Privacy
Datenschutzerklärung.
Who is responsible
Lihtar Ventures UG (haftungsbeschränkt)
Kolonnenstraße 8
10827 Berlin
Germany
Data protection questions go to contact@bentoplan.com.
No data protection officer is appointed. Neither Art. 37 GDPR nor § 38 BDSG requires one at our size.
What we store
| Data | Why | Legal basis |
|---|---|---|
| Venue name, address, opening hours | To locate the venue in a weather grid cell and know when it trades | Art. 6(1)(b) — performance of contract |
| Daily totals: orders, revenue, closed flag | The series the forecast is fitted to | Art. 6(1)(b) |
| Operator notes and event flags | To mark which history to distrust | Art. 6(1)(b) |
| Account name and email | Authentication and the daily notification | Art. 6(1)(b) |
| Sign-in records: IP address, browser | To keep you signed in, and to notice an account being attacked | Art. 6(1)(f) — securing the service |
| Support messages and any file you attach | To answer the request and keep a record of the answer | Art. 6(1)(b) |
| Device token, if you turn on notifications | To deliver the daily forecast to that device | Art. 6(1)(b) |
| Server logs | Operating and debugging the service | Art. 6(1)(f) — keeping the service up |
All of it is data you give us, except the logs and sign-in records, which the service produces as you use it. The account details and the daily totals are what makes a forecast possible: without them there is no service to provide. Nothing else on this list is required of you.
What we deliberately do not store
No guest or reservation records. Counts per service, never people. This keeps the personal-data surface to your own account details and nothing about your customers.
No transaction-level data. Daily totals only. We could not reconstruct an individual receipt if asked to.
No amounts in our logs. Logs record how many rows moved, not what was in them.
Where it lives
Everything you enter is stored in Germany. Analytics and session recordings are held in the EU as well.
PostHog is an American company holding its EU data in Frankfurt, and Google and Apple pass data to their US parents. Those transfers run on the European Commission's standard contractual clauses.
Who else sees it
| Processor | Where it processes | Purpose | Data shared |
|---|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Germany | Hosting and server infrastructure | Everything the service stores |
| Cloudfleet GmbH, Berlin, Germany | Germany | Server infrastructure orchestration | Access to the hosting environment; no data of its own |
| Twilio Ireland Limited, Dublin, Ireland | EU | Transactional email | Recipient email address, message content |
| Google Ireland Limited, Dublin, Ireland | EU, with transfers to Google LLC in the US | Sign in with Google | Email address, first and last name |
| Stripe Payments Europe, Limited, Dublin, Ireland | EU, with transfers to Stripe, Inc. in the US | Subscription billing and payment processing | Billing name and email, billing address, subscription and invoice records |
| Apple Distribution International Limited, Cork, Ireland | EU, with transfers to Apple Inc. in the US | Sign in with Apple | Email address or a Private Relay forwarding address, name if you share it |
| Google Ireland Limited, Dublin, Ireland | EU, with transfers to Google LLC in the US | Web analytics on the marketing site | Pseudonymous usage data from bentoplan.com |
| PostHog Inc., San Francisco, United States | Germany (AWS Frankfurt) | Session replay and product analytics | Product usage events and session recordings |
Card details never reach us. They go from your browser to Stripe, which stores them and is the only party able to charge them. For fraud prevention and its own regulatory obligations Stripe decides on its own account what to do with payment data, and is a controller in its own right for that rather than our processor.
Weather and city events come from third parties we call. They receive a coordinate and a date range. They are never given anything about you or your venue.
Retention
Trading history is kept for as long as the account is open, because a forecast is only as good as the history behind it. On deletion it goes, and so does everything derived from it.
Support tickets and their attachments are kept while the account is open. Sessions are deleted when they expire. Server logs are kept for 14 days. A device token goes when notifications are turned off, or when the device stops accepting them.
Automated decisions
The forecast is a model fitted to your venue's own trading history, the weather over it and the events around it. It predicts orders and revenue for a venue. It makes no decision about a person, automated or otherwise, so Art. 22 GDPR does not apply.
Your rights
Access, rectification, erasure, restriction, portability and objection under Art. 15–21 GDPR, plus the right to complain to a supervisory authority — for Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Where we rely on a legitimate interest, you can object under Art. 21 GDPR. Where you have given consent, you can withdraw it at any time, which leaves everything done before the withdrawal lawful.
Requests go to the address in the imprint.
Changes
Last updated 27 August 2026. If this policy changes we will replace the text here and move that date.