Documentation · Data and backups
Where your data lives, how it is backed up, and what you take with you if you leave
Signing up for management software means handing somebody your till, your menu and your customer list. This page answers, without hedging, the three questions you should ask before signing with anyone — us included: where that data lives, who copies it, and what happens to it the day you walk away.
One-line summary: the data sits on a server in Germany (EU), it is copied every night and the copy verifies itself, and the day you leave you take your data as a ZIP with one CSV per table.
1. Where the data lives
| Main server | A server in Nuremberg (Germany), inside the European Union, rented from Hetzner Online GmbH. Your website, bookings, online shop, POS and their databases all live there. |
| Backups | On that same German server, in a directory only the system administrator can reach. |
| Network and DNS | Cloudflare, in front of the server, for the CDN and attack protection. |
| Payments | We do not store card numbers or bank accounts: Stripe and GoCardless process them in their own systems. |
| Everyone else | The full list of data processors, with their purpose and their country, is published in the privacy policy. |
The full list of data processors — who each provider is, what it processes data for and which country it sits in — is published in the privacy policy.
2. The backups
A backup nobody checks is not a backup: it is an assumption. So what gets published here is not "we do backups", but how often, of what, how long it is kept and how it is verified.
| How often | An automatic backup every night, at 03:17 UTC. It does not depend on anybody remembering: a scheduled job on the server runs it. |
| What is copied | Every database in the system — bookings, POS (including the Verifactu records), online shop — plus the files you upload yourself: shop product images and the attachments from the onboarding form. |
| What is NOT copied | The code, because it is regenerated from the repository. It is not your data and storing it twice adds nothing. |
| How long it is kept | The last 14 days. Each night the new copy is added and anything older than that is removed. |
| Where | On the same Nuremberg server that runs production, in a directory restricted to the administrator. |
| How we know it works | The copy is verified the same night it is taken: the file is checked for corruption and checked to actually contain the POS and bookings databases. If anything fails, the job ends in an error instead of printing "OK". There is also a restore drill that recovers the POS database into a throwaway database and compares row counts against production; the last one ran on 17 July 2026 and matched. |
3. What you take with you, and what happens if you cancel
- The data is yours, in writing. The terms of service state that the client keeps ownership of their brand, their content — text, images, menu — and their data; we only hold a licence to host and display it while we provide the service.
- No lock-in. The subscription can be cancelled at any time. The service stays live until the end of the period already paid for, and then does not renew.
- A package of your data, not a handful of loose reports. From the admin panel, the account holder can download their data as a single ZIP file holding one CSV per table, according to the modules they subscribe to: POS sales and menu, recipe costings if you have Stock & Recipes, bookings if you have the bookings module, and your customers. Whatever you do not subscribe to is not in there, simply because it does not exist. That is the format Excel opens and any accountant accepts, and you do not have to ask us for it — the account holder downloads it, an employee cannot. If you would rather request it by email, we deliver it within a maximum of 5 business days.
- And what is deliberately NOT inside. Credentials and keys are never exported — your tax certificate, tokens, the public booking and waiting-list links, Stripe identifiers: a ZIP that travels by email or lands in a downloads folder is no place for the keys to your business. Neither is the Verifactu ledger, which is kept separately because it is tax material belonging to the Spanish tax authority and out of context it only confuses. Nor the audit log, because it would cross employee, IP, device and time — data that exists to be minimised, not to travel inside a ZIP.
- And the individual reports, separately. Alongside the full package, the panel still exports sales reports, business analytics, the activity log, till movements and the Incentives commission report as CSV, for when you want one specific figure rather than everything.
- The right behind it. The GDPR right to data portability — having your data handed over so you can take it to another controller — is set out in the privacy policy and is exercised by writing to [email protected].
- What happens to the data afterwards. Once the relationship ends it is kept only for the applicable legal periods — up to 6 years for commercial documentation and up to 4 for tax obligations — and then erased or anonymised, unless a legal obligation requires keeping it. The periods per type of data are detailed in the privacy policy.
Frequently asked questions
Where exactly is my data hosted?
On a server located in Nuremberg (Germany), inside the European Union, rented from Hetzner Online GmbH. Your operational data — website, bookings, online shop and POS — is not hosted outside the European Economic Area. The providers that are outside it, such as the CDN or transactional email delivery, are listed one by one, with their country and their transfer basis, in the privacy policy.
Do you take backups? How often, and how long do you keep them?
Yes. An automatic backup every night at 03:17 UTC, covering the complete databases — bookings, POS with its Verifactu records, online shop — and any files you have uploaded. They are kept for the last 14 days. The copy is verified the same night it is taken: if the file came out corrupt or a database were missing from it, the job ends in an error instead of giving an "OK" nobody would check.
If I cancel, what do I take with me?
Your data — while you are a client and once you stop being one: that is written into the terms of service. From the admin panel, the account holder can download their data as a single ZIP file with one CSV per table, according to the modules they subscribe to — POS sales and menu, recipe costings if you have Stock & Recipes, bookings if you have the bookings module, your customers. That is the format Excel opens and any accountant accepts, and the account holder downloads it, not an employee; if you would rather request it by email, we deliver it within a maximum of 5 business days. Deliberately left out: credentials and keys (tax certificate, tokens, public booking and waiting-list links, Stripe identifiers), the Verifactu ledger — tax material kept separately — and the audit log, which crosses employee, IP, device and time. Separately from the package, the panel still exports the individual CSV reports for when you only want one specific figure.
And is my data deleted once I leave?
Once the relationship ends it is kept only for the periods Spanish law requires — up to 6 years for commercial documentation and up to 4 years for tax obligations — and after those periods it is erased or anonymised, unless another legal obligation requires keeping it. The exact periods, by type of data, are in the privacy policy, which is the document that governs.
Who can see my business data?
Each business is a separate tenant inside the system and only ever sees its own. On our side, administrative access belongs to the founder, who maintains the infrastructure and answers support. We do not sell or hand data to third parties; the only third parties that process it are the data processors listed in the privacy policy, each under its own GDPR article 28 contract.
Does this page replace the privacy policy?
No. This page explains things in plain language. The documents that bind are the legal notice, the terms of service, the privacy policy and the cookie policy. If anything here seemed to say something different from them, they govern.
The documents that govern
This page explains; it replaces nothing. What binds is here: privacy policy, terms of service, legal notice and cookie policy.
More worried about what happens when something breaks than about where it is stored? Then read 24/7 support and what to do if the POS fails mid-service and the full offline-mode table.