Privacy policy for guests
Last updated: 22/09/2026Version 6
1. Who processes your data?
This policy applies when you visit menu.aarhusstreetfood.com, order food, follow your order, contact us or subscribe to our newsletter.
Aarhus Street Food ApS (ASF), Danish business registration number (CVR) 37808636, Ny Banegårdsgade 46, 8000 Aarhus C, Denmark. Contact: kontakt@aarhusstreetfood.com.
For online payment, ASF is the seller and data controller. The kitchen processes the necessary order data on ASF's behalf to prepare and hand over the food. For payment on pickup, the kitchen is the seller and data controller, while ASF processes the order on the kitchen's behalf.
ASF and the kitchen are each responsible for processing data to comply with their own legal obligations, maintain security and handle legal claims. Order data is not used for marketing without a separate lawful basis. Contact ASF for the kitchen's legal name and contact details or to have an enquiry forwarded.
2. What data do we use?
Contact and order: name, phone number, email, language, selected dishes and extras, kitchen, quantities, prices, times, order number, status and messages about the order.
Payment: amounts, payment method and status, payment references, card type, masked card number, refunds and payment disputes. ASF does not receive your full card number or card security code.
Communication and choices: phone verification and misuse checks, receipts and email delivery, newsletter subscriptions and consent records, and technical data for browser notifications.
Use and security: IP address (or a code derived from it), browser and device, pages visited, language, times, search text, technical identifiers, errors and performance. When investigating errors, misuse and legal claims, we also record relevant actions, responsible users and support enquiries.
The data comes from you, your browser, the kitchens, payment and technical providers, and ASF's staff and systems. Search text is stored only as aggregate counts with no link to you. Do not enter sensitive data in searches or free-text fields. Discuss allergies directly with the kitchen. Local allergen choices and other storage on your device are described in the cookie and storage policy.
3. Why may we use the data?
We use data only for the relevant purposes below. The letters refer to Article 6(1) of the GDPR.
Purpose | Legal basis |
|---|---|
Menu, basket, ordering, order status, phone verification and requested receipts. | Performance of the contract (b). Phone verification is also used to prevent false orders and SMS misuse (f). |
Payments, refunds, support and complaints. | The contract (b), relevant legal obligations (c) and legitimate interests in customer service, documentation and legal claims (f). |
Accounting, VAT and regulatory requirements. | Legal obligations (c). |
Security, troubleshooting, records of actions and search improvements. | Legitimate interests in a usable and secure service, preventing misuse and loss, and resolving disputes (f). Relevant legal obligations (c). |
Newsletter and browser notifications. | Your voluntary consent (a). Newsletters also comply with the Danish Marketing Practices Act. |
Aggregate traffic statistics: page views and visits, countries and device types, based on the requests your browser sends to Cloudflare. No cookies or scripts for statistics are placed on your device. | Our legitimate interest (f) in understanding how the menu is used. |
Your name and order data are required to order. Payment on pickup also requires a verified mobile number to prevent false orders and allow contact about pickup. Without this data, the selected order cannot be completed. Email is required only if you want an emailed receipt. Newsletters and browser notifications are voluntary and are not a condition of purchase.
4. Who do we share data with?
We share only relevant data for the purposes described or as provided by law:
The kitchens preparing the food or handling your enquiry.
Viva.com, banks and card networks for payments, refunds and fraud checks.
Railway and Tigris for hosting and storage; Cloudflare for security, page delivery and aggregate traffic statistics; jsDelivr for content such as icons. Providers may receive ordinary network data when content is retrieved.
Resend for receipts and service emails, inMobile for phone verification, and ASF's mailing list system with Supabase for newsletters.
Your browser provider's notification service, if you enable it.
e-conomic, banks, auditors, bookkeepers and other necessary advisers, and authorities where disclosure is required or otherwise permitted by law.
Providers processing data on our behalf are covered by data processing agreements. Payment providers and banks, among others, may be independent controllers for their own purposes and provide their own information about this.
5. Data outside the EU/EEA
Our providers may process data outside the EU/EEA, even when we choose European hosting. This includes the United States through Railway, Cloudflare, Resend, Supabase and browser notifications, depending on the browser, as well as the United Kingdom through jsDelivr and other countries through providers' subprocessors.
Transfers rely on an EU adequacy decision, including the EU-U.S. Data Privacy Framework for certified US recipients, or the European Commission's Standard Contractual Clauses with supplementary measures where necessary.
Contact ASF for information about a particular transfer or a copy of the safeguards.
6. How long is data kept?
Data | Retention |
|---|---|
Contact details on orders, including refund email addresses, completed email delivery records and records of operational actions. | Automatically deleted after approximately 24 months. Financial order data is retained without these contact fields. |
Accounting records and financial audit trails. | Five years from the end of the relevant financial year. Longer only for another legal obligation or a specific legal claim. |
Verified phone number. | 24 months after last use. |
Phone verification records. | 30 days. The verification link expires earlier, as shown during verification. |
Newsletter. | The platform's delivery records are deleted after approximately 24 months. Subscriptions and consent records are kept until you unsubscribe, then only for as long as needed for consent documentation or legal claims. |
Browser notifications. | Deleted 30 days after the order is completed, and no later than 12 months without use – or when you withdraw the permission. |
Completed technical background tasks. | 90 days. Active email delivery attempts are kept until completed. |
Search text. | 180 days and no more than the 10,000 most recent or most frequently used search terms. |
Providers' operational and security logs and backups. | In accordance with the retention rules in the provider agreements and the configuration used. Normally 24 months, unless longer retention is required by law or a provider has retention rules that ASF cannot influence. |
Data on your device. | See the cookie and storage policy for periods and deletion. |
Relevant data in a dispute, security incident or authority case may be kept until the matter is closed and legal claims can no longer be brought.
7. Security and your order link
We protect data using measures including encrypted transmission, restricted access, backups and misuse controls. In the event of a data breach, we notify the authority and affected individuals where required by law.
Your order link gives access to the order. Keep it confidential and delete local data after using a shared device. You do not need a guest account.
8. Automated decisions
ASF does not make solely automated decisions that have legal or similarly significant effects on you. Payment providers and banks may carry out their own fraud checks under their own privacy notices.
9. Your rights and choices
Under the applicable rules, you can request access, correction, deletion and restriction of processing, object to processing based on legitimate interests, and receive the data you have provided to us (data portability).
You can withdraw consent for the future; this does not affect the lawfulness of earlier processing. Unsubscribe from newsletters using the email link or by contacting ASF. Turn off browser notifications in your browser settings. See the cookie and storage policy for local choices and deletion.
Email kontakt@aarhusstreetfood.com about your rights. We may request necessary information to verify your identity and locate the order. Do not send full card details. If a legal obligation or claim limits your right, we explain why.
You can always complain to Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, www.datatilsynet.dk, or to the supervisory authority in the EU/EEA country where you normally live or work, or where a possible infringement occurred.
10. Changes
We update the policy when processing changes. If renewed consent or direct notification is required, we arrange this before the change takes effect.
