The Food PleaseEspañol

Draft pending review by a lawyer · Version dated 2026-09-28

Privacy policy

Version dated 2026-09-28 · This English version is provided for convenience. In case of discrepancy, the Spanish version prevails.

This policy explains how [RAZÓN SOCIAL / COMPANY NAME], tax ID (NIF) B87266987, registered office at [DIRECCIÓN / ADDRESS] (“The Food Please”) processes personal data when you visit thefoodplease.com, create an account or use the platform, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection and digital rights (LOPDGDD).

1. Controller

[RAZÓN SOCIAL / COMPANY NAME], tax ID (NIF) B87266987, registered office at [DIRECCIÓN / ADDRESS]. E-mail: [email protected].

Data Protection Officer / privacy contact: [EMAIL DEL DPD / DPO E-MAIL, or state “not appointed” and keep the contact e-mail].

2. Two roles: when we are controller and when we are processor

We are the controller for data of people who visit the website, sign up as administrators of a restaurant, register as suppliers on The Market or contact us (support, sales).

We are a processor for the data each restaurant collects through the platform from its own guests and employees: orders, reservations, customer club, stamps, reviews and working-time records (time clock). In those cases the controller is the restaurant; we process the data on its instructions under the Data processing agreement.

If you are a restaurant's guest (you ordered, booked or left a review through its menu) and want to exercise your rights, contact the restaurant. If you write to us, we will forward your request.

3. Data we process

  • Restaurant account: first and last name, e-mail, password (hashed), phone, venue name and details (address, logo, subdomain) and billing tax details.
  • Payment: Stripe collects and stores card data. We receive a customer identifier, the last four digits, the subscription status and invoices.
  • Platform usage: technical logs (IP address, date and time, browser, pages visited, errors), dashboard actions and aggregated menu statistics (dish views).
  • Communications: support e-mails, forms and, with your consent or as a customer, commercial communications.
  • Market suppliers: company and contact-person details, catalogue and orders received.
  • As processor, on behalf of the restaurant: name, phone and e-mail of whoever orders or books, table, order contents and amount, review rating and comment, club data (name, mobile, stamps) and employees' identification and working-time data (time clock).

4. Purposes and legal bases

  • Providing the contracted service and managing the account, subscription, billing and support: performance of a contract (art. 6(1)(b) GDPR).
  • Complying with legal obligations: invoicing, accounting and tax retention, handling rights requests and requests from authorities (art. 6(1)(c) GDPR).
  • Platform security, fraud and trial-abuse prevention, technical logs: legitimate interest (art. 6(1)(f) GDPR).
  • Service notices to customers (changes, failed payments, relevant product news): performance of a contract and legitimate interest.
  • Commercial communications about similar products to existing customers (art. 21.2 of Spanish Law 34/2002, LSSI), with the option to object in every message; to non-customers only with consent (art. 6(1)(a) GDPR).
  • Sales contact with restaurants and suppliers using professional contact details obtained from public sources (their website, directories): legitimate interest (art. 19 LOPDGDD). You may object at any time.
  • Aggregated statistics and product improvement: legitimate interest, using aggregated or pseudonymised data wherever possible.

5. Recipients and processors

  • Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA): payments, subscriptions and billing. For payment processing Stripe also acts as an independent controller.
  • OVH SAS (OVHcloud, France): hosting of the platform and databases in data centres located in France (European Union).
  • [PROVEEDOR DE EMAIL / E-MAIL PROVIDER]: transactional e-mails (sign-up, order notices, billing) and communications.
  • Google (Google Ireland Ltd.): when you click the reviews or maps link you leave for Google's services, under Google's own privacy policy. We do not share your account data with Google.
  • Advisers (accounting, legal) and public authorities where required by law.

We do not sell personal data or share it with third parties for advertising purposes.

6. International transfers

Our servers are in the European Union. Stripe may transfer data to the United States under the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework. [Check the e-mail provider: if it processes data outside the EEA, state the applicable safeguard.]

7. Retention

  • Account data: while the account is active and, after closure, 30 days to allow export. It is then deleted or anonymised, except as stated below.
  • Invoices and tax data: 4 years under tax law and 6 years under the Spanish Commercial Code, from the last entry.
  • Technical and security logs: up to 12 months.
  • Data processed on behalf of the restaurant: for the term of the contract with the restaurant and on its instructions. Working-time records are kept for 4 years under the restaurant's obligation (art. 34.9 of the Workers' Statute). When the service ends they are returned or deleted under the Data processing agreement.
  • Commercial communications: until you object or withdraw consent.

8. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and not to be subject to automated decisions. You may withdraw consent at any time without retroactive effect.

How: by writing to [email protected] or to [DIRECCIÓN / ADDRESS], stating the right you exercise and, where there is reasonable doubt, proving your identity. We reply within one month, extendable by two further months in complex cases.

If you consider the processing unlawful you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

9. Security

Encrypted communications (HTTPS), hashed passwords, role-based access control, per-customer data separation, regular backups, access logs, servers in the EU and staff bound by confidentiality. Details are set out in the Data processing agreement.

10. Minors

The service is aimed at professionals. We do not knowingly collect data from children under 14. If a restaurant accepts orders or bookings from minors, that is its responsibility as controller.

11. Changes

Changes will be published here with their version date and customers will be notified of material changes.