✅ Regulatory audit
Quewly is designed to comply with
Quewly is designed to comply with
the rules that protect your business
Tax audits, customer data leaks, fraudulent payments — here's how Quewly protects you, with full transparency about what's in place, what's in progress, and what's planned.
✅ Implemented
🟡 Partial
🔵 Planned
10
standards
100% compliant
100% compliant
1
in progress
with a deadline
with a deadline
2
planned
H2 2026
H2 2026
0
card data
stored by us
stored by us
🧾
Tax audits
Your sales log is immutable and exportable in one click. The inspector can verify every transaction, cancellation, and refund.
💳
Online payment
We store no card data whatsoever. Stripe (PCI-DSS Level 1) handles everything — your responsibility ends there.
🫙
Customer data
Your customers trust you. We collect the strict minimum, encrypt everything, and sell nothing. Deletion on request guaranteed.
⚠️ Legal note: This document is a self-assessment for informational purposes.
It does not constitute legal advice. Regulatory requirements may change.
Consult a specialized lawyer to validate your own compliance.
🔐 GDPR — General Data Protection Regulation
EU Regulation 2016/679 · In force since May 2018
- Privacy policy published and accessible from every page
- Separate terms of service and legal notice
- Collection limited to what's strictly necessary (email, name, optional phone)
- No data sold to third parties
- Data encrypted in transit (HTTPS/TLS 1.3)
- Hashed passwords (Django PBKDF2, salted)
- Right to erasure: order anonymization on request
- Time-limited JWT (5 min access, 24 h refresh with rotation)
- Records of processing activities (ROPA): being formalized
- Designated DPO: not required at current scale (< 250 employees, non-sensitive processing)
- ePrivacy-compliant cookie banner (planned H2 2026)
- Online form for exercising rights (access, rectification, portability)
💳 Online payment — PCI-DSS & PSD2
PCI-DSS Level 1 via Stripe · PSD2 Directive (strong customer authentication)
- Payment fully delegated to Stripe — no card data stored by Quewly
- Stripe is certified PCI-DSS Service Provider Level 1 (highest level)
- Strong authentication (3D Secure 2) automatically enabled by Stripe
- Refunds traceable and auditable via the Stripe dashboard
- Stripe webhooks verified via HMAC-SHA256 signature
- HTTPS mandatory on every payment route
- Automated bank reconciliation: CSV export available, direct accounting integration planned
🧾 Restaurant VAT — CGI & BOFiP
10% dine-in rate · 5.5% takeaway · Art. 279 CGI
- Configurable VAT rate per item (10% by default)
- Pre-tax and tax-inclusive prices shown on receipts
- "Tax-inclusive price" mode: enter tax-inclusive, automatically stored pre-tax
- Dual rate 10% / 5.5%: a
tax_takeawayfield per item, configurable from the AI dashboard - Dine-in / takeaway selection at order time — rate applied automatically
- Revenue export broken down by rate (10% / 5.5%) for tax filing
🏦 Cash register software — 2018 VAT anti-fraud law
Article 88, 2015 Finance Act · NF525 conditions or equivalent
- Immutable sales log (soft-delete forbidden on orders)
- UTC timestamp on every transaction
- Traceability of cancellations and refunds
- CSV export of transactions for tax audits
- Sequential
service_order_numbernumbering per service — shown on the customer receipt and kitchen dashboard - End-of-day Z report (service closing): immutable daily fiscal summary, broken down by VAT rate
- Chained HMAC-SHA256 signature on every receipt — tampering is detectable
- NF525 vendor attestation generated on request (compliant with BOI-TVA-DECLA-30-10-30)
📋 Mandatory legal notices (restaurant owner)
Consumer Code · LCEN · Restaurant industry regulations
- Business name, address, phone shown on the customer page
- Terms of sale accessible before ordering
- Refund policy available
- SIRET, legal name, intra-community VAT number: entered in the profile with automatic lookup via SIRET
- 14 EU regulatory allergens (INCO Regulation 1169/2011) declarable per item — bulk grid of Items × 14 allergens
- Confirmed allergens shown as badges on the customer menu, with an adaptive footer message
- Certified dietary markers (Halal, Organic, Vegan, Vegetarian, Gluten-free, Lactose-free, Homemade) — restaurant owner's self-declaration, full audit trail
- AI allergen analysis (suggestions, never shown without the restaurant owner's confirmation)
- Tax-inclusive prices shown on the customer menu (tax-inclusive label shown on every item and combo)
- Meat origin disclosure (INCO 2014 regulation): declared per meat type, shown on the customer menu
♿ Digital accessibility — RGAA 4.1
General Framework for Improving Accessibility · Mandatory for the public sector, recommended for private
- WCAG AA-compliant color contrast (ratio ≥ 4.5:1 on main text)
- Semantic HTML5 structure (h1–h6, nav, main, footer)
altattributes on product images- Keyboard navigation possible on interactive elements
- Published RGAA 4.1 accessibility statement — non-compliances and appeal process documented
- ARIA attributes on dynamic components: being fixed (H2 2026)
- Full RGAA audit by an accredited third party (planned H2 2026)
🛡️ DSA — Digital Services Act
EU Regulation 2022/2065 · In force since February 2024
- Quewly is a micro-enterprise (< 1M users): reduced obligations
- No public user-generated content (reviews, comments) — zero moderation risk
- Single identified point of contact for reports
- Transparency on the use of algorithmic recommendation systems (menu AI)
- Annual transparency report: not required below the thresholds
🔒 Application security — OWASP Top 10
ANSSI best practices · OWASP Application Security Verification Standard
- CSRF protection enabled on every Django view (global middleware)
- SQL injection: Django ORM with parameterized queries — no raw SQL concatenation
- XSS: Django template auto-escaping + Content Security Policy
- Strict multi-tenant isolation: every action verifies the item → menu → truck → owner chain
- JWT access token TTL 5 min, 24 h refresh with rotation and blacklist
- Sensitive values kept in environment variables (never in code)
- HTTPS enforced in production (HSTS)
- External security audit: planned at 10+ active clients (Sentry + pentest)
Summary table
| Regulation | Scope | Status | Deadline |
|---|---|---|---|
| GDPR | Personal data protection | ✅ Compliant | Cookie banner H2 2026 |
| PCI-DSS via Stripe | Card payment security | ✅ Compliant | — |
| PSD2 / 3DS2 | Strong payment authentication | ✅ Compliant | — |
| Restaurant VAT | 5.5% / 10% rate depending on mode | ✅ Compliant | — |
| VAT anti-fraud law (NF525) | Certified cash register software | ✅ Compliant | Vendor certification 2026 |
| LCEN legal notices | SIRET, legal name, VAT, meat origins, tax-inclusive prices | ✅ Compliant | — |
| Allergens (INCO 2014) | 14 mandatory allergens | ✅ Compliant | — |
| Dietary markers | Halal, Organic, Vegan, Homemade… | ✅ Implemented | — |
| RGAA 4.1 | Digital accessibility | 🟡 Partial | Audit H2 2026 |
| DSA | Digital services | ✅ Compliant | — |
| OWASP Top 10 | Application security | ✅ Compliant | Pentest at 10+ clients |
✅ Implemented and verified
🟡 Partial or in progress
🔵 Planned with a deadline
A question about our compliance?
Are you a restaurant owner, lawyer, or accountant looking for details on a specific point? We respond within 48 business hours.
Write to usA solution designed for French food service
Get started for free — your online menu is ready in under 10 minutes.
🤖
Any questions?
Hi! I can answer your questions about Quewly — features, pricing, getting started…