Privacy Policy for the Goldies App
Last updated: 1 April 2026
1. Who is responsible for data processing?
This Privacy Policy applies to your use of the Goldies app (“App”). The controller responsible for processing your personal data in connection with the use of the App is:
Goldies Worldwide GmbH Rottstraße 33 52068 Aachen Germany
Email: info@goldies-smashburger.de
(“Goldies”, “we”, “us”, “our”).
We process your personal data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG) and the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG).
2. What data do we process?
We process the following categories of personal data when you use the App, depending on how you interact with us.
2.1. Identification and contact data
- Name
- Email address
- Mobile phone number
- Postal address and saved delivery addresses
- Language and country settings
- Data from third-party login providers (e.g. when you register or log in with “Sign in with Apple” or Google, as available, we receive basic account information such as your Google-User-ID, name and email address from the respective provider)
2.2. Account and order data
- Login data (email address, password – password stored in hashed form)
- Order history (ordered products, order value, time and location)
- Preferred restaurant locations
- Loyalty/points and rewards information
- Participation in promotions, vouchers and campaigns
2.3. Payment data
- Payment method (e.g. debit/credit card type)
- Payment status (paid, cancelled, refunded)
- Payment provider identifiers
- Card and wallet data are processed by our payment service providers. We ourselves only receive and store limited payment information.
2.4. Technical and usage data
- Device information (device type, operating system, app version, device identifiers)
- IP address and approximate location derived from IP
- Date and time of access
- App interactions (screens viewed, buttons tapped, features used)
- Crash logs and performance data
- If you allow location access in your device settings, we also process: Precise location data from your device to show nearby restaurants, estimate delivery times, and facilitate location-based features. You can switch off location access at any time in your device settings; the App may then offer only limited location-based functions.
2.5. Communication data
- Content of enquiries to customer service (e.g. via contact form or email)
- Feedback, ratings, survey responses
- Records of communication with you (e.g. email, push notifications, SMS)
2.6. Marketing preferences
- Opt-in/opt-out status for email, SMS, push notifications and in-app messages
- Topics and types of offers you are interested in (where you specify this)
2.7. Images and user-generated content
- Profile photo if you choose to upload one
- Photos or other content that you voluntarily submit (e.g. as part of campaigns, feedback or reviews)
2.8. Special categories of data (e.g. allergies) – optional
Our menu and allergen information are generally designed so that you do not need to share health data with us. If you nevertheless voluntarily provide information about allergies or intolerances (for example in a free-text field with order notes), we will process this information only to prepare your order and reduce risks to your health. This processing is based on your explicit consent (Art. 9(2)(a) GDPR) or, in urgent cases, to protect your vital interests (Art. 9(2)(c) GDPR).
Please share only the information that is necessary for your order.
3. For what purposes and on what legal bases do we process your data?
We process your personal data only where permitted by law. The following overview shows the purposes and the corresponding legal bases under Art. 6 and, where applicable, Art. 9 GDPR.
Using the App and creating an account
- Managing registration and login
- Setting your language and country
- Managing saved addresses and preferences
Legal basis: Art. 6(1)(b) GDPR (performance of contract – user account and App use).
Processing orders and payments
- Accepting and processing your food and drink orders
- Processing payments, refunds and cancellations
- Communicating about order status and customer service issues
Legal basis: Art. 6(1)(b) GDPR (performance of contract).
For fraud prevention and misuse detection: Art. 6(1)(f) GDPR (legitimate interests – protecting our business and preventing misuse).
Delivery and collection
- Assigning orders to restaurants and, where applicable, delivery partners
- Using location data (if activated) to suggest nearby restaurants and calculate delivery times
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(f) GDPR (legitimate interests in efficient logistics)
Loyalty programme and promotions
- Managing points, rewards, and status levels
- Providing personalised offers and benefits
- If available, linking in-store counter orders to your account when you present your membership QR code, so that points or rewards can be credited
Legal basis: Art. 6(1)(b) GDPR (if the loyalty programme is part of your contract), or Art. 6(1)(f) GDPR (legitimate interests in customer retention).
Customer support and communication
- Processing support requests
- Responding to complaints and enquiries
- Service notifications (e.g. maintenance, changes to terms)
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in providing customer service).
Marketing communications
- Sending newsletters, offers and promotions via email, SMS, push notifications or in-app messages
- Measuring the success of marketing campaigns
Legal basis: Usually your consent under Art. 6(1)(a) GDPR, in some cases Art. 6(1)(f) GDPR in conjunction with § 7 para. 3 German Unfair Competition Act (UWG) (direct marketing to existing customers, subject to your right to object).
You can withdraw your consent or object to marketing at any time (see Section 9).
Analytics and App improvement
- Analysing usage patterns and performance
- Preventing errors and crashes
- Improving usability, security and features of the App
Legal basis: Art. 6(1)(f) GDPR (legitimate interests in analysing and improving our services). Where technologies are non-essential and require consent under TDDDG, Art. 6(1)(a) GDPR and § 25 para. 1 TDDDG.
Compliance with legal obligations
- Retention for commercial and tax law
- Responding to requests from authorities
Legal basis: Art. 6(1)(c) GDPR in conjunction with German commercial and tax law.
Enforcement and defence of legal claims
Asserting claims and defending ourselves in legal disputes
Legal basis: Art. 6(1)(f) GDPR (legitimate interests in asserting and defending rights).
Processing of special categories of data (allergies)
Taking account of allergy or intolerance information that you voluntarily provide
Legal basis: Art. 9(2)(a) GDPR (explicit consent), in rare emergency cases Art. 9(2)(c) GDPR (vital interests).
4. Who receives your data?
We share your personal data only where necessary and permitted by law.
4.1. Internal recipients: Within Goldies, only those departments and persons have access to your data who need it to fulfil the purposes described, e.g.:
- IT and App development
- Customer service
- Marketing and CRM
- Finance and accounting
- Restaurant operations
4.2. External recipients (service providers and partners)
4.2.1. Our technical service provider and app provider: Samba Technologies Pte. Ltd. 160 Robinson Road, #14-04 068914 Singapore Republic of Singapore (“Cata”). Cata generally acts as our processor within the meaning of Art. 4 No. 8 and Art. 28 GDPR and processes personal data only on our documented instructions.
4.2.2. We may use selected external service providers who act as processors under Art. 28 GDPR and process data only on our instructions, for example:
- Hosting and cloud providers
- Payment service providers
- Customer support tools
- Email and SMS providers
- Analytics and crash reporting providers
- Push notification providers
Where necessary for order fulfilment, we also share data with:
- Our restaurants (for preparation of your order)
- Delivery partners (if available in your area)
In addition, we may transmit data to: Authorities, courts and legal advisers where we are legally obliged to do so or to assert legal claims.
4.2.3. We may also use certain third-party providers who may act as independent controllers rather than processors:
- Third-party login providers (e.g. Apple, Google) where you choose to register or log in using these services. These providers process your data in accordance with their own privacy policies.
- Delivery partners (e.g. Uber Direct) where you place a delivery order. These partners operate independently and process your data for the purpose of fulfilling the delivery in line with their respective privacy policies.
5. Do we transfer data to third countries?
Some recipients, such as Cata or certain cloud and analytics providers, may be located outside the European Economic Area (EEA) in countries whose data protection level is not recognized as equivalent to that of the EU.
In such cases, we ensure appropriate safeguards in accordance with Art. 44 et. seq. GDPR, for example:
- An adequacy decision by the European Commission (Art. 45 GDPR), or
- Standard Contractual Clauses (Art. 46 GDPR) concluded with the recipient, and, where necessary, additional measures.
You can request a copy of the relevant safeguards via the contact details in Section 1.
6. Cookies, SDKs and similar technologies
The App uses cookies and similar technologies (such as local storage, software development kits (SDKs), device identifiers and tracking pixels). Cookies are small text files that are stored on your device (e.g. smartphone or tablet) and can be read by us or by third-party providers when you use the App. These technologies help us recognize your device for a certain period of time and enable specific functions.
Some of the technologies we use are so-called session cookies or temporary storage elements, which are automatically deleted when you close the App. Other technologies remain stored on your device until you delete them. These allow the App to recognize your device on your next visit and to preserve certain settings.
Some cookies are necessary for the use of our App. These cookies are not used for analysis, tracking, advertising or other non-essential purposes. Some of them only contain information about specific settings and are not personalised. These cookies are essential for user guidance, security and the operation of the App. We use these cookies on the basis of § 25 para. 2 TDDDG to ensure basic functions of the App.
You can set your device so that you are informed about the placement of cookies, which makes the use of cookies transparent for you. You can also delete cookies at any time via the corresponding device setting and prevent the setting of new cookies. Please note, however, that this may result in the App not being displayed correctly and certain functions no longer being available.
In addition, we also use technically non-essential cookies on the basis of your consent. This processing only takes place with your express consent in accordance with Art. 6(1)(a) GDPR and § 25 para. 1 TDDDG. You can revoke your consent for us to use the non-essential technologies at any time with effect for the future in the App’s settings. If you do so, parts of the App may not function properly.
For more information on the individual cookies we use on our App, please refer to this privacy policy or our cookie consent banner.
7. How long do we store your data?
We store your personal data only for as long as necessary for the purposes described, or where we have a legal obligation to retain them.
In particular:
- Account and profile data: for the duration of your App account. If you delete your account, we delete or anonymise your data unless statutory retention periods apply or we need the data to assert or defend legal claims.
- Order and payment data: retained for the duration of the contractual relationship and, thereafter, for statutory retention periods under commercial and tax law (usually up to 10 years).
- Loyalty programme data: retained as long as you participate in the programme and there is a valid legal basis.
- Marketing data: we process your contact data for marketing purposes until you withdraw your consent or object to marketing. We may store proof of your consent and withdrawal for up to 3 years after the end of the year in which you withdrew, in accordance with limitation periods.
- Technical logs and analytics data: usually for a short period necessary to analyse and ensure security and stability, unless longer retention is required for evidence.
If legal limitation periods apply (e.g. three years in many cases under German law), we may retain data for this period to be able to defend ourselves against potential claims.
8. Are you obliged to provide data?
You are not legally obliged to provide us with personal data. However, some data are necessary to conclude or perform the contract (e.g. account data, contact details, payment information for orders). If you do not provide these data, we may not be able to offer the App or process your orders. Providing data for marketing and analytics is voluntary. You can refuse or withdraw consent without affecting your use of the App, except for non-essential features linked to such consent.
9. What rights do you have?
You have the following rights under the GDPR with respect to your personal data:
- Right of access (Art. 15 GDPR): to obtain information about whether and which data we process about you.
- Right to rectification (Art. 16 GDPR): to correct inaccurate data and have incomplete data completed.
- Right to erasure (Art. 17 GDPR): to have your data deleted under certain conditions (e.g. if they are no longer needed or processing is unlawful).
- Right to restriction of processing (Art. 18 GDPR): to request processing be restricted in certain cases.
- Right to data portability (Art. 20 GDPR): to receive data you have provided to us in a structured, commonly used and machine-readable format and to transmit those data to another controller.
- Right to object (Art. 21 GDPR): to object at any time to processing based on Art. 6(1)(e) or (f) GDPR (legitimate interests) on grounds relating to your particular situation (see below).
- Right to withdraw consent (Art. 7(3) GDPR): if processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing before withdrawal remains unaffected.
Right to object
You have the right to object, at any time and for reasons arising from your particular situation, to the processing of your personal data based on Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on this provision as defined in Article 4(4) GDPR.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
To exercise your rights, you can contact us at the contact details provided in Section 1.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR). In Germany, data protection authorities exist in each federal state and at federal level.
10. Children and minors
Our App is intended for adults. Persons under 18 should only use the App with the consent of their parent or legal guardian. Where we offer information society services directly to children and rely on consent, a child must generally be at least 16 years old to give valid consent under German data protection law. For younger children, consent must be given or authorised by the holder of parental responsibility. If we become aware that we have processed a child’s personal data without the necessary consent, we will delete this data as soon as possible.
11. Security
We take appropriate technical and organisational measures to protect your data against loss, misuse, unauthorised access, alteration or destruction, taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing as well as the risks. Our measures include, among others, access controls, encryption, pseudonymisation where appropriate, regular security reviews and staff training. However, no IT system can be completely secure; residual risks can never be fully excluded.
12. Automated decision-making and profiling
We do not carry out any automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. We may use limited profiling (e.g. classification into customer segments based on purchase behaviour) for marketing and loyalty purposes as described in Section 3. You can object to such profiling for direct marketing at any time.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time, for example if the App is further developed or legal requirements change. We will inform you of significant changes in an appropriate manner (e.g. via in-App message or email). You can always access the current version in the App. The version date is shown at the top of this Policy.
14. Contact
If you have questions about this Privacy Policy or wish to exercise your rights, you can contact us at:
Goldies Worldwide GmbH Rottstraße 33 52068 Aachen Germany
Email: info@goldies-smashburger.de
