Skip to content

Legal

Privacy policy

This policy describes how Kuvert processes personal data — for the businesses using the service, for the buyers and recipients appearing in a purchase of gift cards or tickets, and for the guests who book a table at a restaurant through Kuvert.

Last updated 15 September 2026

1. Data controller

For information about the business's own account and users, MICCI, CVR 45587452, Fyrretoften 31, 7100 Vejle, is the data controller.

For information about buyers and recipients of gift cards and tickets and about guests who book a table, it is the business selling the card or taking the booking that is the data controller. Kuvert processes this information as a data processor on the business's behalf — see data processing agreement.

2. What information is processed

Depending on your role, the following is processed:

  • Business users: name, email address, role, password in hashed form and login history — and, for a user who turns push notifications on themselves, the address the browser provides to deliver them, and the user's choice of which notifications to send.
  • Buyer of a gift card: name, email address and optionally telephone number, and the personal greeting written to the recipient.
  • Recipient of a gift card: name and the email address or telephone number the card is delivered to.
  • Guest who books a table: name, email address and telephone number, date, time and number of guests, a note to the restaurant, answers to the restaurant's own questions, and any allergies or special needs the guest chooses to give. The restaurant can add its own notes and sees the guest's earlier visits, cancellations and no-shows.
  • If the restaurant asks for a deposit or a card for a no-show fee: the card's brand, the last four digits and the status of the payment. The card details themselves are held by Stripe.
  • If the restaurant asks for a rating after the visit: the guest's ratings and comment, and whether the guest would like a reply.
  • Transaction data: amount, time, order and card status and redemption history.
  • Technical data: IP address and timestamps in connection with security and misuse prevention.

3. Payment information

Kuvert does not receive, store or process card numbers or other payment information. Payment is carried out by Stripe, which is independently responsible as data controller for the payment information entered with them.

4. Purpose and legal basis

The information is processed to be able to provide the service:

  • To create, provide and redeem gift cards — necessary to fulfil the agreement.
  • To send receipt to buyer and gift card to recipient — necessary to fulfil the agreement.
  • To notify the buyer if a purchase is refunded — necessary to fulfil the agreement.
  • To notify the holder if the gift card can no longer be used — necessary to fulfil the agreement.
  • To take a table booking, confirm, change and remind of it, offer a free table from the waiting list and notify the restaurant — necessary to fulfil the agreement with the guest.
  • Allergies and special needs can be health data. They are processed only when the guest has chosen to write them, only so that the restaurant can take them into account, and they are shown only to the staff who receive the guests.
  • To ask the guest for a rating after the visit — the restaurant's legitimate interest in hearing how the visit was. The guest is free not to answer.
  • To send push notifications about bookings to a member of staff — when that person has turned them on themselves.
  • To prevent misuse and ensure operation — legitimate interest.
  • To comply with bookkeeping and accounting requirements — legal obligation.

5. Sharing

Information is shared only with the sub-contractors necessary for operation, and who process the information according to instructions:

  • Stripe — payment processing and identity verification.
  • PostStack — sending of email.
  • The browser's own push service (e.g. Apple, Google or Mozilla) — delivers push notifications to the staff who have turned them on. The notifications are encrypted, so the service cannot read them.
  • HostStack — hosting and operation of application and database.

6. Storage

Information linked to a gift card is stored as long as the card can be exercised — that is, during the card's validity period of at least 36 months plus the subsequent deadline for cash payout.

Bookkeeping material is stored for five years from the end of the financial year to which the material relates, see the Danish Bookkeeping Act (bogføringsloven).

Account information for a business is deleted after the account's termination, unless it is part of bookkeeping material.

Information about a guest who has booked a table is kept for as long as the restaurant uses it for its bookings and its guest book. The restaurant can delete a guest once the guest has no table still to come: the bookings remain without a name, contact details, messages, answers to the restaurant's questions or the restaurant's notes, the guest is taken off the waiting lists, and a rating remains without the guest's own words. Everything about the guest is deleted when the restaurant closes its account.

7. Your rights

You have the right to access the information processed about you, the right to have incorrect information corrected, the right to deletion, the right to restrict processing, the right to data portability and the right to object.

If your enquiry concerns a gift card you have bought or received, or a table you have booked, it is the business that is the data controller. Kuvert forwards the enquiry to the business if it is sent to us.

You can lodge a complaint with the Danish Data Protection Authority (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk.

8. Contact

Enquiries about this policy should be directed to hej@kuvert.dk or MICCI, Fyrretoften 31, 7100 Vejle.

Have questions about this page? Write to hej@kuvert.dk.