Pilot Open
Turn diners into 5-star Google reviews with automated WhatsApp requests No app download. 1-tap rating. 100% compliant with Google review policies 10-second booking entry at the counter. Zero staff training needed Private feedback stays in your dashboard — happy guests go to Google
GDPR & EU Compliant Meta Cloud API Certified

Privacy Policy

Transparent, minimal, and respectful data handling designed specifically for restaurant hospitality.

Last updated:

Our Core Privacy Principles

  • No Selling or Advertising: We never sell, rent, or broker your or your guests' personal data to data brokers, ad networks, or third parties.
  • Tokenized & Passwordless: Diners never register, install apps, or store passwords. Rating links use single-use cryptographic tokens.
  • Strict Data Minimization: We only collect what is strictly necessary to deliver WhatsApp review requests and record private feedback.
  • Easy Right to Erasure: Any restaurant or diner can request complete data erasure anytime via our Delete Account page or email.

1. Who We Are (Data Controller)

Star Pilot (https://starpilot.it) is an automated customer review platform designed for restaurants and hospitality venues. For personal data processed through our website, mobile interface, and review pipeline, Star Pilot operates as the Data Controller in accordance with the EU General Data Protection Regulation (GDPR).

If you have questions about this Privacy Policy or your data, you can contact us directly at:

Entity: Star Pilot

Email: hello@starpilot.it

Phone: +39 366 508 9382

Jurisdiction: Italy / European Union

2. What Data We Collect

We collect and process minimal data categorized into two groups:

A. Restaurant Operators and Staff

  • Account Information: Restaurant name, business address, operator contact email, manager telephone number.
  • Service Configuration: Official Google Business Profile Place ID / review link destination, messaging delay preferences (e.g., 2h, 3h, 4h, 24h).
  • Staff Authentication: Fast employee access codes or credentials used solely to access the counter reservation ledger.

B. Restaurant Diners & Guests

  • Reservation Details: Diner name or nickname, mobile telephone number, reservation date and time, and party size entered by counter staff.
  • Feedback & Ratings: 1-to-5 star rating selections, voluntary written comments, and submission timestamps submitted on the rating page.
  • Interaction Metadata: Single-use token validation status, message delivery receipt flags via Meta WhatsApp Cloud API, and standard web browser user agent strings for responsive layout rendering.

3. How We Use Your Data

We process collected data exclusively for the following operational purposes:

  • Automated Review Dispatch: Transmitting an official, Meta-approved WhatsApp template message to the diner after their dining experience containing a secure rating link.
  • Rating & Private Feedback Collection: Enabling diners to rate their experience via a frictionless web interface without requiring passwords or application downloads.
  • Google Review Redirection: Providing guests with a direct link to the restaurant's public Google Maps listing in strict compliance with Google's non-gating review policies.
  • Dashboard & Service Insights: Displaying reservation statistics, response rates, and customer comments inside the restaurant operator's password-protected dashboard to help them improve hospitality operations.
  • Preventing Unwanted Messages: Synchronizing cancellations and no-shows so guests are never messaged if their reservation did not take place.

4. Legal Bases for Processing (GDPR)

Under Article 6 of the General Data Protection Regulation (GDPR), we process your data under the following legal bases:

  • Performance of Contract (Art. 6(1)(b)): Providing the review automation service requested by our restaurant subscribers.
  • Legitimate Interests (Art. 6(1)(f)): Enabling restaurants to gather customer satisfaction insights, protect customer sentiment, and optimize dining operations.
  • Consent (Art. 6(1)(a)): Where customer contact information is recorded at the counter with customer consent, and when diners choose to submit voluntary feedback on the rating screen.

5. Third-Party Processors & Integrations

We partner with industry-standard, secure infrastructure providers strictly necessary to deliver the service:

Meta Platforms (WhatsApp Cloud API)

Used to deliver verified outbound WhatsApp messages. Subject to Meta's Business Platform and WhatsApp Data Privacy terms.

Google LLC (Google Business Profile)

Diners who choose to leave a Google review are directed to Google's platform, governed by Google's Privacy Policy.

6. Data Security & Cryptographic Tokens

We implement defense-in-depth technical safeguards to protect all data:

  • All HTTP traffic is encrypted using Modern Transport Layer Security (TLS 1.3 / HTTPS).
  • Diner rating links employ 43-character cryptographically random, unguessable tokens with expiration and single-use validation.
  • Administrative dashboards require authenticated session credentials with role-based access separation between counter staff and owners.

7. Data Retention & Erasure

We hold personal data only for as long as necessary to fulfill the service:

  • Active Tokens: Diner rating tokens expire after their active collection window.
  • Reservation Phone Numbers: Retained only for the duration needed to dispatch the scheduled WhatsApp message and allow owner follow-up, after which they are eligible for automated anonymization.
  • Cancelled Reservations: If staff marks a table as cancelled or no-show, outbound message triggers are instantly discarded.

8. Your Rights Under GDPR

If you are a resident of the European Economic Area (EEA) or United Kingdom, you hold the following rights:

  • Right of Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can ask us to correct inaccurate or incomplete information.
  • Right to Erasure ("Right to be Forgotten"): You can request the complete deletion of your personal data from our systems.
  • Right to Restriction & Objection: You can object to or request restriction of our data processing.
  • Right to Data Portability: You can receive your data in a structured, machine-readable format.

To exercise any of these rights, visit our dedicated Account & Data Deletion Instructions or email us at hello@starpilot.it.

9. How to Request Account or Data Deletion

Whether you are a participating restaurant operator or a diner who received a review invitation, you can request total deletion of your records at any time. We process and confirm all verified deletion requests within 30 days without charge.

10. Contact Us

For questions, concerns, or data protection inquiries regarding this policy:

Star Pilot Support: hello@starpilot.it
Direct Phone: +39 366 508 9382