Skip to content
OpenALaCarte
Legal

Privacy Policy

How we collect, use, and protect your personal data.

Last updated: 31 July 2026

1. Who we are

OpenALaCarte («we», «our») operates openalacarte.com. This policy explains how we collect, use, and protect personal data when you use our platform.

2. Data we collect

We collect information you provide directly: name, email address, phone number, and payment details. We also collect usage data (pages visited, features used) and technical data (IP address, browser type, device identifiers) automatically via cookies and similar technologies.

3. How we use your data

We use your data to provide and improve the platform, process bookings and orders, send transactional communications (booking confirmations, order updates), and — with your consent — promotional messages. We do not sell your personal data to third parties.

4. Legal bases (GDPR)

Our processing relies on: contract performance (to fulfil bookings and orders), legitimate interests (platform security, fraud prevention, product improvement), consent (marketing emails, non-essential cookies), and legal obligation (tax and accounting records).

5. Data sharing

We share your data with restaurants you book or order from (necessary to fulfil your reservation), payment processors (Stripe), cloud infrastructure providers, and analytics services — all under strict data processing agreements.

6. Retention

We retain account data for as long as your account is active, plus 3 years after closure for legitimate interest purposes. Transaction records are kept for 7 years to comply with applicable tax law. You may request deletion at any time subject to these legal obligations.

7. Your rights

Under GDPR you have the right to access, rectify, erase, restrict, and port your personal data, as well as to object to certain processing. To exercise any right, email privacy@openalacarte.com. You may also lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).

8. Security

We use TLS encryption in transit, AES-256 at rest, and follow OWASP security guidelines. Access to personal data is restricted to authorised personnel on a need-to-know basis.

9. Contact

Data controller: OpenALaCarte. Email: privacy@openalacarte.com.

Questions about this document? Email legal@openalacarte.com