Skip to content
FeaturesGetting startedPricingManufacturers
  • Español
  • English
Sign in Request a demo
FeaturesGetting startedPricingManufacturers
Sign in Request a demo

Data protection

RestQ privacy policy

Last updated: 18 September 2026

This policy explains how Dazeris Software, S.L.U. processes the personal data collected through the RestQ website and the processing associated with the use of RestQ on Android, iPhone and web. RestQ is an application for professional use by the employees of the stores that subscribe to the service.

Note: This is a courtesy English translation. In the event of any discrepancy, the Spanish version prevails.

There are two distinct roles in RestQ. Dazeris Software, S.L.U. acts as controller with respect to the website, the voluntary diagnostics of the mobile application and the support communications it manages on its own behalf. The store decides the purposes for which its employees' data and the data it enters into the application are processed; the store is therefore the controller of that processing and Dazeris acts as processor.

1. Data controller

The controller for the website processing, the voluntary diagnostics and the support communications managed on its own behalf is:

Controller
Dazeris Software, S.L.U.
Tax ID (NIF)
B93844595
Registered office
Calle Panaderos, 8, 4.º Pta. D · 02400 Hellín (Albacete)
Contact email
privacidad@dazeris.com
Website
https://restq.app

With respect to user accounts, quotes, recorded activity and the remaining working data of the store, the controller is the store the user works for. Dazeris processes that data on behalf of the store under the data processing agreement.

2. Personal data we process

2.1. Data collected through the website

When the user fills in the demo request form, sends an email or uses other available channels, we may process their name, store or company, email address, telephone number, message and any other information they choose to include in their communication.

When the user browses the site, and provided they have given their consent, we may process technical and usage data such as the IP address, the device or browser identifier, the pages visited, the date and time of access and similar statistical data. This information is collected by means of cookies and similar technologies, as detailed in the cookie policy.

2.2. Data processed on behalf of the store

RestQ accounts are not created from the application: they are set up by Dazeris at the request of the store administrator. The application may process the following categories of data about professional users:

  • Account and authentication data: email address, display name, password managed by Firebase Authentication, IP address, user agent, active or deactivated status and signed-in session.
  • Organisational data: store and shop the user belongs to, administrator, manager or salesperson role, and the applicable permission keys.
  • Authorship: internal identifier of the user who created each quote.
  • Audit: internal identifier of whoever adds or deactivates users, changes permissions, changes prices, or opens, renames or closes shops, together with the action, its date and the item affected. The audit log records no person’s name or email address. Automated operations are logged without an author identifier.
  • Price change history: every change to the point value, the margins or the purchase discounts records, in addition to the audit entry and alongside the internal identifier, the display name of whoever made it, with the date and the previous value, so that the store can follow how its prices evolved and who changed them. This history is a separate record from the audit log and is not deleted after 24 months.
  • Data entered into quotes: products, sizes, options, prices and the content of the free-text name or reference field. That field is not intended to collect personal data about the end customer, although it may contain such data if the user enters it.

The store determines the information it enters into RestQ and must prevent the free-text field of quotes from containing names, telephone numbers or other personal data of its customers.

2.3. Voluntary diagnostics of the mobile application

Diagnostics are off by default: nothing is collected or sent until the user accepts them. The application requests them through a notice on first launch, with both options — accept and decline — presented with equal prominence. Declining does not limit any RestQ feature.

If the user enables diagnostics on Android or iPhone, the following is transmitted to Firebase Crashlytics:

  • Crash reports and their stack traces.
  • Log messages from the application itself at error, warning and information levels.
  • Installation identifier, device model, operating system version, RestQ version and session data added by Crashlytics.

RestQ does not add the user's name, email address or account identifier to these reports. Log messages may contain internal identifiers of the store, its shops, its quotes and the catalogue products, which do not identify a person.

Consent may be withdrawn at any time from Settings → Privacy. On withdrawal, and also on every launch where no consent is in place, the application deletes any reports pending submission from the device.

The diagnostics choice, the date on which it is made and the version of the notice are stored on the device only. They are not linked to the account and are not synchronised, precisely so that diagnostics are not associated with an identified person; as a consequence, RestQ asks for the choice again on each device and after each reinstallation.

Crashlytics is not enabled in the web version of the application, so the choice is not requested there. RestQ does not use Google Analytics or Firebase Analytics in the application, nor push notifications, advertising or advertising identifiers, and does not carry out tracking or profiling.

2.4. Support communications

When a person contacts Dazeris to request support, we process their identification and contact details and the content they include in their communication. If handling the request requires consulting store data, that access is carried out as a processor and in accordance with the store's instructions.

2.5. Data stored on the device

RestQ keeps a local cache of the store's working data, in SQLite on mobile devices and in IndexedDB in the browser; the store, rounding and tax preferences; and the Firebase Authentication session. The data cache is cleared on the next launch of the application after signing out.

On Android, automatic backup and device-to-device transfer of this data are disabled. This means that, when reinstalling the application or changing phone, the user has to sign in again.

2.6. Application integrity check

RestQ uses Firebase App Check to verify that requests to its services come from a legitimate installation of the application and not from a program imitating it. To do so, the device or the browser obtains an integrity attestation — from Google Play on Android, from Apple (DeviceCheck) on iPhone and from reCAPTCHA Enterprise on the web version — which Firebase records and requires before serving the request. A request without a valid attestation is rejected: the application starts, but it neither reads nor writes any data. This check does not identify the user and is not linked to their account. RestQ neither receives nor stores the device signals: each provider processes them under its own terms.

3. Purposes of the processing

Data collected through the website is used to:

  • Handle demo and information requests about RestQ.
  • Respond to commercial or professional enquiries.
  • Manage communications relating to RestQ and its implementation.
  • Maintain a pre-contractual or contractual relationship where applicable.
  • Analyse and improve the operation and content of the site using analytics tools.
  • Comply with the applicable legal obligations.

Data processed on behalf of the store is used to:

  • Authenticate users and control their access.
  • Apply permissions and isolation between stores and shops.
  • Allow catalogue lookups, price calculation and the preparation of quotes.
  • Preserve the authorship of quotes and record sensitive actions.
  • Provide support and administer the catalogue where necessary, including access by authorised platform staff from the backoffice.

Voluntary diagnostics are used to detect, analyse and fix technical faults in the Android and iPhone versions.

Communications addressed to Dazeris are used to receive, process and document support or data protection requests.

4. Legal basis for the processing

The website processing is based, depending on the case, on:

  • Consent, when the user voluntarily submits a form or communication and when they accept analytics or measurement cookies.
  • The application of pre-contractual measures, when the enquiry relates to a possible engagement.
  • The performance of a contract, when there is a contractual relationship with the user or with the company they represent.
  • Compliance with legal obligations, where necessary.
  • Legitimate interest in maintaining professional communications with clients, suppliers or business contacts and in ensuring the security and correct operation of the site.

The store determines the legal basis applicable to its employees' data and to the data it enters into RestQ. Dazeris does not process that data for its own purposes, but on behalf of the store and in accordance with its documented instructions.

The sending of diagnostics is based on the user's consent, in accordance with Article 6(1)(a) GDPR. Collection remains disabled until the user accepts it, and declining does not prevent the use of RestQ. Consent may be withdrawn at any time from Settings → Privacy, without affecting the lawfulness of the earlier processing.

Support communications that Dazeris manages on its own behalf are based on its legitimate interest in receiving, documenting and resolving enquiries relating to the service. Where support involves accessing data under the store's responsibility, that access is carried out as a processor.

5. Retention periods

Data obtained through the website is retained for as long as necessary to handle the request, manage the professional or contractual relationship and comply with the applicable legal obligations. When it is no longer necessary, it is kept blocked solely for the periods necessary to address possible legal liabilities, after which it is deleted. Analytics data is retained for the period configured in the measurement tool and as indicated in the cookie policy. The temporary copy of each form kept in Cloud Firestore is deleted automatically 180 days after it is received, whether or not it has been delivered by email.

Data associated with the application is retained according to the following criteria:

Category Criterion or period
User profile and membership of the store For as long as the account remains active or until the store orders its deletion. The deletion operation removes the profile and the membership of the store.
Firebase Authentication Recorded IP addresses are retained for a few weeks. The remaining authentication data is retained until deletion of the account is requested. Google completes deletion from its active systems and backups within a maximum of 180 days.
Authorship of quotes The quote retains the identifier of its author. After the user is deleted, that identifier no longer resolves to a profile. Its retention follows that of the quote, in accordance with the store's instructions and the service contract.
Quotes and other store data Retained for as long as the store keeps the service subscribed and in accordance with its instructions. Return or deletion on termination of the service is governed by the data processing agreement.
Price change history Each entry retains the date, the previous value, the internal identifier and the display name of whoever made the change, and cannot be modified or deleted entry by entry. It is retained for as long as the store keeps the service subscribed, together with its other data, and follows the same return or deletion on termination. Once an account is deleted, the name already recorded on earlier entries remains.
Audit log The log is immutable while it exists: entries are neither modified nor deleted one by one. They are deleted automatically 24 months after their date, and each deletion is recorded in the log itself. It retains the action, its date, the item affected and, where a person performed the operation, their internal identifier; automated operations are left without an author. It may also retain the affected user’s role, which does not identify anyone on its own. It contains no person’s name or email address. Once an account is deleted, or the store leaves the service, its entries follow that same period and its internal identifier no longer resolves to any profile. An exceptional correction — for example, removing a personal data item archived in error — is noted on the entry itself.
Crash traces, minidump data and associated Crashlytics identifiers Google retains them for 90 days before starting their deletion from active and backup systems.
Log messages sent to Crashlytics Google does not publish a separate period for these messages and RestQ has no retention setting of its own.
Support communications For as long as necessary to handle and document the request and, thereafter, for the periods during which liabilities may arise.
Local cache on the device Cleared on the next launch of RestQ after signing out.

When diagnostics are disabled, RestQ stops collecting them and deletes the reports pending submission from the device. Disabling them does not delete what has already been transmitted to Google, which remains subject to the periods indicated in this table.

6. Recipients and data processors

As a general rule, we do not disclose the data to third parties, except where legally required or when necessary to provide the requested service.

For the website we use the following providers, which may have access to personal data and act on behalf of Dazeris under contracts that comply with Article 28 of the GDPR:

Type of provider Purpose Provider
Web hosting and CDN Publish and serve restq.app Firebase Hosting, by Google
Form intake Receive the messages from the demo request form, keep a temporary copy and deliver them by email Cloud Functions for Firebase and Cloud Firestore, by Google (European Union)
Web analytics Measure use of the site and compile statistics Google Analytics, by Google
Email Manage communications by email Google Workspace, by Google

The infrastructure of the RestQ application is provided through Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland, and the applicable Google subprocessors. The Cloud Data Processing Addendum was accepted on 25 August 2026 from the company account.

Service Purpose Location
Firebase Hosting Publication of the restq.app website and of the web application Global service: content delivery network with servers inside and outside the European Economic Area
Cloud Firestore Application database and temporary copy of the website forms eur3, European multi-region
Cloud Functions for Firebase Server-side execution of sensitive operations europe-west1, Belgium
Cloud Storage for Firebase Product images and manufacturer logos europe-west1, Belgium
Firebase Authentication User authentication United States
Firebase Crashlytics Receipt and analysis of voluntary diagnostics Outside the European Economic Area
Firebase App Check Verification that requests come from a legitimate installation of the application Global service: data may be processed at any Google Cloud location

Cloud Storage does not contain personal data: it stores product images and manufacturer logos. On iPhone, the integrity attestation validated by App Check is issued by Apple (DeviceCheck), under the terms of its developer programme.

Cloud Firestore, Firebase Authentication, Cloud Functions, Cloud Storage and Firebase App Check are governed by the Cloud Data Processing Addendum. Firebase Hosting and Crashlytics are governed separately by the Firebase Data Processing and Security Terms.

Authorised Dazeris staff may access a store's data from the backoffice where necessary to provide support or administer the catalogue. That access is carried out as a processor, with the scope necessary for the action requested or authorised.

We do not sell or transfer personal data to third parties for advertising purposes.

7. International transfers

Some website services may process data outside the European Economic Area, especially in the United States: Firebase Hosting delivers the site through the content delivery network of Fastly, Inc. (a Google subprocessor, with servers inside and outside the European Economic Area) and Google Analytics processes measurement data in the United States. Where there is an international transfer, the safeguards provided for in the regulations apply, such as an adequacy decision or the applicable standard contractual clauses. Data subjects may request information about those safeguards by writing to privacidad@dazeris.com.

Firebase Authentication processes authentication data exclusively in the United States, and its location is not configurable. The transfer and subsequent processing are subject to the safeguards set out in Appendix 3 (Specific Privacy Laws), European Data Protection Law terms, Section 4 (Data Transfers), paragraphs 4.1 to 4.8, of the Cloud Data Processing Addendum, including the applicable standard contractual clauses.

Firebase Crashlytics processes diagnostics outside the European Economic Area. Its transfers are governed by paragraphs 10.2 and 10.6 of the Firebase Data Processing and Security Terms: the EU-U.S. Data Privacy Framework applies where Google's US recipient is certified and, where it is not available, the corresponding standard contractual clauses apply.

The current subprocessor lists can be consulted at:

  • Google Cloud Platform subprocessors.
  • Firebase subprocessors (Hosting and Crashlytics).

8. Rights of data subjects

With respect to website data, voluntary diagnostics and support communications that Dazeris manages on its own behalf, the data subject may request access to, rectification, erasure, objection to, restriction of or portability of their data, as well as withdraw consent, by writing to privacidad@dazeris.com. They may also lodge a complaint with the Spanish Data Protection Agency.

Where the request concerns the account, the quotes or the activity of the store, it must be addressed to the store as controller. If Dazeris receives a request relating to that data, it will forward it to the store and provide the assistance set out in the data processing agreement, preserving the date on which the request was received.

Diagnostics sent to Crashlytics do not contain the account identifier, the name or the email address of the user. Dazeris therefore has no key that would allow individual reports already sent to be located and deleted, and will not request additional data solely to create that link. The user can stop collection and delete pending reports from Settings → Privacy; reports already sent are subject to the periods indicated in section 5.

The step-by-step procedure for requesting deletion, setting out what is deleted, what is kept and for how long, is on the Data deletion page.

9. Data security

Dazeris applies reasonable technical and organisational measures to protect website data against unauthorised access, loss, alteration or improper disclosure. No system connected to the Internet can guarantee absolute security, so the user should avoid sending particularly sensitive information through the website forms.

In the application, RestQ applies the following measures:

  • Access control through Firestore and Storage server-side rules, with permissions by role and by permission key.
  • Isolation between stores, so that one store cannot access another store's data.
  • Server-side execution of sensitive operations through functions that verify authorisation.
  • Immutable log of sensitive actions.
  • Encryption in transit and at rest provided by the Google platform.
  • Disabling, on Android, of automatic backup and device-to-device transfer for the application's local data.

10. Data of minors

The website and the RestQ application are aimed at businesses and professionals. There is no intention to collect data of minors.

11. Changes to this policy

Dazeris may update this policy when the processing, the application or the applicable obligations change. The date of the last update appears at the top.

RestQ will ask for consent to diagnostics again where the categories of data collected, their purposes, the recipients, the international transfers or the retention period are substantially extended, or where sending them ceases to be optional. In that case all users will be asked again, including those who had previously declined. Style corrections, clarifications that do not extend the processing and changes that reduce its scope do not give rise to a new request.

The sales platform for mattress and bedding stores and retailers with a dedicated sleep section.

A product by Dazeris

Product

  • Features
  • Getting started
  • Pricing
  • Manufacturers
  • FAQ
  • Request a demo
  • Support

Legal

  • Legal notice
  • Privacy policy
  • Cookie policy
  • Terms of service
  • Data processing agreement
  • Data deletion

© 2026 Dazeris Software, S.L.U. · All rights reserved.

We use analytics cookies to understand how the site is used and improve it. You can accept or reject them; more information in the cookie policy.