Privacy Policy
Last updated: 23 September 2026
1. Information We Collect
At Appetece, we collect different types of information to provide and improve our service:
1.1. Account Information
- First and last name
- Email address
- Password (encrypted)
- User preferences
1.2. Usage Information
- Restaurants visited and searched
- Menus viewed
- Dietary preferences
- Approximate location (if permission is granted)
1.3. Technical Information
- IP address
- Browser and device type
- Operating system
- Cookies and similar technologies
1.4. Workplace Information (optional)
If you provide it voluntarily — by completing the form in your profile — we may store your company name, approximate size, and office city. If your registration email belongs to a corporate domain (for example, name@company.com), we may infer the company name from the domain. You can edit or delete this information at any time from your profile.
We use this data exclusively to identify companies with multiple Appetece users and, where applicable, offer a corporate menu program. We do not use it to profile you individually or share it with your company without your explicit permission.
1.5. Address Book and Phone Number (optional)
If you choose to look for your friends, your device normalises the numbers in your address book and turns them into a SHA-256 hash BEFORE sending them. Only those hashes reach our servers, together with the name you have saved for each contact, and they are used solely to show you who from your address book already uses Appetece. We never store your contacts' numbers in the clear.
When you invite someone over WhatsApp we store only the hash of their number, so that we can credit you for the invitation if that person eventually signs up.
Your own phone number is stored in the clear: you give it to us when booking or in your profile, and it is used to manage your reservations and to let your contacts find you. You can stop being discoverable by phone at any time in Settings → Privacy.
You can delete your synced address book and any pending invitations whenever you want from Settings → Delete my address book.
2. How We Use Your Information
We use the information we collect for:
- Providing and maintaining our service
- Personalizing your experience and showing you relevant restaurants
- Improving our services and developing new features
- Communicating with you about updates and news
- Detecting, preventing, and resolving technical or security issues
- Complying with legal obligations
3. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Consent: For sending commercial communications, using non-essential cookies, and processing workplace information (section 1.4) that you provide voluntarily
- Contract performance: To provide the services you request
- Legitimate interest: To improve our services and prevent fraud
- Legal obligation: To comply with applicable legal requirements
4. Sharing Information
We do not sell your personal information. We may share your information with:
- Associated restaurants: To facilitate reservations and orders
- Service providers: Who help us operate our platform (hosting, analytics, payments). These include HubSpot, Inc. as a CRM to manage communications with companies that have shown interest in Appetece through workplace information provided by their employees (section 1.4)
- Third-party reservation systems: When you make a reservation, it may be processed through our partners' systems — TheFork (TheFork SAS), CoverManager (Restaurant Booking & Distribution Services, S.L.), DISH (DISH Digital Solutions GmbH), Last.app (Last Systems, S.L.), Restoo (Team Interactive, S.L.), and/or Google Reserve (Google Ireland Ltd.). These providers act as independent data controllers in accordance with their own privacy policies
- Legal authorities: When required by law or to protect our rights
4.1. Managing reservations through third parties
To complete a reservation, we share with the restaurant and its reservation system the necessary data to manage it: name, surname, email, phone, date, time, and number of diners, as well as any notes you add (for example, allergies or seating preferences). The legal basis for this communication is the performance of the contract you request when making the reservation (article 6.1.b GDPR).
Some of these providers may process your data outside the European Economic Area; in such cases, the safeguards described in section 9 apply. We recommend reviewing the privacy policies of TheFork, CoverManager, DISH, Last.app, Restoo, and Google to learn how they process your data as independent data controllers.
5. Cookies and Similar Technologies
We use cookies and similar technologies to improve your experience:
- Essential cookies: Necessary for the site to function
- Analytical cookies: To understand how our app is used
- Preference cookies: To remember your settings
You can manage your cookie preferences in your browser settings.
6. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: Request a copy of your personal data
- Right of rectification: Correct inaccurate or incomplete data
- Right of erasure: Request deletion of your data
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive your data in structured format
- Right to object: Object to the processing of your data
- Right to withdraw consent: At any time
To exercise these rights, contact us through the information provided in the contact section.
7. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include data encryption, access controls, and regular security audits.
8. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this policy, unless the law requires or permits a longer retention period. When you delete your account, we will proceed to delete or anonymize your personal data, unless we are legally required to retain it.
9. International Transfers
Your data may be transferred and processed in countries outside the European Economic Area (EEA). In such cases, we ensure that appropriate safeguards are implemented in accordance with GDPR, such as standard contractual clauses approved by the European Commission.
10. Privacy of Minors
Our service is not directed to minors under 16 years of age. We do not knowingly collect personal information from minors. If you are a parent or guardian and know that your child has provided us with personal data, please contact us so we can take necessary action.
11. Changes to This Policy
We may update this Privacy Policy occasionally. We will notify you of any changes by posting the new policy on this page and updating the "last updated" date. We recommend reviewing this policy periodically to stay informed about how we protect your information.
12. Google User Data
When a restaurant owner or manager connects their Google Business Profile account to Appetece Partners (the B2B app for restaurants), we access the following Google data through Google's official APIs. The use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including limited use requirements.
12.1. Permissions (scopes) we request
- https://www.googleapis.com/auth/business.manage: read reviews published on the restaurant's Google Business profile and post responses to those reviews on behalf of the authenticated user.
- openid, userinfo.email, userinfo.profile: identify the user (email + name) during login to associate the Google account with the correct restaurant.
12.2. What we use this data for
- Display the restaurant's Google reviews in Appetece Partners' unified inbox, alongside reviews from other sources (TripAdvisor, Appetece internal reviews).
- Allow the restaurant owner to respond to those reviews from the app, exactly as they would from Google Business Profile.
- List the user's locations during activation, so they can select the correct restaurant if their Google account manages multiple businesses.
12.3. What we do not use this data for
- We do not modify business information (name, hours, phone, address).
- We do not upload photos to the Google profile.
- We do not publish posts or offers.
- We do not access data from other businesses besides the selected restaurant.
- We do not use Google data to train general AI models nor share it with third parties for that purpose.
12.4. Storage and security
- Google access and refresh tokens are stored encrypted at rest on our backend (Convex), never exposed to the client, and renewed on the server.
- Reviews obtained from Google are saved in our database only to display them to the authenticated user and allow them to respond. They are not shared with third parties.
- We do not transfer Google user data to other service providers besides Convex (our backend).
12.5. Retention and deletion
- We retain the tokens and reviews while the Google Business connection is active.
- When the user disconnects their Google account from the app or revokes access from their Google account, we delete the stored tokens and reviews associated with that connection within a maximum of 30 days.
- You can request immediate deletion by emailing us at info@appetece.app.
12.6. Sharing with third parties
We do not share Google user data with third parties. Convex is our backend provider and processes data exclusively on our behalf under a data processing agreement.
13. Contact
If you have questions or concerns about this Privacy Policy or about how we handle your personal data, you can contact us:
- Data controller: Appetece
- Email: info@appetece.app
You also have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD) if you believe your data protection rights have been violated.