Privacy Policy

Last updated: July 2026

This Privacy Policy explains how Oryyx, based in Zurich, Switzerland ("Oryyx", "we", "us", "our"), processes personal data when you use our Services — the website oryyx.ch and the digital ordering and payment platform provided through it. Oryyx enables hospitality businesses ("Venues") to let their guests ("Guests") order and pay at the table via QR code or NFC in the browser, without installing an app. This Policy applies to both Venues and Guests. Swiss data protection law (the revised Federal Act on Data Protection, revDSG) applies. Where the EU General Data Protection Regulation (GDPR) applies to you, it applies in addition. If you have any questions, contact us at contact@oryyx.ch.

1. Data we collect

Data you provide to us: • Venue accounts: your name, email address, password (stored in hashed form), venue details, and the connection to your Stripe account. • Guest accounts (optional): your name, email address, and password (stored in hashed form), along with your loyalty-card balance. You can use the Services and place orders without an account. • Orders: the items ordered, amounts, table number, and timestamps; optionally an email address for your receipt. Payment data: card and payment details are processed exclusively by our payment provider, Stripe. Oryyx does not receive or store full card numbers. Data collected automatically: when you use the Services, we collect technical data such as your IP address, browser and device information, and server log data. We use this to operate, secure, and troubleshoot the Services.

2. How we use your data

We use personal data to: • provide and operate the Services and manage accounts; • process and fulfil orders and enable payment (via Stripe); • send transactional messages, such as order confirmations and loyalty notifications; • ensure security and prevent fraud and abuse; • maintain, analyse, and improve the Services; • comply with legal obligations (for example, accounting and tax retention). We do not use your data for third-party advertising, and we do not sell your personal data.

3. Legal bases

Where the GDPR or revDSG requires a legal basis, we rely on: • Performance of a contract — to provide the Services, manage your account, and process orders and payments; • Legitimate interests — to keep the Services secure, prevent fraud and abuse, and improve our offering; • Consent — for example, when you choose to create an optional Guest account; you may withdraw consent at any time; • Legal obligation — for example, to retain financial records for statutory periods.

4. Who we share data with

Venues: when a Guest places an order, the relevant Venue receives the order details it needs to prepare and fulfil the order. Service providers (processors) who process data on our behalf under contract: • Stripe — payment processing; • TWINT — payment method (via Stripe); • Vercel — website and application hosting; • Neon — database hosting; • Google Cloud — storage of images, such as menu photos; • Resend — sending transactional email. Legal and safety: we may disclose data where required by law, regulation, or legal process, or to protect our rights, safety, or property or those of others. Business transfers: we may transfer data as part of a merger, acquisition, financing, or sale of assets.

5. Cookies and similar technologies

We use only essential cookies and similar technologies: • a cookie to remember your language preference (German or English); • authentication cookies to keep you signed in to your account. We do not use advertising cookies or third-party tracking for marketing purposes.

6. How long we keep data

We keep personal data only as long as necessary for the purposes described in this Policy, or for as long as required by law — for example, financial and transaction records are retained for the statutory retention periods. When data is no longer needed, we delete or anonymise it.

7. How we keep data safe

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, hashed passwords, and access controls. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

8. Children

The Services are directed at Venues and their guests, not at children. We do not knowingly collect personal data from children without appropriate consent. If you believe a child has provided us with personal data, please contact us and we will delete it.

9. Your rights

Depending on where you are located, you have rights under the revDSG and/or the GDPR, including the right to: • access the personal data we hold about you; • have inaccurate data corrected; • have your data erased; • restrict or object to certain processing; • receive your data in a portable format; • withdraw consent where processing is based on consent. To exercise these rights, contact us at contact@oryyx.ch. You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, your local data protection authority.

10. International data transfers

Some of our service providers (for example, Stripe, Vercel, and Google) may process data outside Switzerland or the EU, including in the United States. Where this happens, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses and equivalent Swiss mechanisms, to protect your data.

11. Updates to this Policy

We may update this Policy from time to time. The current version is indicated by the "Last updated" date at the top of this page. We encourage you to review it periodically.

12. Contact

For questions about this Policy or how we handle your data, contact us at contact@oryyx.ch (Oryyx, Zurich, Switzerland).