Last updated: July 23, 2026
Privacy Policy
This policy explains how Noblewolf AS (reg. no. 922 097 941) processes personal data as data controller for the Flowder service. We are also data processor on behalf of the restaurants when it comes to guest ordering data.
1. What we process
Restaurant users (paying customers)
- Name and email at signup
- Password (stored as PBKDF2-SHA256 hash)
- Restaurant name, address, phone (optional)
- Login log (IP, timestamp) for security
- Billing info via Stripe — card numbers are not stored by us, only Stripe Customer ID + Payment Method ID
Restaurant guests (ordering via QR/takeaway/delivery)
- Order details (dishes, prices, time)
- Email and name only if given for confirmation/tracking
- Phone number only for takeaway / delivery
- Delivery address for delivery orders
- Payment reference from Stripe (Payment Intent ID) — not card number
- Table token (anonymous QR signature, no personal data)
2. Legal basis
- Contract (GDPR art. 6(1)(b)): delivering the service
- Legal obligation (art. 6(1)(c)): Norwegian bookkeeping law requires 5-year retention
- Legitimate interest (art. 6(1)(f)): security logs, abuse prevention
3. Cookies
We use essential cookies only (no tracking, no marketing):
nwm_session— login token (30 days, HttpOnly, Secure)nwm_lang— language preference (1 year)nwm_cart_*— cart token for guest (sessionStorage)
4. Sub-processors
| Provider | Purpose | Region |
|---|---|---|
| Cloudflare (Pages, D1, Workers) | Hosting, database | EU (Frankfurt) |
| Bunny CDN | Images and media | EU |
| Stripe Payments Europe | Payment, subscription | EU (Ireland) |
| Resend | Transactional email | EU (Frankfurt) |
| OpenAI | AI translation and image generation | USA (SCC) |
| Anthropic | AI menu import from PDF | USA (SCC) |
5. Retention
- Restaurant account: while subscription active + 12 months
- Order data (bookkeeping): 5 years per Norwegian law
- Login log: 90 days
- Audit log: 12 months
6. Your rights
- Access to your data
- Correction or deletion
- Restriction or objection
- Data portability (JSON/CSV export)
- Complaint to Norwegian DPA — datatilsynet.no
Contact kontakt@noblewolf.no.
7. Security
- All traffic HTTPS (TLS 1.3)
- Passwords hashed with PBKDF2 (100 000 iterations)
- Session cookies HttpOnly + Secure + SameSite=Lax
- Rate limits on login and signup
- Role-based access control (owner/admin/editor/viewer) with org isolation
8. Contact
Noblewolf AS
Email: kontakt@noblewolf.no
Data Processing Agreement available on request