Privacy Statement for Partner Businesses
Last updated: 8 August 2026
This statement describes the personal data we process when a food business registers as a foodfyp partner and offers its dishes through the feed: data about the business and about the contact person who manages the partner account.
This statement does not apply to guests who order through the foodfyp app. Which data about guests a partner receives from us, and what it may use them for, is governed by § 13 of the Terms and Conditions for Partner Businesses.
Where this statement says "you", it means the person whose data we process — the business's contact person and, in the case of sole traders and partnerships, the owner. Information about a business is personal data as soon as it can be attributed to a particular person; with a sole trader that is the rule.
1. Controller
The controller for the processing described here, within the meaning of Article 4(7) GDPR, is foodfyp UG (haftungsbeschränkt), Gänsestieg 27A, 22549 Hamburg, Deutschland, represented by Alexander Frikel.
Address questions about data protection and the exercise of your rights to datenschutz@foodfyp.com. No particular form is required, and it costs you nothing.
We have not appointed a data protection officer. There is therefore no other point of contact within foodfyp you could turn to instead; your request is handled by the management at the address given above. Your right to approach the supervisory authority named in section 14 directly is unaffected by this.
2. Registration and pre-contractual steps
When you register your business, we process the information you enter in the signup form:
We send a confirmation code to the email address you provide. We process that code and the time it is entered in order to establish that the address is reachable and available to you; only then is the registration deemed submitted.
The purpose of this processing is to prepare the partner contract: reviewing the registration, creating the partner account, assigning the location to an address, and communicating with you during onboarding.
The legal basis is Article 6(1)(b) GDPR. The processing is necessary for steps taken at your request prior to entering into the contract and, subsequently, for the performance of that contract.
For entering the address, the form offers an address search. While you type, your browser sends the text you enter directly to the Photon service operated by komoot GmbH in order to suggest matching addresses; your IP address is transmitted to that service in the process. The text therefore leaves your browser before you submit the form. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in a correct and complete address, because a wrong address means orders will not reach your business. You can avoid the search: the form provides a switch that lets you enter street, house number, postal code and city by hand — no transmission to that service takes place then.
None of this information is a statutory requirement. The legal form is optional; the remaining information is necessary for the contract, and without it we cannot create a partner account and cannot forward any orders to your location.
- Business name
- Legal form (optional)
- Street
- House number
- Postal code
- City
- Name of the contact person
- Email address
- Telephone number
- Password
3. Verification and statutory obligations
Before we activate a partner account, we check that the business actually exists and that the trade-law and food-law requirements for selling food to guests are met. For that purpose we process, during the further onboarding, the trade licence, the hygiene certificate, the tax number and, for registered legal forms, the commercial register number.
The purpose of this admission check is twofold: guests should only be able to order from businesses permitted to sell to them, and we need to know with whom we are concluding a contract and to whom we are disbursing payments. To that extent the legal basis is Article 6(1)(b) GDPR, because the check precedes the conclusion of the contract and no location is activated without it.
We additionally process the tax number and the commercial register number in order to meet our own obligations under commercial and tax law — in particular the proper settlement of the commission and the retention of the associated records. The legal basis for that is Article 6(1)(c) GDPR in conjunction with the provisions of the German Commercial Code and the German Fiscal Code.
Nothing separate applies to the evidence submitted: we erase it once the purpose has ceased to apply and no statutory retention obligation stands in the way. What that means is set out in section 12.
4. Payment processing and identity verification
Guests' payments are processed via Stripe. For that purpose a payment account is set up for your business with Stripe Payments Europe, Ltd., and we transmit to Stripe the information required to set that account up. For as long as the account is not activated, a location cannot be made available for ordering.
For payment processing and for identity verification, Stripe is a controller in its own right and not our processor. Stripe collects the information required for that under its own privacy statement. We do not co-determine that processing.
What we receive back is in particular the status of the payment account: whether it has been set up and activated and whether payouts are possible.
The legal basis for that transmission and for the further processing that arises on our side in connection with payment handling is Article 6(1)(b) GDPR, because collecting the guest's payment and paying it out to you are part of the partner contract. To the extent that identity verification serves statutory obligations to be met when handling payments, the legal basis is Article 6(1)(c) GDPR.
5. Order and transaction data
Once your location is available for ordering, data arise in day-to-day operation: the orders forwarded, with the time, the contents of the order and the goods value; the fulfilment route chosen; the acceptance or rejection of an order and the completion time stated with it; refunds and chargebacks; and the commission calculated from all of this together with the statements in the portal.
These data describe the business in the first instance. They are personal data to the extent that they can be attributed to a particular person — with a sole trader, to the owner; otherwise to the person who processed an order in the portal.
The purpose is the performance of the contract: forwarding orders to your location, settling the commission, paying out through the payment account and handling objections to a statement. The legal basis is Article 6(1)(b) GDPR.
Orders and statements are also accounting records. How long we have to retain them for that reason is set out in section 12.
6. Support and communication
When you contact us — through the portal, by email or by telephone — we process your name, the contact details you use, the contents of the correspondence and the course of the matter until it is resolved.
Where your request concerns the contract or its performance — a question about a statement, a disruption in the portal, a complaint under § 18 of the Terms and Conditions — the legal basis is Article 6(1)(b) GDPR.
Where it does not, for example a general question asked before registration, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to answer enquiries addressed to us and to keep a record of what we have promised; your countervailing interest weighs less heavily here because you determine the content of the message yourself.
You may object under Article 21 GDPR to processing we base on a legitimate interest. We will then no longer process the correspondence unless we can demonstrate compelling legitimate grounds, or unless it serves the establishment or defence of legal claims.
7. Information and surveys
Messages concerning the performance of the contract — statements, order notifications, notices of disruptions and announcements of changes — you receive because they are part of the contract. The legal basis for those is Article 6(1)(b) GDPR.
Information going beyond that — developments at foodfyp that are of interest to partner businesses — and invitations to take part in surveys about our cooperation reach you only if you have consented beforehand. The legal basis is then Article 6(1)(a) GDPR.
That consent is obtained separately; the signup form does not ask for it. It is voluntary: whether you give it has no effect on the contract, on the commission or on the visibility of your location in the feed.
You may withdraw your consent at any time. An informal message to datenschutz@foodfyp.com is sufficient; no reasons are needed and no disadvantage arises for you. The withdrawal takes effect for the future — the lawfulness of processing carried out until then is unaffected (Article 7(3) GDPR).
8. Audience measurement
On this website we use PostHog to measure how it is used: which pages are opened, how a visit came about, which controls are used, and the technical characteristics of the device and browser. We evaluate this in order to understand which content is found and where a visit breaks off.
This only happens if you have agreed in the consent banner. Without your agreement PostHog is not loaded and no measurement data are collected — not in anonymised form either.
The legal basis is Article 6(1)(a) GDPR; for storing information on your device and accessing it, it is consent under Section 25(1) of the German Digital Services Data Protection Act (TDDDG).
We store your decision from the banner locally in your browser so that we do not have to ask again on every visit. You may withdraw your consent at any time, and as easily as you gave it: through "Cookie settings" in the footer of every page. The withdrawal stops the measurement immediately — without your having to reload the page — and removes the measurement's entries from your browser. It takes effect for the future; the lawfulness of processing carried out until then is unaffected (Article 7(3) GDPR). A message to datenschutz@foodfyp.com is equally sufficient.
9. Publication in the feed
The purpose of the contract is to show your business to guests. Visible to guests are therefore the business name, the address of the location, the opening hours, the fulfilment route chosen — pickup, self-delivery or both, and for self-delivery the delivery area — the menu with prices and the information about the dishes, and the videos and images that show the location in the feed.
The legal basis is Article 6(1)(b) GDPR: without this publication no guest can find the offering and no order can come about.
The credentials for the partner account and the contact details of the contact person — name, email address and telephone number — are not among the published information.
One note that matters for sole traders and small businesses: the address of the location is published, because guests either collect there or need to know where delivery starts from. So enter the address at which the business is operated, and not a private home address — not even if you work from there. We can remove a published address from the feed, but we cannot retrieve it from copies third parties have made in the meantime.
10. Recipients
We pass on your data only where that is necessary for the purposes described or where we are obliged to do so. Service providers processing on our behalf are bound by contract under Article 28 GDPR.
| Recipient | Purpose |
|---|---|
| Amazon Web Services (Frankfurt) | Operation of the application and storage of the data |
| Stripe Payments Europe, Ltd. | Payment processing, payouts and identity verification |
| Email delivery service provider | Delivery of confirmation and system messages |
| PostHog | Audience measurement, only where consent has been given |
| komoot GmbH (Photon) | Address suggestions while typing in the signup form; omitted if you enter the address by hand |
| Tax advisors and auditors | Compliance with obligations under commercial and tax law |
| Authorities and courts | only on a statutory basis or by court order |
11. Transfers to third countries
Our application runs on Amazon Web Services in Frankfurt am Main; the data stored there are therefore held within the European Union.
With Stripe and with PostHog, processing outside the European Union and the European Economic Area cannot be ruled out, in particular in the United States of America: Stripe belongs to a corporate group based there, and with PostHog it is PostHog, Inc., based in San Francisco, that is itself the provider and our contracting party, and not a European company.
To the extent that personal data thereby reach a third country, we base the transfer on the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023), where the recipient in question is certified, and/or on the European Commission's standard contractual clauses under Article 46(2)(c) GDPR.
We will inform you about the safeguards a transfer is based on and provide you with a copy of them. A message to datenschutz@foodfyp.com is sufficient.
12. Retention periods
We retain data for as long as we need them for the purpose for which we collected them, and beyond that for as long as the law obliges us to. We do not set any period going beyond that.
We process the data of the partner account — the master data of the business, the contact person, the credentials — for the term of the contract. When the contract ends we erase them, unless a retention obligation stands in the way.
Documents we have to retain for commercial and tax purposes — orders, statements, invoices, and submitted evidence where it forms part of them — are subject to the statutory retention periods of German commercial and tax law under Section 257 of the German Commercial Code and Section 147 of the German Fiscal Code. Depending on the type of document these run from six to ten years, each beginning at the end of the calendar year in which the document came into existence. During that time processing is limited to fulfilling the retention obligation.
Data we base on your consent — sections 7 and 8 — are processed until you withdraw it and erased thereafter, unless a retention obligation stands in the way.
We retain support correspondence for as long as the matter is ongoing, and beyond that only where it falls under the retention obligations of the preceding paragraph or where we need it to establish or defend legal claims; the periods stated there, or the statutory limitation periods, then apply.
13. Your rights
You have the following rights. You exercise them by writing to us at datenschutz@foodfyp.com; no particular form is required. We respond within the period set by Article 12(3) GDPR, that is, as a rule, within one month.
If the request does not allow us to identify you as the data subject with certainty, we ask before providing information. That is not an obstacle but the protection that keeps someone else from obtaining information about you.
- Access under Article 15 GDPR: we tell you whether and which data about you we process, for which purposes, to which recipients and for how long, and we provide you with a copy.
- Rectification under Article 16 GDPR: we correct inaccurate data and complete incomplete data.
- Erasure under Article 17 GDPR: we erase your data once the purpose has ceased to apply, once you have withdrawn consent, or where the processing was unlawful — unless a statutory retention obligation under section 12 stands in the way.
- Restriction of processing under Article 18 GDPR: where it is disputed between us whether data are accurate or may be processed, we process them only in a restricted manner for the duration of the review instead of erasing them.
- Data portability under Article 20 GDPR: data you have provided to us which we base on consent or on the contract and process by automated means are released to you in a structured, commonly used and machine-readable format, or transmitted directly to another controller at your request.
- Objection under Article 21 GDPR: you may object at any time, on grounds relating to your particular situation, to processing we base on a legitimate interest — which concerns the correspondence under section 6.
- Withdrawal of consent under Article 7(3) GDPR: you may withdraw consent given at any time with effect for the future; the lawfulness of processing carried out until then is unaffected.
14. Right to lodge a complaint
You may lodge a complaint about the processing of your data with a supervisory authority, Article 77 GDPR. The competent authority is the one of your habitual residence, of your place of work or of the place of the alleged infringement.
The authority competent for us is Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg. It can be reached online at https://datenschutz-hamburg.de.
A complaint does not require you to have contacted us first. It is usually the shorter route nonetheless, and your right to an effective judicial remedy remains available alongside it.
15. Security
The connection between your device and our servers is encrypted with TLS. What you enter in the signup form or in the portal is therefore not transmitted across the network in the clear.
Within foodfyp, access to partner data is given only to those who need it for their task, and only to the extent that task requires. Service providers processing on our behalf are bound under Article 28 GDPR.
We take these measures under Article 32 GDPR and adjust them when the technology, the processing or the risks change. Nobody who transmits data over the internet can promise seamless protection; we therefore state what we do, rather than what cannot happen while we do it.
16. Changes to this statement
We amend this statement when the processing changes — for instance because a function is added, a service provider changes, or the legal position or the practice of the supervisory authorities changes. The version published here applies in each case; its date is stated above.
An amendment concerning processing you have arranged yourself around — a new recipient, a new purpose, a new legal basis — is announced to the email address stored in your partner account before it takes effect.
Where processing is based on your consent, we do not amend this statement in order to widen the purpose: for a new purpose we obtain fresh consent.