Legal

Privacy Policy

This policy explains how Delitip collects, uses, shares, and protects information when businesses, staff, and guests use delitip.com and the Delitip platform.

Last updated: August 30, 2026 · Draft placeholder pending counsel review

1. Who we are and what this policy covers

Delitip, of Pelasgon 32, Heraklion, Greece (“Delitip,” “we,” “us,” or “our”), provides a digital tipping, employee recognition, and customer feedback platform. We are the data controller for the personal information described in this policy, unless stated otherwise.

This policy applies to information processed through: our marketing website; the business dashboard used by owners, managers, accountants, and staff; employee profiles created within a business's account; and the QR-code tipping and review flow used by customers at the point of service. It does not cover third-party sites we link to, or a business's own website or systems outside delitip.com.

2. Information we collect

Business and staff accounts. When a business signs up or invites staff, we collect email address, phone number, first and last name, a hashed password, and role (Owner, Manager, Employee, or Accountant). We never store passwords in plain text.

Employee profiles. A business can add employee profiles that include name, email, position, and an optional photo. Employee profiles are typically created and maintained by the business, not by the employee directly; see Section 13 for how employees can exercise their own rights over this information.

Uploaded media. Business logos, cover images, and employee photos that a business uploads are stored on our behalf by our cloud storage provider (Section 6).

Tipping and review activity (customers). Customers scan a QR code to tip and optionally rate or review an employee or business. This flow does not require an account. We collect the tip amount and currency, a payment reference from our payment processor, and, if the customer chooses to leave one, a star rating and written feedback. Providing a name or email address at this step is always optional — if left blank, the tip or review is recorded without any identifying information about the customer. We do not collect or store the customer's IP address, device identifiers, or location as part of this flow.

Payment information. Card and bank details are collected and processed directly by our payment processor, Stripe. Delitip does not receive or store full card numbers; we store only a payment reference and status supplied by Stripe.

Communications. If you contact us, or if a business subscribes staff to optional marketing communications, we collect the content of that correspondence and the contact details needed to respond.

Usage information. Our servers and hosting infrastructure generate standard technical logs (such as timestamps and request status) needed to operate and secure the service. We do not currently use analytics, advertising, or tracking cookies on delitip.com.

3. How we use information

We use the information described above to:

  • operate the tipping, review, and feedback flow, and process payments and payouts through Stripe;
  • show businesses and employees their own tips, reviews, feedback, and performance analytics;
  • generate feedback summaries and sentiment analysis using our AI provider (Section 5), to help businesses spot trends without reading every review manually;
  • create, secure, and support user accounts, including password resets and account verification;
  • send transactional communications, such as password-reset codes and service notices;
  • send optional marketing communications where a recipient has opted in (Section 14);
  • detect, investigate, and prevent fraud, abuse, and security incidents;
  • comply with legal, tax, and accounting obligations; and
  • improve and maintain the platform.

We do not sell personal information, and we never will.

4. Legal bases for processing (EEA/UK users)

Where the General Data Protection Regulation (GDPR) applies, we rely on the following legal bases:

  • Contract: to create and administer business, staff, and employee accounts, and to process tips and payouts.
  • Legitimate interests: to keep the platform secure, prevent fraud and abuse, generate aggregate feedback analytics for a business, and improve the service — balanced against your interests and rights.
  • Consent: where a customer voluntarily provides their name or email with a tip or review, and for optional marketing communications.
  • Legal obligation: to meet tax, accounting, and payment-regulation requirements.

5. How we use AI to process feedback

We use OpenAI's models to analyze the sentiment of, and generate trend summaries from, review and feedback text submitted by customers, so a business can see patterns (for example, a satisfaction shift or a recurring complaint) without reading every entry individually. Review and feedback text may be sent to OpenAI for this purpose under a data-processing agreement that restricts its use of that content. Composite metrics such as the Customer Experience Score are informational and always shown with an explanation of the factors behind them — we do not use AI to make fully automated decisions that produce legal or similarly significant effects about any individual, such as employment or disciplinary decisions.

6. Who we share information with

We share information with the following categories of service providers, each acting on our instructions to help us run the platform:

  • Stripe — payment processing, payouts, and connected business accounts;
  • OpenAI — feedback sentiment analysis and summarization (Section 5);
  • Google Cloud Storage — storage of uploaded logos, cover images, and employee photos;
  • Resend and our SMTP provider — delivery of transactional and, where opted in, marketing email;
  • Twilio — delivery of one-time SMS verification codes;
  • Google Maps — geocoding and time zone lookup for a business's location, not for tracking any individual's location; and
  • our infrastructure and hosting providers, who host the application and database.

A business using Delitip can see tips, reviews, feedback, and analytics for its own locations and employees. Employees granted dashboard access can see their own tips, ratings, and feedback. We do not give one business access to another business's data.

We may also disclose information where required by law, to respond to a valid legal request, or to protect the rights, property, or safety of Delitip, our users, or the public. If Delitip is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this policy.

7. International data transfers

Delitip is based in Greece, in the European Economic Area. The service providers listed in Section 6 are based in, or process data in, the United States. Where we transfer personal information outside the EEA/UK, we rely on appropriate safeguards recognized under GDPR, such as the European Commission's Standard Contractual Clauses or an equivalent mechanism, and we require our providers to protect information to a standard consistent with this policy.

8. How long we keep information

We keep personal information for as long as needed for the purposes described in this policy, then delete or deactivate it. In practice:

  • Business, staff, and employee accounts are retained while active. A deactivated or archived account is marked inactive rather than immediately erased, so a business can restore staff access or historical records; underlying authentication data (such as password-reset codes) is removed when an account is deleted.
  • Tip, payment, and refund records are kept for as long as required to meet our tax, accounting, and financial regulatory obligations, even after an associated account is deactivated.
  • Reviews and feedback are retained to preserve a business's historical analytics and performance record, unless a customer who provided identifying information requests its removal (Sections 10–11).

Where we are not required to retain information, we will delete it, or remove identifying details from it, upon a verified request.

9. How we protect information

We use technical and organizational measures appropriate to the sensitivity of the data we hold, including encryption of data in transit, hashed (never plain-text) passwords, token-based authentication, and role-based access controls so staff only see the locations, employees, and data their role permits. We do not store full payment card details — that is handled entirely by Stripe.

Session access to the dashboard is authenticated using a bearer token that, on the web, is currently stored in your browser's local storage rather than a server-set cookie. As with any credential, avoid using the dashboard on shared or untrusted devices, and sign out when finished.

No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal information, we will notify affected individuals and relevant authorities as required by applicable law.

10. Your rights under GDPR

If you are located in the EEA or UK, you have the right to:

  • access the personal information we hold about you;
  • correct inaccurate or incomplete information;
  • request erasure of your information, subject to our retention obligations in Section 8;
  • restrict or object to certain processing, including processing based on legitimate interests;
  • receive your information in a portable format; and
  • withdraw consent at any time, where processing is based on consent, without affecting processing carried out before the withdrawal.

To exercise any of these rights, contact us using the details in Section 16. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Greece) or your local supervisory authority.

11. Your rights under CCPA/CPRA (California residents)

If you are a California resident, you have the right to:

  • know what personal information we have collected about you and how it has been used and disclosed;
  • request deletion of your personal information;
  • correct inaccurate personal information we hold about you; and
  • opt out of the sale or sharing of personal information — we do not sell or share personal information as those terms are defined under the CCPA/CPRA, so there is nothing to opt out of.

We will not discriminate against you for exercising any of these rights. To submit a request, contact us using the details in Section 16.

12. Cookies and local storage

delitip.com uses a single functional cookie to remember whether the dashboard sidebar is expanded or collapsed. It does not identify you or track you across sites. The dashboard also stores your session sign-in token in your browser's local storage so you stay signed in between visits (Section 9).

We do not currently use analytics, advertising, or cross-site tracking cookies. If that changes, we will update this policy and provide a cookie consent and preference tool before doing so. You can control or clear cookies and local storage through your browser settings at any time, though doing so may sign you out or reset dashboard preferences.

13. Employee profile information

Employee profiles (name, email, position, and photo) are usually created by the business a person works for, as part of setting up tipping and recognition for its team. If you are an employee featured on a business's Delitip page and want to access, correct, or request removal of your profile information, you can ask your employer, or contact us directly at the address in Section 16 and we will work with the relevant business to resolve your request.

14. Marketing communications

With your opt-in consent, we or a business may send marketing communications by email or SMS — for example, product updates or promotional offers. These are separate from the transactional messages described in Section 3 (such as password-reset codes), which are necessary to operate your account and are not optional. Every marketing message includes a clear way to unsubscribe or opt out, and we will honor that choice going forward.

15. Children's privacy

Delitip is not directed at children, and we do not knowingly collect personal information from anyone under 16 (or the relevant minimum age in your jurisdiction, such as 13 in the United States). If you believe a child has provided us with personal information, contact us using the details in Section 16 and we will delete it.

16. Changes to this policy

We may update this policy from time to time to reflect changes to our practices or for legal, regulatory, or operational reasons. We will update the "Last updated" date above, and where a change is material, we will provide additional notice, such as an email to account holders or a notice on our website.

17. Contact us

For privacy questions or to exercise any of the rights described above, contact us at info@delitip.com, or by mail at Delitip, Pelasgon 32, Heraklion, Greece.

Also see our Terms of Service. Questions? Contact us.