Legal
Privacy Policy
Last updated: 17 April 2026
Preamble
With the following privacy policy we would like to inform you about the types of your personal data (hereinafter also referred to as "data") we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the "online offering").
The terms used are not gender-specific.
Controller
EAT THIS
Ersan Erkut
Berlin, Germany
Email address: hello@eatthisdot.com
Overview of processing operations
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
• Inventory data.
• Payment data.
• Contract data.
• Contact data.
• Content data.
• Usage data.
• Meta, communication and procedural data.
• Log data.
• Location data.
Categories of data subjects
• Communication partners.
• Users.
• Third parties.
Purposes of processing
• Provision of contractual services and fulfilment of contractual obligations.
• Communication.
• Security measures.
• Reach measurement.
• Feedback.
• Profiles with user-related information.
• Provision of our online offering and user-friendliness.
• Information technology infrastructure.
• Public relations.
Relevant legal bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or domicile.
• Consent (Art. 6(1)(a) GDPR) — the data subject has given consent to the processing of their personal data for one or more specific purposes.
• Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR) — processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps prior to entering into a contract.
• Legal obligation (Art. 6(1)(c) GDPR) — processing is necessary for compliance with a legal obligation to which the controller is subject.
• Legitimate interests (Art. 6(1)(f) GDPR) — processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the fundamental rights and freedoms of the data subject do not override those interests.
National data protection provisions in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany, in particular the Federal Data Protection Act (BDSG).
Security measures
In accordance with the legal requirements, and taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of processing, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as the access, input, disclosure, securing of availability and separation relating to it.
Securing online connections with TLS/SSL encryption (HTTPS): We use TLS/SSL encryption to protect data transmitted via our online services against unauthorised access. HTTPS in the URL indicates that encryption is active.
Transfer of personal data
In the course of our processing of personal data, it may happen that the data is transferred to, or disclosed to, other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks, or providers of services and content embedded in a website. In such cases we observe the legal requirements and, in particular, conclude corresponding contracts or agreements serving to protect your data with the recipients of your data.
International data transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the course of using third-party services, this is always done in accordance with the legal requirements.
For data transfers to the USA we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission of 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers.
Further information on the DPF and a list of certified companies can be found on the website of the US Department of Commerce at https://www.dataprivacyframework.gov/.
General information on data storage and erasure
We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consent is withdrawn or no further legal bases for the processing exist.
In particular, data that must be retained for commercial or tax law reasons, or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons, must be archived accordingly.
Retention periods under German law:
• 10 years — books and records, annual financial statements, inventories, management reports, opening balance sheet (Section 147(1) no. 1 AO, Section 14b(1) UStG, Section 257(1) no. 1 HGB).
• 8 years — accounting vouchers such as invoices and expense receipts (Section 147(1) nos. 4 and 4a AO, Section 257(1) no. 4 HGB).
• 6 years — other business documents and commercial or business letters received or sent (Section 147(1) nos. 2, 3, 5 AO, Section 257(1) nos. 2 and 3 HGB).
• 3 years — data required to consider potential warranty and damages claims (Sections 195, 199 BGB).
Rights of data subjects
As a data subject you have various rights under the GDPR, which arise in particular from Articles 15 to 21 GDPR:
• Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you; this also applies to direct marketing and profiling.
• Right to withdraw consent: You have the right to withdraw consent given at any time.
• Right of access: You have the right to request confirmation as to whether data concerning you is being processed, to obtain information about that data, and to receive a copy of the data.
• Right to rectification: You have the right to request the completion or rectification of data concerning you.
• Right to erasure and restriction of processing: You have the right to request that data concerning you be erased without delay, or that its processing be restricted.
• Right to data portability: You have the right to receive data concerning you in a structured, commonly used and machine-readable format.
• Complaint to a supervisory authority: You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence.
Provision of the online offering and web hosting
We process users' data in order to be able to provide them with our online services. For this purpose we process the user's IP address, which is necessary in order to transmit the content and functions of our online offering to the user's browser or device.
Types of data processed: Usage data; meta, communication and procedural data (e.g. IP addresses, timestamps); log data (server log files).
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Collection of access data and log files: Access to our online offering is logged in the form of so-called "server log files". This is done for security purposes and to ensure server load and stability. Log file information is stored for a maximum of 30 days and then deleted or anonymised.
Hosting provider: Firebase App Hosting (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The application runs in the Google Cloud region us-central1 (USA) — third-country transfer on the basis of the Data Privacy Framework (DPF).
Database and file storage: The data of our offering — such as your Must-Eat collection and the counts of our reach measurement — are held in Google Cloud Firestore, and files you upload in Cloud Storage for Firebase; both in the same Google Cloud project as the application. The Firestore database is located in the nam5 multi-region (USA) — third-country transfer on the basis of the Data Privacy Framework (DPF).
Use of cookies
The term "cookies" refers to functions that store information on users' devices and read information from them. Cookies can be used for the functionality, security and convenience of online offerings, as well as to create analyses of visitor flows. We use cookies in accordance with the statutory provisions and, where required, obtain users' consent in advance.
Storage period: Temporary cookies (session cookies) are deleted at the latest after you leave the online offering. Permanent cookies remain stored even after the browser is closed — for up to 2 years.
Withdrawal and objection (opt-out): Users may withdraw consent given at any time and object to processing in accordance with the legal requirements, including by means of their browser's privacy settings.
Legal bases: Consent (Art. 6(1)(a) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
Blogs and publication media
We use blogs and publication media. Readers' data is processed only to the extent necessary for the presentation and communication between authors and readers, or for security reasons.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Contact and enquiry management
When you contact us (e.g. by email or via social media), the details of the enquiring persons are processed to the extent necessary to answer the contact enquiries and any measures requested.
Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
User accounts and authentication
Users can create a user account on our online offering in order to manage their personal Must-Eat collection. We use Google Firebase Authentication (Google Ireland Limited) for authentication. Name and email address are processed in this context.
Optionally, we offer sign-in via Google ("Sign in with Google"). If you use this option, your Google sign-in is used for authentication; we receive your name, email address and profile picture.
Legal bases: Performance of a contract (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f) GDPR) — third-country transfer on the basis of the Data Privacy Framework (DPF).
Payment procedures
For the purchase of our Booster Packs we use the payment service provider Stripe. Payment takes place on a payment page hosted by Stripe (Stripe Checkout), to which you are redirected. You enter your payment details — such as your card number or PayPal credentials — exclusively there; they never reach us and are neither processed nor stored by us. Which payment methods are offered (e.g. card, PayPal, Link, Apple Pay, Google Pay, Klarna) is configured in our Stripe account; you make the choice on the payment page.
Transmitted to Stripe are the selected item and its price, the language of the payment page and an internal transaction reference. If you are signed in with us, we additionally transmit your email address; if you buy as a guest, Stripe collects it itself on the payment page. Back from Stripe we receive the confirmation that payment was made and, for a guest purchase, the email address — which we need in order to assign the purchase to you: we create a user account for this and send you a sign-in link. All that is stored with us is the scope of what was purchased, the time of purchase and the reference number of the Stripe payment.
Service provider: Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Privacy policy: https://stripe.com/privacy. Third-country transfer on the basis of the Data Privacy Framework (DPF).
Types of data processed: Inventory data; contact data (email address); payment data; contract data.
Legal bases: Performance of a contract and prior requests (Art. 6(1)(b) GDPR).
Web analytics, monitoring and optimisation
Web analytics serves to evaluate the visitor flows of our online offering and may include pseudonymous behavioural, interest-related or demographic information about visitors. With the help of reach analysis we can identify when our online offering is used most frequently and which areas require optimisation. IP addresses are pseudonymised (IP masking).
Google Analytics: We use Google Analytics (Google Ireland Limited) to measure and analyse the use of our online offering on the basis of a pseudonymous user ID. Google Analytics does not log individual IP addresses for EU users; coarse geolocation is derived exclusively on EU servers for EU traffic and the IP data is deleted afterwards. Privacy policy: https://policies.google.com/privacy. Opt-out: https://tools.google.com/dlpage/gaoptout. Third-country transfer on the basis of the Data Privacy Framework (DPF).
Legal bases: Consent (Art. 6(1)(a) GDPR).
Consent-free reach measurement (our own counter): Alongside Google Analytics we operate our own reach measurement, which requires no consent and runs exclusively on our own infrastructure; no third party is involved. It stores no information on your device and reads none — no cookie, no local or session storage, no fingerprinting. We process your IP address, your browser identification (user agent), the page called up, the previously called page of our own offering, the host name of a referring website (never its full address, since that can contain search terms) and the name of an interaction defined by us in advance (e.g. “map opened”). The IP address and browser identification are not stored in plain text: together with the calendar date and a secret known only to us they are turned into a check value (SHA-256). Only this check value is stored, and solely for the purpose of counting one person once per day; it is deleted automatically after two days at the latest and changes daily, so that visits on different days cannot be related to one another. Only daily totals without any personal reference are stored permanently: page views, visitor count, pages called up, entry pages, referring host names and the number of interactions.
Objection (opt-out): If your browser sends the “Sec-GPC” (Global Privacy Control) or “Do Not Track” header with the value 1, the request is neither counted nor stored in any form. No cookie is required for this — the setting takes effect on every single request. Both can be enabled in the privacy settings of common browsers.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR) — our interest in being able to evaluate the use of our offering in a data-minimising way and without profiling. Storage takes place in our database at our hosting provider (see “Provision of the online offering and web hosting”).
Error monitoring
To detect and fix technical errors we use Sentry (Functional Software, Inc. dba Sentry, San Francisco). Sentry records technical information about runtime errors such as browser type, operating system, the URL called and the stack trace, as well as a pseudonymised IP address.
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR) — third-country transfer on the basis of standard contractual clauses.
Presence on social networks (social media)
We maintain online presences within social networks and, in this context, process user data in order to communicate with the users active there or to offer information about us.
We point out that user data may be processed outside the European Union in this context. This may give rise to risks for users, because it could, for example, make the enforcement of users' rights more difficult.
Furthermore, user data within social networks is generally processed for market research and advertising purposes. For example, usage profiles can be created on the basis of usage behaviour, which may be used for advertisements within and outside the networks.
For a detailed description of the respective forms of processing and the options to object, we refer to the privacy policies of the operators.
Instagram: Social network. Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Website: https://www.instagram.com. Privacy policy: https://privacycenter.instagram.com/policy/. Third-country transfer on the basis of the Data Privacy Framework (DPF).
Legal bases: Legitimate interests (Art. 6(1)(f) GDPR).
Plug-ins and embedded functions and content
We embed functional and content elements into our online offering that are obtained from the servers of their respective providers (hereinafter "third-party providers"). Embedding requires the third-party providers to process users' IP addresses, since without an IP address they could not send the content to their browser.
Adobe Fonts (Typekit): Retrieval of fonts from Adobe servers for the purpose of a consistent presentation. The user's IP address is transmitted to Adobe in the process. Service provider: Adobe Systems Software Ireland Limited, 4-6 Riverwalk, Citywest Business Campus, Dublin 24, Ireland. Privacy policy: https://www.adobe.com/privacy/policy.html. Third-country transfer on the basis of standard contractual clauses.
OpenStreetMap / OpenFreeMap (MapLibre): For our interactive food map we use map data from OpenStreetMap plus tile and font servers from OpenFreeMap, rendered in the browser with the open-source library MapLibre GL. The user's IP address is transmitted to those servers in the process. According to its own statement, OpenFreeMap does not store IP addresses in its regular server logs; logging is enabled only during a security incident and for no longer than 30 days. Providers: OpenStreetMap Foundation (St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, UK) and Hyperknot Software Kft. (Petőfi Sándor utca 48., Újlengyel, 2724, Hungary). Privacy policies: https://osmfoundation.org/wiki/Privacy_Policy and https://openfreemap.org/privacy/.
Sanity CMS: For managing and delivering editorial content we use Sanity (Sanity.io, 201 Mission Street #1240, San Francisco, CA 94105, USA). The user's IP address is transmitted to Sanity servers in the process. Privacy policy: https://www.sanity.io/legal/privacy. Third-country transfer on the basis of standard contractual clauses.
Legal bases: Consent (Art. 6(1)(a) GDPR), legitimate interests (Art. 6(1)(f) GDPR).
Changes and updates
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Definitions of terms
This section gives you an overview of key terms.
• Personal data: Any information relating to an identified or identifiable natural person.
• Processing: Any operation involving personal data — collection, analysis, storage, transfer, erasure, etc.
• Controller: The natural or legal person who, alone or jointly with others, determines the purposes and means of processing.
• Inventory data: Essential information for identifying and managing contractual partners, user accounts and profiles.
• Contact data: Information for communicating with persons — telephone numbers, addresses, email addresses, etc.
• Usage data: Information on interaction with digital products — page views, time spent, click paths, device types, etc.
• Location data: Information on the geographical position of a device or a person.
• Meta, communication and procedural data: Information about how data is processed, transmitted and managed.
• Log data: Information about events or activities in a system (timestamps, IP addresses, user actions).
• Reach measurement: Analysis of the visitor flows of an online offering, usually by means of pseudonymous cookies and web beacons.
— Created with the free Datenschutz-Generator.de by Dr. Thomas Schwenke —
This English version is a translation provided for convenience. In the event of any discrepancy, the German version is authoritative.
