Legal
Privacy policy
Last updated: 10 October 2026
This policy explains how Ginger Dialogue collects and uses personal data when you visit gingerdialogue.com, order from a restaurant or business on our platform, use a customer account, register as a partner business or work in a partner’s team. We follow the General Data Protection Regulation (GDPR – Regulation (EU) 2016/679) and Portuguese Law no. 58/2019. The Portuguese version prevails in case of doubt.
1. Who is responsible
The controller is Ginger Dialogue, Lda., NIPC 519653955, Peral CDV Portugal (“Ginger Dialogue”, “we”). For any privacy question or request: [email protected] · +351 916 026 688.
2. Our role and the role of partner businesses
Ginger Dialogue operates a marketplace: we connect Customers with Partner businesses (restaurants, cafés, shops and others).
- Ginger Dialogue is the controller for the website, customer and partner accounts, the ordering system, payments and payouts, security and fraud prevention, reviews, support and our own communications.
- Each Partner is an independent controller for the Order data it receives to prepare, deliver and invoice your Order and to meet its own legal obligations (for example invoicing and food safety). Partners have their own privacy obligations; you can contact the Partner directly.
- When we host a Partner’s own website or process data only on a Partner’s instructions, we act as its processor under our Data Processing Agreement.
3. What data we collect
Visitors: IP address, browser and device data, pages visited, your cookie choices (see the Cookie Policy) and, if you allow it, your approximate location to show businesses near you.
Customers: name, mobile number, email, delivery address and its map coordinates, the Order (products, options, notes, time, type, total, discount code), payment status and method (never the full card number), Order history, reviews you write, messages, and a random device identifier stored in your browser.
Partners and their teams: business name, tax number (NIF/NIPC), address, contact person, phone, email, opening hours, documents submitted at registration, menus and photos, IBAN and account holder for payouts, commission and payout statements, user accounts and roles of team members, login and security records, support messages.
Security and anti-abuse: login attempts, 2-step login codes, IP address, records of no-shows, blocks and reports, and the result of the anti-robot check. Phone numbers, emails, device identifiers and IP addresses kept for abuse prevention are stored in a pseudonymised (hashed) form.
Please do not write health information (for example allergies) in order notes unless needed; if you do, it is used only so the Partner can prepare your Order safely.
4. Why we use your data and on what legal basis
- To provide the platform and process Orders – send the Order to the Partner, show the tracking page, send confirmations and status updates by email or SMS, manage refunds: performance of a contract (Art. 6(1)(b) GDPR).
- Customer and partner accounts, partner registration and verification, payouts: contract and pre-contractual steps (Art. 6(1)(b)).
- Invoicing, accounting, tax and answering authorities: legal obligation (Art. 6(1)(c)).
- Security, fraud and abuse prevention – anti-robot check, SMS code before the first pay-at-the-shop Order, device identifier, limits on open Orders, no-show records and blocks, 2-step login, activity logs, backups: our and our Partners’ legitimate interest in protecting the platform, Customers and Partners (Art. 6(1)(f)).
- Reviews: legitimate interest in offering verified reviews (Art. 6(1)(f)); you decide whether to write one.
- Support and complaints: contract or legitimate interest.
- Improving the platform and statistics, using aggregated data where possible: legitimate interest.
- Marketing emails, optional cookies and precise location: your consent (Art. 6(1)(a)), which you can withdraw at any time.
5. Automated decisions to prevent abuse
Some anti-abuse rules work automatically: for example, after repeated unpaid no-shows a phone number or device may be allowed to pay only online, or be blocked. These rules are applied to protect Partners from false Orders. You have the right to ask for a person at Ginger Dialogue to review the decision, to give your point of view and to contest it: write to [email protected].
6. Location
The “Near you” page can use your device’s location, only if you allow it in the browser, or an address you type. It is used to calculate distances and show nearby businesses, and is kept only in your browser session. Address suggestions and maps are provided by OpenStreetMap-based services (Photon by komoot and OpenStreetMap tiles), which receive the address you type and your IP address.
7. Payments
Online payments are processed by Stripe and PayPal, who act as independent controllers for the payment data they need (and must comply with financial law). We receive only the information needed to confirm and reconcile the payment (status, reference, amount, method) – never your full card details.
8. Who we share data with
- The Partner you order from – the Order details, your name, phone, email and (for delivery) address, so it can prepare, deliver and invoice the Order.
- Service providers working for us under contract, only as needed: our website hosting provider; Cloudflare (network security, protection against attacks and the anti-robot check); Stripe and PayPal (payments); our email provider; Twilio (SMS and WhatsApp messages, if enabled); OpenStreetMap-based map and address services; Dropbox (encrypted off-site backup copies, if enabled); Anthropic (AI that turns a menu file uploaded by a Partner into menu items – it receives the Partner’s menu, not Customer data).
- Authorities, courts and lawyers, when required by law or to defend our rights.
- A buyer or successor of our business, under the same protections.
We do not sell personal data.
9. Transfers outside the European Economic Area
Some providers (for example Cloudflare, Stripe, PayPal, Twilio, Dropbox and Anthropic) may process data in the United States or other countries. In those cases, transfers are based on the EU-U.S. Data Privacy Framework (for certified companies), on the European Commission’s standard contractual clauses, or on another safeguard allowed by the GDPR. You can ask us for more information.
10. How long we keep data
- Orders and invoicing records: for the period required by tax and accounting law (currently 10 years); data not needed for that is deleted or anonymised earlier.
- Customer access: the customer login cookie lasts 60 days; Order history remains available while Order records are kept.
- Partner accounts: while the account is active. After an account is closed it is kept for 30 days (so it can be restored if closed by mistake) and then deleted, except data we must keep by law.
- Unfinished partner registrations: deleted after 30 days. Applications not approved: deleted after 12 months.
- Cookie choices: proof of consent kept for 12 months.
- Security and anti-abuse records: for as long as needed for that purpose, normally no more than 24 months.
- Backups: daily copies kept for 7 days and then replaced.
11. Security
We use encryption in transit (HTTPS), a protection layer and firewall (Cloudflare), anti-robot checks, rate limits and login lockouts, 2-step login for administrators and teams, strict separation between Partners’ data, role-based access, pseudonymisation of anti-abuse data, automatic backups and monitoring. No system is 100% secure; if a breach is likely to put you at risk, we will tell you and the authority as required by law.
12. Your rights
You have the right to access your data, to correct it, to have it deleted, to restrict or object to its use (including at any time to direct marketing), to data portability, and to withdraw consent without affecting earlier processing. Partners can also download their data or ask to close their account in the dashboard (Privacy area).
To exercise your rights, write to [email protected]. We will reply within one month (extendable in complex cases, with notice). We may ask you to confirm your identity. For data held by a Partner about your Order, you can also contact the Partner directly.
You may also complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt.
13. Children
The platform is not intended for children. You must be 18 or over to create an account or place an Order. We do not knowingly collect data from children; if you believe a child has given us data, contact us and we will delete it.
14. Cookies
We use cookies and similar technologies as explained in our Cookie Policy. You can change your choices at any time: Cookie settings.
15. Changes to this policy
We may update this policy. The current version is always on this page with its date. If a change is significant, we will inform you on the website or by email.