SHEMOQMEDI
← Shemoqmedi

Privacy Policy

Last updated: 31 July 2026

This Privacy Policy explains how Shemoqmedi (“we”, “us”), operated by Saba Khvichia (Individual Entrepreneur, registered in Georgia), collects, uses, and protects personal data when you use our website shemoqmedi.space, our NFC/QR digital menus, and the AI features within them (the “Service”). We comply with the Law of Georgia on Personal Data Protection and, for visitors in the European Economic Area, with the standards of the EU General Data Protection Regulation (GDPR).

Who this applies to

The Service has two kinds of users: venue partners (café and restaurant managers we invite and onboard) and diners (guests who open a venue's menu). Diners do not create accounts.

What we collect

  • Venue partners: name, email, and organization details, handled through our authentication provider (Clerk). Partner access is invite-only.
  • Diners: an anonymous device identifier generated in your browser's local storage. If you tell the AI about dietary needs or allergies, those preferences are stored on your device and are only sent to power your recommendations — see “Health-related data” below.
  • Conversations & orders: messages you send to the in-menu AI, and the items, table/seat, and totals of any order you place. We do not store your payment card details — card payments (for partners' subscriptions) are handled by our payment processor.
  • Automatically: privacy-friendly analytics (Ahrefs Web Analytics — no cookies, no personal data — and Vercel Analytics), plus standard technical data such as browser type and approximate region. A single functional session cookie keeps a dine-in table session working.
  • Venue public data: publicly available Google Business Profile information (name, rating, reviews count, hours, location) to enrich venue pages.

How we use it

To provide and operate the Service; to power AI menu recommendations; to improve the quality of our AI; to process partners' subscriptions; to keep the Service secure and prevent abuse; and to understand aggregate, anonymous usage.

Legal bases

We rely on: performance of a contract (to run the Service for partners and diners), consent (for any health-related dietary data and for using conversations to improve our AI), and legitimate interests (security, abuse prevention, and aggregate analytics that do not identify you).

Health-related data (allergies & dietary needs)

Allergy and dietary information is a special category of personal data. We only process it with your explicit consent, we keep it on your device by default, and we send it only transiently to generate your recommendations. You can clear it at any time by clearing your browser data. Allergen information shown in a menu is provided by the venue — always confirm with staff before ordering if you have a serious allergy.

Using conversations to improve our AI

With your consent, anonymized excerpts of menu conversations may be used to improve our AI models. We take steps to remove personal identifiers before this use. You may decline, and doing so does not affect your ability to use the menu.

Cookies & local storage

We use one functional, httpOnly session cookie for dine-in table sessions, and your browser's local storage to remember your anonymous ID and any preferences you set. Our analytics (Ahrefs) is cookieless. We do not use advertising or cross-site tracking cookies.

Who we share data with (processors)

We use trusted service providers who process data on our behalf: Clerk (authentication), Convex (database & backend), Google (Gemini AI and Maps/Places), ImageKit (image hosting), Resend (transactional email), Upstash (rate limiting), Flitt (card payments for partner subscriptions), Ahrefs and Vercel (analytics & hosting). We do not sell your personal data.

International transfers

Some providers are located outside Georgia and the EEA. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

Retention

We keep partner account data for as long as the partnership is active. Diner chat and session data are retained only as long as needed to operate the Service and are then deleted or anonymized. On-device preferences remain on your device until you clear them.

Your rights

Under Georgian law and the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent at any time (in the same form in which you gave it). You may also lodge a complaint with the Personal Data Protection Service of Georgia (personaldata.ge), or your local EEA supervisory authority. To exercise any right, contact us at the email below.

Children

The Service is not directed at children under 16 and we do not knowingly collect their personal data.

Security

We use industry-standard measures to protect personal data, including access controls and encryption in transit. No method of transmission is perfectly secure, but we work to protect your information.

Changes

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.

Contact

hello@shemoqmedi.space, Tbilisi, Georgia.