✅ Regulatory audit

Quewly is designed to comply with
the rules that protect your business

Tax audits, customer data leaks, fraudulent payments — here's how Quewly protects you, with full transparency about what's in place, what's in progress, and what's planned.

✅ Implemented 🟡 Partial 🔵 Planned
10
standards
100% compliant
1
in progress
with a deadline
2
planned
H2 2026
0
card data
stored by us
🧾
Tax audits
Your sales log is immutable and exportable in one click. The inspector can verify every transaction, cancellation, and refund.
💳
Online payment
We store no card data whatsoever. Stripe (PCI-DSS Level 1) handles everything — your responsibility ends there.
🫙
Customer data
Your customers trust you. We collect the strict minimum, encrypt everything, and sell nothing. Deletion on request guaranteed.
⚠️ Legal note: This document is a self-assessment for informational purposes. It does not constitute legal advice. Regulatory requirements may change. Consult a specialized lawyer to validate your own compliance.
🔐 GDPR — General Data Protection Regulation
EU Regulation 2016/679 · In force since May 2018
Compliant
  • Privacy policy published and accessible from every page
  • Separate terms of service and legal notice
  • Collection limited to what's strictly necessary (email, name, optional phone)
  • No data sold to third parties
  • Data encrypted in transit (HTTPS/TLS 1.3)
  • Hashed passwords (Django PBKDF2, salted)
  • Right to erasure: order anonymization on request
  • Time-limited JWT (5 min access, 24 h refresh with rotation)
  • Records of processing activities (ROPA): being formalized
  • Designated DPO: not required at current scale (< 250 employees, non-sensitive processing)
  • ePrivacy-compliant cookie banner (planned H2 2026)
  • Online form for exercising rights (access, rectification, portability)
💳 Online payment — PCI-DSS & PSD2
PCI-DSS Level 1 via Stripe · PSD2 Directive (strong customer authentication)
Compliant
  • Payment fully delegated to Stripe — no card data stored by Quewly
  • Stripe is certified PCI-DSS Service Provider Level 1 (highest level)
  • Strong authentication (3D Secure 2) automatically enabled by Stripe
  • Refunds traceable and auditable via the Stripe dashboard
  • Stripe webhooks verified via HMAC-SHA256 signature
  • HTTPS mandatory on every payment route
  • Automated bank reconciliation: CSV export available, direct accounting integration planned
🧾 Restaurant VAT — CGI & BOFiP
10% dine-in rate · 5.5% takeaway · Art. 279 CGI
Compliant
  • Configurable VAT rate per item (10% by default)
  • Pre-tax and tax-inclusive prices shown on receipts
  • "Tax-inclusive price" mode: enter tax-inclusive, automatically stored pre-tax
  • Dual rate 10% / 5.5%: a tax_takeaway field per item, configurable from the AI dashboard
  • Dine-in / takeaway selection at order time — rate applied automatically
  • Revenue export broken down by rate (10% / 5.5%) for tax filing
🏦 Cash register software — 2018 VAT anti-fraud law
Article 88, 2015 Finance Act · NF525 conditions or equivalent
Compliant
  • Immutable sales log (soft-delete forbidden on orders)
  • UTC timestamp on every transaction
  • Traceability of cancellations and refunds
  • CSV export of transactions for tax audits
  • Sequential service_order_number numbering per service — shown on the customer receipt and kitchen dashboard
  • End-of-day Z report (service closing): immutable daily fiscal summary, broken down by VAT rate
  • Chained HMAC-SHA256 signature on every receipt — tampering is detectable
  • NF525 vendor attestation generated on request (compliant with BOI-TVA-DECLA-30-10-30)
📋 Mandatory legal notices (restaurant owner)
Consumer Code · LCEN · Restaurant industry regulations
Compliant
  • Business name, address, phone shown on the customer page
  • Terms of sale accessible before ordering
  • Refund policy available
  • SIRET, legal name, intra-community VAT number: entered in the profile with automatic lookup via SIRET
  • 14 EU regulatory allergens (INCO Regulation 1169/2011) declarable per item — bulk grid of Items × 14 allergens
  • Confirmed allergens shown as badges on the customer menu, with an adaptive footer message
  • Certified dietary markers (Halal, Organic, Vegan, Vegetarian, Gluten-free, Lactose-free, Homemade) — restaurant owner's self-declaration, full audit trail
  • AI allergen analysis (suggestions, never shown without the restaurant owner's confirmation)
  • Tax-inclusive prices shown on the customer menu (tax-inclusive label shown on every item and combo)
  • Meat origin disclosure (INCO 2014 regulation): declared per meat type, shown on the customer menu
♿ Digital accessibility — RGAA 4.1
General Framework for Improving Accessibility · Mandatory for the public sector, recommended for private
Partial (~75%)
  • WCAG AA-compliant color contrast (ratio ≥ 4.5:1 on main text)
  • Semantic HTML5 structure (h1–h6, nav, main, footer)
  • alt attributes on product images
  • Keyboard navigation possible on interactive elements
  • Published RGAA 4.1 accessibility statement — non-compliances and appeal process documented
  • ARIA attributes on dynamic components: being fixed (H2 2026)
  • Full RGAA audit by an accredited third party (planned H2 2026)
🛡️ DSA — Digital Services Act
EU Regulation 2022/2065 · In force since February 2024
Compliant (micro-platform)
  • Quewly is a micro-enterprise (< 1M users): reduced obligations
  • No public user-generated content (reviews, comments) — zero moderation risk
  • Single identified point of contact for reports
  • Transparency on the use of algorithmic recommendation systems (menu AI)
  • Annual transparency report: not required below the thresholds
🔒 Application security — OWASP Top 10
ANSSI best practices · OWASP Application Security Verification Standard
Compliant
  • CSRF protection enabled on every Django view (global middleware)
  • SQL injection: Django ORM with parameterized queries — no raw SQL concatenation
  • XSS: Django template auto-escaping + Content Security Policy
  • Strict multi-tenant isolation: every action verifies the item → menu → truck → owner chain
  • JWT access token TTL 5 min, 24 h refresh with rotation and blacklist
  • Sensitive values kept in environment variables (never in code)
  • HTTPS enforced in production (HSTS)
  • External security audit: planned at 10+ active clients (Sentry + pentest)

Summary table

Regulation Scope Status Deadline
GDPR Personal data protection ✅ Compliant Cookie banner H2 2026
PCI-DSS via Stripe Card payment security ✅ Compliant
PSD2 / 3DS2 Strong payment authentication ✅ Compliant
Restaurant VAT 5.5% / 10% rate depending on mode ✅ Compliant
VAT anti-fraud law (NF525) Certified cash register software ✅ Compliant Vendor certification 2026
LCEN legal notices SIRET, legal name, VAT, meat origins, tax-inclusive prices ✅ Compliant
Allergens (INCO 2014) 14 mandatory allergens ✅ Compliant
Dietary markers Halal, Organic, Vegan, Homemade… ✅ Implemented
RGAA 4.1 Digital accessibility 🟡 Partial Audit H2 2026
DSA Digital services ✅ Compliant
OWASP Top 10 Application security ✅ Compliant Pentest at 10+ clients
✅ Implemented and verified
🟡 Partial or in progress
🔵 Planned with a deadline

A question about our compliance?

Are you a restaurant owner, lawyer, or accountant looking for details on a specific point? We respond within 48 business hours.

Write to us

A solution designed for French food service

Get started for free — your online menu is ready in under 10 minutes.