Flowder

Last updated: September 7, 2026

Privacy Policy

This policy explains how Noblewolf AS (reg. no. 922 097 941) processes personal data as data controller for the Flowder service. We are also data processor on behalf of the restaurants when it comes to guest ordering data.

1. What we process

Restaurant users (paying customers)

  • Name and email at signup
  • Password (stored as PBKDF2-SHA256 hash)
  • Restaurant name, address, phone (optional)
  • Login log (IP, timestamp) for security
  • Billing info via Stripe — card numbers are not stored by us, only Stripe Customer ID + Payment Method ID

Restaurant guests (ordering via QR/takeaway/delivery)

  • Order details (dishes, prices, time)
  • Email and name only if given for confirmation/tracking
  • Phone number only for takeaway / delivery
  • Delivery address for delivery orders
  • Payment reference from Stripe (Payment Intent ID) — not card number
  • Table token (anonymous QR signature, no personal data)

2. Legal basis

  • Contract (GDPR art. 6(1)(b)): delivering the service
  • Legal obligation (art. 6(1)(c)): Norwegian bookkeeping law requires 5-year retention
  • Legitimate interest (art. 6(1)(f)): security logs, abuse prevention

3. Cookies

We use essential cookies only (no tracking, no marketing):

  • nwm_session — login token (30 days, HttpOnly, Secure)
  • nwm_lang — language preference (1 year)
  • nwm_cart_* — cart token for guest (sessionStorage)

Web analytics: We use Cloudflare Web Analytics for aggregate traffic statistics. It sets no cookies, does not fingerprint, and does not store IP addresses or other personal data about visitors. Fonts are served from our own servers — no third party (e.g. Google Fonts) is contacted when you open a menu.

4. Sub-processors

ProviderPurposeRegion
Cloudflare (Pages, D1, Workers)Hosting, databaseEU (Frankfurt)
Cloudflare Web AnalyticsAggregate, cookie-free traffic statisticsEU
Bunny CDNImages and mediaEU
Stripe Payments EuropePayment, subscriptionEU (Ireland)
ResendTransactional emailEU (Frankfurt)
OpenAIAI translation and image generationUSA (SCC)
AnthropicAI menu import from PDFUSA (SCC)

5. Retention

  • Restaurant account: while subscription active + 12 months
  • Order data (bookkeeping): 5 years per Norwegian law — but personal data on the order (name, phone, address, free-text notes) is removed automatically after 12 months. Amounts, items and payment reference are kept without any link to the guest.
  • Raw payment-provider (Stripe) data tied to an order: minimised after 12 months
  • Contact-form requests: 12 months
  • Login log: 90 days
  • Audit log: 12 months

Deletion runs automatically every night.

6. Your rights

  • Access to your data
  • Correction or deletion
  • Restriction or objection
  • Data portability (JSON/CSV export)
  • Complaint to Norwegian DPA — datatilsynet.no

Contact kontakt@noblewolf.no.

7. Security

  • All traffic HTTPS (TLS 1.3)
  • Passwords hashed with PBKDF2 (100 000 iterations)
  • Session cookies HttpOnly + Secure + SameSite=Lax
  • Rate limits on login and signup
  • Role-based access control (owner/admin/editor/viewer) with org isolation

8. Contact

Noblewolf AS
Email: kontakt@noblewolf.no
Data Processing Agreement available on request