This English version is provided for your convenience. The German version at foodprints.app/datenschutz is the legally binding one.
1. Controller
Anna Thumann and Moritz Garger (private individuals), Bäckerstrasse 51, 8004 Zürich, Switzerland
Data protection contact: support@foodprints.app
This statement describes how we process personal data. Swiss data protection law (FADP) applies. Where the European General Data Protection Regulation (GDPR) applies, the rights set out there apply in addition.
2. Which data we process
| Category | Examples | From whom |
|---|---|---|
| Account data | Name, email, password hash, language | All user groups |
| Profile data | Profile picture, channels, reach | Influencers |
| Business data | Company, address, VAT ID, contact person | Restaurants |
| Usage data | Viewed specials, favourites, redemptions with timestamp | End users |
| Transaction data | Special ID, amount, involved parties, billing period | Restaurants, influencers |
| Communication | Support requests, messages via the platform | All |
| Technical data | IP address, device type, app version, timestamps, logs | All |
| Consent records | Accepted contract version, time, IP address | All |
Payment data: Card numbers and bank details are processed by Stripe. We neither see nor store full card numbers.
3. Why we process the data
| Purpose | Legal basis |
|---|---|
| Providing and operating the platform | Performance of contract |
| Registration, authentication, account management | Performance of contract |
| Logging redemptions and billing fees | Performance of contract |
| Enabling payment processing via Stripe | Performance of contract |
| Support and communication | Performance of contract, legitimate interest |
| Security, abuse and fraud prevention | Legitimate interest |
| Proof of accepted contract versions | Legitimate interest, legal obligation |
| Aggregated statistics and product improvement | Legitimate interest |
| Retention of business records and receipts | Legal obligation (Art. 958f CO) |
| Newsletter and push marketing | Consent, revocable at any time |
4. Where the data comes from
Generally from you. In addition, data arises automatically during use (for example logs) and through the interaction between user groups, such as when a restaurant confirms a redemption.
5. Sharing between user groups
- To restaurants: in a collaboration, the influencer's name or company and profile as well as the logged redemption data. For end users there is generally no sharing of personal data, only the confirmation of a valid redemption.
- To influencers: information about the cooperating restaurant and the redemption data assigned to them.
- To end users: public information about the restaurant and, for promoted specials, about the influencer.
6. Service providers and recipients
We use carefully selected service providers that process data on our behalf or as their own controllers:
| Provider | Purpose | Location |
|---|---|---|
| Stripe | Payment processing, identity verification of influencers | Ireland/USA |
| AWS | Operation of servers and database | Sweden (eu-north-1), EU |
| Resend | Transactional emails | USA |
In a collaboration between a restaurant and an influencer, Stripe is an independent controller for the payment processing. Stripe's privacy policy applies in addition.
7. Disclosure abroad
Some service providers process data outside Switzerland. We only disclose data to countries with adequate data protection or otherwise ensure protection, in particular through Standard Contractual Clauses or a recognised adequacy decision. You can obtain a copy of the safeguards at support@foodprints.app.
8. How long we keep data
| Data | Duration |
|---|---|
| Account data | Until the account is deleted, then at most 90 days |
| Redemption and transaction logs | 10 years (Art. 958f CO) |
| Receipts and invoices | 10 years (Art. 958f CO) |
| Proof of accepted contract versions | 10 years from the end of the contract |
| Technical logs | 90 days |
| Support communication | 2 years |
After that, data is deleted or anonymised.
9. Your rights
You have the right to access, rectification, deletion, release or transfer of your data, as well as the right to object to processing. You can revoke a consent you have given at any time.
To do so, please contact support@foodprints.app. For security, we may request proof of identity.
Statutory retention obligations and overriding interests can prevent deletion, for example redemption logs that we must keep for ten years.
You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
10. Data security
We take appropriate technical and organisational measures: encrypted transmission (TLS), encrypted storage of credentials, role-based access restriction, logging of administrative access, and regular backups.
11. Cookies and similar technologies
We use technically necessary cookies and local storage for login and security. We do not currently use technologies for statistics or marketing.
12. Automated decisions
Payments between a restaurant and an influencer are triggered automatically based on logged redemptions. This is the execution of a contractually predefined rule without any discretion; no evaluation of your person takes place.
13. Changes
We may adapt this statement. The version published at https://foodprints.app/privacy applies. We will actively inform you of material changes.
Version 1.0 · 6 August 2026 · Contact: support@foodprints.app