Privacy Policy
This Privacy Policy explains how Digirete, MB collects, uses, and protects personal data when you use the Forko platform ("Service"), in line with the EU General Data Protection Regulation (GDPR) and applicable Lithuanian data protection law.
Digirete, MB
Company code: 306730607
Registered office: Vilties g. 5A, Dauparų k., LT-96169 Klaipėdos r.
Email: info@forko.lt
This policy applies to two groups of people: restaurant owners who register for and manage a Forko account, and diners who view a public menu page — their data is handled very differently, and this is noted below wherever it matters.
1. What data we collect
a) Restaurant owners (account holders)
- Account data — name, email address, password (stored hashed, never in plain text), and your chosen subdomain or custom domain.
- Verification data — a one-time verification code sent to your email to confirm your account (an SMS-based version using a phone number is planned but not yet active).
- Restaurant/business content — anything you enter into the admin panel: restaurant name, description, contact details, opening hours, menu items, prices, and images you upload.
- Billing data — subscription status, plan, and invoice history. We do not store your full card number; card details are entered directly into Stripe's own secure checkout and handled entirely by Stripe (see "Third parties" below).
- Technical data — IP address, browser/device information, and basic request logs, collected automatically for security and reliability purposes (e.g. rate limiting, fraud/bot protection, error diagnostics).
b) Diners (public menu visitors)
Viewing a public restaurant menu on Forko does not require an account, and we don't ask diners for any personal information to browse a menu. Diners are subject only to basic technical data collection (IP address, browser data) as described above, used solely for security and reliability, not for identifying or tracking individual diners.
2. Why we process your data (legal basis)
- Performance of a contract — to create your account, provide the Service, process your subscription, and deliver the features you're paying for.
- Legitimate interests — to keep the Service secure and reliable (fraud prevention, rate limiting, bot protection, error monitoring), and to communicate essential service-related messages.
- Legal obligation — where we're required to retain certain records (e.g. billing/accounting records) under applicable law.
- Consent — for anything not covered above, such as optional marketing communications or non-essential cookies, if introduced in the future. You can withdraw consent at any time.
3. Third parties we share data with
We use a small number of trusted service providers ("processors") to run the Service. We don't sell your data to anyone. The processors currently in use are:
| Provider | Purpose | Data involved |
|---|---|---|
| Stripe | Payment processing & billing | Payment/card details, billing address, subscription data |
| MailerSend | Sending transactional emails (verification codes, receipts, account notices) | Email address, email content |
| Cloudflare | DNS, network security, and bot/abuse protection (Turnstile) | IP address, technical request data |
| Sentry | Error monitoring, so we can find and fix bugs | Technical error data, may incidentally include account email/ID |
| Hetzner | Server hosting (EU-based, Germany) | All data described in this policy, as stored on our servers |
We only share what each provider needs to perform its specific function, under its own data processing terms. We may disclose data if required by law, court order, or to protect our rights, users, or the public.
4. International data transfers
Our server infrastructure (Hetzner) is located in the EU. Some of our processors (such as Stripe and Cloudflare) may process data outside the European Economic Area. Where that happens, we rely on the transfer mechanisms recognized under GDPR, such as Standard Contractual Clauses or an equivalent adequacy framework, as implemented by that provider.
5. How long we keep your data
- Account and restaurant data is kept for as long as your account is active.
- If you close your account, we delete or anonymize your personal data within a reasonable period, except where we're legally required to retain certain records (e.g. billing/invoice records, typically retained for the period required by Lithuanian accounting law).
- Technical/security logs are kept for a limited period sufficient for security and diagnostic purposes, then routinely deleted.
6. Cookies
We currently use only cookies that are strictly necessary for the Service to function — for example, to keep you logged in and to protect against cross-site request forgery. These don't require consent under applicable e-Privacy rules. If we introduce non-essential cookies in the future (such as analytics), we will update this policy and add a proper cookie consent mechanism before doing so.
7. How we protect your data
We apply reasonable technical and organizational measures to protect personal data against unauthorized access, loss, or misuse — including encrypted connections (HTTPS), access controls, rate limiting and bot protection, and monitoring for errors and abuse. No system is 100% secure, but we take these obligations seriously and continue to improve our security practices as the Service grows.
8. Your rights under GDPR
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten"), subject to legal retention obligations;
- Restrict or object to certain processing;
- Data portability — receive your data in a structured, commonly used format;
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us at info@forko.lt. You also have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (Valstybinė duomenų apsaugos inspekcija, VDAI) or your local supervisory authority.
9. Children's privacy
The Service is intended for business use by restaurant owners and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll remove it.
10. Changes to this policy
We may update this Privacy Policy from time to time, for example as the Service or our data practices evolve (such as adding real SMS verification or analytics tools). Material changes will be communicated by email or a notice in the admin panel before they take effect.
11. Contact
For any questions about this Privacy Policy or how your data is handled, contact us at info@forko.lt.