Privacy policy
What we collect when you order, why we are allowed to, how long we keep it, who else touches it, and what you can ask us to do about it.
The short version: you can order without an account, we keep what we need to cook your food, deliver it, take payment and issue a lawful invoice, and we do not advertise to you or sell your data to anyone. There is no tracking pixel and no ad network on this site, and the only analytics is a cookieless count of visits and page speed, described in section 3.
1. Who is responsible for your data
We are Oli's House BV, Hoogstraat 186, 8800 Roeselare, Belgium, enterprise number 0790.776.068, and we are the controller of the personal data described here. That means we decide why it is collected and what happens to it, and we are the first place you take a complaint. You can go to the supervisory authority instead, or afterwards. Section 12 says how. Write to [email protected], or telephone 0491220044.
This website and the systems behind it are run for us by our technology provider, acting as our processor under a written data processing agreement. They handle your data on our instructions, they do not decide what it is used for, and they do not use it for their own purposes. Those decisions are ours, and so is answering for them.
2. What we collect, and why
When you order, as a guest or signed in:
| What | Why we need it | Legal basis |
|---|---|---|
| Name | The driver has to ask for somebody at the door; the counter has to call a name. | Contract |
| Email address | Your confirmation, your receipt and your order-tracking link. Once the tab is closed it is the only way to reach you. | Contract |
| Phone number | So a driver who cannot find your door can call you. | Contract |
| Delivery address, including any note such as “third floor, ring twice” | To bring the food to the right door. | Contract |
| What you ordered, including customisations | To cook it, charge for it, and invoice it. | Contract and legal obligation |
| Where your address resolved to on the map, how far it is from our kitchen, and the drive-time estimate | To decide whether you are inside our delivery area, what the fee is, and what to quote you. | Contract |
The details in that table are required rather than optional: without them an order cannot be cooked, brought to you or invoiced, and it cannot be placed at all. Everything further down this section is something you choose (an account, a voucher, a table, notifications), and declining it costs you that feature and nothing else.
We ask for a phone number on every order, including from customers who have an account, and we copy the details onto the order rather than pointing at your account record. Section 5 explains why.
If you create an account: your name, email, phone number, any addresses you choose to save, your order history, and your loyalty stamps and rewards where we run a stamp card. Legal basis: contract, and legitimate interests for the loyalty scheme you opted into.
If you buy a gift voucher: your email address and the voucher itself. If you send one to somebody else, we also hold the recipient’s name, their email address and the message you write them, snapshotted onto the voucher when it is issued. We keep them as long as the voucher, because they are part of what the voucher is. We do not use a recipient’s address for anything else, and the only mail they get from us is the one carrying the voucher.
If you book a table: your name, email, phone number, the date, time and party size, and anything you tell us in the booking note.
If you turn on order notifications: a push subscription: an address for your browser on your device, and the keys needed to encrypt a message to it. We use it only to tell you what is happening with your order. Legal basis: consent, which you give through your browser’s own permission prompt, and which you can withdraw in your browser at any time. We delete a subscription that has been silent for 90 days.
If you use “use my current location” at checkout: your browser asks your permission and, if you give it, sends us your coordinates. We pass them to Google’s geocoding service from our server to turn them into a street address to fill the form with. Your position is not stored or logged by us. Legal basis: consent, given through your browser’s prompt.
Automatically, as you use the site: your IP address, briefly, to count requests against a rate limit (this is how the site survives somebody hammering it), and ordinary server logs of what was requested, when, and whether it worked. Legal basis: legitimate interests in keeping the site up and not being defrauded.
Visit statistics, on every page except order-tracking, payment-return and voucher-status pages: Cloudflare Web Analytics counts the visit and measures how fast the page loaded. It records the country you are visiting from, the page address (without anything after a “?”), the page that sent you here, your type of device, browser and operating system, and the page’s loading times. Like any request on the web, the one your browser sends to Cloudflare arrives with your IP address; the statistics Cloudflare shows us contain only a country, not the address, and Cloudflare says it does not use IP addresses or browser details to fingerprint visitors. It sets no cookie, stores nothing on your device, and is not used for advertising or to build a profile of you. Legal basis: legitimate interests in knowing how many people use the site and whether its pages load quickly enough.
We never see your card number. Payment happens on Stripe’s own payment page. Card details are typed into Stripe, not into this website, and never reach our systems. We are told that the payment succeeded, its reference, and the amount.
3. What we do not do
- No advertising, no ad networks, no remarketing pixels, no social plugins.
- No Google Analytics, no Meta pixel, no heatmaps, no session recording. The only analytics is Cloudflare Web Analytics, which counts visits and measures page speed without cookies and without storing anything on your device, and never runs on order-tracking, payment-return or voucher-status pages.
- No profiling and no automated decision-making with legal or similarly significant effects.
- No selling or sharing your data with anyone not listed in section 6.
- No marketing email unless you have separately asked for it. Your order confirmation is not marketing.
Two things watch this site, and both watch the software rather than you: error monitoring, which sends a report when a page fails so that we find out from the site instead of from you, and the visit statistics above, which count visits and time how fast pages load. Both are described in section 6, and the cookie policy lists everything the site stores on your device.
4. How long we keep it
| Data | Kept for | Why that long |
|---|---|---|
| Orders, invoices and credit notes, including the name, phone, email and address on them | 10 years, counted from 1 January of the year after the invoice date | Belgian accounting and VAT law. Not our choice, and not shortenable. |
| Abandoned baskets | 7 days after they expire | So we can answer “my order did not go through last Tuesday”. |
| Baskets that were paid for | 90 days | A payment provider can redeliver a notification days late; sweeping one early would turn a successful payment into an order nobody can find. |
| Phone-verification codes | 2 days | The code is dead within the hour. Holding the number longer would build a list of everyone who ever tried to order. |
| Internal event records containing order details | 30 days | Kept only long enough to guarantee the message was delivered. |
| Push subscriptions | 90 days of silence, or sooner if your browser tells us it is dead | A subscription that no longer reaches a device is not worth keeping. |
| Rate-limit counters | 7 days | Long enough to outlast the longest limit; not a moment longer. |
| Loyalty anti-double-counting records | 30 days | They exist only to stop the same message being counted twice, and hold no more than an identifier. |
| Loyalty stamps and rewards | Kept after you close your account, until you ask us to delete them | Nothing deletes them on a schedule yet, and we would rather say so than publish a number we do not keep to. Ask us and we will delete them. |
| A note that an account was closed: an opaque sign-in identifier, the restaurant and the date | For as long as the restaurant uses our platform; deleted when it leaves | It is what keeps a closed account closed: without it, a sign-in still open in a browser could recreate the account. It holds no name, email, phone number or address. |
| Address lookups: where an address is on the map | Kept indefinitely: nothing deletes it on a schedule | Kept so the same address does not have to be sent to a mapping provider twice. Holds no name, order or customer. Ask us and we will delete the entry for your address: nothing obliges us to keep it, so unlike an invoice, this one we can erase. |
| Error reports | 90 days | Long enough to see whether a fix worked. They describe the software, not you. |
| Server logs | 30 days | Operations and security. |
| Visit statistics (Cloudflare Web Analytics) | Cloudflare’s published retention: 7 days in full, after which the data is aggregated down to around 10%. Cloudflare publishes no period beyond that | Set by Cloudflare, not by us. We use it only to count visits and measure page speed. |
5. Why we keep your address even though you ordered as a guest
The question people actually ask. The honest answer has three parts.
One: an invoice is not deletable. The moment we accept your order it becomes an invoiced sale with a sequence number, and Belgian law requires us to keep it, with the customer’s details on it, for years. That is a legal obligation and it outranks a deletion request, in the same way it does for a paper receipt in a till roll.
Two: your order carries a copy, not a link. Your name, phone number and address are written onto the order itself rather than pointed at from a customer record. If we stored a reference and you later edited a saved address, every past order would silently start claiming it went somewhere it did not, which would be rewriting an invoiced document. A guest has no record to point at in the first place. And it is what makes deleting your account possible at all: because the order does not depend on your customer record, we can delete the record and leave the invoice standing.
Three: we also keep where the address turned out to be and how far away it was. The coordinates, the distance and the point we measured from are stored on the order, not to track you, but to be able to answer, six months later, why we accepted a delivery to that address. Roads change, mapping data is revised, and our delivery area gets edited. A measurement you cannot reproduce is not evidence of anything.
Separately from your order, we remember where addresses are so that we do not have to ask a mapping provider twice about the same street. That record holds the address and the point it sits on and nothing else: no name, no email, no phone number, no order, and nothing recording who asked. It is the same kind of fact as a street map, and it is the one thing we keep about an address even when there was no order: if you checked whether we deliver to you and we do not, that lookup is still remembered. We will say plainly that it is kept indefinitely: nothing deletes it on a schedule, and we would rather write that down than publish a number we do not keep to. The legal basis is our legitimate interest in not paying twice for the same answer. You can object to it, and you can ask us to delete the entry for your address: no law requires us to hold it, so unlike an invoice, this one we can erase on request.
What that means for you in practice:
- You can ask us to delete your account, and we will, along with your saved addresses and your notification settings. Your loyalty stamps and rewards are kept unless you ask us to delete them too.
- You cannot have your past orders erased while the statutory period runs, and neither can we.
- Your email and phone number stop being used for anything once the order is done. Nothing markets to you off the back of an order.
6. Who else touches your data
We use the providers below. Most are our processors, bound by a written contract to handle your data only on our instructions. Two are not, and the table says which: Stripe is also a controller in its own right, for fraud prevention and its own regulatory duties; and the OpenStreetMap Foundation is not our processor at all (your browser fetches map tiles from them directly, so that request is between you and them).
| Provider | What it does | What it sees |
|---|---|---|
| Stripe | Takes the payment | Your name, email, the amount, and the card details you type into their page. Stripe is also a controller in its own right for anti-fraud and regulatory purposes. |
| Google Maps Platform (Geocoding and Routes) | Turns an address into a point and measures the drive, so we can tell you whether we deliver to you and what it costs | Your delivery address, and our kitchen’s location, reached from our server. Not your name, email, phone, or what you ordered. |
| Google Cloud Identity Platform | Signs you in, if you have an account | Your email address and sign-in activity. Its code runs in your browser during sign-in. |
| OpenStreetMap Foundation | Serves the map tiles on our contact page | Your browser requests map images directly from their servers, so they see your IP address and which part of the map you looked at. Nothing else, and only on that page. |
| Sentry | Error monitoring: tells us when a page has broken | A description of the failure: the error, the page it happened on, and the browser. Reports are sent to our own server first and forwarded from there, so Sentry does not see your IP address. There is no session recording, and personal data is stripped before an event leaves your browser. |
| Resend | Sends your confirmation, receipt and tracking link | Your email address and the contents of the email. |
| Infobip | Sends SMS where we use it | Your phone number and the message. |
| Cloudflare R2 | Stores the menu photographs | Nothing about you. |
| Cloudflare Web Analytics | Counts visits and measures how fast pages load. Never on order-tracking, payment-return or voucher-status pages | It records the country you are visiting from, the page address without anything after a “?”, the page that sent you here, your type of device, browser and operating system, and the page’s loading times, including when you move from page to page within the site. Like any request on the web, your browser’s request reaches Cloudflare with your IP address; the statistics Cloudflare shows us contain only a country, not the address. It sets no cookies and stores nothing on your device, and Cloudflare says it does not use your IP address or browser details to fingerprint you and does not follow you across other sites that use it. |
| Railway | Runs the servers and the database | Everything, at rest, as the custodian of the systems. |
Where the data goes. Several of these are US-headquartered. Transfers outside the EEA rely on the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Your address goes to a mapping provider before you have committed to anything. Checking whether we can deliver to you means asking where that address is, and that happens as you enter it at checkout, before you pay and before there is an order. It is necessary to answer the question you asked, and we keep the answer briefly so we do not have to ask twice.
7. Your rights
Under the GDPR you can ask us to:
- See what we hold about you, and get a copy.
- Correct anything wrong.
- Delete what we hold, subject to section 5: invoiced orders stay for the statutory period.
- Restrict or object to our processing, including anything we do on the basis of legitimate interests.
- Take your data elsewhere in a portable form.
- Withdraw consent at any time where we relied on it (for push notifications, by turning them off in your browser).
Write to [email protected]. We answer within one month. If you ordered as a guest, tell us the order number and the email address you used, so we can find you without asking for more identification than the request needs.
Closing your account is self-service, from your account page. When you do, we delete your customer record, your saved addresses and your notification subscriptions, and we delete your sign-in credential at our identity provider. Your loyalty stamps and rewards are not deleted automatically: they stay on record, no longer linked to an account you can sign in to, until you ask us to delete them. We keep an internal note that the account was closed (no more than an opaque identifier and a date, with no name, email or address in it) so that a sign-in session still open in a browser cannot silently recreate the account we just deleted. We keep that note for as long as the restaurant uses our platform, and delete it when the restaurant leaves. Your past orders remain, as section 5 explains.
9. Security
Payments are handled entirely by Stripe, so card details never reach our systems. Your sign-in is held in an encrypted cookie that your browser cannot read and no script on the page can reach; the cookie policy says how long it lasts. Order-tracking links carry an unguessable code, and we keep only a one-way hash of it. Treat the link itself like a key, because anyone holding it can see that order. Access to customer data is limited by role, and traffic to and from this site is encrypted.
No system is perfectly secure. If a breach puts your rights at risk we will tell you and the supervisory authority, as the law requires.
10. Children
This site is not aimed at children and we do not knowingly collect their data. We do not ask anybody’s age or date of birth online; where an order contains alcohol, age is checked in person at handover.
11. Changes
We will post any change here and update the date at the foot of this page. Material changes will be flagged on the site.
12. Complaining
Come to us first, at [email protected]. If you are not satisfied you can complain to the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels.
Version 1.0 · last updated September 9, 2026