Privacy Policy
Last updated: 25 July 2026 · Applies to xereport.online and the XEREPORT service
On this page
1. Who we are
This Privacy Policy is issued by XEREPORT OÜ ("XEREPORT", "we", "us", "our"), a private limited company registered in Estonia under registry code 17560134, with its registered address in Tallinn, Estonia. XEREPORT operates the website xereport.online and the Restaurant Vitals Report service (the "Service").
We are committed to protecting personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Estonian data protection law.
2. Data we collect
We collect and process the following categories of data:
| Category | Examples | Source |
|---|---|---|
| Account & billing data | Name, business name, email, phone, billing address, VAT number | Provided directly by you |
| Connected system data | POS sales records, accounting ledger entries, delivery-app order, commission and payout data | Read-only APIs from your POS, accounting and delivery-platform providers (Wolt, Bolt Food, Foodora, Uber Eats, Glovo) |
| Communications | Contact-form submissions, support emails, call notes | Provided directly by you |
| Technical data | IP address, browser type, device identifiers, pages visited | Automatically collected via cookies and server logs |
3. Why we process your data
- To generate your signed monthly Restaurant Vitals Report (Prime Cost, Delivery Margin, Cash Runway, Bankability Score).
- To create and administer your account and process billing.
- To respond to enquiries submitted through our contact form or by email.
- To maintain the security, integrity and performance of the Service.
- To comply with legal and accounting obligations.
- Where you have given consent, to send service updates and improve the Service using analytics.
4. Legal basis for processing
We rely on the following legal bases under Article 6 GDPR:
- Contract performance — processing connected-system data to generate your report and provide the Service you subscribed to.
- Legitimate interest — securing our systems, preventing fraud, and improving the Service, balanced against your rights and freedoms.
- Consent — for optional analytics cookies and marketing communications, which you may withdraw at any time.
- Legal obligation — retaining billing records as required by Estonian accounting and tax law.
5. Who we share data with
We do not sell personal data. We share data only with:
- Sub-processors providing EU-based hosting, infrastructure and email delivery, bound by data processing agreements.
- Your connected providers (POS, accounting, delivery platforms) solely to the extent required to retrieve data you have authorized us to access.
- Professional advisors (accountants, auditors, legal counsel) under confidentiality obligations.
- Authorities where required by law or a valid legal request.
6. Data retention & the 90-day deletion rule
XEREPORT is built around data minimisation:
- Source transaction data retrieved from your POS, accounting system and delivery-platform APIs is automatically and permanently deleted no later than 90 days after collection.
- Signed monthly reports (the finished PDF output) are retained for as long as your account remains active, or until you request deletion.
- Account and billing data is retained for the duration of the contract plus any period required by Estonian tax and accounting law (generally 7 years for accounting records).
- Contact-form and support communications are retained for up to 24 months for service-quality purposes, unless you request earlier deletion.
- Upon account cancellation, you may request immediate deletion of all source data; deletion will in any event occur automatically within the 90-day window described above.
7. How we protect your data
- Encryption in transit (TLS) and at rest.
- Read-only API access to connected systems — we never write to or modify your live POS, accounting or delivery-platform accounts.
- Role-based access control limiting employee access to the minimum necessary.
- EU-based hosting infrastructure.
- Regular review of security practices and incident-response procedures.
8. Your rights under the GDPR
Subject to applicable conditions, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Request erasure of your data ("right to be forgotten");
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Withdraw consent at any time, without affecting prior processing;
- Lodge a complaint with a supervisory authority, including the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
To exercise any of these rights, contact us at privacy@xereport.online. We respond to verified requests within 30 days.
9. Cookies
Our website uses essential cookies required for the site to function, and — only with your consent — optional analytics cookies to help us understand site usage. See our Cookie Policy for full details and how to manage your preferences.
10. International transfers
Our infrastructure is hosted within the European Union. Where a sub-processor is located outside the European Economic Area, we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses.
11. Children's data
The Service is intended for business use by restaurant operators and is not directed at individuals under 18. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via the website or by email to active account holders. The "Last updated" date above reflects the most recent revision.
13. Contact & complaints
XEREPORT OÜ · Registry Code 17560134 · Tallinn, Estonia
Data protection enquiries: privacy@xereport.online
General enquiries: hello@xereport.online