Política de Privacidade

Versão 1.0 · em vigor desde 2026-05-11

Privacy Policy

⚠️ Notice: This text is a generic template and requires review by a lawyer before going into production.

1. Data Controller

The entity responsible for processing your personal data is [empresa], NIPC [NIPC], with registered office at [morada], contactable at [email] or [telefone].

Data Protection Officer (DPO): — [email DPO].

2. Data Collected

We collect the following personal data depending on the type of interaction:

  • Reservations and orders: name, email, telephone, number of people, occasion, allergies and dietary preferences.
  • Customer account: name, email, telephone, date of birth (optional), marketing preferences.
  • Payments: amount, date, method (sensitive card data is processed directly by Stripe and never reaches our servers).
  • Table via QR: optional identification (name, email, telephone) and participation in games/quizzes.
  • Reviews and feedback: ratings, comments, language.
  • Technical data: IP address, device identifiers, cookies, browsing data (see Cookie Policy).

3. Purposes and Legal Bases

The purposes for which we process your data, with the corresponding GDPR legal basis:

  • Performance of the contract (reservations, orders, payments) — Art. 6(1)(b)
  • Invoicing and tax obligations — Art. 6(1)(c)
  • Loyalty programme and customer tier — Art. 6(1)(b)
  • Marketing communications — Art. 6(1)(a) – consent
  • Aggregated statistical analysis — Art. 6(1)(f) – legitimate interest
  • Handling of complaints and ADR — Art. 6(1)(c)

4. Sub-processors

In order to provide the service, we share data with the following sub-processors:

  • Supabase Inc. — database and authentication (EU/USA, with Standard Contractual Clauses)
  • Stripe Payments Europe Ltd — payment processing (Ireland, transfers to the USA under SCC)
  • Resend Inc. — sending of transactional emails (USA, SCC)
  • Google LLC — Google Tag Manager, Maps, Business Profile (subject to cookie consent)
  • Cloudflare Inc. — CDN and protection against abuse
  • Vercel Inc. — application hosting

5. Retention Periods

  • Reservation data: 5 years after the visit
  • Invoices and tax documents: 10 years (legal obligation — Tax Code)
  • Marketing data: until consent is withdrawn
  • Reviews: indefinitely, unless deletion is requested
  • Technical logs: 90 days
  • Deleted customer account: 30 days until anonymisation

6. Your Rights

You have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict the processing
  • Object to processing based on legitimate interest
  • Data portability in a structured format
  • Withdraw consent at any time (this does not affect prior processing)

You may exercise these rights in your customer area or by sending an email to [email DPO].

7. Complaints to the Supervisory Authority

You have the right to lodge a complaint with the National Data Protection Commission (CNPD): www.cnpd.pt — Av. D. Carlos I, 134 - 1.º, 1200-651 Lisboa.

8. Security

We adopt appropriate technical and organisational measures: TLS encryption, role-based access control, audit logs, encrypted backups, and periodic review of permissions.

9. Changes

This Policy may be updated. The version in force is displayed with the respective date. In the event of material changes, fresh acceptance will be requested at the next login.

10. Contact

For questions about this Policy, please contact:

  • Email: [email]
  • Telephone: [telefone]
  • DPO: [email DPO]
  • Address: [morada]

Em caso de dúvidas legais ou pedidos relacionados com proteção de dados, consulte a ficha técnica e contactos.

This site uses cookies

We use cookies to improve your experience, analyse traffic and personalise content. You can choose which categories to accept. View Cookie Policy