Legal
Privacy policy
What data we process, why, who we share it with and how to exercise your rights.
Last updated: August 30, 2026
1. Who processes the data
The data controller is domangia, which provides the restaurant management system described on this site. You can contact us about any privacy matter at hola@domangia.com.
3. If you are only visiting this site
This site asks you for no data, has no forms and creates no account. There is no log-in and you are not identified.
Our infrastructure provider logs technical request data —IP address, time and page requested— for the sole purpose of serving the site and protecting it from abuse. We do not use it to profile anyone.
4. Cookies and measurement
This site uses no cookies. There are no analytics cookies, no advertising cookies and no third-party cookies, which is why there is no banner asking you to accept them: there would be nothing to accept.
We also load no third-party measurement tools and no tracking tags. The only thing the site stores in your browser is the language you picked, and only if you changed it.
The admin panel —which is a different application, at a different address— does use a technical cookie to keep you signed in. It is essential for the panel to work and is not used to track you.
5. Data about those who subscribe to domangia
If you register a business, we process the data needed to provide the service:
- Account data: name, email address and an encrypted, irreversible version of your password.
- Business data: name, public address, phone number, country and business type.
- Billing data: what the payment processor needs to charge the subscription. Full card details are handled by Stripe, not by us.
- Usage data: which modules you have subscribed to, plus technical activity logs used to diagnose problems.
6. Data about guests
When a guest scans the QR code and places an order, that order is stored against the table, not against the person. The public menu does not ask them to register or identify themselves.
As for data a business chooses to record about its own customers —in a booking, for example— that business is the data controller and we act as processor: we handle it on their instructions and solely to provide the service to them.
7. What we use the data for
- To provide the service and run the features you subscribed to.
- To charge your subscription and issue the corresponding receipt.
- To give you support when you ask for it.
- To meet legal, accounting and tax obligations.
- To protect the platform against fraud, abuse and unauthorised access.
8. Who we share it with
We do not sell data and we do not pass it on for commercial purposes. We share it only with the providers the service needs in order to exist, and only as far as necessary:
- The payment processor (Stripe), to charge the subscription.
- The infrastructure provider where the platform runs and the database is stored.
- The competent authorities, when a law or a court order requires it.
9. How long we keep it
While you have an active account, we keep your business's data so we can provide the service. On cancellation the account is paused and the data is kept for a reasonable period so you can retrieve it or reactivate; after that it is deleted.
Records we are legally required to keep —billing, mainly— are retained for the period that law sets, even if you have cancelled the account.
10. Your rights
You can ask us to access your data, correct it if it is wrong, delete it, obtain a machine-readable copy, object to a processing activity or ask us to restrict it. Write to hola@domangia.com and we will respond.
These rights are granted to you, depending on where you are, by Law 25.326 on the Protection of Personal Data in Argentina, the Lei Geral de Proteção de Dados (LGPD) in Brazil and the General Data Protection Regulation in the European Union. If you believe we did not handle your request properly, you can complain to your country's supervisory authority.
11. How we protect it
Each business's data is isolated in the database itself, not just in the screen that queries it: a badly written query cannot return another business's information because the database refuses it.
All traffic travels encrypted over HTTPS. Passwords are not stored: we keep an argon2 hash, which cannot be turned back into the original password. Access within each business is controlled by role, and material changes are logged.
12. Changes to this policy
If we update this policy, we change the date in the header and, when the change is material, we tell you by email or from the admin panel before it takes effect.
13. Contact
For any privacy question or to exercise your rights, write to hola@domangia.com. We reply in Spanish, English and Portuguese.