Information
Privacy.
This draft policy explains how the generic Pizza Place website handles information. A real operator must replace it with its own legal identity, contacts and processing details before launch.
Draft updated: 19 August 2026
Public visitors
The public menu does not ask for a name, email address, account or payment information. The browser stores only the visitor’s cookie preference. Hosting security logs may temporarily include an IP address, browser information, requested URL and request time.
Menu administrator
The protected administration area uses GitHub OAuth. After authorisation, the site receives the GitHub login and avatar URL needed to enforce the owner allowlist and display the signed-in account. It does not receive or store the GitHub password. A short-lived, signed, secure and HTTP-only session cookie is used.
Menu and media data
Product names, descriptions, ingredients, prices and settings are stored in Cloudflare D1. Uploaded menu images are stored in Cloudflare KV. Administrative changes are recorded in an audit log with the authorised GitHub login, action and timestamp.
External services
Links to maps, social profiles or food-hygiene information leave this website. Those services apply their own privacy notices.
Your rights and contact
The final restaurant operator must add a verifiable privacy contact and explain applicable data rights, retention periods and complaint routes for its jurisdiction.