Skip to content

Privacy policy

What we collect when you order, why we are allowed to, how long we keep it, who else touches it, and what you can ask us to do about it.

The short version: you can order without an account, we keep what we need to cook your food, deliver it, take payment and issue a lawful invoice, and we do not advertise to you or sell your data to anyone. There is no tracking pixel and no ad network on this site, and the only analytics is a cookieless count of visits and page speed, described in section 3.

1. Who is responsible for your data

We are Oli's House BV, Hoogstraat 186, 8800 Roeselare, Belgium, enterprise number 0790.776.068, and we are the controller of the personal data described here. That means we decide why it is collected and what happens to it, and we are the first place you take a complaint. You can go to the supervisory authority instead, or afterwards. Section 12 says how. Write to [email protected], or telephone 0491220044.

This website and the systems behind it are run for us by our technology provider, acting as our processor under a written data processing agreement. They handle your data on our instructions, they do not decide what it is used for, and they do not use it for their own purposes. Those decisions are ours, and so is answering for them.

2. What we collect, and why

When you order, as a guest or signed in:

WhatWhy we need itLegal basis
NameThe driver has to ask for somebody at the door; the counter has to call a name.Contract
Email addressYour confirmation, your receipt and your order-tracking link. Once the tab is closed it is the only way to reach you.Contract
Phone numberSo a driver who cannot find your door can call you.Contract
Delivery address, including any note such as “third floor, ring twice”To bring the food to the right door.Contract
What you ordered, including customisationsTo cook it, charge for it, and invoice it.Contract and legal obligation
Where your address resolved to on the map, how far it is from our kitchen, and the drive-time estimateTo decide whether you are inside our delivery area, what the fee is, and what to quote you.Contract

The details in that table are required rather than optional: without them an order cannot be cooked, brought to you or invoiced, and it cannot be placed at all. Everything further down this section is something you choose (an account, a voucher, a table, notifications), and declining it costs you that feature and nothing else.

We ask for a phone number on every order, including from customers who have an account, and we copy the details onto the order rather than pointing at your account record. Section 5 explains why.

If you create an account: your name, email, phone number, any addresses you choose to save, your order history, and your loyalty stamps and rewards where we run a stamp card. Legal basis: contract, and legitimate interests for the loyalty scheme you opted into.

If you buy a gift voucher: your email address and the voucher itself. If you send one to somebody else, we also hold the recipient’s name, their email address and the message you write them, snapshotted onto the voucher when it is issued. We keep them as long as the voucher, because they are part of what the voucher is. We do not use a recipient’s address for anything else, and the only mail they get from us is the one carrying the voucher.

If you book a table: your name, email, phone number, the date, time and party size, and anything you tell us in the booking note.

If you turn on order notifications: a push subscription: an address for your browser on your device, and the keys needed to encrypt a message to it. We use it only to tell you what is happening with your order. Legal basis: consent, which you give through your browser’s own permission prompt, and which you can withdraw in your browser at any time. We delete a subscription that has been silent for 90 days.

If you use “use my current location” at checkout: your browser asks your permission and, if you give it, sends us your coordinates. We pass them to Google’s geocoding service from our server to turn them into a street address to fill the form with. Your position is not stored or logged by us. Legal basis: consent, given through your browser’s prompt.

Automatically, as you use the site: your IP address, briefly, to count requests against a rate limit (this is how the site survives somebody hammering it), and ordinary server logs of what was requested, when, and whether it worked. Legal basis: legitimate interests in keeping the site up and not being defrauded.

Visit statistics, on every page except order-tracking, payment-return and voucher-status pages: Cloudflare Web Analytics counts the visit and measures how fast the page loaded. It records the country you are visiting from, the page address (without anything after a “?”), the page that sent you here, your type of device, browser and operating system, and the page’s loading times. Like any request on the web, the one your browser sends to Cloudflare arrives with your IP address; the statistics Cloudflare shows us contain only a country, not the address, and Cloudflare says it does not use IP addresses or browser details to fingerprint visitors. It sets no cookie, stores nothing on your device, and is not used for advertising or to build a profile of you. Legal basis: legitimate interests in knowing how many people use the site and whether its pages load quickly enough.

We never see your card number. Payment happens on Stripe’s own payment page. Card details are typed into Stripe, not into this website, and never reach our systems. We are told that the payment succeeded, its reference, and the amount.

3. What we do not do

  • No advertising, no ad networks, no remarketing pixels, no social plugins.
  • No Google Analytics, no Meta pixel, no heatmaps, no session recording. The only analytics is Cloudflare Web Analytics, which counts visits and measures page speed without cookies and without storing anything on your device, and never runs on order-tracking, payment-return or voucher-status pages.
  • No profiling and no automated decision-making with legal or similarly significant effects.
  • No selling or sharing your data with anyone not listed in section 6.
  • No marketing email unless you have separately asked for it. Your order confirmation is not marketing.

Two things watch this site, and both watch the software rather than you: error monitoring, which sends a report when a page fails so that we find out from the site instead of from you, and the visit statistics above, which count visits and time how fast pages load. Both are described in section 6, and the cookie policy lists everything the site stores on your device.

4. How long we keep it

DataKept forWhy that long
Orders, invoices and credit notes, including the name, phone, email and address on them10 years, counted from 1 January of the year after the invoice dateBelgian accounting and VAT law. Not our choice, and not shortenable.
Abandoned baskets7 days after they expireSo we can answer “my order did not go through last Tuesday”.
Baskets that were paid for90 daysA payment provider can redeliver a notification days late; sweeping one early would turn a successful payment into an order nobody can find.
Phone-verification codes2 daysThe code is dead within the hour. Holding the number longer would build a list of everyone who ever tried to order.
Internal event records containing order details30 daysKept only long enough to guarantee the message was delivered.
Push subscriptions90 days of silence, or sooner if your browser tells us it is deadA subscription that no longer reaches a device is not worth keeping.
Rate-limit counters7 daysLong enough to outlast the longest limit; not a moment longer.
Loyalty anti-double-counting records30 daysThey exist only to stop the same message being counted twice, and hold no more than an identifier.
Loyalty stamps and rewardsKept after you close your account, until you ask us to delete themNothing deletes them on a schedule yet, and we would rather say so than publish a number we do not keep to. Ask us and we will delete them.
A note that an account was closed: an opaque sign-in identifier, the restaurant and the dateFor as long as the restaurant uses our platform; deleted when it leavesIt is what keeps a closed account closed: without it, a sign-in still open in a browser could recreate the account. It holds no name, email, phone number or address.
Address lookups: where an address is on the mapKept indefinitely: nothing deletes it on a scheduleKept so the same address does not have to be sent to a mapping provider twice. Holds no name, order or customer. Ask us and we will delete the entry for your address: nothing obliges us to keep it, so unlike an invoice, this one we can erase.
Error reports90 daysLong enough to see whether a fix worked. They describe the software, not you.
Server logs30 daysOperations and security.
Visit statistics (Cloudflare Web Analytics)Cloudflare’s published retention: 7 days in full, after which the data is aggregated down to around 10%. Cloudflare publishes no period beyond thatSet by Cloudflare, not by us. We use it only to count visits and measure page speed.

5. Why we keep your address even though you ordered as a guest

The question people actually ask. The honest answer has three parts.

One: an invoice is not deletable. The moment we accept your order it becomes an invoiced sale with a sequence number, and Belgian law requires us to keep it, with the customer’s details on it, for years. That is a legal obligation and it outranks a deletion request, in the same way it does for a paper receipt in a till roll.

Two: your order carries a copy, not a link. Your name, phone number and address are written onto the order itself rather than pointed at from a customer record. If we stored a reference and you later edited a saved address, every past order would silently start claiming it went somewhere it did not, which would be rewriting an invoiced document. A guest has no record to point at in the first place. And it is what makes deleting your account possible at all: because the order does not depend on your customer record, we can delete the record and leave the invoice standing.

Three: we also keep where the address turned out to be and how far away it was. The coordinates, the distance and the point we measured from are stored on the order, not to track you, but to be able to answer, six months later, why we accepted a delivery to that address. Roads change, mapping data is revised, and our delivery area gets edited. A measurement you cannot reproduce is not evidence of anything.

Separately from your order, we remember where addresses are so that we do not have to ask a mapping provider twice about the same street. That record holds the address and the point it sits on and nothing else: no name, no email, no phone number, no order, and nothing recording who asked. It is the same kind of fact as a street map, and it is the one thing we keep about an address even when there was no order: if you checked whether we deliver to you and we do not, that lookup is still remembered. We will say plainly that it is kept indefinitely: nothing deletes it on a schedule, and we would rather write that down than publish a number we do not keep to. The legal basis is our legitimate interest in not paying twice for the same answer. You can object to it, and you can ask us to delete the entry for your address: no law requires us to hold it, so unlike an invoice, this one we can erase on request.

What that means for you in practice:

  • You can ask us to delete your account, and we will, along with your saved addresses and your notification settings. Your loyalty stamps and rewards are kept unless you ask us to delete them too.
  • You cannot have your past orders erased while the statutory period runs, and neither can we.
  • Your email and phone number stop being used for anything once the order is done. Nothing markets to you off the back of an order.

6. Who else touches your data

We use the providers below. Most are our processors, bound by a written contract to handle your data only on our instructions. Two are not, and the table says which: Stripe is also a controller in its own right, for fraud prevention and its own regulatory duties; and the OpenStreetMap Foundation is not our processor at all (your browser fetches map tiles from them directly, so that request is between you and them).

ProviderWhat it doesWhat it sees
StripeTakes the paymentYour name, email, the amount, and the card details you type into their page. Stripe is also a controller in its own right for anti-fraud and regulatory purposes.
Google Maps Platform (Geocoding and Routes)Turns an address into a point and measures the drive, so we can tell you whether we deliver to you and what it costsYour delivery address, and our kitchen’s location, reached from our server. Not your name, email, phone, or what you ordered.
Google Cloud Identity PlatformSigns you in, if you have an accountYour email address and sign-in activity. Its code runs in your browser during sign-in.
OpenStreetMap FoundationServes the map tiles on our contact pageYour browser requests map images directly from their servers, so they see your IP address and which part of the map you looked at. Nothing else, and only on that page.
SentryError monitoring: tells us when a page has brokenA description of the failure: the error, the page it happened on, and the browser. Reports are sent to our own server first and forwarded from there, so Sentry does not see your IP address. There is no session recording, and personal data is stripped before an event leaves your browser.
ResendSends your confirmation, receipt and tracking linkYour email address and the contents of the email.
InfobipSends SMS where we use itYour phone number and the message.
Cloudflare R2Stores the menu photographsNothing about you.
Cloudflare Web AnalyticsCounts visits and measures how fast pages load. Never on order-tracking, payment-return or voucher-status pagesIt records the country you are visiting from, the page address without anything after a “?”, the page that sent you here, your type of device, browser and operating system, and the page’s loading times, including when you move from page to page within the site. Like any request on the web, your browser’s request reaches Cloudflare with your IP address; the statistics Cloudflare shows us contain only a country, not the address. It sets no cookies and stores nothing on your device, and Cloudflare says it does not use your IP address or browser details to fingerprint you and does not follow you across other sites that use it.
RailwayRuns the servers and the databaseEverything, at rest, as the custodian of the systems.

Where the data goes. Several of these are US-headquartered. Transfers outside the EEA rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

Your address goes to a mapping provider before you have committed to anything. Checking whether we can deliver to you means asking where that address is, and that happens as you enter it at checkout, before you pay and before there is an order. It is necessary to answer the question you asked, and we keep the answer briefly so we do not have to ask twice.

7. Your rights

Under the GDPR you can ask us to:

  • See what we hold about you, and get a copy.
  • Correct anything wrong.
  • Delete what we hold, subject to section 5: invoiced orders stay for the statutory period.
  • Restrict or object to our processing, including anything we do on the basis of legitimate interests.
  • Take your data elsewhere in a portable form.
  • Withdraw consent at any time where we relied on it (for push notifications, by turning them off in your browser).

Write to [email protected]. We answer within one month. If you ordered as a guest, tell us the order number and the email address you used, so we can find you without asking for more identification than the request needs.

Closing your account is self-service, from your account page. When you do, we delete your customer record, your saved addresses and your notification subscriptions, and we delete your sign-in credential at our identity provider. Your loyalty stamps and rewards are not deleted automatically: they stay on record, no longer linked to an account you can sign in to, until you ask us to delete them. We keep an internal note that the account was closed (no more than an opaque identifier and a date, with no name, email or address in it) so that a sign-in session still open in a browser cannot silently recreate the account we just deleted. We keep that note for as long as the restaurant uses our platform, and delete it when the restaurant leaves. Your past orders remain, as section 5 explains.

8. Cookies and storage on your device

This has its own document, and it is separate from this one on purpose: Belgian guidance is that a cookie policy is presented on its own, and that agreeing to storage on your device is not agreeing to a privacy policy or to terms of sale.

Briefly: this site stores a few things in your browser so that it can work at all: your basket, your sign-in, your recent orders, and a marker that protects a shared device. It sets no advertising or analytics storage, so there is nothing here that requires your consent and we do not ask for it. The cookie policy names every item individually, says how long each lasts, and explains what breaks if you block it.

9. Security

Payments are handled entirely by Stripe, so card details never reach our systems. Your sign-in is held in an encrypted cookie that your browser cannot read and no script on the page can reach; the cookie policy says how long it lasts. Order-tracking links carry an unguessable code, and we keep only a one-way hash of it. Treat the link itself like a key, because anyone holding it can see that order. Access to customer data is limited by role, and traffic to and from this site is encrypted.

No system is perfectly secure. If a breach puts your rights at risk we will tell you and the supervisory authority, as the law requires.

10. Children

This site is not aimed at children and we do not knowingly collect their data. We do not ask anybody’s age or date of birth online; where an order contains alcohol, age is checked in person at handover.

11. Changes

We will post any change here and update the date at the foot of this page. Material changes will be flagged on the site.

12. Complaining

Come to us first, at [email protected]. If you are not satisfied you can complain to the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels.

Version 1.0 · last updated September 9, 2026