Skip to content
← Foodibo

Privacy Policy (DSGVO / GDPR)

Template — review with legal counsel and fill the operator details in src/lib/legal.ts (COMPANY) before launch.

1. Controller

The controller responsible for processing personal data under Art. 4(7) GDPR is [Your full name] (Einzelunternehmen (Kleingewerbe)), trading as Foodibo, [Street and number], [Postal code, City], Germany. For any data-protection request, contact [email@foodibo.de].

2. What we process & why

  • Restaurant account data (email, role) — to operate your restaurant workspace. Legal basis: contract (Art. 6(1)(b)).
  • Diner account data (email, name) — only if a diner chooses to sign in; authentication is handled by Clerk. Guest ordering needs no account. Legal basis: contract / consent (Art. 6(1)(b)/(a)).
  • Restaurant & menu data — content you publish. Legal basis: contract.
  • Customer & order data (name, email, phone, address, order contents) — to fulfil orders placed on a restaurant's storefront. Legal basis: contract / legitimate interest (Art. 6(1)(f)).
  • Payment data — handled by Stripe; we store only payment status and references, never card details.
  • Fiscal data — transaction signatures via Fiskaly TSE, where legally required (Art. 6(1)(c)).
  • Delivery location — a rider's live GPS during an active own-fleet delivery, deleted once delivered. Legal basis: contract.

3. Processors

We use the following processors under Art. 28 GDPR (data-processing agreements in place):

  • Supabase — database, file storage, and restaurant/platform authentication
  • Clerk — diner account authentication
  • Stripe — payment processing and payouts (Connect)
  • Fiskaly — fiscal TSE signatures (KassenSichV)
  • Resend — transactional email (order confirmations / status)
  • Render — application hosting · Cloudflare — DNS / CDN

Tenant data is isolated per restaurant via row-level security. Some processors are based outside the EU/EEA (e.g. the USA); such transfers are safeguarded by EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

4. Retention

Account data is kept until the account is deleted. Orders and fiscal/tax records are retained for the statutory period (10 years under German tax law, § 147 AO) and then deleted. Other personal data is deleted when no longer needed; dormant customer records are anonymised automatically.

5. Your rights

You have the right to access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20) and objection (21), and to lodge a complaint with a supervisory authority. Contact [email@foodibo.de] to exercise these rights.

6. Cookies

Foodibo sets only strictly necessary cookies — for sign-in sessions (Supabase / Clerk) and your language/location preference. No analytics or marketing cookies are used, so no consent is required for them; if such cookies are added later, a consent manager will be provided.