Lieferking

Privacy Policy

Note: Highlighted passages must be reviewed/completed by legal before go-live (data-processing agreements, exact data categories, legal bases).

1. Controller

LTA Gastro Solutions GmbH
Krummspät 78
26810 Westoverledingen, Germany
Email: kontakt@lieferking.de

2. Hosting & infrastructure

This application and its backend run on DigitalOcean LLC (New York, USA) in a data centre in Frankfurt am Main, Germany (processing on our behalf, Art. 28 GDPR). Legal basis: our legitimate interest in secure, efficient delivery (Art. 6(1)(f) GDPR). Any transfer to the USA is based on the EU Standard Contractual Clauses.

3. Server log files & CDN (Cloudflare)

On access, technical information is processed automatically (IP address, time, page requested, referrer, browser/OS details). For secure, fast delivery and attack mitigation we use the CDN of Cloudflare, Inc. (San Francisco, USA). Legal basis: Art. 6(1)(f) GDPR; any transfer to the USA is based on the EU Standard Contractual Clauses.

4. Customer account & sign-in

To place an order we create an account (including for guests). We process your email, name and phone number. Authentication runs via FusionAuth (identity management). Legal basis: contract initiation/performance (Art. 6(1)(b) GDPR). We use strictly necessary (httpOnly) session cookies (§ 25(2) TDDDG).

5. Order processing & sharing with the partner restaurant

To fulfil your order we process your order data (items, options, delivery address, contact details, notes) and share the data required for preparation and delivery with the selected partner restaurant. Legal basis: Art. 6(1)(b) GDPR.

6. Payments (Stripe)

Online payments are processed via Stripe Payments Europe, Ltd. (Ireland). Payment and transaction data are processed directly by Stripe; we do not receive full card data. Legal basis: contract performance (Art. 6(1)(b) GDPR). Stripe's privacy notice applies in addition.

7. Address entry (Google Maps)

To determine your delivery address and nearby restaurants we use services of Google Ireland Ltd. (Google Maps Platform). Your input and IP address may be transmitted to Google. Legal basis: Art. 6(1)(b)/(f) or consent – to be reviewed.

8. Retention

We retain your data only as long as necessary for the stated purposes or as required by statutory retention periods (e.g. commercial and tax law). Server log files are usually deleted or anonymised after a short period.

9. Your rights

You have the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object to processing (Art. 21 GDPR)
  • withdraw consent (Art. 7(3) GDPR)

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).