Privacy & data protection
This notice describes how personal data is processed when you use restaurant booking, ordering, and related services on this platform. Where applicable, you have rights under data protection law (including rules similar to the GDPR).
Who is responsible for your data?
The data controller decides why and how your personal data is processed. That may be a company or a person responsible for operating this service. Below you will find the identity and contact details of the controller.
Controller: KRISHNA BAHADUR THAPA
Contact (data protection): [email protected]
What personal data we process
Depending on how you use the service, we may process:
- Reservations: name, email, phone, party size, date and time, table assignment where applicable, notes or special requests, status updates, and linked account data if you book while logged in.
- Orders: name, contact details, delivery or collection information, ordered items, and payment-related references (card payments are handled by payment providers; we do not store full card numbers on this system).
- Accounts (restaurant staff / owners): name, email, authentication details, and activity needed to operate the panel.
- Newsletter: email and optionally name, only if you have signed up; you can unsubscribe using the option provided when you subscribed.
- Technical logs: IP address, timestamps, and similar metadata may be kept in server or security logs for a limited time.
- Analytics (e.g. menu search): usage events may be stored to improve the service; please avoid entering personal data in free-text search fields.
Purposes and legal bases
- Contract / pre-contract steps — to take and manage reservations and orders you request.
- Legitimate interests — to secure the platform, prevent abuse, and improve the service, in balance with your rights.
- Consent — where required (for example certain marketing or newsletter messages); you may withdraw consent at any time.
- Legal obligation — where we must keep or disclose information to comply with the law.
How long we keep data
We keep personal data only as long as needed for the purposes above, including any period required by law (for example accounting or tax rules). After that, data is deleted or anonymised where appropriate.
Recipients and transfers
We use service providers (such as hosting, email delivery, payments, or notifications) who process data on our instructions. If a provider is outside the European Economic Area, we use appropriate safeguards where required (for example Standard Contractual Clauses).
Restaurant operators may access guest data relating to their own venue in order to fulfil bookings and orders.
Your rights
Where the law applies, you may have the right to access, rectification, erasure, restriction, objection, and data portability, and to withdraw consent where processing is based on consent. You may also lodge a complaint with a supervisory authority.
In Portugal, the supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD).
To exercise your rights, contact us at [email protected].
Automated decisions
We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects concerning you.
Updates
We may update this notice from time to time. The current version is always the one published on this page.