Privacy policyexplanation
How and why we process personal data on the GastroSprint website and restaurant apps.
1. Responsible person
Darren Jeffrey Thomas
gastro sprint
Bieshausener Str. 2a
51580 Reichshof
Germany
Email: kontakt@gastrosprint.de
2. Overview of processing
We process data that you provide to us as well as technical data that is generated when you access the website or use a GastroSprint restaurant app. This includes, in particular, contact and form data, account and order data, connection and device data as well as voluntarily transmitted information.
The processing takes place to provide the website and apps securely, to carry out orders, to prevent misuse and to process business inquiries. We do not purchase any personal profiles and do not use the data for cross-app advertising or profile creation.
3. Provision of the website and server logs
When you access this website, technically necessary connection data is processed. This may include, in particular, IP address, date and time of access, resource accessed, referrer URL, browser and operating system information as well as status codes.
The processing is carried out to deliver the website, ensure its stability and security and prevent misuse. The legal basis is Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in the safe and reliable operation of our online offering.
For hosting, content delivery and security functions we use Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. In particular, Cloudflare can process IP addresses, routing and system information as well as other traffic-related data. Details can be found in the Cloudflare privacy policy.
4. Transport encryption
The productive website is provided encrypted via TLS. This protects data that your browser transmits to our website from being read or altered by third parties during transmission. You can recognize an encrypted connection by “https://” in the address bar of your browser.
5. Demo and contact requests
When you submit the contact form, we process your name, restaurant name and email address. Telephone number, message and values from the savings calculator are voluntary. The processing serves to answer your query, arrange appointments and prepare a possible contract.
The legal basis is Article 6 Paragraph 1 Letter b GDPR, as long as the request is directed to a contract. Otherwise, the processing is based on Article 6 Paragraph 1 Letter f GDPR; Our legitimate interest lies in processing business inquiries.
If you contact us directly by email, we will also process the information you provide to process and respond to your message on the same legal basis.
Online booking and subscription payment via Stripe
Our booking buttons lead to a checkout page provided by Stripe. Only there do you enter your company and contact details, billing address and payment information. Stripe processes this information as well as technical connection and transaction data for payment processing, subscription management and fraud prevention. We receive the booking, invoice and payment status information necessary to process the contract. There is no Stripe payment form embedded on our pricing page.
We process the contract and billing data to fulfill the contract on the basis of Article 6 Paragraph 1 Letter b GDPR and to fulfill statutory retention obligations according to Article 6 Paragraph 1 Letter c GDPR. Depending on the processing, Stripe can act as a processor or an independent controller. This contains information about the responsible Stripe companies, other recipients, international data transfers and your rights Stripe privacy policy.
6. Email delivery with Resend
For the technical transmission of the form request, we use Resend, a service provided by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA. The information will be sent to our internal contact address; the website does not create an additional contact database.
Processing is carried out on the basis of Article 6 Paragraph 1 Letter b and Letter f of the GDPR. Resend processes data primarily in the USA. Further information can be found in the Privacy Policy and in Data Processing Addendum by Resend.
7. Protection against abuse with Cloudflare Turnstile
On the contact page, we use Cloudflare Turnstile to detect automated and abusive form requests. For this purpose, Cloudflare processes technical signals from the browser and end device and provides a short-lived test result. Server-side validation can also include the IP address.
The legal basis is Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in protecting the form, our systems and our communication channels. Cloudflare processes signals to provide the service on our behalf and certain signals to improve bot detection under its own responsibility. Further details are contained in the Turnstile Privacy Notice from Cloudflare.
8. Savings calculator and session storage
The entries in the savings calculator are initially only processed locally in your browser. If you select "Discuss this savings," the values will be temporarily stored in your browser's session memory and displayed on the contact page. They will only be sent to us when you submit the form. The session memory is deleted when the browser session is closed or after a successful request.
Views via partner links
For selected partner links, we count the views and successfully transmitted requests per campaign on the server side. This counting data contains only the calendar day, the event type and a random event identifier; they do not contain any IP address, browser data or contact details and are deleted after 200 days. For this purpose, we do not set any additional cookies and do not store any visitor identification in the browser. Repeated views can be counted multiple times.
General campaign information in the link, such as the name of the comparison portal and the placement, is retained in the link when the page changes internally. If you send the contact form, this information will be included in the inquiry email. They help us understand the origin of business inquiries. This does not change the settings and consent for Google Ads.
9. Voluntary website analysis and advertising measurement
With your voluntary consent, we use Google Ads conversion tracking from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland on the marketing website. We measure whether a demo or contact request was successfully transmitted after an ad click. It will not be activated without consent to the respective measurement; the form remains fully usable.
In particular, Google may process IP addresses, browser and device information, ad click identifiers and the conversion event including a random request ID. Google uses cookies for assignment purposes, in particular the _gcl_ family (regularly up to 90 days). We do not transmit names, email addresses, phone numbers or message texts via the conversion event. Enhanced conversions and personalized advertising are disabled in this integration.
With separate, voluntary consent, we use Google Analytics 4 from the same provider to evaluate page views and interactions on gastrosprint.de and to improve our website. Google processes, among other things, browser and device information, pages viewed, usage events and cookie identifiers. The IP address is also technically transmitted. The analytics cookies (_ga and _ga_*) are limited by our integration to up to 90 days. Google Signals and advertising personalization remain disabled. Website analytics and advertising measurement can be allowed or denied independently.
If you consent, we also store campaign parameters and ad click identifiers in session storage so that they are retained when you change pages until the request is made. This information is transmitted internally along with your request and helps us allocate advertising costs to requests. The session storage ends with the browser session. We save your selection locally in the browser for up to 180 days.
You can opt out of website analytics and advertising measurement at any time via “Privacy Settings” at the bottom of the page or revoke your consent. The revoked measurement will then be deactivated and the associated measurement cookies will be removed. If you revoke advertising measurement, we will also remove the advertising allocation in the browser. The revocation applies to the future. The legal basis for voluntary website analysis and advertising measurement is Article 6 Paragraph 1 Letter a GDPR and Section 25 Paragraph 1 TDDDG; The storage of your data protection selection serves to implement this selection.
Processing by Google in the USA is possible. Google provides information about recipients, protective measures and data processing in its Privacy Policy and the Data processing conditions for advertising products ready. These measurements only apply to the marketing website, not the restaurant apps.
10. Recipients and international data transfers
The only recipients of personal data are the internally responsible departments, the restaurant selected when placing an order and the technical service providers mentioned, insofar as this is necessary to provide the website and apps, to carry out your order or to process your request.
Data can also be processed by Cloudflare and Resend in the USA. According to the providers, such transfers are carried out, where applicable, on the basis of the EU-US Data Privacy Framework and, additionally or alternatively, on the basis of the EU standard contractual clauses. You can find further details in the data protection information and contractual conditions of the providers linked above.
11. Storage period
We only store personal data for as long as necessary for the respective purpose. If no contract is concluded, contact requests are regularly deleted after final processing, provided there are no legal retention requirements or legitimate interests in providing evidence. Contract, order and billing documents are stored in accordance with the statutory retention periods. Technical protocol and security data is deleted or anonymized after the time limits configured for the respective service.
12. Your rights
You have the right to information, correction, deletion, restriction of processing and data portability within the framework of the legal requirements. You can object to processing based on Article 6 Paragraph 1 Letter f of the GDPR for reasons arising from your particular situation. You can revoke your consent at any time with effect for the future.
You also have the right to complain to a data protection supervisory authority. In particular, you can contact the authorities of your place of residence, your place of work or the place of the alleged violation.
13. Obligation to provide
The information marked as mandatory fields is required so that we can process your request. Without this information, processing via the form is not possible. There is no automated decision-making, including profiling.
14. GastroSprint Restaurant Apps
GastroSprint provides individual restaurants with a branded customer app. An account is not mandatory for normal guest ordering. Account details, order history, addresses, points, consents and notifications are processed separately for each restaurant.
The selected restaurant is the guest's contractual partner for processing an order and is responsible for acceptance, preparation, collection or delivery. GastroSprint operates the technical platform. As far as we process data for the restaurant, we do so according to its instructions. We are responsible for the GastroSprint account, platform operation, security and protection against misuse to the extent required by law.
15. Account, Order and Customer Features
When you place a guest order, we process the information required for the order. This may include name, email address, telephone number, delivery address, selected dishes and extras, order value, payment method, order status and voluntary order information. When you register, we also process an internal user ID, account data, saved addresses, securely assigned orders and session information.
The data is used to provide the menu, check prices and delivery terms, transmit the order to the restaurant, view the status, prepare a reorder and provide support. The legal basis is Article 6 Paragraph 1 Letter b GDPR, insofar as processing is necessary for orders, accounts or pre-contractual measures. Security and protection against misuse are also based on Article 6 Paragraph 1 Letter f of the GDPR.
Previous guest orders will not be associated with a later created account based solely on a matching email address or phone number. An assignment only takes place via a planned, verified one-time process.
16. Loyalty points and rewards
If the applicable restaurant has a loyalty program activated, we process qualified completed orders, points credits, redemptions, offsetting transactions and documented corrections. Points and rewards are restaurant-related. Points will not be awarded for guest orders without secure account association.
The processing serves to implement the selected loyalty program on the basis of Art. 6 Para. 1 lit. b GDPR. The immutable points log is also used to prevent double bookings and misuse and to make corrections traceable.
17. Push Notifications and Consents
Notifications about a current order and marketing communications are managed separately. Marketing communications will only be sent with express, restaurant-related consent. Consent can be revoked at any time in the app. The revocation does not affect the lawfulness of the previous processing.
If you enable notifications, we process an installation identifier, the device and app-related push token provided by Apple, the app and system environment, consent status and shipping status. Delivery takes place via the Apple Push Notification service. Push content does not contain shipping address, customer name or complete order information. When opened, the app loads the protected details from the GastroSprint server.
The legal basis for marketing communications is Article 6 (1) (a) GDPR. Order status notifications are used to execute the contract in accordance with Article 6 Paragraph 1 Letter b GDPR, provided you activate them. Further information is contained in the Apple Privacy Policy.
18. App certificate and technical security
We use Apple App Attest to protect against manipulated app instances and automated misuse. Cryptographic key identifiers, one-off server tasks, attestation and signature data, app and installation references, and technical integrity signals are processed. The check is intended solely for the security of sensitive processes and not for advertising or creating a user profile.
The legal basis is Article 6 Paragraph 1 Letter f GDPR. Our legitimate interest lies in protecting orders, customer accounts, loyalty points and notification functions from misuse. Apple provides further information at App certificate ready.
19. Supabase and Email Delivery
We use Supabase for authentication and the technical storage of app data. In particular, account, session, order, restaurant relationship, points, consent and device assignment data are processed. The app does not have direct access to protected business data; these are checked via the GastroSprint server.
Further information can be found in the Supabase privacy policy and in Data Processing Addendum. The Resend service described in Section 6 can also be used for company emails and one-time codes.
20. Account Deletion and Privacy Options
A registered account can be removed directly in the app under Account and Delete Account. Sessions, push assignments, restaurant relationships and profile data that are no longer required are deleted. Order data that is subject to legal retention or proof requirements will be decoupled from the account or anonymized and only retained for the required period.
Regardless, marketing consent can be deactivated in the app. You can find further help and contact options at App support.
21. Changes to this Privacy Policy
We will adapt this privacy policy if the website, services used or legal requirements change.