This policy explains what personal information Mandoz Pizzeria collects when you order through this website, and how it's used.
Who's responsible for your data
QORVANI LIMITED takes your orders and prepares your food - for the purposes of data protection law, QORVANI LIMITED is the "data controller" for the personal information in your order (your name, contact details, and what you ordered). Our ordering platform provider processes that data on QORVANI LIMITED's behalf as a "data processor," under a data processing agreement, and never uses it for its own purposes. If you have a question about your data, or want to exercise any of the rights below, contact QORVANI LIMITED directly using the details on our Restaurant Info page.
What we collect
When you place an order: your name, email address, and phone number; your delivery address, if you order delivery; details of what you ordered, including any allergen information you're shown; and payment confirmation from Stripe (we never see or store your full card details - Stripe handles that directly). If you opt in to marketing, we also keep a record of that consent and when you gave it.
If you create an account, we also keep: your password, stored securely as a one-way hash so that no one, including us, can read it; your name, email address and phone number; any delivery addresses you choose to save; the cards you choose to save for faster checkout, which are held by Stripe (we only ever see the card type, the last four digits and the expiry date); and, if this restaurant runs a loyalty scheme, the points you've earned and spent here.
How we use it, and our lawful basis
We use your order details to take payment, prepare and fulfil your order, and get it to you. This is necessary to perform our contract with you. We also use order data to meet our legal obligations - for example keeping financial records for tax purposes. If you've opted in, we may email or text you about offers or news - only ever with your consent, and you can withdraw it at any time.
If you create an account, we use your account details to provide it - saving your details, delivery addresses, cards and any loyalty points - which is also necessary to perform our contract with you. We also rely on our legitimate interests in keeping this website secure and working properly: checking that sign-ins aren't made by automated programs, and monitoring for errors.
Cookies
This site only uses strictly-necessary cookies and similar storage on your device - to keep your basket, keep you signed in if you have an account, check that sign-ins aren't automated, and process payments securely. We don't use analytics, advertising, or tracking cookies. Full details are in our Cookie Policy.
Marketing
We only send marketing emails or texts if you've actively opted in - the checkbox is never pre-ticked. Every marketing message includes a clear way to unsubscribe or reply STOP, which we action immediately.
Who we share it with
We use the following service providers to run this website, each under a data-processing agreement:
- SupabaseDatabase & Auth
database, authentication, and realtime hosting
- StripePayments & Fraud
payment processing and fraud prevention
- ResendEmail Delivery
transactional and marketing email delivery
- CloudflareCDN & Security
content delivery, network security, and the security check on sign-in pages
- StuartCourier Delivery
courier delivery, for orders delivered by a courier partner rather than by the restaurant's own staff
- GeoapifyAddress Lookup
address lookup at checkout, to find and check your delivery address
- SentryError Monitoring
error monitoring, so we can find and fix faults in this website. Error reports are set up to leave out personal details such as your email address, delivery address and payment details, but they can include internal reference numbers, such as the ID of an order that was involved in an error.
- TwilioSMS Delivery • Reserved for Future
SMS delivery. Reserved for a future feature and not currently used: we don't send any text messages yet, and no data about you has been shared with Twilio. We're naming them here in advance so this list is complete on the day SMS notifications go live.
We don't sell your data, and we don't share it with anyone for their own marketing purposes.
Some of these providers are based in, or process data in, countries outside the UK, including the United States. Where that happens, the transfer is protected by the safeguards UK data protection law requires - either UK adequacy regulations (including the UK-US "data bridge" for certified US companies), or the UK International Data Transfer Addendum included in the provider's data-processing agreement. You can ask us for details of the safeguards that apply to any provider.
How long we keep it
We keep order records for around six years, in line with UK tax record-keeping requirements. If you ask us to delete your data (see "Your rights" below), we remove your personal details from past orders but keep the underlying financial record - amounts, dates, VAT - in a de-identified form for that same retention period, since we're legally required to. Marketing consent records are kept for as long as you're subscribed, plus a short period afterwards so we can demonstrate when and how you opted in or out.
If you've paid for an order in the last 120 days, we keep your name, email address and phone number on that order until 120 days after you paid, so that we can respond if the payment is disputed with your card provider. After that they're removed automatically. Your delivery address and any order notes are removed straight away.
We keep backup copies of our database for up to 14 days so that we can recover from errors. When we delete or anonymise your data, it's removed from our live systems straight away, and backups that still contain it are deleted within 14 days. If we ever have to restore from a backup, we re-apply your deletion before the restored data is used, so deleted data doesn't come back.
Some records are held by service providers in their own systems, and we can't delete them through those systems: Stripe keeps records of payments you've made, under its own legal and regulatory obligations; our delivery courier partner keeps the delivery details (your name, phone number and delivery address) we gave them for any order they delivered; and our email provider, Resend, keeps logs of the emails sent to you. Each keeps these records under its own retention policy, and you can contact them directly about records they hold.
Your rights
Under UK data protection law, you can ask us to:
- Access a copy of the personal data we hold about you
- Correct inaccurate details (for example a mistyped name or email)
- Erase your personal data, subject to our legal duty to retain financial records for tax purposes as described above
If you have an account, you can do two of these yourself from your account page: download a copy of the data we hold about your account, and delete your account. Deleting your account permanently deletes your profile, saved delivery addresses, saved cards and any loyalty points - points can't be restored - and anonymises your past orders as described in "How long we keep it". You can't delete your account while an order is still in progress.
To exercise any of these rights, contact QORVANI LIMITED using the details on our Restaurant Info page. We'll verify your identity before actioning any request.
