Legal

Privacy Policy

Last updated 16 July 2026 · Deposiq is a service of Horecarte BV

This Privacy Policy explains how Horecarte BV, trading as Deposiq (“Deposiq”, “we”, “us”), handles personal data when you use our website deposiq.com and our application app.deposiq.com (together, the “Service”).

Template to be reviewed by legal counsel before it is relied upon. Complete the company details in brackets (KvK number, registered address, VAT) before publishing.

1. Who we are

The Service is operated by Horecarte BV, a company incorporated in the Netherlands (KvK [number], registered office [address], VAT [number]). For questions about this policy or your data, contact us at privacy@deposiq.com.

2. Our two roles

We process personal data in two different capacities:

  • As controller — for data about our own customers (the merchants who open a Deposiq account) and visitors to our website: account details, billing information and support correspondence.
  • As processor — for data that a merchant collects from their own guests through Deposiq (for example a guest’s name, contact details and deposit evidence). Here the merchant is the controller; we process this data only to provide the Service to them, under the Data Processing Agreement.

3. What we collect

Merchant account data

  • Name, business name, email address and password (stored hashed).
  • Plan, usage counts and billing records.
  • Payment-provider connection details (e.g. your Stripe or Mollie account identifier — never your customers’ card numbers).
  • Support messages and tickets.

Guest & deposit data (processed for the merchant)

  • Guest name, email and/or phone number entered by the merchant.
  • Deposit amount, status, method and timeline of events.
  • Evidence uploaded by the merchant (photos, documents), fingerprinted with SHA-256.
  • Technical data such as IP address and timestamp recorded against guest actions, for audit and fraud-prevention purposes.

4. Cookies

Our website uses no analytics, advertising or third-party tracking cookies, and no tracking scripts. The application sets a single strictly-necessary session cookie so you stay signed in. Because this cookie is essential to a service you have requested, it is exempt from consent under the ePrivacy Directive — which is why you will not see a cookie banner. If we ever introduce analytics or marketing cookies, we will ask for your consent first.

5. Why we process data (legal bases)

  • Performance of a contract — to provide the Service you signed up for.
  • Legitimate interests — to secure the Service, prevent abuse and improve the product.
  • Legal obligation — to meet accounting and tax duties.
  • Consent — where specifically requested (e.g. optional communications).

6. Payments

Deposiq is not a payment institution and never holds or moves your funds. Card deposits run on the merchant’s own Stripe or Mollie account. We never receive or store full card numbers; card data is handled by the PCI-DSS certified payment provider.

7. Sub-processors

We use a small number of carefully selected providers to run the Service. All are located in the European Union:

Sub-processorPurposeLocation
Hetzner Online GmbHCloud hosting & infrastructureGermany / Finland (EU)
Stripe Payments Europe, Ltd.Card payment processing (on the merchant’s own connected account)Ireland (EU)
Mollie B.V.Payment processing (on the merchant’s own connected account)Netherlands (EU)
Brevo (Sendinblue SAS)Transactional email deliveryFrance (EU)

8. International transfers

Personal data is stored and processed within the European Union. We do not transfer personal data outside the EU/EEA. Should that ever change, we will rely on an appropriate safeguard such as the European Commission’s Standard Contractual Clauses.

9. How long we keep data

Merchant account data is kept for as long as your account is active and for a reasonable period afterwards, and longer where the law requires (e.g. Dutch fiscal retention). Guest and deposit data is retained according to the merchant’s instructions and is deleted or returned when our agreement with the merchant ends, subject to any legal retention the merchant is bound by.

10. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and object to the processing of your personal data, and the right to data portability. To exercise a right, email privacy@deposiq.com. If your data was collected by a merchant through Deposiq, we will forward your request to that merchant, who is the controller. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

11. Security

We apply technical and organisational measures to protect personal data, described on our Security page.

12. Changes

We may update this policy from time to time. Material changes will be announced through the Service. The date at the top shows when it was last revised.

13. Contact

Horecarte BV — privacy@deposiq.com.