Privacy

Datenschutzerklärung.

Who is responsible

Lihtar Ventures UG (haftungsbeschränkt)
Kolonnenstraße 8
10827 Berlin
Germany

Data protection questions go to contact@bentoplan.com.

No data protection officer is appointed. Neither Art. 37 GDPR nor § 38 BDSG requires one at our size.

What we store

DataWhyLegal basis
Venue name, address, opening hoursTo locate the venue in a weather grid cell and know when it tradesArt. 6(1)(b) — performance of contract
Daily totals: orders, revenue, closed flagThe series the forecast is fitted toArt. 6(1)(b)
Operator notes and event flagsTo mark which history to distrustArt. 6(1)(b)
Account name and emailAuthentication and the daily notificationArt. 6(1)(b)
Sign-in records: IP address, browserTo keep you signed in, and to notice an account being attackedArt. 6(1)(f) — securing the service
Support messages and any file you attachTo answer the request and keep a record of the answerArt. 6(1)(b)
Device token, if you turn on notificationsTo deliver the daily forecast to that deviceArt. 6(1)(b)
Server logsOperating and debugging the serviceArt. 6(1)(f) — keeping the service up

All of it is data you give us, except the logs and sign-in records, which the service produces as you use it. The account details and the daily totals are what makes a forecast possible: without them there is no service to provide. Nothing else on this list is required of you.

What we deliberately do not store

No guest or reservation records. Counts per service, never people. This keeps the personal-data surface to your own account details and nothing about your customers.

No transaction-level data. Daily totals only. We could not reconstruct an individual receipt if asked to.

No amounts in our logs. Logs record how many rows moved, not what was in them.

Where it lives

Everything you enter is stored in Germany. Analytics and session recordings are held in the EU as well.

PostHog is an American company holding its EU data in Frankfurt, and Google and Apple pass data to their US parents. Those transfers run on the European Commission's standard contractual clauses.

Who else sees it

ProcessorWhere it processesPurposeData shared
Hetzner Online GmbH, Gunzenhausen, GermanyGermanyHosting and server infrastructureEverything the service stores
Cloudfleet GmbH, Berlin, GermanyGermanyServer infrastructure orchestrationAccess to the hosting environment; no data of its own
Twilio Ireland Limited, Dublin, IrelandEUTransactional emailRecipient email address, message content
Google Ireland Limited, Dublin, IrelandEU, with transfers to Google LLC in the USSign in with GoogleEmail address, first and last name
Stripe Payments Europe, Limited, Dublin, IrelandEU, with transfers to Stripe, Inc. in the USSubscription billing and payment processingBilling name and email, billing address, subscription and invoice records
Apple Distribution International Limited, Cork, IrelandEU, with transfers to Apple Inc. in the USSign in with AppleEmail address or a Private Relay forwarding address, name if you share it
Google Ireland Limited, Dublin, IrelandEU, with transfers to Google LLC in the USWeb analytics on the marketing sitePseudonymous usage data from bentoplan.com
PostHog Inc., San Francisco, United StatesGermany (AWS Frankfurt)Session replay and product analyticsProduct usage events and session recordings

Card details never reach us. They go from your browser to Stripe, which stores them and is the only party able to charge them. For fraud prevention and its own regulatory obligations Stripe decides on its own account what to do with payment data, and is a controller in its own right for that rather than our processor.

Weather and city events come from third parties we call. They receive a coordinate and a date range. They are never given anything about you or your venue.

Retention

Trading history is kept for as long as the account is open, because a forecast is only as good as the history behind it. On deletion it goes, and so does everything derived from it.

Support tickets and their attachments are kept while the account is open. Sessions are deleted when they expire. Server logs are kept for 14 days. A device token goes when notifications are turned off, or when the device stops accepting them.

Automated decisions

The forecast is a model fitted to your venue's own trading history, the weather over it and the events around it. It predicts orders and revenue for a venue. It makes no decision about a person, automated or otherwise, so Art. 22 GDPR does not apply.

Your rights

Access, rectification, erasure, restriction, portability and objection under Art. 15–21 GDPR, plus the right to complain to a supervisory authority — for Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Where we rely on a legitimate interest, you can object under Art. 21 GDPR. Where you have given consent, you can withdraw it at any time, which leaves everything done before the withdrawal lawful.

Requests go to the address in the imprint.

Changes

Last updated 27 August 2026. If this policy changes we will replace the text here and move that date.