FoodoZone
Privacy

Privacy Policy

The short version: we collect only what we need to run FoodoZone, we don't sell your data, and we never see your full card number. The long version is below.

Last updated 23 June 2026
01

Who we are

FoodoZone Inc. ("we", "us", "our") operates the FoodoZone website, mobile apps, and the restaurant and rider portals. We are the data controller for the personal data described in this Privacy Policy.

Our registered office is 10 Borough High Street, London SE1 9QQ, United Kingdom. You can reach our Data Protection Officer at dpo@foodozone.com.

02

What data we collect

We collect only what's needed to run the service.

  • Account data

    Your name, email address, password (hashed, never stored in plain text), phone number, and profile photo if you upload one.

  • Order data

    The restaurants and dishes you've ordered, your delivery address(es) or pickup choice, order notes, promo codes used, and order status history.

  • Payment data

    We never see or store your full card number. Stripe (our payment processor) tokenises your card and gives us a reference plus the brand, last 4 digits, and expiry — for display only.

  • Device & technical data

    Browser type, app version, OS, IP address, device identifiers, and a push notification token if you opt in. Used to operate the service and prevent fraud.

  • Communications

    Messages you send us via the contact form or email, and customer support conversations.

  • Reviews & ratings

    Star ratings and review text you submit about restaurants. These are public on the restaurant's page.

03

How we collect your data

We gather data in three ways:

  • Directly from you

    When you sign up, place an order, save an address or card, leave a review, or message support.

  • Automatically

    Through the website, app, and our backend logs — for example, device info, order timestamps, and page interactions.

  • From third parties

    From Stripe (payment confirmation), Google (if you sign in with Google), and restaurants and riders that need information to fulfil your order.

04

Why we use your data (and our legal basis)

Under UK GDPR, we need a lawful basis for each use of your data. Ours are:

  • Performance of a contract

    To create and manage your account, process and deliver orders, charge payment, calculate fees, and provide customer support. Without this data the service can't work.

  • Legitimate interests

    To improve and secure the service, prevent fraud, debug technical issues, and analyse aggregate usage. We balance these interests against your privacy.

  • Legal obligation

    To retain order and payment records for tax, accounting, and consumer-protection law (typically up to 6 years).

  • Consent

    For optional things like push notifications, marketing emails, and non-essential cookies. You can withdraw consent at any time.

05

Who we share your data with

We share only what's necessary, and only with:

  • Restaurants

    Your name, contact phone, and delivery address (for delivery orders) so they can prepare and fulfil your order.

  • Riders

    Your delivery address, phone, and order details — only for the duration of the delivery.

  • Stripe

    For payment processing. Stripe is the only party that handles your card number directly.

  • Cloud infrastructure

    Supabase (database, EU region), Railway (servers), and Cloudflare (CDN). All under data processing agreements.

  • Communication tools

    Expo (mobile push), web push providers, and our email-sending tool. They process notifications on our behalf.

  • Legal authorities

    Where we're legally required to disclose data — for example, by court order or regulatory request.

We don't sell your data to advertisers. Ever.

06

Cookies and tracking

We use a small number of strictly necessary cookies to keep you signed in (your JWT session token) and remember your cart. These don't require consent under UK ePrivacy rules.

We currently don't use any third-party analytics, advertising, or tracking cookies. If that ever changes, we'll add a cookie banner and only set non-essential cookies after you opt in.

07

How long we keep your data

  • Active account data

    Kept while your account is open and for 12 months of inactivity. After that we may delete or anonymise it.

  • Order and payment records

    Retained for 6 years from the end of the relevant tax year, as required by UK accounting and consumer-protection law.

  • Support conversations

    Kept for 2 years so we can reference past issues if you contact us again.

  • Marketing consent

    Stored until you withdraw consent or your account is closed.

When you ask us to delete your account, we remove your personal data — but the legally-required order and tax records stay in our books, anonymised where possible.

08

Your rights under UK GDPR

You have the following rights over your personal data. To exercise any of them, email dpo@foodozone.com from the email address on your account.

  • Right of access

    Ask us for a copy of the personal data we hold about you. We'll respond within 30 days.

  • Right of rectification

    Ask us to correct anything that's inaccurate or incomplete. You can edit most of this yourself in your profile.

  • Right of erasure

    Ask us to delete your data. Some records (orders, payments) must be retained for legal reasons — we'll explain what we keep and why.

  • Right to restrict processing

    Ask us to pause certain uses of your data while we look into a concern.

  • Right to data portability

    Ask for a machine-readable export of the data you've given us.

  • Right to object

    Object to processing based on legitimate interests, including any direct marketing.

  • Right to withdraw consent

    Where we rely on consent (push notifications, marketing emails), withdraw it any time without affecting prior processing.

  • Right to complain

    Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

09

International data transfers

Most of your data is stored in the EU (Supabase EU region). Some processors — including Stripe and Expo — are based in the United States or operate global networks.

Where data leaves the UK or EEA, we rely on the UK Government's adequacy decisions or the International Data Transfer Addendum (IDTA) to the EU Standard Contractual Clauses to keep your data protected.

10

How we secure your data

We encrypt data in transit using TLS, hash passwords using bcrypt, and store databases behind firewalled cloud infrastructure.

Card details are tokenised and stored by Stripe — a PCI-DSS Level 1 certified processor. We never see or store full card numbers.

We restrict employee access to personal data on a need-to-know basis and log access for audit. No system is perfectly secure, but we apply industry-standard controls and continuously improve them.

11

Children's data

FoodoZone is intended for users aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account on FoodoZone, email dpo@foodozone.com and we'll delete it.

12

Changes to this policy

When we make material changes — for example, adding a new third-party processor or a new lawful basis — we'll notify you by email or via an in-app banner at least 14 days before they take effect.

The current version is always available at foodozone.com/privacy, with the date at the top.

13

Contact our DPO

Questions, concerns, or rights requests? Email our Data Protection Officer at dpo@foodozone.com.

Postal address: Data Protection Officer, FoodoZone Inc., 10 Borough High Street, London SE1 9QQ, United Kingdom.