Last updated: July 2026
Privacy Policy
SavEat ("we", "us", "our") operates the platform available at saveat.lu ("SavEat" or the "Service"). We are based in Luxembourg. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you have over your data. It applies to both consumers and food providers (vendors) using SavEat.
This policy is drafted in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Luxembourg Data Protection Act of 1 August 2018. If anything here conflicts with those laws, the law prevails.
1. Who is responsible for your data
The data controller responsible for your personal data is SavEat, Luxembourg. You can contact us about data protection matters at hello@saveat.lu.
2. What data we collect
We collect only the data we need to provide the service:
- Account data — your name and email address when you create an account.
- Order data — the listings you reserve, the amounts you pay, pickup codes, and the status of your orders.
- Payment data — payments are processed by Stripe. We do not receive or store your full card number or other authentication data; we only keep the information Stripe returns to us (e.g. a payment intent identifier).
- Favorites & reviews — stores you favorite and the ratings/reviews you submit.
- Location data — only when you choose to share it, and only in your browser session, to sort nearby listings. We do not store your precise location.
- Vendor data — for food providers, business name, address, contact details, and information required for payouts (managed by Stripe).
- Push notification data — if you enable push notifications, we store the browser subscription your device generates so we can send you reminders.
- Technical data — standard log information such as device type and approximate region, collected automatically by our hosting provider.
3. Why we use your data (legal bases)
- To perform a contract with you (Art. 6(1)(b) GDPR) — to process your reservations, payments, and pickups.
- To comply with legal obligations (Art. 6(1)(c) GDPR) — for example accounting records of transactions.
- For our legitimate interests (Art. 6(1)(f) GDPR) — to keep the platform secure, prevent fraud, and improve the service, as long as that does not override your rights.
- With your consent (Art. 6(1)(a) GDPR) — for push notifications and optional marketing communications. You can withdraw consent at any time.
4. Who can see your data
We do not sell your personal data. We share it only when necessary:
- Food providers — vendors see the orders placed with them, including your name and pickup code, so they can hand over your food.
- Stripe — our payment processor, to handle charges and vendor payouts. Stripe processes data under its own policies.
- Email provider (Resend) — to send you transactional emails and reminders.
- Hosting & infrastructure — our platform hosting provider (Base44) stores the application data and keeps it encrypted.
- Authorities — where required by law.
Each processor only receives the data needed for its task and is bound to protect it. We have data processing agreements in place with our key subprocessors.
5. Where your data is stored
Your data is stored by our hosting provider. Data is encrypted in transit and at rest. Depending on your plan, data may be stored in the United States or, where available, in an EU cluster. If you would like your data stored in the EU, please contact us.
6. How long we keep your data
- Active accounts — kept while your account exists. You can delete your account at any time.
- Order & payment records — retained as long as required by accounting and tax law (typically up to 10 years), then deleted.
- Push subscriptions — deleted when you turn off notifications.
- Favorites & reviews — deleted when you remove them or delete your account.
7. Your rights under GDPR
You have the following rights regarding your personal data:
- Access — ask for a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data ("right to be forgotten").
- Restriction — ask us to limit processing in certain cases.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — for any processing based on your consent, without affecting prior processing.
To exercise any of these rights, email us at hello@saveat.lu. We will respond within one month. If you believe we have mishandled your data, you can also lodge a complaint with the Luxembourg data protection authority (CNPD).
8. Children's data
SavEat is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe a minor has registered, please contact us and we will delete the account.
9. Security
We use encryption in transit and at rest, access controls, and regular reviews to protect your data. No system is completely secure, but we work with certified providers and follow industry best practices.
10. Cookies
We use only essential cookies and local storage needed for the service to function (for example, remembering that you accepted our terms). We do not use tracking cookies for advertising.
11. Changes to this policy
If we make important changes, we will let you know by email at least 14 days before they take effect. Continued use after that date means you accept the updated policy.
12. Contact
Questions about your data? Write to hello@saveat.lu or to SavEat, Luxembourg. For any other questions, see our Terms & Conditions.
Have a question? Write to hello@saveat.lu
We're happy to help — with data matters and more.