Legal
Privacy Policy
Last updated: August 17, 2026
This Privacy Policy explains what personal data Redyo collects, why we collect it, and the choices you have. It also covers our use of cookies and analytics. We keep data collection to what we actually need to run the service.
1. Who is responsible for your data
The data controller for Redyo is Vladimir Popović, Sokolska 7, 11000 Belgrade, Serbia. For any privacy question or request, contact us at office@redyo.app.
2. What data we collect
Business account holders and their staff. When you register and use Redyo, we collect:
- your name and the contact name for the business;
- email address and phone number;
- business name, business type, and address;
- your password, stored only in a hashed (non-readable) form;
- PIN codes you create for staff to update their status.
If you choose to sign in with Google, we receive your email address from your Google account so we can match it to your Redyo account. We do not receive your Google password.
Visitors to a public wait-time page. Customers who simply view a business’s live wait-time page are not asked for personal data. We only process anonymous, aggregated analytics as described below. (We may, in a future phase, offer an optional notification feature where a customer can leave a phone number or email; if we introduce it, we will update this policy and ask for consent at that point.)
Public business reviews. For a business’s own page, we may retrieve its publicly available Google rating and review count through the Google Places API. This is public business information, not personal data about you.
3. How we use your data and the legal basis
- To provide the service (create and manage your account, display your live status page): performance of our agreement with you.
- To communicate with you about your account, such as password resets: performance of our agreement and our legitimate interest in operating the service.
- To understand and improve the site through analytics: only with your consent (see cookies below).
- To meet legal obligations where the law requires us to keep or disclose certain information.
We do not sell your personal data, and we do not send marketing or newsletter emails. The only emails we currently send are transactional (for example, resetting your password).
4. Cookies and analytics
Redyo uses Google Analytics (GA4) to understand how the site is used so we can improve it. We do not run advertising cookies.
Analytics cookies are set only after you accept them in our cookie banner. Until you accept, analytics storage is disabled by default (using Google Consent Mode). You can change your choice at any time by clearing the site’s stored preference in your browser, which brings the banner back. Strictly necessary cookies needed to keep you logged in and to run the site are always used, as the service cannot function without them.
5. Service providers we share data with
We use a small number of trusted providers to run Redyo. They process data on our behalf, for the purposes above only:
- Google: Google Analytics (usage analytics), Google Sign-In (optional login), and the Google Places API (public business reviews).
- HostGator: website and database hosting.
- Email delivery: to send transactional messages such as password resets.
- Payment processor: if and when we enable online payments, a provider such as Stripe would process payments under its own terms; we would not store your full card details.
6. International data transfers
Our hosting provider (HostGator) and some service providers (such as Google) operate servers in the United States. This means your data may be processed outside Serbia and the European Economic Area. Where that happens, we rely on the providers’ own safeguards for such transfers (for example, standard contractual clauses).
7. How long we keep your data
We keep account data for as long as your account is active, and for up to 90 days after the account is closed, after which it is deleted, unless a longer period is required by law (for example, accounting records). Anonymous analytics data is retained according to our analytics provider’s settings.
8. Your rights
Under Serbian data protection law (and the GDPR where it applies), you have the right to:
- access the personal data we hold about you;
- correct inaccurate data;
- ask us to delete your data;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent (such as for analytics cookies) at any time.
To exercise any of these, email office@redyo.app. You also have the right to lodge a complaint with the Serbian supervisory authority, the Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs).
9. Security
We take reasonable technical and organizational measures to protect your data, including storing passwords only in hashed form and restricting access to accounts. No system is completely secure, but we work to keep your information safe and to address issues promptly.
10. Children
Redyo is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date above, and for significant changes we will take reasonable steps to let you know.
12. Contact
For any privacy question or request, email us at office@redyo.app.
See also our Terms of Use.