Privacy Policy

Last updated: August 13, 2026

This Privacy Policy explains how Springlink OÜ, registry code 17416182, processes personal data and uses cookies and similar technologies when you visit Springlink websites, use the manager platform, communicate with us, or use a Springlink-powered restaurant service.

1. Our roles

  • Springlink is the controller for its website visitors, prospects, manager accounts, billing contacts, security records, support communications, and platform usage data.
  • A restaurant is normally the controller for its loyalty members, offers, referrals, and restaurant website interactions. Springlink processes that data on the restaurant's behalf.
  • Springlink is the controller for the global account and authentication needed to let a restaurant client use one session across restaurant pages.

2. Data we collect

  • Identity and contact data, such as name, email, phone number, language, and login details.
  • Business data, including restaurant identity, manager role, locations, and billing information.
  • Loyalty data, such as memberships, points, rewards, referrals, offers, consent, and Wallet passes.
  • Content supplied for restaurant websites, menus, marketing rules, and communications.
  • Technical data, including IP address, device, browser, cookies, identifiers, and activity logs.
  • Support, sales, payment-status, and other communications with Springlink.

3. Why we use data

PurposeTypical legal basis
Provide accounts, websites, loyalty, Wallet passes, offers, support, and billingContract or steps requested before contract
Secure, diagnose, prevent abuse, and improve the ServicesLegitimate interests and legal obligations
Measure use and marketing performanceConsent where required; otherwise legitimate interests
Send restaurant marketing by email, SMS, or push notificationConsent or another basis available to the restaurant under applicable law
Comply with tax, accounting, privacy, and law-enforcement dutiesLegal obligation

4. Automated communications and AI

Springlink AI can generate and automatically send restaurant communications according to rules selected by the restaurant. The restaurant can change or pause those rules. These marketing operations do not make decisions that produce legal or similarly significant effects. Springlink does not use restaurant-client personal data to train its own general-purpose AI models.

5. Sharing and processors

We share data only where needed with the restaurant concerned, authorised managers, payment, hosting, security, analytics, communications, wallet, mapping, social-media, AI, professional-adviser, and public authority recipients. Our main service providers are listed in the Subprocessor List. We do not sell personal data.

6. International transfers

Springlink hosts its main service and database in Frankfurt, Germany. Some providers can process data outside the European Economic Area. Where required, we use an adequacy decision, EU Standard Contractual Clauses, and supplementary safeguards.

7. Retention

  • Active-account data is retained while needed to provide the Services.
  • After an ordinary paid-account closure, account data is scheduled for permanent deletion, typically within 180 days.
  • After a trial-account closure, account data is scheduled for permanent deletion within 60 days.
  • An authorised manager can request accelerated deletion from [email protected]. After verification, the manual process can take up to 48 hours and is irreversible.
  • Restaurant clients can request deletion through [email protected]. We verify identity and involve the restaurant where it is the controller.
  • Tax, payment, contract, consent, security, and dispute records remain as long as legally necessary.
  • Inaccessible backup copies expire under the protected backup cycle.

8. Restaurant separation

A restaurant client can use one session to visit several restaurants, but must join each restaurant separately. Springlink does not expose one restaurant's membership, loyalty, or marketing data to another restaurant.

9. Cookies and similar technologies

A cookie is a small text file stored by your browser. Similar technologies include local storage, pixels, tags, and software identifiers. Springlink uses them on springlink.io, the Springlink manager application, Springlink subdomains, and custom restaurant domains powered by Springlink. A restaurant can also be a controller for technologies used for its loyalty, website, and marketing purposes.

TypePurposeExamples
RequiredAuthentication, security, language, referrals, sessions, and service operationSpringlink authentication, language, and referral cookies
AnalyticsUnderstand visits, navigation, errors, feature use, and performancePostHog and Google Analytics
MarketingMeasure advertising and campaign effectivenessGoogle Ads and related measurement tags
External mediaDisplay content provided by another serviceInstagram feeds, maps, videos, and social content

Cookie banner choice

The Springlink banner lets you Continue or Reject. It stores the selected banner choice for one year so that the banner does not appear on every visit. Deleting the choice in your browser causes the banner to appear again. The current banner records your selection. It does not delay analytics or marketing technologies before you select a button.

Current technologies and duration

The precise cookie names can change when providers update their services. Springlink currently uses browser storage and cookies for authentication, language choice, referral attribution, PostHog analytics, Google advertising measurement, and the Springlink banner choice. Session technologies expire when the session ends or under the applicable authentication period. The banner choice remains for one year. Other persistent technologies remain for the period configured by Springlink or the provider unless removed earlier.

Browser controls

You can inspect, block, or delete browser cookies through your browser settings. Blocking required cookies can prevent login, language, loyalty, referral, or other functionality from working. Provider-specific controls and browser privacy features can also limit analytics and advertising technologies.

10. Your rights

Subject to applicable law, you can request access, correction, deletion, restriction, portability, or objection. You can withdraw consent at any time without affecting earlier lawful processing. You have an absolute right to object to direct marketing. You can complain to the Estonian Data Protection Inspectorate or your local supervisory authority.

11. Children

Restaurant-client membership is intended for people aged 15 or older. Manager accounts are for adults authorised by a business. If we learn that data was collected contrary to an applicable age rule, we will take appropriate steps to remove it.

12. Security

We use access controls, encryption in transit, protected hosting, logging, backups, and organisational controls appropriate to the risks. No online service is completely secure. Please notify us promptly if you suspect unauthorised account use.

13. Changes and contact

We can update this policy and will publish its new effective date. For privacy requests, contact [email protected] or Springlink OÜ, Krüüsli tn 3-2, Kristiine linnaosa, 12916 Tallinn, Estonia.

Ready to grow your restaurant with smart marketing?

Become the most successful restaurant in town with Springlink.

Alexis Boix
Alexis BoixSpringlink cofounder

Book a 30‑minute demo with Alexis

I’ll walk you through how Springlink helps restaurants bring guests back automatically.