Skip to Content

Privacy Notice

This notice explains how company name uses personal data of the people who use Ordoria Business: restaurant and supplier owners and staff, people who request a demo, and Diners who view a QR menu. It meets Articles 13 and 14 of the UK GDPR.

Updated 7 October 2026

Draft. This document is being reviewed before launch. Company details still to be confirmed are highlighted.

1. Who We Are

1.1 The controller is company name, company number company number, registered office address ("Ordoria", "we"). ICO registration number: ICO number. Contact for privacy questions: support@ordoria.com.

1.2 For some data we act for a Business or Supplier, as their processor (for example, staff details a Business enters about its team). In that case the Business or Supplier is the controller, and you should contact them first.

2. What We Collect

CategoryExamplesSource
AccountName, email, phone, password (stored hashed), Apple or Google account identifier, languageYou, or Apple/Google if you sign in with them
ProfileProfile photo, job role from our list (for example chef, owner or buyer), date of birthYou
Business or supplierOrganisation name, address, map location, VAT number, opening hours, your role and permissionsYou or your organisation
Orders and returnsOrders, carts, templates, delivery details, return claims, notes and photos, reviewsYou, your organisation, Suppliers
PaymentsCard brand, last four digits, expiry, Stripe customer and payment references, subscription status. Full card numbers are held only by StripeYou, Stripe
Device and usageDevice type, operating system, app version, push notification token, in-app events (such as screens viewed, searches, orders started), crash reportsYour device
SearchesText search queries, including text produced from voice search, and scanned barcodes. We do not receive the audio; your device's speech service converts itYou
Technical logsIP address, request logs, security events from our firewallYour device
CommunicationsSupport emails, feedback, demo requests (name, company, role, email, phone, message)You
Diners (QR menu)Technical logs only. We do not ask Diners to sign inYour device

3. Why We Use It and Our Lawful Bases

PurposeLawful Basis (UK GDPR Article 6)
Create and run your account, sign-in and securityContract with you or your organisation; legitimate interests in securing the Platform
Process orders, send them to Suppliers, show invoices and handle returnsContract; legitimate interests of your organisation and Suppliers
Take Service Fees and subscriptions, prevent payment fraudContract; legal obligation; legitimate interests
Age check for alcohol and other age-restricted goods (using your date of birth)Legal obligation (Licensing Act 2003); legitimate interests
Send service notifications (order status, returns, security, account changes)Contract; legitimate interests
Send a birthday greetingLegitimate interests. You can turn this off at any time
Send promotional notifications and marketing emailsConsent, or for business contacts at corporate subscribers, legitimate interests with a right to opt out
Product analytics, crash diagnostics and improving the appLegitimate interests in a reliable, useful product
Support, feedback and demo requestsLegitimate interests; steps before a contract
Comply with tax, accounting and legal duties, and defend legal claimsLegal obligation; legitimate interests

3.1 You can ask us for the legitimate interests assessments we rely on.

3.2 We do not use your data to make decisions based solely on automated processing that have legal or similarly significant effects on you. Suppliers may set prices for an organisation automatically by delivery distance; this concerns the organisation's pricing and is set by the Supplier.

4. Who We Share It With

4.1 Suppliers you order from. We share the order, delivery details, organisation details, and the name and contact details of the person who placed the order or is the delivery contact. Each Supplier is an independent controller and has its own privacy notice.

4.2 Your organisation. Owners and managers of your Business or Supplier can see your activity in their account, such as orders you placed, returns you raised and changes you made (recorded in the audit log).

4.3 Service providers who host, secure, send or support the Platform, under contract, as listed in our Sub-processor List.

4.4 Stripe processes payments as our processor and, for its own fraud prevention and legal duties, as an independent controller.

4.5 Apple and Google, if you sign in with them or use their speech recognition or push notification services.

4.6 Authorities and advisers: HMRC, the police, trading standards, the Food Standards Agency, courts and our professional advisers, where the law requires or to protect rights and safety.

4.7 A buyer of our business, if Ordoria is sold or restructured, under confidentiality.

4.8 We do not sell personal data.

5. International Transfers

5.1 Some providers store or access data outside the UK. We transfer data only to countries with UK adequacy regulations, to US organisations certified under the UK Extension to the EU–US Data Privacy Framework, or under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

6. How Long We Keep It

DataRetention
Account and profileWhile the account is open. After you delete it, a restricted copy is kept for 30 days for disputes or requests, then erased
Orders, invoices, returns and payment records6 years after the end of the financial year they relate to (tax and accounting law), then deleted or anonymised
Audit log entries6 years
Push tokensUntil you sign out, uninstall the app or the token expires
Analytics events and crash reports24 months, then aggregated or deleted
Technical and security logs90 days
Demo requests and support emails24 months after the last contact
Marketing preferences and opt-outsAs long as needed to respect them

7. Your Rights

7.1 You have the right to: access your data; correct it; erase it; restrict or object to its use (including an absolute right to object to direct marketing); data portability; and withdraw consent at any time. You can also complain to us.

7.2 Many choices are in the app: edit your profile; manage notifications; delete your account (Account › Settings › Delete account).

7.3 Email support@ordoria.com to exercise any right. We will reply within one month, which may be extended by two further months for complex requests.

7.4 You can complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113. We would appreciate the chance to deal with your concern first.

8. Security

8.1 We protect data with encryption in transit and at rest, hashed passwords, role-based access, a web application firewall, rate limiting, a tamper-evident audit log and staff confidentiality duties.

9. Age

9.1 Ordoria Business is for adults acting for a business. We do not knowingly collect data from anyone under 18. QR menus may be viewed by anyone, and collect no personal data beyond technical logs.

10. Changes

10.1 We will tell you about material changes in the app or by email before they take effect.