1. Introduction
This Privacy Policy explains how AppEatByte Ltd ("AppEatByte", "we", "us", or "our") collects, uses, stores, and shares personal data when you use our website at appeatbyte.com and our mobile applications (collectively, the "Platform").
We process your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Please read this policy carefully. If you have any questions, contact us using the details in section 14.
2. Who We Are
AppEatByte Ltd is the data controller responsible for your personal data. We are registered in England and Wales.
If you have questions or concerns about how we handle your data, you can reach our data team at privacy@appeatbyte.com.
3. Data We Collect
We collect different categories of personal data depending on how you interact with the Platform:
Account & Registration Data
- Name, email address, and password (hashed) when you create an account.
- Date of birth (where age verification is required).
- Profile picture, if you choose to add one.
Order & Transaction Data
- Delivery address, contact phone number, and Order details.
- Payment method type and last four digits of your card, and transaction references — we do not store full card numbers.
- Order history and fulfilment status.
Usage & Device Data
- IP address, browser type, operating system, and device identifiers.
- Pages visited, features used, and time spent on the Platform.
- Approximate location data (for showing nearby restaurants), and precise location if you grant permission in the app.
Communications Data
- Messages sent through in-app support or email.
- Feedback, reviews, and ratings you submit.
Marketing Preferences
- Your consent choices and communication preferences.
Authentication & Session Data
- Email address, display name, and unique account identifier when you create an account or sign in via a store website powered by AppEatByte.
- A session token stored in a strictly necessary browser cookie when you are signed in. This cookie expires when you sign out or your session ends and does not require your consent.
4. How We Use Your Data
We use your personal data for the following purposes:
- Providing the Services: Creating and managing your account, processing Orders, facilitating payments, and enabling delivery, collection, and dine-in features.
- Customer Support: Responding to enquiries, resolving complaints, and processing refunds.
- Personalisation: Showing you relevant restaurants, offers, and recommendations based on your location, preferences, and order history.
- Platform Improvement: Analysing usage patterns to fix bugs, improve features, and develop new services.
- Safety & Fraud Prevention: Detecting and preventing fraudulent activity, abuse of promotions, and security incidents.
- Marketing: Sending you promotional communications, where you have opted in to receive them. You can unsubscribe at any time.
- Legal Obligations: Complying with applicable laws, regulations, and court orders.
5. Legal Basis for Processing
We rely on the following legal bases under UK GDPR to process your personal data:
- Contract (Article 6(1)(b)): Processing necessary to provide the Services you have requested, including Order fulfilment and account management.
- Legitimate Interests (Article 6(1)(f)): Platform security, fraud prevention, service improvement, and analytics — where these interests are not overridden by your rights.
- Consent (Article 6(1)(a)): Marketing emails and push notifications, and placement of non-essential cookies. You may withdraw consent at any time.
- Legal Obligation (Article 6(1)(c)): Retaining financial records and responding to lawful requests from authorities.
6. Sharing Your Data
We do not sell your personal data. We share it only in the following circumstances:
- Merchants (marketplace orders and white-label store websites): Whether you order through the AppEatByte Customer App or a restaurant's own website built on the AppEatByte platform, AppEatByte remains the data controller for your personal data up to the point your Order is transmitted to the relevant Merchant. We share with the Merchant only your name, delivery or collection details, contact phone number, and Order contents — solely so they can fulfil your Order. From the point a Merchant receives your Order, it acts as an independent data controller for that specific data, solely for the purposes of preparing and fulfilling your Order and its own legal record-keeping obligations. Merchants are contractually prohibited from using this data for any other purpose, including building their own customer database or using it for marketing, and a link to the relevant store's own privacy notice is provided at checkout where available.
- Payment Processors: We use PCI-compliant third-party payment providers to process transactions securely. They receive only the data necessary to process your payment.
- Service Providers: We engage trusted third parties (such as hosting providers, analytics platforms, and email delivery services) who process data on our behalf under strict data processing agreements.
- Legal Requirements: We may disclose data to law enforcement or regulatory authorities where required by law or to protect the rights, safety, or property of AppEatByte, its users, or the public.
- Business Transfers: If AppEatByte is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, subject to equivalent privacy protections.
7. International Transfers
Where we transfer your personal data outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or adequacy regulations. We only transfer data to countries or organisations that provide an adequate level of protection.
We use Firebase (Google LLC) for user authentication, database storage, and file storage. Google acts as a data processor under its Data Processing Agreement, which incorporates Standard Contractual Clauses. Transfers to Google's US-based infrastructure are covered by the UK-US Data Bridge adequacy framework.
For more details about the specific safeguards applied to any such transfer, please contact privacy@appeatbyte.com.
8. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes described in this policy, or as required by law:
- Account data: Retained for the lifetime of your account and for up to 2 years after account deletion, for fraud prevention and legal purposes.
- Order & transaction records: Retained for 7 years to comply with financial and tax obligations.
- Marketing preferences: Retained until you withdraw consent or request deletion.
- Usage & analytics data: Retained in aggregated or anonymised form for up to 3 years.
When your data is no longer required, we securely delete or anonymise it.
9. Your Rights
Under UK GDPR you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate or incomplete data.
- Erasure: Request deletion of your data where there is no compelling reason for us to continue processing it.
- Restriction: Ask us to restrict processing of your data in certain circumstances.
- Portability: Receive a copy of data you have provided to us in a structured, machine-readable format.
- Object: Object to processing based on legitimate interests, including for direct marketing.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please email privacy@appeatbyte.com. We will respond within one month. We may need to verify your identity before processing your request.
10. Cookies
We use cookies and similar technologies to operate the Platform, remember your preferences, and analyse usage. We also set a strictly necessary session cookie when you sign in to a store website — this cookie does not require your consent and is deleted when you sign out or close your browser. For full details of the cookies we use, their purposes, and how to manage them, please read our Cookie Policy.
11. Children's Privacy
The Platform is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact privacy@appeatbyte.com and we will delete it promptly.
Users aged 13–17 may only use the Platform with the consent and supervision of a parent or legal guardian, who accepts responsibility for ensuring the child's use complies with these terms.
12. Third-Party Links
The Platform may contain links to third-party websites. This Privacy Policy does not apply to those sites. We encourage you to read the privacy policy of any website you visit. AppEatByte is not responsible for the privacy practices of third parties.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes via the Platform or by email, and indicate the date of the latest revision at the top of this page.
We encourage you to review this policy periodically.
14. Contact & Complaints
If you have questions, concerns, or wish to exercise your rights, please contact us:
AppEatByte Ltd — Data TeamEmail: privacy@appeatbyte.com
Website: appeatbyte.com
If you are not satisfied with our response, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)Website: ico.org.uk
Helpline: 0303 123 1113
This policy was last reviewed and updated on 10 August 2026.