Skip to main content
FeaturesMeet DomPricingAboutFAQ
EN
EnglishENDeutschDEHrvatskiHRFrançaisFREspañolESPolskiPLSlovenčinaSKČeštinaCSItalianoITMagyarHUSrpskiSRΕλληνικάELTürkçeTRSlovenščinaSL
Start Free
EN
EnglishENDeutschDEHrvatskiHRFrançaisFREspañolESPolskiPLSlovenčinaSKČeštinaCSItalianoITMagyarHUSrpskiSRΕλληνικάELTürkçeTRSlovenščinaSL
FeaturesMeet DomPricingAboutFAQStart Free

Legal

Privacy Policy

This policy explains what personal data Forkestra handles, why we handle it, who it may be shared with, and the choices available to you.

Effective 10 August 2026Draft

On this page

Who we areScope and our rolesData we handleHow we use dataDom and AICookies and analyticsWhen we share dataInternational transfersRetentionSecurityYour rightsContact us

1. Who we are

Forkestra is a venue-operations service. In this policy, “Forkestra”, “we”, “us”, and “our” refer to the provider of that service.

Privacy contact: info@forkestra.app

2. Scope and our roles

This policy covers the Forkestra website, owner and manager application, staff and chef companion apps, digital menus, Dom conversations, connected messaging channels, and related support and billing services.

We act as a controller for data needed to operate our website, manage accounts, bill customers, keep the service secure, communicate with users, and improve Forkestra. When a venue sends us operational or staff data so we can provide the service, we generally act as that venue’s processor. The venue remains responsible for deciding why that data is used and for giving its team members any notices required by law.

If you are a venue employee and want to exercise a right relating to staff, rota, attendance, absence, or similar records, contact your employer first. We will assist the venue in responding where required by our data-processing agreement and applicable law.

3. Data we handle

The data involved depends on which Forkestra features and integrations you use. It may include:

  • Account and identity data: name, work email, phone number, authentication identifiers, role, permissions, venue membership, and account settings.
  • Venue and operational data: POS transactions, sales, margins, products, inventory, waste, orders, deliveries, intake, suppliers, recipes, production plans, menus, prices, forecasts, and performance records.
  • Staff data: names, contact details, roles, shifts, availability, attendance, hours, labour cost, leave or absence information, shift-cover requests, and activity recorded through companion apps. Some absence information could reveal health-related data if a venue chooses to enter it.
  • Finance and document data: invoices, supplier details, uploaded images or files, extracted invoice fields, billing profile, tax details, subscription status, and payment references. Card details are handled by our payment provider rather than stored by Forkestra.
  • Dom and communication data: questions, responses, conversation history, feedback, approved actions, scheduled tasks and reports, uploaded files, channel identifiers, group participants, and the audit trail showing who requested or approved an action.
  • Integration data: identifiers, tokens, events, and content needed to connect a POS, Telegram, or another service you deliberately enable.
  • Device, usage, and security data: IP address, browser and device type, timestamps, app routes or product areas viewed, diagnostic events, consent choices, and security logs.
  • Website preferences: selected language and similar settings stored in your browser.

We receive data directly from you, from the venue that gives you access, from connected systems such as a POS or messaging channel, and from your use of Forkestra.

4. How and why we use data

Provide Forkestra

Run accounts, dashboards, forecasts, inventory, ordering, staffing, production, digital menus, Dom, reports, integrations, and support. Our legal basis is performance of our contract or steps requested before entering it.

Secure and improve the service

Prevent abuse, investigate failures, maintain audit records, understand feature adoption, and improve reliability. We rely on our legitimate interests in operating a safe and useful B2B service, while limiting the data used.

Billing and legal obligations

Administer subscriptions, calculate tax, keep accounting records, respond to lawful requests, and establish or defend legal claims. We rely on contract and applicable legal obligations.

Optional analytics and communications

Use product analytics, session replay, or send marketing where your consent is required. You can withdraw consent at any time without affecting earlier lawful processing.

Where we process customer data as a processor, the venue’s instructions and data-processing agreement determine the purpose and legal basis. A customer using staff or health-related information must have an appropriate lawful basis, access controls, and retention policy.

We do not sell personal data.

5. Dom and artificial intelligence

Dom is Forkestra’s AI venue manager. The interface identifies Dom as AI. To answer a question, prepare work, or carry out an authorised instruction, Forkestra may send relevant conversation content and venue data to an AI service provider under contractual data-protection controls.

Dom’s output is generated and can be incomplete or wrong. It is designed to support a human operator, not replace professional, legal, tax, employment, food-safety, or accounting judgement. Actions that require confirmation in Forkestra are carried out only after an authorised user approves them. Standing instructions—such as a report the owner has already scheduled—may run without a fresh approval each time and remain attributable in the audit trail.

Forkestra does not use Dom to make decisions based solely on automated processing that produce legal or similarly significant effects about individuals. Customers must not configure Forkestra as the sole decision-maker for employment or other high-impact decisions.

Dom is not intended to recruit, dismiss, promote, discipline, set pay, infer emotions or sensitive traits, or make a final worker-management decision based on profiling. Forkestra identifies Dom as AI. Where applicable law requires it, Forkestra will label AI-generated or manipulated content or supply machine-readable information designed to identify its artificial origin. A customer that publishes AI-generated material remains responsible for human editorial review and for preserving or adding legally required disclosures.

6. Cookies, local storage, and analytics

Forkestra uses necessary browser storage for authentication, security, consent choices, and requested preferences. Optional analytics storage is used only after the relevant consent. Our current first-party browser-storage register is:

Language preference

forkestra_locale is a necessary first-party cookie used to remember the website language you selected. It expires after up to 12 months.

Local language settings

forkestra.locale stores the equivalent preference in local storage until it is removed in the browser.

Consent record

forkestra_analytics_consent is a necessary first-party cookie on the website, owner app, and digital menu that records whether optional analytics was accepted or rejected. It expires after up to 180 days.

Venue and app preferences

forkestra_locale, forkestra_selected_venue_id, and forkestra_collapsed_panels remember the app language, selected venue, and panel state for up to 12 months. sidebar_state remembers sidebar state for up to 7 days.

Local app settings

forkestra:selected-venue-id, forkestra:period-nav, forkestra-theme, forkestra.sidebarCollapsed, forkestra.dom.readAt, and forkestra.dom.workspaceWidth preserve the selected venue, reporting period, appearance, navigation, and Dom workspace state until removed in the browser. A per-chat key records when a fresh-chat suggestion has been dismissed.

Temporary working state

inventory-stock-sort and venue-scoped inventory-stock-items entries keep sort choices and the current stock working set in session storage. They expire with the browser session; venue-scoped entries are also swept when their active scope changes.

Digital-menu preferences

forkestra_menu_language and forkestra_menu_intro_seen remember the menu language and whether its introduction has been seen for up to 12 months.

Sign-in and checkout

Clerk and Stripe may set cookies or similar storage strictly needed to authenticate a user, prevent fraud, maintain a secure session, or complete checkout. Their exact duration depends on the session or transaction.

Product analytics

After consent, PostHog may use cookies or local storage to distinguish a browser, measure feature use, and preserve the consented analytics session. Forkestra uses PostHog’s EU service endpoints; exact names and duration depend on the active project configuration.

Session replay

Replay is separately optional. When enabled, inputs and visible text are masked and the Dom panel is excluded. Replay storage and retention follow the consent and configured PostHog EU settings.

Website analytics

After consent on the public website, Google Analytics may set _ga and _ga_<measurement-id> cookies for up to two years to distinguish a browser and preserve session state. We disable Google Signals and advertising-personalisation features. Details and controls are in our Cookie Policy.

You can reject optional analytics or change the choice in cookie settings without losing the core service. Browser settings can also remove stored data, although blocking necessary storage may stop sign-in or other requested features from working. We update this register when a change materially affects browser storage.

7. When we share data

We disclose data only as needed for the purposes described above, including to:

  • The customer and its authorised users, according to venue roles and permissions.
  • Service providers, including Hetzner for EU-hosted production infrastructure, Clerk for authentication, Stripe for billing, PostHog for consented product analytics, Google Ireland Limited for consented public-website analytics, OpenAI for Dom capabilities, Mistral AI for document OCR, and Mailjet/Sinch Email for service email and report delivery. We may also use providers for support or monitoring where a feature requires them.
  • Connected services, such as a POS or Telegram, when a customer chooses to connect them. Those services process data under their own terms and privacy policies.
  • Advisers and authorities, where reasonably necessary to meet a legal obligation, protect rights and security, or establish and defend claims.
  • A successor organisation, as part of a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and data-protection safeguards.

We require processors to use personal data only on documented instructions and to protect it appropriately. Customers give general authorisation for subprocessors under the Data Processing Terms. We notify the account owner before a material new or replacement subprocessor begins handling Customer Data and provide a reasonable opportunity to object on documented data-protection grounds. A current subprocessor register, including processing purpose and transfer safeguard, is available from info@forkestra.app.

8. International transfers

Production infrastructure: Hetzner, hosted within the European Union.

Forkestra’s production application, databases, object storage, and backups are hosted by Hetzner in the EU. Some specialised providers may process data or permit support access outside the European Economic Area. Their jurisdictions are recorded in our current subprocessor register and are available on request. When personal data leaves the EEA, we use an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. Contact us to request information about the location and safeguard relevant to your data.

For non-personal data held in the EU, we use contractual, organisational, and technical measures designed to prevent unlawful international government access or transfer, including access controls, encrypted transport, review of requests, challenge where legally available, and disclosure limited to what is legally required. We will keep the infrastructure jurisdiction and this general description current on this page.

9. How long we keep data

We keep personal data only for as long as needed for the service, the customer’s documented instructions, security, dispute resolution, and legal or accounting obligations. The exact period depends on the record, plan, feature, and customer configuration.

Account and venue data is generally retained while the account is active. Account deletion removes the owner’s authentication identity and app-user record and disables the tenant and its venues. The production Janitor then archives inactive venues and permanently deletes venue-scoped application and analytics data after six months, unless law, a legal hold, or an unresolved claim requires longer retention.

Venue, item, and staff analytics aggregates are retained for up to two years. Item forecasts are retained for 30 days and venue forecasts for 120 days. Inactive Dom chats are compacted after 45 days; Forkestra keeps no more than the 100 most recent provider-backed chat contexts. Deleting a chat removes its messages, chat-owned uploads, participants, and linked channel state through a staged deletion process. Completed tasks, execution history, and other operational or audit records survive chat deletion and follow their own justified schedule.

Internal records for cancelled or expired subscriptions and related invoice references are scheduled for deletion after six months. Accounting copies are kept for the statutory period where required, including by our billing provider. Analytics/replay, security logs, uploads, reports, support records, and backups follow their configured provider or system lifecycle. Customers may request the applicable schedule or configure deletion where the product supports it.

10. Security

We use technical and organisational measures designed to protect data, including role-based access, authentication, encrypted transport, access logging, tenant separation, private storage for Dom uploads and reports, and deletion controls. No online service can guarantee absolute security. Customers are responsible for protecting their accounts, assigning appropriate roles, and telling us promptly about suspected unauthorised access.

11. Your choices and rights

Depending on where you live and how we process your data, you may have rights to be informed, access your data, correct it, request deletion or restriction, receive portable data, object to processing based on legitimate interests, withdraw consent, and avoid decisions based solely on automated processing that have legal or similarly significant effects.

Email info@forkestra.app to exercise a right. We may need to verify your identity. If a venue controls the relevant data, we will direct the request to that venue or assist it in responding. You may also complain to the Estonian Data Protection Inspectorate or the data-protection authority where you live or work.

Forkestra is a business service and is not directed to children. Venue customers are responsible for ensuring that any account holder is authorised to use the service and that staff data is handled lawfully.

12. Changes and contact

We may update this policy as Forkestra, our providers, or the law changes. We will post the revised version here and update its effective date. If a change materially affects how we use personal data, we will provide additional notice where required.

Questions and privacy requests can be sent to info@forkestra.app.

Sales, stock, staffing, and prep — all working in rhythm.

HomeFeaturesMeet DomPricingAboutFAQ
Explore Forkestra
AI restaurant & bar managerOperations overviewMenu optimisationLive digital menuInventory & orderingIntake & stock appStaff planningKitchen productionPOS integrations

Ask AI about Forkestra

ChatGPTClaudePerplexityGrok
Privacy PolicyTerms of ServiceCookie Policy
© 2026 Forkestra. All rights reserved.

Cookie choices

Choose how Forkestra uses cookies

Necessary cookies remember your language and choices. With your permission, Google Analytics helps us understand which pages are useful. We do not use advertising cookies. Cookie Policy

Cookie choices

Cookie preferences

You can change this choice at any time. Core website features work without analytics.

Necessary cookies

Remember your language and consent choice. These are required for the website preferences you request.

Always on
Cookie Policy

Cookie preferences saved.