Product policy snapshot reviewed 5 September 2026. Scope: the current SofraPiwas web service.
The policy on SofraPiwas’s website is the maintained product source. For deletion requests, use our account-deletion page.
Piwas, operator of SofraPiwas
- Registered name
- Piwas
- Contact person
- Mahmut Kaya
- Business address
- Aulentistraat 159
2132 HG Hoofddorp
Netherlands - Chamber of Commerce
- KVK 95898115
- VAT identification
- NL005177244B88
- domainio@piwas.nl
- Phone
- +31 6 86433636
Product privacy contact: mahmutkaya.nl@gmail.com.
Who is responsible
The company named above is the controller for the data described here — the data of SofraPiwas's own customers and partners. This page does not cover a restaurant's own guests: their bookings and orders live in that restaurant's own installation, and that restaurant publishes its own privacy policy for them.
What we collect
For accounts: your name, email address and a password hash. For billing: your company's legal name, address, registration number, VAT number and billing email, together with payment records from our payment provider and what the VAT service returned when we checked your number. If you contact us or apply to the partner programme, whatever you write in the form, including a phone number and city if you give them. For a partner: the restaurants you introduce, their contact details and your notes on them. We keep security logs of sign-in attempts, which include the email address that was tried. We run no analytics and no advertising trackers.
Why
To give you an account, to bill you, and to issue the invoices the law requires us to issue. We check VAT numbers against the European Commission's VIES service so we can apply the right tax treatment, and we keep the reference of that check as evidence.
How long we keep it
Invoices, and the billing details printed on them, are kept for the period Dutch tax law requires. Sign-in and administrative logs are kept for 18 months. A partner application we turned down is kept for 12 months, then deleted. Sign-up invitation links expire and are deleted after 30 days. Accounts and CRM records are kept while the relationship lasts, and we remove them on request — there is no automatic clock on those. If your restaurant leaves us — including at the end of a free trial — we keep one encrypted backup of its data for 24 months, so you can pick up where you left off if you come back. You can ask us to delete it sooner and we will.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to the address above and we will answer. Some things we cannot delete on request, and it is fairer to say so: an issued invoice and the legal details printed on it, because we are required to keep them; and security logs, until their 18 months are up.
Cookies
A session cookie when you are signed in, and a cookie remembering your language. Your light or dark preference is stored in your browser and never sent to us. No analytics or advertising cookies.
Who else sees it
We use a small number of suppliers, and each receives only what its job needs. We also check VAT numbers against the European Commission's VIES service, which means sending it the number you gave us.
- Netcup GmbH — hosting and databases (Germany)
- Mollie B.V. — subscription payments (Netherlands)
- Resend — email delivery (United States)
- Sentry — error monitoring (EU)
- GitHub (Microsoft) — code, builds, and restaurant provisioning records including name, city and administrator email (United States)