Skip to content
Angie EatsSet your addressYour basket is empty
← Back

Privacy

Last updated 2026-08-01 · v2026-08-01.1

Draft — not yet reviewed by a lawyer

The descriptions of how this service works are accurate. The legal conclusions have not been checked by anyone qualified to check them, and this must not be relied on as it stands.

1. What this covers

This notice describes what Angie Eats does with information about you. It covers the ordering platform, the ordering assistant, and the delivery of your order. It is written to satisfy the General Data Protection Regulation, which applies to you if you are in Greece or anywhere else in the EU, and the California Consumer Privacy Act as amended by the CPRA, which applies to you if you are in California. Sections are marked where they apply to only one of those.

We are the controller of the information described here, except where this notice says otherwise. Where a restaurant or a courier receives information about you, section 6 explains who is responsible for what.

Needs a qualified lawyer: Name the controlling legal entity per market and its representative. If the controlling entity is outside the EU, a GDPR Art. 27 representative in the EU is mandatory and one has not been appointed. Confirm whether an Art. 37 DPO is required: on the combination of large-scale health data (allergies), profiling and courier location tracking, the answer is likely yes.

2. What we collect

When you order: your name, contact details, delivery address where relevant, what you ordered, and payment information. Card details are handled by our payment processor and we do not store your card number.

When you tell us something about how you eat: dietary preferences, and any allergy you declare. Section 4 deals with allergies separately because the law treats them differently.

When you use the ordering assistant: what you type, for the duration of the conversation. Conversation memory is held in a cache with a thirty-minute expiry and is not written to a database. Nothing from a conversation becomes a stored fact about you unless you tap to confirm it.

When a delivery is in progress: the courier's position, and where a photograph is taken as proof of delivery, that photograph.

Technical information needed to run the service: a hashed record of the network address a signup came from, device and session identifiers, and fraud signals.

3. Why we use it, and on what legal basis

Greece and the EU only

Taking and fulfilling your order, including passing what is needed to the restaurant and the courier: performance of our contract with you (GDPR Article 6(1)(b)).

Taking payment, issuing receipts, and meeting tax, invoicing and anti-money-laundering obligations: performance of the contract, and compliance with a legal obligation (Article 6(1)(b) and 6(1)(c)).

Preventing fraud and defending payment disputes: our legitimate interests in not being defrauded and in being able to answer a chargeback (Article 6(1)(f)). You can object to this and we will consider the objection, but we may keep processing where we have compelling grounds.

Showing a courier's position to you while your order is on its way: performance of the contract. Recording the courier's position at all: our legitimate interests in running a delivery operation, never the courier's consent, because an employer or platform cannot rely on a worker's consent.

Remembering what you like — the taste profile: your consent (Article 6(1)(a)), and where it touches dietary or health matters, your explicit consent (Article 9(2)(a)). You can withdraw it, and withdrawing it deletes the profile rather than merely stopping its use.

Marketing email: your consent, except where you have actually ordered from us and we are telling you about similar things, which Greek law permits with an opt-out in every message. Promotional push notifications: your consent, separately from the permission your phone asks for.

Keeping evidence of a complaint or a dispute: our legitimate interests and, where the evidence includes an allergy, the establishment or defence of legal claims (Article 9(2)(f)).

Needs a qualified lawyer: The lawful basis for the taste profile is stated as consent, which is the correct and conservative answer (EDPB Guidelines 2/2019 Examples 7 and 8 rule out Art. 6(1)(b); C-621/22 makes legitimate interests unsafe for optional behavioural profiling). VERIFY AGAINST THE BUILD: if the profile is in fact populated without a consent gate, this sentence is false and must change before launch, not after. A legitimate interests assessment must also be written for fraud prevention and for courier location, and neither exists yet.

4. Allergies, and why they are treated differently

An allergy you declare is health information. Under EU law that is a special category of personal data and needs your explicit consent as well as an ordinary legal basis. We ask for it, we tell you it goes to the kitchen, and it goes to the kitchen.

We never infer an allergy. Not as a fallback, not as a guess, and not from what you avoid ordering. Our software is built so that an inferred allergy cannot be recorded at all: the structure that holds an observation about your eating has no field for severity, the code that would build a dietary fact from behaviour refuses outright, and the database rejects any allergy record whose origin is not you telling us. Not ordering something is not the same as being unable to eat it, and treating it as such is how a system ends up telling somebody a dish is safe.

What you can see: every allergy and preference we hold, with a note of how we learned it — whether you set it in your profile, said it at checkout, told the assistant, or had it confirmed by support. You can delete any of them individually or all of them at once.

Needs a qualified lawyer: The Art. 9 classification is settled enough to rely on (Art. 4(15), Recital 35; reinforced by CJEU C-21/23 Lindenapotheke, 4 Oct 2024, holding that even non-prescription pharmacy order data is health data). Two consequences to confirm: (1) the explicit consent must be separate, specific and recorded, not bundled into acceptance of these terms; (2) a dietary tag such as halal or kosher may reveal religious belief and is arguably also Art. 9 data on the same reasoning — counsel to decide whether the same explicit-consent treatment should extend to it.

5. Who we share it with

The restaurant you ordered from receives what it needs to make and hand over your order. On the kitchen ticket that is your name, your telephone number, and your delivery address only where the restaurant is delivering it itself. It also receives any allergy or dietary notice you declared, in the restaurant's own language, so that the kitchen can act on it.

Where a restaurant looks up a past order in its own history screen, it can also see the email address associated with that order. That is so it can call or write to you about an order you raised.

The courier delivering your order receives what is needed to find you and hand it over.

Our payment processor receives what is needed to take the payment. Our infrastructure and communications providers process information on our instructions and for no purpose of their own.

The ordering assistant sends the text of your conversation and a snapshot of the menu to Anthropic, which operates the model. It does not send your name, your address or your payment details.

We do not sell your information, and we do not share it for advertising. There is no advertising network, no analytics provider and no tracking pixel on this platform.

Needs a qualified lawyer: CONFIRM THE ASSISTANT TRANSFER. Anthropic is a US processor, so a Chapter V transfer mechanism is required: either reliance on the EU-US Data Privacy Framework if Anthropic is certified, or Standard Contractual Clauses plus a transfer impact assessment. Neither has been put in place. Confirm also whether the menu snapshot or conversation can contain an allergy declaration, because that would make it an Art. 9 transfer and raise the bar.

6. The restaurant is a separate controller, not ours

Greece and the EU only

When we pass your details to a restaurant so it can make your food, the restaurant becomes responsible for that information in its own right. It is not acting on our instructions; it is running its own business, cooking food it sells, and meeting its own food-safety, tax and consumer-law obligations. In data protection terms we are separate controllers, not joint controllers and not controller and processor.

What that means for you in practice: we are responsible for deciding to send it, for sending only what is needed, and for telling you that we do. The restaurant is responsible for what it does with it afterwards. Our agreement with every restaurant requires it to use your details only for your order, not to keep them longer than it needs, and not to market to you off the back of an order you placed with us.

You can exercise your rights against either of us. If you contact us about something a restaurant did, we will help you reach them and we will not use this section as a reason to do nothing.

Needs a qualified lawyer: THE MOST IMPORTANT DETERMINATION IN THIS DOCUMENT, AND IT SHOULD BE PRESSURE-TESTED. Separate controllership is the better reading on EDPB Guidelines 07/2020 paras. 70, 82, 92 and the "travel agency", "disclosure between companies" and "taxi service" examples, and there is NO EU decision or guidance on food platforms and their merchants either way. The exposure is the allergy flow specifically: Angie Eats defines the allergen taxonomy, the fields, and what the kitchen is told to do with them, which on Jehovan todistajat (C-25/17, para. 75) and IAB Europe (C-604/22) is the fact pattern a regulator uses to find joint controllership. RECOMMENDATION ALREADY IMPLEMENTED IN THE MERCHANT AGREEMENT: conclude separate controllers, but write the merchant terms to Art. 26 standard anyway and publish this paragraph as the "essence", so that a recharacterisation costs an argument rather than an artefact. Counsel to confirm and to decide whether an express Art. 26 arrangement should be signed instead.

7. How long we keep things

A courier's recorded positions are deleted after 30 days. This runs as a scheduled job, not as an intention.

A delivery photograph is deleted after 30 days. The record that a photograph existed and was deleted survives, because "there was a photograph and it has been deleted" and "there was never a photograph" are different statements.

The remaining delivery record — time, distance, who delivered it — is deleted after 180 days. That is longer than the photograph on purpose: a card scheme allows up to 120 days for a customer to dispute a delivery they say never arrived, and the bank then asks us for evidence, so a 30-day window would mean losing every dispute that arrives through a bank rather than through the app.

Records of attempts to contact you about a delivery are deleted after 90 days.

Fraud signals are stripped of the network address and device identifier after 90 days.

A device registration for push notifications is deleted after 180 days without use.

Assistant conversation memory expires after 30 minutes and is never written to a database.

Order and payment records are kept for as long as tax and accounting law requires, and no longer.

Needs a qualified lawyer: The periods above are read from scheduled code and are accurate as at this version. Two gaps: (1) the retention period for order, payment and account records is stated as "as long as tax law requires" and no such job exists — Greek accounting law (L.4308/2014) and US state rules set different periods and one must be chosen and built; (2) CPRA requires the actual retention period, or the criteria used, to be disclosed for EACH category of personal information, which the last sentence does not yet satisfy.

8. Your rights — Greece and the EU

Greece and the EU only

You have the right to know what we hold about you and to get a copy; to have it corrected; to have it deleted; to restrict how we use it; to take it elsewhere in a portable form; and to object to processing based on our legitimate interests. Where we rely on your consent you can withdraw it at any time. We answer within one month.

Two of these are already built rather than promised. You can list everything the assistant has learned about you, each item labelled with how we learned it, and you can delete any of it or all of it, from your own account, immediately and without asking us.

You can complain to the Hellenic Data Protection Authority. Complaining to us first is not a precondition, though we would rather you did.

The right to deletion is not absolute: where we need a record to defend a legal claim, or to meet a tax obligation, we keep that record and tell you why.

9. Your rights — California

United States only

You have the right to know what personal information we collect, use and disclose; to get a copy of it; to have it corrected; to have it deleted; and to limit our use of sensitive personal information. Exercising any of them does not change the price you pay or the service you get.

An allergy or health information you give us is "sensitive personal information" under the CCPA. We use it only to get your order made correctly and to defend a dispute about it, which are permitted purposes, so there is nothing further to limit — but you can delete it at any time and the control is in your account.

We do not sell your personal information and we do not share it for cross-context behavioural advertising. There is no "Do Not Sell or Share My Personal Information" link because there is nothing for it to do. If that ever changes, this notice changes first.

You can ask an authorised agent to make a request for you.

Needs a qualified lawyer: Confirm (a) whether the business currently meets a CCPA applicability threshold at all — if it does not, this section is voluntary and should say so rather than implying a duty; (b) that no Global Privacy Control signal handling is required, which follows from the no-sale/no-share position but should be re-checked if any analytics or advertising tag is ever added; (c) the CPPA's ADMT regulations and their compliance dates, which may reach a recommendation engine; (d) which other US state privacy laws are engaged if the platform lists outside California.

10. Automated decisions and profiling

We build a picture of what you like from what you order, and we use it to suggest things. That is profiling, and it is the only profiling we do.

It does not decide anything about you. It orders a list of suggestions you can ignore. Nothing on this platform automatically refuses you service, changes your price, or restricts what you can see, and no model is involved in pricing or in taking payment.

The Automated Processing notice sets this out properly, including what would have to change for that answer to be different.

11. Security, and what happens if something goes wrong

We protect information with measures appropriate to how sensitive it is. Where we hold something we later do not need — a delivery photograph, a courier's trail — we delete it on a schedule rather than leaving it lying about, because the safest data is the data that is gone.

If there is a breach that puts you at risk we will tell you, and we will tell the regulator within 72 hours of becoming aware of it where the law requires.

12. Children

This service is not for children. We do not knowingly collect information from anyone under 16 in the EU or under 13 in the United States, and if we learn that we have, we delete it.

Needs a qualified lawyer: Greece has set the GDPR Art. 8 digital-consent age at 15 (Law 4624/2019 Art. 21), not 16. Correct this figure before publication in Greece, and confirm the US position against COPPA.

13. Changes to this notice, and how to reach us

Every version of this notice has its own date and its own address, and old versions stay readable. When something material changes we say what changed rather than only republishing.

Write to us about anything in this notice using the contact details published on the platform.

Needs a qualified lawyer: Insert the data protection contact address and, if appointed, the DPO's contact details, which GDPR Art. 13(1)(b) requires to be stated.

9 clauses on this page carry a note above because they need a qualified lawyer. They are published rather than hidden: a reader is better served by an open question than by a confident answer that is wrong.

sha256 173a33f780c293342eaa1c7498580b231de389ef766115fe37ba9892e46a2838