Privacy policy
Last updated 8 October 2026
How Bordly handles personal data: for guests who tap a table tag, and for the venues that use Bordly.
For guests
Short version: you are anonymous. We use no tracking cookies and no advertising. The café or restaurant you are visiting is the controller of your data; Bordly (Codexier (Jamshaid Amjad, enskild firma)) processes it on their behalf.
- Loyalty card: when you tap “Show my code”, a random code is stored in a cookie on your phone so the card is recognised next time. It is needed for the service you asked for.
- Email (optional): if you save your card with your email, we use it to find your card again and to tell you about your own card, for example that a reward is waiting. Offers are only sent if you ticked the box, and every email has an unsubscribe link.
- Feedback: what you write, your rating and any photo go to the owner. You only leave contact details if you want a reply.
- Statistics: we count visits without cookies, using a daily-rotating hash that can't be linked to you.
- Delete: under “Show my code” there is “Delete my card”, which removes the card immediately. You can also contact the venue or us at hej@codexier.com.
- Retention: cards unused for 24 months are deleted automatically. Raw visit statistics are deleted after 400 days.
Who is responsible for what
Guest data (loyalty cards, optional email, feedback): the venue is the controller. Codexier (Jamshaid Amjad, enskild firma) is the processor and handles the data only on the venue's instructions, under our data processing agreement.
Venue owner and staff accounts (name, email, password hash, billing): Codexier (Jamshaid Amjad, enskild firma) is the controller.
What we collect and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Loyalty card code and stamp history | Run the stamp card the guest asked for | Art. 6(1)(b) contract |
| Guest email (optional) | Find a lost card and send messages about the guest's own card; offers only with consent | 6(1)(b); offers 6(1)(a) consent |
| Feedback text, rating, photo, optional contact | Let the venue improve and reply | 6(1)(f) legitimate interest |
| Page visits (cookieless, daily-rotating hash) | Aggregate statistics for the venue | 6(1)(f) legitimate interest |
| Owner name, email, password hash | Account and security | 6(1)(b) contract |
| Billing details | Invoicing and bookkeeping (Bokföringslagen: 7 years) | 6(1)(c) legal obligation |
Cookies
We only set cookies that are strictly necessary for something you asked for: your loyalty card (guests), your login session (owners), your language choice, and a staff session on the scanner device. No analytics, advertising or third-party tracking cookies, so no cookie banner is needed under the Swedish Electronic Communications Act (LEK 9 kap. 28 §).
Sub-processors
| Provider | Purpose | Transfer safeguard |
|---|---|---|
| Vercel Inc. | Hosting and serverless functions (EU region, Frankfurt) | EU + SCCs / EU–US DPF |
| Supabase Inc. or Neon Inc. | Postgres database (EU region) | EU + SCCs |
| Resend Inc. | Sending emails (alerts, reports, campaigns) | SCCs / EU–US DPF |
| Stripe Payments Europe Ltd. | Subscription billing (venue owners only) | EU |
| Google LLC | Google Wallet passes; reading public rating via Places API | SCCs / EU–US DPF |
| Apple Inc. | Apple Wallet pass updates (push notifications) | SCCs / EU–US DPF |
| Anthropic PBC | AI menu import (menu text and photos only, no guest data) | SCCs / EU–US DPF |
Data is stored in the EU. Wallet and email providers may process data outside the EU under Standard Contractual Clauses or the EU–US Data Privacy Framework.
Retention
- Loyalty cards: deleted automatically after 24 months without use, or immediately on request.
- Feedback: kept until the venue deletes it or closes its account.
- Raw visit statistics: 400 days. Aggregated numbers have no personal data.
- Venue accounts: deleted with all guest data when the owner deletes the venue. Backups roll over within 30 days.
Your rights
You can ask for access, correction, deletion, restriction, portability, or object to processing. Guests: contact the venue or us at hej@codexier.com and we'll help the venue respond within 30 days. You can also complain to Integritetsskyddsmyndigheten (IMY), imy.se.
Security
TLS everywhere; passwords hashed with bcrypt; guest card secrets stored only as SHA-256 hashes; database row-level security that blocks direct API access; rate limiting against brute force; access to production limited to named staff at Codexier (Jamshaid Amjad, enskild firma).