orderbird logo

Privacy Policy Order Management

Berlin, 26 June 2024

General information

The following privacy policy explains how we handle your personal data when you use our order management system.

Data means all information relating to an identified or identifiable natural person, that is, in particular, information by which you can be personally identified.

We take the protection of your personal data very seriously. We treat your personal data confidentially accordingly and process it only in line with the statutory data protection provisions, as explained in this privacy policy.

I. Basic principles

1. Controller

The controller for data processing within this online service is:

Name: orderbird GmbH
Street: Ritterstraße 12, entrance 3
Postal code, city: 10969 Berlin
Tel.: +49 30 208 983 099
Fax: +49 321 214 681 89
Email: [email protected]

2. Contact details of our data protection officer

Sebastian Dramburg/orderbird GmbH
Ritterstraße 12, Aufg. 3
10969 Berlin
E-Mail: [email protected]
Website: www.orderbird.com

3. Scope of this privacy policy

This privacy policy applies to all users who either view the services of restaurants and place orders as end customers via our online service ("guests") or use our service as operators of restaurants ("hospitality businesses"). This privacy policy does not cover third-party services to which the online service may refer by means of links. We generally accept no responsibility for their content or for those third parties' compliance with data protection provisions, unless stated otherwise in the privacy policy of the linked content. This applies, for example, to links to social networks such as Facebook and X. You will find information on how personal data is handled and protected on those platforms in the privacy policy of the platform concerned.

4. Encryption and encrypted payment processing

For security reasons and to protect the transmission of confidential content, such as orders or enquiries you send to us, this online service generally uses TLS encryption. In particular, where your payment data is transmitted in connection with concluding a paid contract, this is done exclusively via an encrypted connection. You can recognize such an encrypted connection by "https://" appearing before the website address in your browser's address bar and by a closed padlock symbol. When this TLS encryption is active, the data you transmit to us generally cannot be read by unauthorized third parties during transmission.

5. Disclosure of personal data

Subject to other provisions in this privacy policy, we generally disclose personal data to third parties only where this is necessary to provide our services, in particular to provide the order management menu and to process payments under a contract with you. Accordingly, data is transferred to such service providers (for example technical service providers and payment service providers) for the purposes of performing the contract with you on the basis of Article 6(1)(b) GDPR. Before disclosing your personal data we naturally make sure that the service provider concerned has taken appropriate technical and organizational measures to guarantee the security of the data.

Otherwise your personal data is not disclosed to third parties unless you have expressly consented to the disclosure (Article 6(1)(a) GDPR) and we are not entitled or obliged to disclose it on the basis of statutory provisions or court orders. In the latter case the transfer is made by us to comply with a legal obligation under Article 6(1)(c) GDPR.

6. General storage period and erasure

We store your personal data for as long as is necessary to fulfill the intended purpose (for example performance of the contract) or as long as statutory retention periods make storage necessary. As long as statutory retention obligations, such as tax and commercial law provisions, prevent your personal data from being erased, we restrict the processing of your data; your data is then erased in accordance with the statutory provisions.

7. Data subject rights, in particular to access, blocking and erasure

As a guest or, if you use our online service for hospitality businesses as a natural person, you have the following rights within the applicable statutory provisions.

a. Right to object

You have the right to object at any time, on grounds relating to your particular situation, to data processing based on Article 6(1)(e) or (f) GDPR, unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims. You can object to data processing for direct marketing purposes at any time without needing to give any particular reason.

b. Right of access

You have the right to be informed by us free of charge and in writing about the personal data concerning you that we hold, the purposes of processing, its origin, what disclosure has been made to which recipients or categories of recipients, the storage period and the data subject rights available to you.

c. Right to rectification, erasure and/or restriction of processing

You also have the right to request at any time the rectification of incorrect data, the erasure and/or restriction of processing of the personal data stored about you, in so far as we are under no statutory retention obligation. Where this covers personal data that is required in order to provide services to you, the erasure or restriction of processing of that data can only take place once you no longer use our service.

d. Right to data portability

Where you provide data concerning you and we process that data on the basis of your consent or to perform a contract, you can request that you receive that data from us in a structured, commonly used and machine-readable format, or that we transfer that data to another controller, in so far as this is technically feasible (the right to data portability).

e. Right to withdraw consent

You can freely withdraw any consent you have given to the use of personal data at any time with effect for the future.

f. Right to lodge a complaint with a supervisory authority

You can also lodge a complaint with a supervisory authority against data processing that in your view breaches the statutory provisions. The supervisory authority with which the complaint was lodged informs the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78 GDPR.

8. Changes to this privacy policy

We reserve the right to change this privacy policy at any time, in particular to take account of changes in the legal position and in processing operations, whereby we will of course always comply with the statutory data protection requirements.

We therefore recommend that you review the privacy policy in force from time to time. We will inform you in advance about any further use of data.

II. Data collection within the order management menu

1. Registration

You have to register in order to use parts of our services such as the order management menu. For this we collect the data you enter in the registration form, in particular your name and your contact details including your address and, where applicable, data for payment processing. Providing this information is necessary in order to complete the registration and thus to conclude the contract on the use of the services concerned. We use the data entered for this purpose only for the purpose of using the offer or service for which you have registered.

For important changes, for instance to the scope of the service or where technically necessary changes are made, we use the email address given on registration to inform you in this way about such matters as are relevant to the performance of the contractual relationship with you.

Where applicable we record further data that you provide voluntarily while using the order management menu, for example when you submit a review to the restaurant as a guest, and we process it in order to provide the corresponding functions of the order management menu.

The data entered on registration and while using the order management menu is processed in order to conclude and perform the contract with you on the use of the order management menu, on the basis of Article 6(1)(b) GDPR.

Where applicable we verify the address given on registration with the help of services in order to prevent errors or misuse, for example for collection or take-away orders. The basis for this processing is our legitimate interest under Article 6(1)(f) GDPR in preventing misuse of our services.

Where applicable you can also register for our online service using a single sign-on function of certain third-party providers, for example a social network, for which a user account with that third-party provider is required. We offer this function on our website with the help of the service provider Auth0, Inc., 10900 NE 8th Street, Bellevue, WA 98004, USA ("Auth0").

Registration by means of an account or single sign-on function is supported by the following third-party providers:

  • Google LLC (more on data protection at Google at:

https://policies.google.com/pr...) and

  • Facebook, Inc. (more on data protection at Facebook at https://dede.

facebook.com/policy.php).

For this function you have to enter your access details for your user account with the aforementioned third-party provider; these are sent directly to that third-party provider for verification, without us gaining access to that data. After verification the third-party provider informs us only of the data necessary for registration with us, such as your name and your email address, which we process in order to create your account with us. By using this single sign-on function, the third-party provider concerned receives the information that you have created a profile for our online service and can link that information to your respective user account with that third-party provider.

In the course of registration by single sign-on function and subsequent logins, the data required for this is sent to Auth0 servers in the USA and processed by Auth0 on our behalf in order to validate correct registration and login (such as your IP address, login time, login method and the third-party provider's information about the successful verification of your access details with it). All other data in your profile with us, such as the favorites and orders you have created, is stored exclusively on our servers in Germany and is not transferred to Auth0. You will find more information on data protection at Auth0 at: https://auth0.com/privacy.&nbs...;

We have also concluded a data processing agreement with Auth0. With regard to the transfer of data to the USA, we would point out that Google is a company based in the United States. The European Union has issued an adequacy decision (EU-U.S. Data Privacy Framework) governing the transfer of personal data to the USA. Google has undertaken to comply with the data protection provisions of the U.S. Data Privacy Framework and is certified accordingly.

The legal basis for the data processing within these single sign-on functions is your consent (Article 6(1)(a) GDPR), which you give when calling up the individual single sign-on option and subsequently entering your access details for your account with the third-party provider. You have the option of withdrawing your consent to this data processing at any time. A withdrawal does not affect the validity of data processing operations carried out in the past.

2. Processing of data for orders via order management (customer and contract data)

In order to place an order and, where applicable, process payment via the order management menu as a guest, we collect, process and use the personal data required to carry out your order, in particular your name, the exact order and the payment method chosen, and transfer that data to the respective hospitality business with which you placed the order, in so far as it is required for concluding the contract on your order and for processing it

To call up a restaurant's menu you can scan a QR code provided in the restaurant using the camera of your smartphone or other device. This requires a corresponding app for recognizing the QR code to be installed on your device.

This data processing within orders via the order management menu takes place on the basis of Article 6(1)(b) GDPR, which permits the processing of data in order to perform the contract with you on the use of the order management menu.

3. Payment processing for orders

In order to handle a guest's orders via the order management menu we collect and process the usage data required for this in accordance with the preceding sections, as well as the payment information you provide, and make the information on payment required for their billing available to the hospitality business.

For payment processing by credit card we use the payment service Stripe. The provider of this payment service is Stripe Payments Europe, Ltd, 61A Nile St, Hoxton, London N1 7RD, United Kingdom. If you select payment by credit card, the payment data you enter is transferred to Stripe for the purpose of processing your payment. Where applicable Stripe also transfers the data to servers of Stripe, Inc. in the USA for this purpose. You will find more details in Stripe's privacy policy at https://stripe.com/de/privacy....;

We have also concluded an agreement on data processing with Stripe incorporating the EU standard contractual clauses. The disclosure of data to Stripe is therefore based on Articles 45 and 28 GDPR.

Where applicable we also offer payment via PayPal in the order management menu. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg ("PayPal"). If you select payment via PayPal, you are redirected to a PayPal website and the payment data you enter there is transferred to PayPal. Payment by PayPal requires you to have registered an account with that service. PayPal therefore processes your data independently in accordance with the agreement you concluded with PayPal when registering your PayPal account. You will find more detailed information on data processing by PayPal in the PayPal privacy policy at https://www.paypal.com/de/weba....

Where applicable PayPal also transfers the data to servers of PayPal, Inc. in the USA for payment processing. For this transfer we have concluded the standard contractual clauses approved by the EU Commission with PayPal, Inc. The disclosure of data to PayPal, Inc. is therefore based on Article 46(2)(b) GDPR.

The legal basis for the data processing to handle payments and to involve the payment service providers explained above is Article 6(1)(b) GDPR, because this is required in order to perform the user contract concluded with you on the order management menu, in so far as you use the payment function in the order management menu.

4. SMS notification

Guests can have themselves notified by SMS on their mobile phone when an order is ready for collection. To send the SMS order notification we use a service from Vonage. (Vonage Holdings Corp., 101 Crawfords Corner Rd Ste 2416 Holmdel, NJ, 07733-1980, USA). We have concluded a contract with this company under Article 28 GDPR (processing on behalf of a controller).

Within the SMS notification we process the guest's telephone number. It is stored only for the purpose of the order notification and erased after two weeks. Notification by SMS is part of our service and the processing therefore takes place in accordance with Article 6(2)(b) GDPR.

With regard to the transfer of data to the USA, we would point out that Vonage is a company based in the United States. The European Union has issued an adequacy decision (EU-U.S. Data Privacy Framework) governing the transfer of personal data to the USA. Vonage has undertaken to comply with the data protection provisions of the U.S. Data Privacy Framework and is certified accordingly.

You will find further information in Vonage's privacy policy, which can be viewed here: www.vonage.com/legal/privacy-policy/