Gastronomy Under One Hour

Privacy Policy

Effective 2026-08-17 · what we hold, why, and how you get it back.

[REVIEW REQUIRED — before launch] Controller identity is a placeholder; the allergy-data consent flow and the US-region database transfer noted below need confirmation by a privacy professional. This draft is not legal advice.

1 · Who is responsible

Controller: [TRADER LEGAL NAME], [BUSINESS ADDRESS], Netherlands — table@gastronomyunderonehour.com.

2 · What we process, and why

We do not sell or rent personal data, run no advertising, and the website sets no tracking cookies.

3 · Where it lives

Data is stored with Supabase (database hosting) and served via Cloudflare; Stripe processes payments. Our database is currently hosted in a US region: transfers rest on the EU–US Data Privacy Framework and/or Standard Contractual Clauses of these providers. [REVIEW REQUIRED: confirm Supabase region/DPF status, or migrate the project to an EU region before launch.] Your own conversations with Claude are governed by Anthropic's privacy terms — Anthropic is your provider there, not ours.

4 · How long

Account, profile, and shelf data: for the life of your subscription and 12 months after it ends (so a lapsed table can come back), then deleted. Invoices: 7 years (tax law). You can request earlier deletion at any time.

5 · Your rights

Access, rectification, erasure, portability (your shelf exports in a readable format), restriction, objection, and withdrawal of consent — write to table@gastronomyunderonehour.com and we respond within a month. You can always complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

6 · Changes

Material changes to this policy are announced by email before they take effect.

← back to the table · terms of service