and social content |
Cookie banner choice
The Springlink banner lets you Continue or Reject. It stores the selected banner choice for one year so that the banner does not appear on every visit. Deleting the choice in your browser causes the banner to appear again. The current banner records your selection. It does not delay analytics or marketing technologies before you select a button.
Current technologies and duration
The precise cookie names can change when providers update their services. Springlink currently uses browser storage and cookies for authentication, language choice, referral attribution, PostHog analytics, Google advertising measurement, and the Springlink banner choice. Session technologies expire when the session ends or under the applicable authentication period. The banner choice remains for one year. Other persistent technologies remain for the period configured by Springlink or the provider unless removed earlier.
Browser controls
You can inspect, block, or delete browser cookies through your browser settings. Blocking required cookies can prevent login, language, loyalty, referral, or other functionality from working. Provider-specific controls and browser privacy features can also limit analytics and advertising technologies.
10. Your rights
Subject to applicable law, you can request access, correction, deletion, restriction, portability, or objection. You can withdraw consent at any time without affecting earlier lawful processing. You have an absolute right to object to direct marketing. You can complain to the Estonian Data Protection Inspectorate or your local supervisory authority.
11. Children
Restaurant-client membership is intended for people aged 15 or older. Manager accounts are for adults authorised by a business. If we learn that data was collected contrary to an applicable age rule, we will take appropriate steps to remove it.
12. Security
We use access controls, encryption in transit, protected hosting, logging, backups, and organisational controls appropriate to the risks. No online service is completely secure. Please notify us promptly if you suspect unauthorised account use.
13. Changes and contact
We can update this policy and will publish its new effective date. For privacy requests, contact [email protected] or Springlink OÜ, Krüüsli tn 3-2, Kristiine linnaosa, 12916 Tallinn, Estonia.

