Back to home
Legal document, GDPR

Privacy Policy

Last updated:

Mealio SAS (hereinafter “Mealio”, “we” or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, share and protect your personal data when you use the Mealio platform, in accordance with the General Data Protection Regulation (GDPR, Règlement UE 2016/679) and French law n° 78-17 of January 6, 1978 on information technology, data files and civil liberties.

1. Data controller

The controller of your personal data is:

Mealio SAS

42 Rue de la Tech, 75011 Paris, France

SIRET: 123 456 789 00012

Email: contact@mealio.fr

Phone: +33 1 23 45 67 89

2. Personal data collected

We collect different categories of data depending on your profile and your use of the Platform.

2.1 Data you provide directly

  • Identity information: last name, first name, date of birth;
  • Contact details: email address, phone number, billing address;
  • Account information: login credentials (email, hashed password);
  • Payment information: bank card data tokenized by Stripe (we never store raw card data);
  • Dietary preferences and allergens provided voluntarily;
  • For restaurant owners: establishment information (name, address, SIRET number, bank details for transfers, menu photos).

2.2 Data collected automatically

  • Browsing data: IP address, browser and device type, operating system;
  • Geolocation data (with your consent) to suggest nearby restaurants;
  • Log data: connection logs, pages visited, time spent on pages;
  • Transaction data: order history, amounts, payment methods used;
  • Data from cookies and trackers (see our Cookie Policy).

2.3 Data from third parties

If you register via a third-party service (Google, Apple, Facebook), we may receive certain public profile information in accordance with your privacy settings on those services. We only collect the data strictly necessary to identify you.

3. Purposes of processing and legal bases

We process your personal data for the following purposes:

Creating and managing your account

Performance of the contract

Recording your information, authentication and managing your preferences.

Processing orders and payments

Performance of the contract

Receiving, processing, invoicing and tracking your orders; fraud prevention.

Order tracking

Performance of the contract

Real-time tracking of your order preparation and related notifications.

Customer service and complaints

Performance of the contract / Legitimate interest

Handling your requests, refunds and complaints.

Improving the Platform

Legitimate interest

Statistical analysis of Platform usage to improve our services.

Marketing communications

Consent

Sending newsletters, promotional offers, Mealio news (unsubscribe at any time).

Legal and accounting obligations

Legal obligation

Retention of billing data, tax and legal compliance.

Fraud prevention and security

Legitimate interest / Legal obligation

Detecting fraud attempts, protecting users and the Platform.

4. Data retention period

Your personal data is retained only for the period necessary for the purposes for which it was collected, in compliance with applicable legal obligations.

Data categoryRetention period
Active account dataDuration of the contract + 3 years after inactivity
Order and billing data10 years (legal accounting obligation)
Payment data (tokenized)13 months after the transaction
Connection and security logs12 months
Geolocation dataNot retained beyond the session
Marketing / consent data3 years after the last contact
Complaint data5 years (statutory limitation period)

5. Data recipients

Your personal data may be shared with the following categories of recipients, strictly limited to what is necessary for the purposes described:

  • Partner restaurantsreceive your first name and order details to prepare your meal.
  • Payment providersStripe Inc. processes your secure payment data; Mealio does not store your bank card data.
  • HostVercel Inc. hosts the Platform's technical infrastructure.
  • Analytics toolstools such as Google Analytics (with IP anonymization) may analyze Platform usage.
  • Legal authoritiesupon judicial or administrative request, we may be required to disclose certain data.

All our subprocessors are bound by contractual clauses guaranteeing the protection of your data in accordance with the GDPR.

6. Transfers outside the European Union

Some of our subprocessors are established outside the European Union, in particular Vercel Inc. (United States) and Stripe Inc. (United States). These transfers are governed by appropriate safeguards in accordance with Articles 46 et seq. of the GDPR:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission;
  • Certification under the EU-U.S. Data Privacy Framework, where applicable;
  • Additional technical measures (encryption in transit and at rest).

You can obtain a copy of the safeguards put in place for these transfers by contacting our DPO at dpo@mealio.fr.

7. Your rights

In accordance with the GDPR, you have the following rights regarding your personal data. You can exercise these rights at any time by contacting our DPO.

Right of access

Art. 15 GDPR

Obtain confirmation that data concerning you is being processed and receive a copy of it.

Right to rectification

Art. 16 GDPR

Have inaccurate or incomplete data concerning you corrected.

Right to erasure

Art. 17 GDPR

Request the deletion of your data in the cases provided for by the regulation.

Right to data portability

Art. 20 GDPR

Receive your data in a structured, machine-readable format in order to transfer it.

Right to object

Art. 21 GDPR

Object to the processing of your data for direct marketing purposes or for reasons relating to your particular situation.

Right to restriction

Art. 18 GDPR

Request the temporary suspension of the processing of your data in certain cases.

Withdrawal of consent

Art. 7(3) GDPR

Withdraw your consent at any time for processing based on it, without retroactive effect.

Post-mortem instructions

French Data Protection Act

Set instructions regarding the retention and communication of your data after your death.

How to exercise your rights?

To exercise any of these rights, contact our Data Protection Officer (DPO) by email at dpo@mealio.fr or by mail at the registered office address. We undertake to respond to your request within one (1) month. This period may be extended by two additional months for complex requests.

Proof of identity may be requested in order to verify your identity before processing your request.

8. Cookies and trackers

The Mealio site uses cookies and similar technologies to improve your experience, measure traffic and ensure the proper functioning of the Platform. Some cookies are placed with your consent, others are strictly necessary for the operation of the service.

For complete information on the cookies used and how to manage them, see our Cookie Policy.

9. Data security

Mealio implements appropriate technical and organizational measures to protect your personal data against any loss, accidental destruction, alteration, disclosure or unauthorized access. These measures include in particular:

  • Encryption of data in transit via the TLS 1.3 protocol;
  • Encryption of sensitive data at rest (passwords hashed via bcrypt, tokenized payment data);
  • Access control to internal data based on the principle of least privilege;
  • Regular security audits and annual penetration tests;
  • Data breach management procedure in accordance with Article 33 of the GDPR;
  • Two-factor authentication (2FA) available for all accounts.

In the event of a data breach likely to result in a risk to your rights and freedoms, Mealio will notify the CNIL within 72 hours and inform you as soon as possible if your individual risk warrants it.

10. Data Protection Officer (DPO)

Mealio SAS has appointed a Data Protection Officer (DPO) in accordance with Article 37 of the GDPR. You can contact our DPO for any question regarding the processing of your personal data or the exercise of your rights:

DPO, Mealio SAS

42 Rue de la Tech, 75011 Paris, France

Email: dpo@mealio.fr

11. Complaint to the CNIL

If you believe that the processing of your personal data does not comply with applicable laws, you have the right to lodge a complaint with a supervisory authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL):

CNIL

3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07

Phone: +33 1 53 73 22 22

Website: https://www.cnil.fr

We encourage you to contact us first in order to resolve any issue amicably before referring the matter to the CNIL.

12. Amendments to this policy

Mealio reserves the right to amend this Privacy Policy at any time, in particular to comply with regulatory developments or changes in our data processing practices. The date of the last update is indicated at the top of this document.

In the event of substantial changes, you will be informed by email or by a notice visible on the Platform before the changes take effect. Continued use of the Platform constitutes acceptance of the updated policy.