Privacy Policy
Last updated: March 31, 2026
1. Data Controller
The data controller is sardegna.delivery, based in Olbia (SS), Sardinia, Italy. For any privacy-related requests, contact us at: privacy@sardegna.delivery.
2. Data We Collect
We collect the following categories of personal data:
- Identity data: name, surname, email address, phone number
- Delivery data: delivery address, geographic coordinates (for zone verification)
- Payment data: payments are processed through Stripe. We do not store full credit card details on our servers
- Business data: for B2B clients — company name, VAT number, PEC, SDI code
- Usage data: access logs, food preferences, order history
- Allergy data: allergies and food intolerances reported by the user
3. Purposes of Processing
Personal data is processed for the following purposes:
- Account management and authentication
- Order processing and delivery
- Subscription and payment management
- Service communications (order confirmations, reminders, delivery notifications)
- Electronic invoicing (for B2B clients)
- Service improvement and aggregate analytics
- Compliance with legal and tax obligations
4. Legal Basis
Data processing is based on:
- Contract performance: to provide the meal delivery service
- Consent: for marketing communications and non-essential cookies
- Legal obligation: for tax compliance and invoicing
- Legitimate interest: for service security and fraud prevention
5. Data Sharing
Personal data may be shared with:
- Stripe: for payment processing
- Google Cloud Platform: for hosting and infrastructure
- Firebase (Google): for authentication
- Mailgun: for transactional emails (EU servers)
- Couriers: limited to data necessary for delivery (name, address, phone)
We do not sell personal data to third parties.
6. Data Retention
Personal data is retained for the duration of the contractual relationship and subsequently for the period required by Italian tax law (10 years for invoicing data). Account data can be deleted upon request, subject to legal retention requirements.
7. Your Rights
Under the GDPR (EU Regulation 2016/679), you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request data deletion
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent at any time
To exercise your rights, contact us at privacy@sardegna.delivery.
8. Cookies
For information on the cookies we use, please see our Cookie Policy.
9. Security
We implement appropriate technical and organizational measures to protect personal data, including TLS encryption, role-based access control, and two-factor authentication for administrators.
10. Changes
We reserve the right to update this policy. Changes will be published on this page with the update date.
11. Contact and Complaints
For any questions or complaints, contact us at privacy@sardegna.delivery. You also have the right to file a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).