Privacy Policy
Last updated: March 2025
1. Data Controller
This Privacy Policy informs you transparently about how Sushi N Poke ("we", "us", or "our") collects, uses, and protects your personal information when using our website and ordering platform at https://www.sushinpoke.fr.
Controller details:
Establishment: Sushi N Poke
Address: 4 Quai du Pont Neuf 56700 Hennebont
Email:sushinpoke56700@gmail.com
Phone:02 97 50 00 53
2. Data We Actually Collect
We strictly limit data collection to what is required to provide online ordering, delivery, and loyalty rewards:
- Customer Account & Identity: First name, last name, email address, phone number, securely hashed and salted password, and optional avatar image.
- Orders & Delivery Logistics: Selected food items, options, special notes, order type (home delivery or takeaway pickup), scheduled time slot (ASAP or chosen date/time), exact delivery address (street, postal code, city, floor, access codes), GPS coordinates strictly used to calculate delivery zones, order history, real-time preparation status, and secure tracking tokens.
- Payment Information: Online card payments are processed directly through Stripe (PCI-DSS Level 1 certified). Card numbers, expiration dates, and security codes (CVVs) are tokenized directly by Stripe and are never received or stored on our servers. For in-person or cash-on-delivery orders, only your chosen payment method is recorded.
- Loyalty Program (when enabled): Points accumulated per order, points redeemed, discount vouchers applied, and reward tier history.
- Abandoned Carts: If you start an order by entering your contact details but leave before completing payment, your cart contents and contact info may be kept temporarily to send a reminder, unless you object.
- Customer Reviews & Feedback: Ratings and written reviews you submit for menu items or services.
- Technical & Browsing Data: IP address (for network security, DDoS protection, and rate limiting), device and browser type, and essential local storage keys (session state, cart contents, order tracking tokens, cookie consent status).
3. Purposes & Legal Bases for Processing
Under Article 6 of the General Data Protection Regulation (GDPR), each processing activity is grounded in a specific legal basis:
| Purpose | Data Categories | Legal Basis (GDPR) |
|---|---|---|
| Preparing, processing, and delivering your orders | Contact info, cart items, delivery address, time slots | Contract performance (Art. 6.1.b) |
| Payment processing and fraud prevention | Transaction amounts, Stripe tokens, IP address | Contract performance & Legal obligation (Art. 6.1.b & c) |
| Order tracking and communication (SMS/Email) | Phone number, email address | Contract performance (Art. 6.1.b) |
| Customer account management & loyalty rewards | Identity, encrypted credentials, point balances | Contract performance (Art. 6.1.b) |
| Abandoned cart recovery reminders | Email, phone, pending cart items | Legitimate interest (Art. 6.1.f) |
| Audience insights & storefront performance (Google Analytics) | Aggregated browsing events and journeys (no PII) | User consent (Art. 6.1.a) |
| Advertising attribution & campaign effectiveness (Meta, TikTok) | Aggregated conversion events (order totals in EUR) | User consent (Art. 6.1.a) |
| Accounting, tax, and invoicing compliance | Order records, invoices, sales totals, VAT | Legal obligation (Art. 6.1.c) |
4. Third-Party Service Providers
Your data is shared exclusively with necessary technical sub-processors:
- Stripe Payments: Secure online credit/debit card processing.
- Uber Direct: On-demand dispatch of couriers for home delivery (only name, delivery address, and phone number required for order handover).
- Email & SMS Services (Postmark / SMTP / Twilio): For sending order confirmations, password resets, and delivery status alerts.
- Google Analytics, Meta, TikTok (Subject to your consent): For audience metrics and advertising attribution if granted in the cookie banner.
5. Data Retention Periods
- Invoices and accounting records: 10 years as required by commercial law.
- Customer account data: For the duration of your active account; deleted 3 years after the last interaction or immediately upon closure request.
- Abandoned cart data: Kept for a maximum of 48 hours, then automatically purged or anonymized.
- Cookie consent choices: Kept for 180 days (6 months) in your browser's localStorage.
- Analytics & marketing cookies: Maximum 13 months after consent.
6. Security Measures
We implement strict technical and organizational safeguards: end-to-end SSL/TLS (HTTPS) encryption, securely salted and hashed passwords, strict administrative role-based access controls, and non-guessable random tracking tokens that protect order details from unauthorized access.
7. Your GDPR Rights
Under the GDPR, you have the right to:
- Access & Portability: Obtain a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete information.
- Erasure ("Right to be Forgotten"): Request deletion of your account and personal data (subject to mandatory invoice retention periods).
- Restriction & Objection: Object to processing or request restriction of certain operations.
- Withdraw Consent: Change your cookie preferences at any time using the button below.
To exercise your rights, email us at sushinpoke56700@gmail.com. You also have the right to lodge a complaint with your supervisory data protection authority (CNIL in France: www.cnil.fr).
8. Cookies and Storage
To learn more about how cookies and browser storage are used on this site, please read our Cookie Policy.
