Skip to content
Security & data protection

What We Do With Your Data

Written for the person who has to sign off on us. Everything below is something the platform actually does — and the last section answers the five questions every security questionnaire asks.

Architecture and Hosting

Cloud

Google Cloud and Firebase — Firestore and Realtime Database, Cloud Functions, Firebase Authentication, Cloud Storage and Hosting, plus a MongoDB reporting replica, a Redis cache and a queue for reporting sync.

Region

Your tenant runs in the Google Cloud region agreed at provisioning — EU and UK tenants in Europe, others in the region closest to their operations. A tenant is moved only with written agreement.

Tenancy

Per-tenant isolation: every record is stored under your tenant, and database security rules plus server-side middleware check the tenant on every read and write. Dedicated projects are available on enterprise plans.

Client integrity

Firebase App Check — reCAPTCHA v3 on web, Play Integrity on Android, App Attest on iOS — validates that requests come from genuine builds of your apps.

Encryption and Payments

Where card data goes — and how it stays out of our systems.

In transit

TLS for every app, API and webhook. HTTPS only.

At rest

Google Cloud encrypts databases, storage and backups at rest. Provider secrets are held server-side and are never returned to a browser or app once saved.

Card data

Never stored on our systems. Cards are tokenised by your processor, and card-present terminals talk directly to it — which puts the platform out of PCI DSS scope.

Access and Roles

Identity
Firebase Authentication: email and phone OTP for customers, staff accounts issued by your admins. OTP bypass identities are disabled by default and enabled per project only for app-store review.
Roles
Role-based access with signed claims — admin, co-admin, outlet owner, outlet manager, franchise, zone and dispatch manager, driver, customer and enrolled device. Money-moving actions are server-side and audit-logged.
Devices
Kiosk, POS and kitchen displays enrol with a single-use 8-character code and are tied to one outlet. The in-store tablet pairs with a one-time PIN and then uses a rotating device secret. POS refunds require a manager PIN, and any device can be deactivated and its tokens revoked from the admin.
Rate limiting
On every public API and webhook.

Sub-processors

The named providers that process data on our behalf. Payment gateways, POS systems, delivery networks and your own SMS or email sender are contracted by you directly, so they are not our sub-processors — those are listed on integrations. Changes are published here; where your agreement includes a sub-processor notice period, it applies.

Sub-processors used by the platform
Provider Purpose Location
Google Cloud / Firebase Application hosting, database and authentication Your tenant’s agreed project region
MongoDB (hosted) Reporting database behind the analytics endpoints Region confirmed on request
Upstash Redis Cache and rate limiting Region confirmed on request
Amazon Web Services (SQS) Queue moving order events to the reporting database Region confirmed on request
Cloudinary Image storage and delivery for menu and brand assets Global CDN
Sentry Error monitoring EU or US, per account configuration
Google Maps Platform Addresses, delivery zones and driver tracking Global
OneSignal Push delivery, where our platform account is used rather than yours US

This website

Netlify (Hosting and form submissions for this website); Crisp (Chat widget on this website); Cal.com (Demo booking widget on this website — the form you fill in to pick a slot); HubSpot (Form submissions and attribution — analytics consent only); Google Analytics (Aggregate traffic measurement — analytics consent only).

Privacy Tooling

You are the controller. These are the tools we give you to act like one.

  • Per-channel marketing consent (email, SMS, push) recorded with its provenance — the source, version and actor of every consent change — and SMS STOP/START honoured through a suppression list.
  • Built-in erasure: a customer erasure purges the profile, addresses, saved-card references and favourites, and redacts that customer from order records.
  • Contact fields are masked by default in reports and CSV exports; an unmasked export is logged.
  • You are the controller and hold the data-subject relationship; we assist under the Data Processing Annex.

Backups and monitoring

Managed backups of the primary database, with the retention and restore procedure described on request. Error monitoring scrubs request headers, cookies and bodies, and integration health checks surface provider failures in the admin.

Data ownership and export

You own your data. Export menus, customers, orders and reports at any time as CSV, JSON or PDF and through the reporting API. After termination your data stays available for export, read-only, for 90 days.

For your security questionnaire

Five Questions Procurement Always Asks

Answered here the way we answer them on the form, so nothing surprises you later in the process.

  • Certifications

    Do you hold SOC 2 or ISO 27001?

    The platform runs on Google Cloud, whose infrastructure carries those certifications. Supaorder does not hold a separate report of its own today — and everything an auditor would ask for is written up on this page and in the Data Processing Annex.

  • Support and availability

    Is support 24/7, and is there an uptime guarantee?

    Support runs business hours with fast responses across time zones, and response-time targets are written into your contract — a commitment you hold, rather than a marketing availability figure. Planned maintenance is announced in advance.

  • Card data

    Are you PCI DSS certified?

    Card data goes from the customer's device straight to Stripe, Finix or your chosen processor — each PCI DSS certified — and never touches our servers. That is what keeps both of us out of PCI scope.

  • Data protection

    Are you GDPR compliant?

    Compliance belongs to you as controller, and the platform is built to make it straightforward: consent provenance on every record, erasure that reaches orders and exports, masked exports, and a Data Processing Annex covering us as processor. We call it GDPR-ready, because compliance is a property of how you run it.

  • Hosting

    Are you on AWS or US data centres?

    Your tenant runs on Google Cloud in the region agreed at provisioning — EU and UK tenants in Europe — and is moved only with written agreement. One queue component runs on AWS; nothing is placed in the US by default.

Questions, the full Data Processing Annex and the Master SaaS Agreement are available from contact@devkart.com.

Ready to Keep 100% of Your Revenue?

Get your own branded ordering platform. Live in as little as 48 hours — zero commission, no contracts.

Book a live demo on a real store · Free setup for early customers