Privacy Policy

Last updated: 2026-06-10

1. Information We Collect

We collect information you provide directly (name, email, phone, business details) and information generated by your use of the platform (order data, delivery addresses, menu content, store configuration). We also record technical data — your IP address and browser/device information — when you give or withdraw consent (kept as proof of consent) and when administrators perform sensitive actions such as refunds (for security and audit). For order data processed for an individual store, the store is the data controller and Orderoo acts as its processor; for your platform-wide Orderoo account (login, saved cards, saved addresses and communication preferences), Orderoo is the data controller. If you are a prospective partner whose contact details we collected for sales outreach, we process them on a legitimate-interest basis (B2B prospecting) and you may object at any time. The service is not directed at children under 15 (the digital-consent age in Greece, Law 4624/2019).

2. How We Use Your Information

We use the information to provide and improve the Orderoo platform, process payments, send service-related communications, and comply with legal obligations. We do not sell your data or your customers' data to third parties. Our lawful bases are: performance of a contract (orders, account, billing); consent (marketing emails and any non-essential cookies); legitimate interest (transactional notices, fraud prevention, security); and legal obligation (tax and accounting retention). Marketing emails are sent only with your prior opt-in consent and every message includes a one-click unsubscribe; transactional order and receipt emails are sent on the contract basis.

3. Data Storage and Security

Data is stored on Supabase (PostgreSQL) hosted in the EU (Frankfurt, Germany). We apply industry-standard encryption in transit (TLS) and at rest. Database access is restricted to authorised personnel; images you upload (for example chat photos) are served via unguessable public links and are deleted within 24 hours of the related chat closing. Card payments are handled end-to-end by Stripe: Orderoo never receives or stores your full card number, security code or magnetic-stripe data — only a payment token and the last four digits ever reach our systems.

4. Third-Party Services

The platform relies on the following service providers (processors), each operating under its own privacy terms and GDPR safeguards: Stripe (payment processing — name, email, payment data); Resend (transactional email — order details, delivery addresses); Google (OAuth sign-in, and Google Maps for address search and geocoding); Supabase (database and file storage, hosted in the EU / Frankfurt); Vercel (hosting and privacy-friendly, cookieless web analytics); Upstash (short-lived order and rate-limit caching); Anthropic (an internal AI assistant used only for prospect/sales data, never end-customer order data); and browser push services (Google, Apple, Mozilla) when you enable notifications. Some providers are located in the United States; such transfers rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses (2021/914).

5. Cookies

We use strictly necessary cookies for authentication and CSRF protection, plus Vercel Web Analytics — a cookieless, aggregated analytics service that sets no cookies, does not identify you individually, and does not track you across other websites. No advertising or cross-site tracking cookies are used by Orderoo. For full details see our Cookie Policy.

6. Your Rights (GDPR)

If you are in the EEA you have the right to access, correct, delete, or restrict processing of your personal data, to data portability, to object to processing based on legitimate interests (Article 21), and to withdraw consent at any time without affecting processing already carried out. You can download your data and delete your account from your account settings, or contact us at privacy@orderoo.gr; we respond within one month. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα — www.dpa.gr, Κηφισίας 1-3, 115 23 Αθήνα).

7. Data Retention

We retain personal data by category: your account and profile data until you delete your account; order records for at least 5 years as required by Greek tax law (ΚΦΔ); records proving your consent choices (including the IP address and browser identifier captured at the moment of consent) for up to 5 years as evidence of compliance; chat messages until 24 hours after the conversation closes; push-notification subscriptions until you disable them or delete your account; and invoices for 5 years for tax purposes. When you delete your account we anonymise or remove your personal data, keeping only what tax law requires. If you are a merchant winding down your store or ending your subscription, export your sales and order history first — retaining your own fiscal records is your responsibility, and once your data is deleted we hold on to only what Greek tax law obliges us to keep.

8. Tax and Fiscal Responsibility

Orderoo is an ordering and point-of-sale platform, not an accounting, invoicing or tax-reporting service. We do not transmit your sales to AADE myDATA, issue statutory fiscal documents on your behalf, or file anything with the tax authorities for you. Your order and sales records are always yours to export, but reporting them correctly and meeting your own tax, myDATA and accounting obligations remains the responsibility of you, the merchant.

9. Contact & Data Controller

Data controller: Δημήτριος Χρηστάκης (Hexaigon Solutions), ΑΦΜ 167755989, Λεωφόρος Κυπρίων Ηρώων 3, 163 41 Ηλιούπολη, Αθήνα. Contact: privacy@orderoo.gr