Privacy Policy
Informative translation. In case of doubt, the Spanish version prevails.
Last updated: 6 May 2026
1. Controller
- Holder: Ángel Rives García
- NIF: 15415960A
- Address: Calle Redován 3, 03350 Cox (Alicante), España
- General contact: hola@elpizzero.com
- Privacy contact: privacidad@elpizzero.com
- Telephone: +34 664 37 36 76
2. Processing model: dual controller
elpizzero is a multi-restaurant platform. This means two distinct roles in the processing of your data:
- elpizzero is the controller of the data necessary to operate the platform (registration, session, anonymised analytics, security).
- Each restaurant from which you place an order is the controller of the data of the order itself (name, telephone, delivery address, contents of the order) as regards the provision of the catering service. In this case elpizzero acts as processor, storing the data and transmitting it to the restaurant.
3. Data we collect
- Order data: name, telephone, optional email, delivery address (for home delivery), contents of the order, special instructions and, where applicable, proof of payment.
- Location data: the delivery address is geocoded (converted into coordinates) using OpenStreetMap / Nominatim in order to calculate the delivery zone and display it on a map. We never track the location of your device. If the restaurant manages its deliveries with a delivery platform with tracking, while your order is on its way you will be able to see on a map the position of the courier —never your own—, and only while the courier is carrying the order: once it is delivered, that position is no longer shown.
- Booking data: name, telephone, optional email, date, time, number of guests and notes (when the restaurant offers table booking).
- Customer account data (optional): if you decide to create an account to save your addresses and consult your order history: name, email, encrypted password, saved addresses.
- Restaurant account data (only for establishment managers): legal name, NIF, billing details, contact person, credentials for access to the panel.
- Browsing data: IP address (stored with each order and in the security logs, to prevent fraud and protect the service), browser, operating system, device type, pages visited, technical cookies.
- Payment data: when payment is made by card, the full details are NOT stored on our servers: they are handled entirely by the external payment provider (PCI-DSS). We only keep a transaction identifier and the last 4 digits.
4. Purposes of the processing
- To process and manage your orders and bookings, and to transmit them to the relevant restaurant for preparation and delivery.
- To notify you by email, or by a notification in your browser if you allow it, of the status of your order or booking (confirmation, being prepared, out for delivery, delivered).
- To maintain your customer account and allow you to consult your history.
- To handle enquiries, incidents and support requests.
- To comply with the accounting, tax and invoicing obligations arising from the operation.
- To improve the service through anonymised and aggregated analytics (without individual profiling).
- To send commercial communications from the restaurant or the platform only where you have given your express consent by means of the corresponding box.
5. Legal basis for the processing
- Performance of a contract (art. 6.1.b GDPR): to process your orders, bookings and customer account.
- Compliance with a legal obligation (art. 6.1.c GDPR): to keep invoices and tax records.
- Consent (art. 6.1.a GDPR): for non-essential cookies and commercial communications.
- Legitimate interest (art. 6.1.f GDPR): for improving the service, preventing fraud and the security of the platform.
6. Recipients of the data
- Restaurant receiving the order or booking: the necessary data (name, telephone, delivery address where applicable, contents of the order) are transmitted to the restaurant so that it can prepare and deliver it. Each restaurant is obliged to process these data in accordance with the GDPR and exclusively for the purpose of providing the service.
- Own couriers or external couriers engaged by the restaurant: they receive the delivery address, the telephone number and the summary of the order in order to carry out the delivery.
- Delivery platform: if the restaurant organises its deliveries with a logistics platform (for example, Reparto), the latter receives the delivery address and coordinates, the contact telephone number, the amount to be collected and the details of the order, for the sole purpose of assigning the delivery and carrying it out. It acts on behalf of the restaurant and under a processor contract. If you request the erasure of your data, the instruction is also communicated to that platform, in accordance with article 19 of the GDPR.
- Payment provider (when paying by card): the transaction is processed by the gateway engaged by the restaurant (PCI-DSS certified).
- Technical service providers: hosting (Hostinger, servers in the European Union), sending of transactional email (own SMTP), notifications to the restaurant of new orders, if the restaurant activates them: an automated call with Twilio (without any data about you) and Telegram messages (only the number and amount of the order, without any data about you).
- Public authorities: where there is a legal obligation or a court order.
- Payment provider: when the restaurant offers online payment, the payment data are processed through Stripe under its own terms and security measures (PCI-DSS).
- AI providers: we use artificial intelligence services (e.g. OpenAI) to translate the menu and the notes you write in your order (so that the kitchen understands them in its language) and to read menus and invoices. We do not send them your name, telephone, email or address; avoid putting personal data in the notes.
- We do not sell or transfer personal data to third parties for commercial purposes.
7. Data retention
- Orders and bookings: they are kept for the period legally required for invoicing and tax obligations (up to 6 years under the Commercial Code and the General Tax Act).
- Customer accounts: while the account is active. When its deletion is requested, the personal data will be erased within a maximum of 30 days, except where there is a legal obligation to retain the orders.
- Restaurant accounts: for the duration of the commercial relationship, plus the statutory accounting retention periods. An account that has never been used (no orders or invoices) and which nobody accesses for 3 months is deleted: we give notice beforehand by email 15 days before, 7 days before and on the same day, and it is enough to log in to the panel to keep it. Invoices and invoicing records, if any, are never deleted by this route.
- Browsing data: anonymised analytics are kept for a maximum of 26 months.
- Commercial communications: until you withdraw your consent.
8. Rights of the data subject
In accordance with the GDPR and the LOPDGDD, you may exercise the following rights:
- Access: to know what personal data we process about you.
- Rectification: to correct inaccurate or incomplete data.
- Erasure: to request the deletion of your data when they are no longer necessary.
- Objection: to object to the processing in certain circumstances.
- Restriction: to request the restriction of the processing.
- Portability: to receive your data in a structured and commonly used format.
- Withdrawal of consent: to withdraw it at any time without affecting the lawfulness of the processing carried out before.
To exercise any of these rights, send an email to privacidad@elpizzero.com stating your full name, the right you wish to exercise and, where applicable, the restaurant concerned. We will reply within a maximum of 30 days.
If you consider that the processing of your data does not comply with the regulations, you may lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) at www.aepd.es.
9. Security
We apply technical and organisational measures to protect your data:
- Encryption in transit (HTTPS/TLS) in all communications.
- Secure storage of passwords using bcrypt hashing.
- Parameterised SQL queries (prepared statements) against injection.
- CSRF protection in forms and modification requests.
- Rate limiting against abusive access attempts.
- Access to the data restricted by roles (end customer, restaurant manager, administrator).
- Active security headers: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
10. Minors
The service is intended for persons over 14 years of age. If you are under that age, you must have the consent of your parents or guardians in order to place orders or create an account.
11. Amendments
We reserve the right to update this policy. Any change will be published on this page with the corresponding update date. In the event of substantial changes, we will notify registered users by email.