Last updated: September 7, 2026
Privacy Policy
This policy explains how Noblewolf AS (reg. no. 922 097 941) processes personal data as data controller for the Flowder service. We are also data processor on behalf of the restaurants when it comes to guest ordering data.
1. What we process
Restaurant users (paying customers)
- Name and email at signup
- Password (stored as PBKDF2-SHA256 hash)
- Restaurant name, address, phone (optional)
- Login log (IP, timestamp) for security
- Billing info via Stripe — card numbers are not stored by us, only Stripe Customer ID + Payment Method ID
Restaurant guests (ordering via QR/takeaway/delivery)
- Order details (dishes, prices, time)
- Email and name only if given for confirmation/tracking
- Phone number only for takeaway / delivery
- Delivery address for delivery orders
- Payment reference from Stripe (Payment Intent ID) — not card number
- Table token (anonymous QR signature, no personal data)
2. Legal basis
- Contract (GDPR art. 6(1)(b)): delivering the service
- Legal obligation (art. 6(1)(c)): Norwegian bookkeeping law requires 5-year retention
- Legitimate interest (art. 6(1)(f)): security logs, abuse prevention
3. Cookies
We use essential cookies only (no tracking, no marketing):
nwm_session— login token (30 days, HttpOnly, Secure)nwm_lang— language preference (1 year)nwm_cart_*— cart token for guest (sessionStorage)
Web analytics: We use Cloudflare Web Analytics for aggregate traffic statistics. It sets no cookies, does not fingerprint, and does not store IP addresses or other personal data about visitors. Fonts are served from our own servers — no third party (e.g. Google Fonts) is contacted when you open a menu.
4. Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Cloudflare (Pages, D1, Workers) | Hosting, database | EU (Frankfurt) |
| Cloudflare Web Analytics | Aggregate, cookie-free traffic statistics | EU |
| Bunny CDN | Images and media | EU |
| Stripe Payments Europe | Payment, subscription | EU (Ireland) |
| Resend | Transactional email | EU (Frankfurt) |
| OpenAI | AI translation and image generation | USA (SCC) |
| Anthropic | AI menu import from PDF | USA (SCC) |
5. Retention
- Restaurant account: while subscription active + 12 months
- Order data (bookkeeping): 5 years per Norwegian law — but personal data on the order (name, phone, address, free-text notes) is removed automatically after 12 months. Amounts, items and payment reference are kept without any link to the guest.
- Raw payment-provider (Stripe) data tied to an order: minimised after 12 months
- Contact-form requests: 12 months
- Login log: 90 days
- Audit log: 12 months
Deletion runs automatically every night.
6. Your rights
- Access to your data
- Correction or deletion
- Restriction or objection
- Data portability (JSON/CSV export)
- Complaint to Norwegian DPA — datatilsynet.no
Contact kontakt@noblewolf.no.
7. Security
- All traffic HTTPS (TLS 1.3)
- Passwords hashed with PBKDF2 (100 000 iterations)
- Session cookies HttpOnly + Secure + SameSite=Lax
- Rate limits on login and signup
- Role-based access control (owner/admin/editor/viewer) with org isolation
8. Contact
Noblewolf AS
Email: kontakt@noblewolf.no
Data Processing Agreement available on request