Back to Home

Privacy & Cookie Policy

Last Updated: July 2026 | UK GDPR & EU GDPR Compliant

1. Introduction & Overview

FoodTakeaway.co.uk ("we", "our", "us") is committed to protecting your privacy and fulfilling our obligations under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).

This policy explains how we collect, use, store, and protect your personal data when you use our online food ordering platform, browse restaurant menus, place takeaway orders, or interact with our native mobile applications.

2. Legal Bases for Processing Data

Under GDPR, we rely on the following legal bases to process your personal information:

Contractual Performance

Processing necessary to fulfill your food order, process payments, and communicate order updates.

Consent

Obtained for optional cookies, marketing push notifications, and promotional emails.

Legitimate Interests

Fraud prevention, platform security audit logging, and improving user experience.

Legal Obligation

Retention of transactional tax and accounting records as mandated by applicable laws.

3. Information We Collect

  • Customer Details: Name, email address, phone number, and delivery address provided during checkout or registration.
  • Order Details: Items ordered, customization addons, delivery options (`delivery`, `pickup`, `dine-in`), table numbers, and payment status.
  • Verification Data: 6-digit email verification codes used for guest checkout verification.
  • Technical & Forensics Data: IP address, device type, browser user agent, and timestamp logged during order submission for fraud prevention.
  • Restaurant Partner Data: Business owner names, contact info, banking details, and store configuration settings.

4. Cookies & Tracking Technologies

We use small text files called cookies to ensure essential site operations, maintain your cart session, and provide a seamless ordering experience. Below is a transparent breakdown of all cookies set by our platform:

Cookie NameCategoryPurposeDuration
__sessionEssentialFirebase authentication session state for logged-in accounts.14 Days
ft_cart_idEssentialPersists anonymous shopping cart session across refreshes.7 Days
ft_store_idEssentialStores current restaurant context in multi-store ordering.30 Days
ft_table_noEssentialRemembers table number for instant dine-in QR code ordering.24 Hours
ft_fulfillment_modeFunctionalRemembers selected preference (`delivery`, `pickup`, `dine-in`).30 Days
ft_postcodeFunctionalSaves postal code for fast delivery eligibility verification.30 Days
ft_utm_sourceAttributionTracks referral sources (e.g. table QR codes, marketing campaigns).14 Days
ft_cookie_consentConsentStores your privacy banner consent choice (`accepted`/`declined`).1 Year

All essential and functional cookies are configured with `SameSite=Lax` and `Secure` attributes.

5. Third-Party Sub-Processors

We share personal data strictly with authorized third-party service providers essential to operating our service:

Stripe: Processes payment transactions securely. We do not store credit card details on our servers.

Google Cloud / Firebase: Hosts database services, user authentication, FCM push notifications, and hosting infrastructure.

Google Maps API: Used for address geocoding and interactive delivery area verification.

Nodemailer & SMTP Services: Delivers guest email verification codes and order confirmation receipts.

6. Data Security & Retention

  • Security: All communication between your browser and our platform is encrypted via SSL/TLS (HTTPS). Firestore database access is governed by strict security rules.
  • Order History Retention: Customer order history is maintained in active databases to enable past order history viewing and re-ordering.
  • Verification Data Expiration: Email verification codes and temporary tokens expire automatically within 15 minutes.

7. Your Rights Under GDPR

Under UK GDPR and EU GDPR, you have the following rights regarding your personal data:

Right of Access: Request a copy of all personal data held about you.
Right to Erasure: Request the deletion of your account and personal data ("Right to be Forgotten").
Right to Rectification: Request correction of incorrect or incomplete information.
Right to Object: Object to processing based on legitimate interests or direct marketing.

Contact Our Privacy Team

To exercise your GDPR data rights or submit a Data Subject Access Request (DSAR), please email us at privacy@foodtakeaway.co.uk.

© 2026 FoodTakeaway.co.uk. Committed to data privacy and security.