privacy policy
last updated: 11.06.2026
bagel bagel V.O.F. ("bagel bagel", "we", "us", "our") takes the protection of your personal data seriously. we process personal data in accordance with the General Data Protection Regulation (GDPR / AVG) and other applicable Dutch privacy legislation. this privacy policy explains what personal data we collect, on what legal basis, how we use it, who we share it with, and what your rights are.
by using our website or placing an order, you acknowledge that you have read and understood this privacy policy.
1. who are we?
bagel bagel V.O.F. is the data controller responsible for the processing of your personal data.
registered address: Zwaanshals 430, 3035 KT Rotterdam, the Netherlands
chamber of commerce (KvK): 92927033
VAT number: NL866219511B01
contact: [email protected]
for any questions or requests regarding your personal data, you can reach us at the email address above.
2. what personal data do we collect?
we collect and process personal data only when necessary. the specific data depends on how you interact with us:
a) catering orders
- name, email address, phone number (optional)
- company name and delivery address (if applicable)
- order contents, order history, and payment information
- payment details are processed directly by our payment provider Stripe — we never store your card number, expiry date, or CVC on our own servers
b) orders via delivery platforms
- when you order through platforms such as Uber Eats, we receive your name, delivery address, and order contents in order to prepare your order
- these orders are also subject to the delivery platform's own privacy policy
c) website visitors
- anonymised usage data via Google Analytics and Microsoft Clarity (see section 10 on cookies)
- Google Analytics is configured with IP anonymisation enabled. Microsoft Clarity records anonymised session activity (such as pages viewed, clicks, scrolling, and mouse movement) to build heatmaps and session replays, with text inputs and personal data masked
d) contact & communication
- name and email address when you contact us via [email protected]
- contents of your messages
3. on what legal basis do we process your data?
under the GDPR, we must have a valid legal basis for each processing activity. we rely on the following:
- performance of a contract (art. 6(1)(b) GDPR): processing your catering order, payment, delivery, and invoicing — this data is necessary to fulfil the agreement between you and bagel bagel
- consent (art. 6(1)(a) GDPR): sending you marketing emails and placing non-essential cookies. you can withdraw your consent at any time
- legitimate interest (art. 6(1)(f) GDPR): operating and securing our website and improving our services. we have assessed that these interests do not override your privacy rights
- legal obligation (art. 6(1)(c) GDPR): retaining order and financial records as required by Dutch tax law (Algemene wet inzake rijksbelastingen)
4. how do we use your data?
we use your personal data for the following purposes:
- processing, confirming, and delivering catering orders
- sending order confirmations, invoices, and delivery reminders
- receiving and preparing orders placed through delivery platforms
- responding to your questions or requests
- analysing anonymised website usage to improve our services
- sending promotional emails — only with your explicit consent
- complying with legal and tax obligations
5. how long do we keep your data?
we do not keep your data longer than necessary. the retention periods below apply:
- order & payment data: 7 years after the order date (required under Dutch tax law)
- invoices & financial records: 7 years (required under Dutch tax law)
- email communication: up to 2 years after our last correspondence
- marketing consent records: until you withdraw consent, plus 1 year for accountability purposes
- promotion entries: up to 12 months after the promotion ends, then deleted
- anonymised analytics data: 14 months (Google Analytics default)
6. third parties & data processors
we never sell, rent, or trade your personal data to third parties. we only share data with trusted service providers (processors) who are strictly necessary to deliver our services. these processors act on our instructions and are contractually bound to protect your data.
payment & invoicing
- Stripe — processes card payments and iDEAL transactions. Stripe is certified PCI-DSS Level 1 and acts as an independent data controller for payment data. privacy policy
- Moneybird — generates and sends invoices for business catering orders. privacy policy
hosting & infrastructure
- Vercel — hosts our website and serves web pages. privacy policy
- Supabase — database hosting and data storage. our database is hosted in the EU (Frankfurt, Germany). privacy policy
communication
- Resend — delivers transactional emails (order confirmations). privacy policy
analytics
- Google Analytics — collects anonymised website usage statistics. IP anonymisation is enabled. no personal data is shared with Google for advertising purposes. privacy policy
- Microsoft Clarity — provides anonymised heatmaps and session replays so we can see how visitors use the site. Clarity automatically masks text inputs and personal data, and we load it only after you accept analytics cookies. Microsoft (the processor) may process this data in the United States. privacy policy
delivery platforms
- Uber Eats — delivery order platform. orders placed via Uber Eats are subject to both our and Uber's privacy policy. Uber acts as an independent data controller for customer data on their platform. privacy policy
7. international data transfers
some of our processors are based in the United States (Stripe, Vercel, Resend, Google, Microsoft, Apple). when personal data is transferred outside the European Economic Area (EEA), we ensure adequate protection through one or more of the following safeguards:
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- the EU-US Data Privacy Framework, where the processor is certified (for example Microsoft and Google)
- the processor's participation in recognised certification frameworks
- an adequacy decision by the European Commission (where applicable)
our primary database is hosted within the EU (Supabase, Frankfurt, Germany).
8. how do we protect your data?
we take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. these measures include:
- encrypted connections (HTTPS/TLS) for all data in transit
- encrypted database storage at rest
- secure password hashing (bcrypt) — we never store passwords in plain text
- role-based access control for employee accounts
- rate limiting and account lockout on login to prevent brute-force attacks
- regular security updates and monitoring
9. your rights under the GDPR
as a data subject, you have the following rights under the GDPR. you can exercise any of these rights free of charge by emailing [email protected].
- right of access (art. 15): request a copy of the personal data we hold about you
- right to rectification (art. 16): request correction of inaccurate or incomplete data
- right to erasure (art. 17): request deletion of your personal data ("right to be forgotten"), unless we are legally required to retain it
- right to restriction (art. 18): request that we temporarily stop processing your data while a dispute is resolved
- right to data portability (art. 20): receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV)
- right to object (art. 21): object to processing based on legitimate interest, including profiling
- right to withdraw consent (art. 7): withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal
we will respond to your request within 30 days. in exceptional cases, we may extend this by a further 60 days, in which case we will inform you of the reason for the delay.
to verify your identity, we may ask you to confirm your request from the email address associated with your account.
10. cookies & analytics
our website uses a limited number of cookies:
- essential cookies: session cookies required for login functionality and the shopping cart. these do not require consent as they are strictly necessary for the service to work
- analytics cookies (Google Analytics): only loaded if you accept them via our cookie banner. when active, Google Analytics collects anonymised statistics about website visits (pages viewed, time on site, device type) with IP anonymisation enabled. cookies used:
_ga,_ga_61TMEM2MD6. retention: 14 months - analytics cookies (Microsoft Clarity): only loaded if you accept them via our cookie banner. when active, Clarity records anonymised session replays and heatmaps (pages viewed, clicks, scrolling, mouse movement) to help us improve the site. text you type and personal data are masked and not recorded. cookies used:
_clck,_clsk. session data is processed by Microsoft and may be transferred to the United States under EU Standard Contractual Clauses and the EU-US Data Privacy Framework
on your first visit you will see a cookie banner offering an equally prominent "accept" and "reject" choice. we only place analytics cookies after you click accept. you can change your mind at any time by clicking "cookies" in the footer, which reopens the banner. rejecting analytics also clears any existing analytics cookies from this site.
we do not use marketing cookies, retargeting pixels, or third-party advertising trackers.
11. automated decision-making
we do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you (as described in art. 22 GDPR). we do carry out limited, non-significant profiling of loyalty members for analytics and menu improvement. this is described in full in the "loyalty insights & customer profiling" section, it never makes automated decisions about you, and you can object to it at any time. our rewards programme fraud detection system flags potentially suspicious activity for human review but does not automatically make decisions about your account.
12. children's data
our services are not directed at children under the age of 16. we do not knowingly collect personal data from children under 16. if you believe a child has provided us with personal data, please contact us at [email protected] and we will delete it promptly.
13. promotions & marketing
on our website we occasionally run interactive promotions (such as games or contests). to participate, we ask for your first name and email address. this data is used to:
- identify participants and award prizes
- send promotional emails about bagel bagel — only if you explicitly tick the marketing consent checkbox
the marketing consent checkbox is never pre-checked. you can withdraw your consent at any time by emailing [email protected] or by clicking the unsubscribe link in any marketing email.
data retention: promotion entries are kept for up to 12 months after the promotion ends, then deleted. if you opted in to marketing, your name and email are kept until you unsubscribe.
14. complaints
we hope to resolve any concerns directly. if you are not satisfied with our response, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
Autoriteit Persoonsgegevens
Bezuidenhoutseweg 30, 2594 AV Den Haag
autoriteitpersoonsgegevens.nl
telephone: +31 (0)70 888 8500
15. loyalty insights & customer profiling
as part of our rewards (loyalty) programme, we link the purchases you make in our shop to your loyalty profile so we can understand what our customers enjoy and improve what we offer. this section explains exactly what that involves, because it is a form of profiling under the GDPR and we want to be transparent about it.
what we combine
- your loyalty profile information that you gave us when you signed up: your name, email, and, where you provided them, your date of birth and your postcode/city
- your in-store purchase history: the items on the receipts from purchases you made while using your loyalty card. these are matched to your loyalty account using the time of the purchase and the till (cashier) it was rung up on, so that the right receipt is linked to the right member
- from your date of birth we derive an age group (for example "25–34"), and from your postcode we derive an area. we do this so we can analyse trends across groups rather than singling you out
why we do this (purpose)
- to understand which products and which age groups buy what, so we can improve our menu and assortment, reduce waste, and stock the things our customers actually want
- to make our rewards programme and any offers more relevant to you
- to produce aggregated, internal business analytics about our customers as a whole
we do not use this profiling to make automated decisions that have legal effects or similarly significantly affect you (see the "automated decision-making" section). it never affects the stamps or rewards you are entitled to. it informs our business and menu decisions only.
legal basis
we rely on two legal bases for this processing:
- your consent (art. 6(1)(a) GDPR), which you give when you join the loyalty programme and agree to us using your purchase and profile data for these insights. you can withdraw this consent at any time (see "your choices and rights" below), and withdrawing it does not affect the lawfulness of anything we did before you withdrew it
- our legitimate interest (art. 6(1)(f) GDPR) in understanding our customers and improving our products and service. we have weighed this interest against your privacy rights and limited the processing to what is necessary (we keep the analysis internal, we work with age groups and areas rather than pinpointing individuals wherever we can, and we never sell this data)
we do not use special categories of personal data for this profiling, and we do not link it to any third-party advertising profiles.
how long we keep it
- linked purchase history tied to your loyalty profile: kept for as long as your loyalty account is active, and deleted within 24 months of your account becoming inactive or of you withdrawing consent / closing your account, whichever comes first
- the underlying receipt and financial records are kept separately for 7 years as required by dutch tax law, but those are not part of your loyalty profile
- aggregated insights that no longer identify you (for example "customers aged 25–34 prefer X") may be kept indefinitely, because they are no longer personal data
your choices and rights
this profiling is entirely optional and you stay in control:
- right to object (art. 21 GDPR): you can object to us linking your purchases to your profile for analytics at any time, and we will stop. you keep your loyalty card and your rewards either way
- right to withdraw consent (art. 7 GDPR): you can withdraw your consent at any time
- right of access (art. 15 GDPR): you can ask for a copy of the purchase and profile data we hold about you
- right to erasure (art. 17 GDPR): you can ask us to delete the purchase history linked to your loyalty profile (subject to records we must keep by law)
- you can also simply not give us your date of birth or postcode, or remove them from your profile, if you'd rather we didn't derive age group or area
to exercise any of these, email us at [email protected]. we respond within 30 days, as described in the "your rights under the GDPR" section.
16. changes to this policy
we may update this privacy policy from time to time to reflect changes in our services, legal requirements, or data practices. when we make material changes, we will update the "last updated" date at the top of this page. the latest version is always available at bagelbagel.nl/privacy.
we encourage you to review this page periodically.