This is an unofficial English translation provided for accessibility. Under Hungarian Act XCVI of 2001, the Hungarian text is the legally binding version. In any inconsistency between the two, the Hungarian wording prevails.
1. Data controller
- Company: Plutosz Vendéglátó Kft.
- Registered seat: 1141 Budapest, Komócsy utca 5., Hungary
- Company registration number: 01-09-175397
- Tax number: 24649276-2-42
- Email: plutoszkft@gmail.com
- Phone: +36 30 577 2094
2. Categories of personal data we process
To process orders and payments we collect:
- First and last name
- Email address
- Billing address (postcode, city, street, number) — optional
- Tax number — optional, only when invoicing a company
- Order contents and total
- The payment-transaction identifier returned by the card processor. We never see or store the full card number (PAN); however, the encrypted payment-confirmation record we receive from SimplePay does contain the card's last 4 digits and brand, for reconciliation
- Keyed HMAC-SHA-256 hash of the request IP and the User-Agent string — for audit purposes
For users of the mobile app we additionally process:
- Password hash (bcrypt + HMAC-SHA256 pepper, stored in non-reversible form)
- If you sign in with an external provider, that provider's stable user identifier (Google
sub, Applesub) - For Apple sign-in: the SIWA refresh token, stored encrypted with AES-256-GCM, used solely for the server-side revocation call we issue when you delete your account
- Push notification token (stored with AES-256-GCM encryption, with a separate SHA-256 lookup/deduplication hash) and device platform (iOS / Android)
- Loyalty points balance and points transactions
- Birthday / date of birth and name-day (optional; used for (i) birthday and loyalty bonuses and (ii) age verification for alcoholic products (18+; see §11). Only accepted from users aged 16 or older — see §10)
- Location data (your device's GPS coordinates) — only with your permission, to show the nearest pickup restaurant and to check order distance; coordinates are not stored beyond serving the request
- Communication preferences (push notifications, marketing)
- Crash reports and error logs — with automatic personal-data redaction (password / token / email fields are stripped before persistence)
3. Purpose and legal basis
| Purpose | Legal basis | Retention period |
|---|---|---|
| Performance of the order | Performance of contract [GDPR Art. 6(1)(b)] | 8 years from order completion (accounting law) |
| Issuance and retention of the invoice | Legal obligation [GDPR Art. 6(1)(c); Hungarian Act C of 2000 §169] | 8 years |
| Card payment processing | Performance of contract [GDPR Art. 6(1)(b)] | 8 years from transaction close |
| Audit log of consents (Terms, Privacy, Data Transfer) | Consent [GDPR Art. 6(1)(a)] and legitimate interest [GDPR Art. 6(1)(f)] | 5 years from withdrawal of consent |
| Personalised loyalty offers (profiling): analysing your order history (frequency, recency, total spend) to assign you to a customer lifecycle/loyalty segment and send you relevant coupons and rewards [profiling within the meaning of GDPR Art. 4(4)]. These offers produce no legal or similarly significant effect on you [GDPR Art. 22]; the profiling is used only to provide benefits, never to set prices or restrict access to the service. | Consent [GDPR Art. 6(1)(a)] — under your marketing consent | Until you withdraw consent or object (see section 7) |
Guest checkout (ordering without registration). Using the web checkout does not require a user account. In that case we still collect the data above to fulfil the order (name, email, optional billing address). The legal basis remains performance of contract [GDPR Art. 6(1)(b)]; the separate registration-time consent that mobile- app users grant is not collected here — instead, you explicitly accept this Privacy Policy as part of the checkout flow. Records created via guest checkout are subject to the same 8-year accounting retention obligation set out above.
4. Sub-processors
We engage the following sub-processors:
4.1. SimplePay (SimplePay Zrt.)
Online card payments are processed by SimplePay Zrt. (registered seat: 1138 Budapest, Váci út 135–139. B. ép. 5. em.; company number 01-10-143303, Court of Registration of the Budapest-Capital Regional Court) acting as a sub-processor.
Data shared with SimplePay: first and last name, email, billing address (country, postcode, city, street, number). Full card data (card number, CVV) is captured by SimplePay directly from you — it never reaches our systems, neither transiently nor at rest; only the card's last 4 digits and brand appear in the payment-confirmation record (see §2).
SimplePay's privacy notice: https://simplepay.hu/adatkezelesi-tajekoztatok/ .
4.2. Hosting provider
Application data is hosted on the infrastructure of Rackhost Zrt. (registered seat: 6722 Szeged, Tisza Lajos krt. 41.; company number 06-10-000489; email: info@rackhost.hu). Access is granted only to the extent strictly necessary for technical operation.
4.3. Invoicing (KBOSS.hu Kft. / Számlázz.hu)
Invoice issuance and the real-time XML reporting to the Hungarian tax authority (NAV), required by Decree 23/2014 (VI. 30.) NGM, is performed by the Számlázz.hu system, operated by KBOSS.hu Kereskedelmi és Szolgáltató Kft. (registered seat: 1031 Budapest, Záhony utca 7.; company number 01-09-303201; email: info@szamlazz.hu) acting as a sub-processor.
Data shared: first and last name, email, billing address, tax number (if provided), order contents and total. The XML submitted to NAV cannot be revoked by law; if you exercise your right to erasure, the issued invoice and its retained PDF copy remain for the statutory period. We erase direct account and billing fields from the operational database and pseudonymise the related order and payment records. Those retained records may still constitute personal data, for example because the payment provider also holds the transaction identifier.
KBOSS.hu Kft. privacy notice: https://www.szamlazz.hu/adatvedelem/ .
4.4. Push notification delivery (Expo)
Mobile push notifications are delivered by Expo (650 Industries, Inc., 650 Castro Street, Suite 120-219, Mountain View, CA 94041, USA), which in turn forwards messages to Google FCM (Android) and Apple APNs (iOS).
Data shared: the device-bound Expo push token, the message body, and the delivery metadata. The token is stored in our system with AES-256-GCM encryption and a separate SHA-256 hash used for lookup and deduplication. It may also remain in server memory for up to 48 hours while a delivery receipt is pending; account deletion immediately removes that user's outstanding in-memory entries.
Because Expo's servers are located in the USA, the cross-border transfer relies on the EU–US Data Privacy Framework and EU Standard Contractual Clauses (SCC) — see §5. Expo's privacy notice: https://expo.dev/privacy .
4.5. Sign in with Google
Google sign-in is provided by Google Ireland Limited
(registered seat: Gordon House, Barrow Street, Dublin 4, Ireland). We
only verify the ID token against Google's servers — data shared:
the email address, the display name, and the Google user identifier
(sub). Your password is never disclosed to us.
Google's privacy notice: https://policies.google.com/privacy .
4.6. Sign in with Apple
Apple sign-in is provided by Apple Distribution International
Limited (registered seat: Hollyhill Industrial Estate, Hollyhill,
Cork, Ireland) on Apple Inc. (One Apple Park Way, Cupertino, CA 95014,
USA) infrastructure. Data shared: the email address (or Apple's private
relay address — @privaterelay.appleid.com), the display
name (only on first sign-in), and the Apple user identifier (sub).
When you delete your account, we issue a server-side revocation request
to Apple (POST /auth/revoke) using the stored SIWA refresh
token, as required by App Store Review Guideline 5.1.1(v).
Apple's privacy notice: https://www.apple.com/legal/privacy/ .
4.7. Email delivery (SMTP)
Verification emails, password reset emails, account notifications, and invoice attachments are delivered through SMTP servers operated by us. The SMTP relay provider is part of the hosting configuration; today delivery runs on the same infrastructure as the hosting provider (4.2). Data shared: the recipient email address, the message subject and body.
5. International transfers (third countries)
We transfer personal data outside the EEA only where the contract or the nature of a sub-processor service requires it:
- Expo (USA) — push notification delivery (§4.4). Legal basis: EU–US Data Privacy Framework and the EU Standard Contractual Clauses (SCC) approved by the European Commission.
- Apple (USA / Ireland) — ID-token verification and SIWA token revocation traffic to Apple's servers (§4.6).
- Google (USA / Ireland) — ID-token verification for Google sign-in (§4.5).
The sub-processors at §4.1 (SimplePay), §4.2 (Rackhost), §4.3 (KBOSS.hu) and §4.7 (SMTP) operate in Hungary or otherwise within the EEA.
We disclose data to public authorities only where required by law.
6. Security measures
- HTTPS encryption (TLS 1.2+) on all client connections
- Billing and contact personal data stored encrypted with AES-256-GCM
- IP addresses are stored as keyed HMAC-SHA-256 hashes in application customer and diagnostic logs and with AES-256-GCM encryption in the security audit log
- Access governed by strict role-based authorisation, with audited operation history
- Passwords hashed with bcrypt + HMAC-SHA256 pepper (non-reversible)
- Apple SIWA refresh tokens encrypted at rest; revoked at Apple-side on account deletion
- Crash reports and error logs sanitised before persistence to strip secrets and PII
7. Your rights
Under the GDPR you have the following rights:
- Right to be informed — about the data we hold and our processing
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten") — within the limits of statutory retention obligations
- Right to restriction of processing
- Right to data portability
- Right to object — in particular against processing based on legitimate interest
- Right to withdraw consent — without affecting the lawfulness of processing carried out before withdrawal
Objection to direct marketing and profiling. You may object at any time, free of charge, to the processing of your personal data for direct-marketing purposes, including the related profiling/segmentation [GDPR Art. 21(2)–(4)]. You can do this in the app's marketing/profiling settings or by emailing plutoszkft@gmail.com; once you object we stop the profiling immediately.
Send requests to plutoszkft@gmail.com. We respond within 30 days of receipt.
You may request account deletion in the app or, without the app installed, at /account/delete.
Deletion can finish only when there is no active order, payment, refund, or unresolved invoicing process. If one remains, resolve it first and request a new single-use confirmation link. We pseudonymise the related order and payment records. An issued invoice and its PDF copy remain with the buyer data required by law for the eight-year accounting period and remain within GDPR scope during that period.
8. Lodging a complaint
If you believe we have breached the GDPR or the Hungarian Information Act (Act CXII of 2011), you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
- NAIH — 1055 Budapest, Falk Miksa utca 9–11.
- Postal address: 1363 Budapest, Pf. 9.
- Phone: +36 (1) 391-1400
- Email: ugyfelszolgalat@naih.hu
- Web: https://naih.hu
You may also seek judicial remedy at the regional court (törvényszék) with jurisdiction over your place of residence or stay.
9. Cookies
The site uses only strictly necessary (technical) cookies. A separate cookie notice and banner will be introduced before any optional cookies are added.
10. Children's data (16-year minimum)
We do not knowingly collect personal data from anyone under the age of 16, and we do not create user accounts for them. This is consistent with GDPR Art. 8 and the 16-year default applied in Hungary under the Information Act (Act CXII of 2011).
The optional birthdate provided at registration is validated server-side: a birthdate that would make the user younger than 16 is rejected. The age threshold is configurable in our system, and any administrative change is recorded in the audit log.
If we become aware that we have collected data from a person under 16, we will delete it promptly. A parent or guardian can flag such cases by writing to plutoszkft@gmail.com.
11. Age verification (alcoholic products)
Our offering may include certain alcoholic products, which may only be ordered and sold to persons aged 18 or over (under the Hungarian Trade Act, Act CLXIV of 2005 §5(7), and the Consumer Protection Act, Act CLV of 1997 §16/A). For this purpose:
- From the (optional) date of birth provided at registration, our system computes whether the user is at least 18. We use only the fact that the age threshold is met to control access: users with no date of birth on file, or who are under 18, do not see and cannot order alcoholic products.
- The actual age check for alcoholic products takes place in person at the restaurant on pickup: in case of doubt, staff may require a valid photo ID and will refuse service if it is not presented.
The legal basis for age-verification processing is compliance with a legal obligation [GDPR Art. 6(1)(c)] — the prohibition on selling alcohol to minors. Date of birth is not special-category data under GDPR Art. 9. In line with data minimisation, we collect no data beyond the above for age verification.
12. Changes to this notice
We may update this notice at any time. Changes take effect upon publication on this site. We will notify registered users separately of any material change.