Back to site
Privacy Policy
Last updated: 10 August 2026
This Privacy Policy explains how OHMYFOOD, Lda. processes personal data through
www.ohmyfood.eu, the OhMyFood customer, restaurant, and courier applications, and related
services made available in Portugal and the European Union.
Summary: we collect only the data needed to create and secure accounts, locate restaurants and deliveries, process
orders and payments, provide support, and send notifications chosen by the user. We do not sell personal data and
do not store full card numbers or CVV codes.
Controller and contact
The controller is OHMYFOOD, Lda., a Portuguese company with
NIPC 519 515 382. For privacy questions, data-subject requests, consent withdrawal, or deletion
requests, contact geral@ohmyfood.eu.
Scope
This policy applies to the public website, OhMyFood mobile and web applications, restaurant and courier portals,
and the APIs and services that support them. Some flows may show additional notices when a permission is requested;
those notices supplement this policy.
Data processed and how it is collected
-
Account and identity: name, email address, phone number, protected credentials, verification
status, Google sign-in identifiers when that option is used, and information needed to distinguish customer,
restaurant, or courier roles. This data is provided by the user or authentication provider.
-
Address and location: saved addresses, postal code, city, and geographic coordinates; current
location only when the user authorises device access. We use this data to check coverage, show nearby restaurants,
geocode addresses, and track an active delivery. We do not request background location for normal app operation.
-
Orders and service: selected restaurant, items, options, amounts, order status, history, reviews,
favourites, support messages, and, where applicable, information needed for customer, restaurant, and courier
communications to complete a delivery.
-
Payments and billing: billing information, including name and tax number where provided,
payment references, method, authorisation status, refunds, and data needed for tax obligations. The payment form
and full card-data processing are handled by Stripe; OhMyFood does not intend to store the full card number or CVV.
-
Photos and content: profile images and other files voluntarily uploaded by a user or partner,
as well as reviews and support requests.
-
Device, notifications, and security: push-notification token, device type, operating system, app
version, browser, IP address, sessions, technical events, and records needed for authentication, fraud prevention,
security, availability, and diagnostics. The push token is used only to deliver notifications and can be disabled
in the app or device settings.
-
Website and local storage: language preference and analytics-cookie choice. The Google tag sends
analytics page views only after analytics consent is accepted; essential preferences may remain in browser local
storage.
-
Partner and compliance data: when someone acts as a restaurant or courier, we may process
professional, contact, tax, vehicle, identity, and verification data required for approval, operations, payments,
and legal compliance.
Purposes and legal bases
- Accounts and orders: create and secure an account, authenticate, display restaurants, receive and deliver orders, and provide support, based on the contract or pre-contractual steps.
- Payments and billing: authorise charges, manage refunds, prevent abuse, and meet tax and accounting obligations, based on the contract and legal obligations.
- Location: check coverage, calculate distances, show nearby restaurants, and support an active delivery, based on the user’s choice/permission and the requested service.
- Notifications: send order, security, and support updates when the feature is enabled and according to the user’s preferences.
- Security and operation: protect accounts and systems, detect fraud, resolve incidents, keep technical records, and improve reliability, based on legitimate interests and, where applicable, legal obligations.
- Communications and analytics: respond to contacts and, on the website, measure usage in aggregate only after analytics consent.
Sharing and service providers
We share data only when needed for an informed purpose, to provide the service, comply with law, or protect rights.
Providers processing data on our behalf must provide the same or equivalent protection described in this policy and
process data only under our instructions.
- Restaurants and couriers: receive data needed to prepare, deliver, and support an order, such as name, address, instructions, contact details, and order information.
- Stripe: payment processing, saved payment methods, authorisations, and refunds.
- Google: sign-in, maps/geocoding, Firebase Cloud Messaging for notifications, and on the website Google Analytics/Google tag only when analytics consent is accepted.
- HERE: geocoding and address search when enabled as a technical alternative.
- Cloudinary: storage and delivery of images uploaded for profiles and platform content.
- Resend and Twilio: transactional email and, when enabled, SMS/phone verification.
- Infrastructure: hosting, database, queue, security, and technical-support providers with access limited to what is needed to operate the service.
- Authorities: public bodies, courts, advisers, or auditors when disclosure is required or necessary to meet a legal obligation or defend rights.
We do not sell personal data, use order data for behavioural advertising, or share data with third parties for
incompatible purposes without informing the user and obtaining consent where required.
International transfers
Some providers may process data outside the European Economic Area. When this happens, we seek an appropriate legal
basis, such as an adequacy decision, standard contractual clauses, or another GDPR-recognised mechanism, together
with appropriate technical and organisational measures.
Retention, deletion, and withdrawal
We retain each category of data only for as long as needed for the relevant purpose, service security, dispute
resolution, and legal, tax, and accounting obligations. When there is no valid need to retain it, we delete,
anonymise, or restrict access to the data.
Customers can start account deletion at Profile → Security → Delete account; restaurant managers at
Settings → Manager account → Delete manager account; and drivers at
Profile → Account → Delete account. They can also use the
public account-deletion request page or email
geral@ohmyfood.eu.
We verify the request to protect the account, disable access, and immediately delete or anonymise profile identifiers,
credentials, saved addresses, tokens, cart, favourites, notifications, and user-created content. Minimal support,
security, fraud, and audit metadata may remain for up to 24 months; order, payment, billing, wallet, payout, and compliance
records may remain for up to 10 years where needed for tax, accounting, regulatory, or fraud-prevention obligations. Those
records are pseudonymised and restricted to the applicable retention purpose.
Website analytics consent can be withdrawn through the cookie options. Location, photo, camera, and notification
permissions can be changed in the app or operating-system settings. Users can also contact us to withdraw consent
where applicable.
Your rights
Under the GDPR, you may have rights of access, rectification, erasure, restriction of processing, portability,
objection, and withdrawal of consent. To exercise a right, contact
geral@ohmyfood.eu; we may request reasonable information to confirm your
identity. You may also lodge a complaint with the
Portuguese Data Protection Authority (CNPD).
Security
We apply appropriate technical and organisational measures, including HTTPS, access controls, authentication,
credential protection, data minimisation, payment tokens instead of full card data, security logging, and restrictive
permissions. No transmission or storage method is completely risk-free.
Children
The services are not directed at children. We do not knowingly seek to collect children’s personal data without the
legal basis and parental consent required. If you believe a child has provided us with personal data, contact us so
we can assess and delete it where appropriate.
Changes to this policy
We may update this policy to reflect legal, technical, or product changes. The date at the start of the page shows
the most recent version. When a change is material, we will seek to communicate it through appropriate channels.
For any question about this policy or your personal data, contact
geral@ohmyfood.eu.