Back to HYPEBURGER
Legal information

PRIVACY
POLICY.

Your data in the Hypeburger app

This policy explains, in clear terms, how personal data is handled when you use the HYPEBURGER mobile application (the “App”).

Digidoy operates the App and its customer-account platform. The restaurant you select separately controls the data it needs to accept, prepare and fulfil your order. Neither party sells your personal data.

01

Who is responsible for your data?

For customer accounts, App operation, security and platform support, the data controller is Digidoy, 4 Rue Parisis, 28100 Dreux, France. You can contact Digidoy at contact@digidoy.fr or visit digidoy.fr.

For the sale, preparation, collection or delivery of your order, the selected restaurant is an independent controller. Its identity and contact details are shown in the App, at checkout or on your order receipt. Digidoy also processes order data for that restaurant as its technology provider.

02

Data we collect

  • Account and identity data: name, email address, mobile number, verification status, encrypted password credentials, account identifiers and authentication provider.
  • Order and transaction data: selected restaurant, basket, customisations, fulfilment method, prices, discounts, loyalty activity, payment status, order notes, timestamps and order history.
  • Delivery data: saved address, label, building, floor, unit, instructions and address coordinates. If you permit foreground location, the App uses the device’s current position to help select a nearby saved address or restaurant; Digidoy does not use it to create a continuous movement history.
  • Payment data: payment method, transaction references, status and limited billing information. Card numbers and security codes are collected directly by Stripe and are not stored by Digidoy or the restaurant.
  • Communications and feedback: support messages, delivery and rider ratings, tags and comments you submit.
  • Device and technical data: IP address and server logs, device model, operating-system version, App version, session and security events, push-notification token, crash reports and diagnostics.
  • Third-party sign-in data: when you choose Apple or Google sign-in, we receive the provider identifier and the profile details you authorise that provider to share.
03

Why we use data and our legal bases

  • To create and secure your account, authenticate you, save addresses, process baskets and orders, take payment, deliver or prepare food, provide loyalty benefits and send essential order updates: performance of our contract or steps requested before entering it.
  • To keep invoices and transaction records, respond to lawful authorities, handle food-safety traceability and meet accounting or tax duties: compliance with legal obligations.
  • To prevent fraud and misuse, protect the App, diagnose failures, improve reliability, manage disputes and defend legal claims: our legitimate interests and those of participating restaurants, balanced against your rights.
  • To access device location, send non-essential notifications or send direct marketing where consent is legally required: your consent, which you may withdraw at any time without affecting earlier processing.
04

Required and optional information

Fields marked as required are needed to create an account or fulfil an order. Without them, the relevant feature or order may not be available. Creating an account, saving an address, enabling location and allowing notifications are optional unless the App clearly says otherwise. You can order only through the fulfilment methods currently offered by the restaurant.

05

Who receives your data?

  • The selected restaurant and its authorised staff, only as needed to accept, prepare and support your order.
  • Assigned delivery providers and riders, who receive only the delivery and contact information required to complete the delivery.
  • Service providers acting under contract, including cloud hosting, email or verification delivery, customer support, security and infrastructure providers.
  • Stripe for payment processing; Firebase/Google for push messaging and crash diagnostics; Apple or Google when you choose their sign-in service; and mapping or geocoding providers when you use address features.
  • Professional advisers, insurers, courts, regulators or public authorities where necessary to establish or defend rights or comply with law.
  • A purchaser or successor in a genuine corporate transaction, subject to confidentiality and applicable data-protection law.
06

International transfers

We favour hosting and processing in the European Economic Area. Some providers may nevertheless process data in countries outside it. Where that happens, we rely on a European Commission adequacy decision, approved Standard Contractual Clauses with supplementary measures where required, or another lawful safeguard. You may ask contact@digidoy.fr for information about the safeguard relevant to your data.

07

How long we keep data

  • Account and saved-address data: while your account is active, then normally up to 3 years after your last activity, unless you ask for earlier deletion or a legal exception applies.
  • Order and dispute records: for operational use and the applicable limitation period, generally 5 years; invoices and accounting records may be retained for 10 years as required by French law.
  • Verification codes: only for their short validity period; security and server logs: normally no more than 12 months unless an incident requires longer preservation.
  • Push tokens: until you sign out, disable the service or the token becomes invalid. Crash diagnostics are retained according to the configured provider period and are then deleted or aggregated.
  • The current foreground location used to suggest a nearby address is not retained as a location history. A saved delivery address and its coordinates remain until you delete them or the related account is deleted.
  • Where deletion is requested, limited data may remain in restricted backups for a short technical rotation period and in protected archives where retention is legally required.
08

Your rights

To exercise a right concerning the platform, email contact@digidoy.fr and describe your request. For restaurant-specific order processing, you may also contact the restaurant shown on the receipt. We may request proportionate proof of identity when reasonably necessary and will normally respond within one month.

You may lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL) at cnil.fr. We encourage you to contact us first so we can address the issue.

  • You may request access to and a copy of your data, correction of inaccurate data, deletion, restriction of processing and—where applicable—data portability.
  • You may object to processing based on legitimate interests and object at any time to direct marketing. You may withdraw consent at any time through the App, your device settings or by contacting us.
  • You may provide instructions concerning your personal data after death, where French law allows.
  • These rights can be limited where an exemption applies, including legal retention duties or the establishment, exercise or defence of legal claims.
09

Device permissions and choices

Location and notification permissions can be refused or withdrawn in your device settings. Refusing location does not prevent ordering: you can select or enter an address manually. Refusing notifications may mean you do not receive push updates, but order status remains available in the App. Camera access, when offered for scanning payment-card details, is handled on your device for that feature and is not used for unrelated purposes.

10

Automated decisions

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you. Automated checks may flag suspected fraud or payment risk, but a restriction can be reviewed when you contact us.

11

Security

We use proportionate technical and organisational safeguards, including encrypted network transport, access controls, secure session storage, logging and provider oversight. No service can guarantee absolute security. Keep your credentials confidential and contact us promptly if you suspect unauthorised account use.

12

Children

The App is not directed to children and an account may not be created by anyone under 15. A person under 18 may place an order only with permission and supervision from a parent or legal guardian. If you believe a child provided data contrary to this rule, contact us so we can investigate and delete it where appropriate.

13

Changes and contact

We may update this policy when the App, our providers or the law changes. Material changes will be brought to your attention in the App or by another appropriate method before they take effect where required.

Privacy questions and rights requests: contact@digidoy.fr · Digidoy, 4 Rue Parisis, 28100 Dreux, France · digidoy.fr

Questions or rights requestscontact@digidoy.fr

Return to HYPEBURGER