1. Who we are (Data Controller)
Foodly (operating at foodly.solutions) is the data controller responsible for the personal data processed through the Foodly mobile apps, the Foodly web platform and this website (together, the "Service").
- Controller: Foodly (an Apps 369 company)
- Website: https://foodly.solutions
- Contact: hello@foodly.solutions
- Privacy requests: privacy@foodly.solutions
2. What data we process
Depending on how you use the Service, we may process the following categories of personal data:
- Account data — your name, email address and the credentials you use to sign in (including sign-in via biometric authentication on your device; biometric data itself never leaves your device).
- Location data — your approximate or precise location, used to show you restaurants, bars and other food businesses near you. Location access is optional and controlled through your device permissions; you can also search by typing an address.
- Photos and content you upload — profile pictures, review photos, posts and, for business accounts, menu and venue imagery.
- Reservation data — bookings you request, party size, dates, status, and messages exchanged with the business about a reservation.
- Order and payment data — items in individual or group orders, amounts, split shares, tips and payment status. Payments are processed by Stripe; Foodly never stores your card number (see section 5).
- Push notification tokens — device tokens used to send you notifications (e.g., reservation confirmations, order updates) via Firebase Cloud Messaging (FCM).
- Basic analytics and technical data — app events (e.g., screens viewed, features used), device type, operating system, language and crash reports, used to understand usage and improve the Service.
3. Why we process it (purposes and legal bases)
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and managing your account; providing the core Service (menus, discovery, reservations, orders, community features) | Account, reservation, order and content data | Performance of a contract (Art. 6(1)(b)) |
| Showing you nearby businesses | Location data | Consent (Art. 6(1)(a)) — via your device's location permission, revocable at any time |
| Processing payments, split payments and tips; preventing fraud | Order and payment data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for accounting records |
| Sending push notifications about your reservations and orders | Push tokens, reservation/order data | Performance of a contract (Art. 6(1)(b)); consent for optional/marketing notifications |
| Improving and securing the Service; fixing bugs | Analytics and technical data | Legitimate interests (Art. 6(1)(f)) — running a safe, reliable product |
4. How long we keep your data (retention)
- Account data — kept while your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where we must keep it longer by law.
- Reservation and order records — kept for the duration required for accounting, tax and payment-dispute purposes (generally up to 10 years for invoicing records under Portuguese law, where applicable).
- Photos and posts — kept until you delete them or delete your account.
- Analytics data — kept in aggregated or pseudonymised form; raw event data is retained for a limited period.
- Push tokens — deleted when you log out, disable notifications or uninstall the app.
5. Payments — Stripe as processor
All in-app payments (including group orders, split payments and tips) are processed by Stripe Payments Europe, Ltd. and its affiliates ("Stripe"), a PCI-DSS certified payment provider. Your card details are collected directly by Stripe through secure payment interfaces; Foodly does not receive and does not store your full card number. Foodly only receives confirmation of payment status and limited metadata (e.g., last four digits, card brand) needed to display your payment history. Stripe acts as a processor/independent controller for its own compliance obligations — see Stripe's Privacy Policy.
6. Who we share data with
- Food businesses on Foodly — when you make a reservation or place an order, the business receives the details needed to fulfil it (your name, party size, order items, payment status — never your card details).
- Service providers (processors) — Google Cloud / Firebase (hosting, database, authentication, push notifications, analytics) and Stripe (payments). All are bound by data processing agreements.
- Authorities — only where required by law.
We do not sell your personal data.
7. International transfers
Your data is primarily stored in the European Union. Some of our providers (Google Cloud/Firebase, Stripe) may transfer limited data outside the EU/EEA. Where that happens, transfers are protected by the European Commission's Standard Contractual Clauses and/or an adequacy decision (such as the EU–US Data Privacy Framework), together with additional safeguards.
8. Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — ask us to delete your data ("right to be forgotten");
- Restriction — limit how we process your data in certain cases;
- Portability — receive your data in a structured, commonly used, machine-readable format;
- Objection — object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent — at any time, without affecting processing already carried out (e.g., disable location access in your device settings).
To exercise any of these rights, email privacy@foodly.solutions. We will respond within one month. You also have the right to lodge a complaint with your supervisory authority — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt.
9. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encrypted storage, role-based access controls, and EU-hosted infrastructure on Google Cloud. No system is 100% secure, but we work to protect your data at every layer.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Cookies and analytics on this website
On foodly.solutions (this website) we use Google Analytics 4 to understand how visitors find and use the site — pages viewed, language, approximate region, app-store clicks and scroll depth. This is optional: analytics cookies are set only after you accept them in the banner shown on your first visit. If you reject, Google receives anonymous, cookie-less signals that cannot identify you or your device.
- Strictly necessary — required for the site to work (security, your cookie choice). Always active; no consent needed.
- Analytics (optional) — Google Analytics 4, with IP anonymisation and advertising features disabled. Legal basis: your consent (GDPR Art. 6(1)(a)). Retention: up to 14 months.
You can change your mind at any time by clearing this site's data in your browser, which makes the banner appear again. We do not use advertising or tracking cookies, and we do not share this data with advertisers.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a new "Last updated" date and, for material changes, notify you in the app or by email.
13. Contact
Questions about this policy or your data? Write to privacy@foodly.solutions or hello@foodly.solutions.