Privacy Policy
Last updated: 19 April 2026 · Applies to bobbosburger.be
1. Who We Are
BobbosBurger ("we", "us") is the data controller for personal data collected through this website and our ordering system. Contact us at hello@bobbosburger.be.
2. Data We Collect
- Account data: name, email address, phone number, hashed password.
- Order data: items ordered, order type, total amount, timestamps.
- Loyalty data: points balance and transaction log.
- Consent data: timestamp, IP address, and user agent recorded when you agree to this policy.
- Technical data: IP address, browser type (collected automatically via server logs).
3. Legal Basis for Processing
- Contract performance (Art. 6(1)(b) GDPR): processing your order and managing your account.
- Legitimate interests (Art. 6(1)(f) GDPR): fraud prevention, security, and service improvement.
- Consent (Art. 6(1)(a) GDPR): the loyalty programme and any marketing communications.
- Legal obligation (Art. 6(1)(c) GDPR): tax and accounting records.
4. Data Retention
| Data type | Retention period |
|---|---|
| Account data | Until account deleted or 3 years inactive |
| Order data | 7 years (Belgian tax law) |
| Loyalty log | 3 years |
| Server logs | 90 days |
5. Your Rights
Under GDPR you have the right to: access · rectification · erasure · restriction · portability · object · withdraw consent.
Exercise your rights via your account privacy panel or by emailing hello@bobbosburger.be. We respond within 30 days.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).
6. Data Sharing
We do not sell your data. We share data only with:
- Hostinger — cloud hosting (EU data centres).
- Stripe — Secure payment gateway for processing your transactions.
7. Cookies
We use a strictly necessary session cookie to maintain your login. See our Cookie Policy for details.
8. Changes to This Policy
We may update this policy. Material changes will be communicated via email or a notice on this page.