Privacy policy

Last updated: 3 October 2026

This English version is provided for convenience. The legally binding version is the German one: Datenschutzerklärung.

1. Scope and roles

This privacy policy applies to the website hfoods.de including the booking route, to the admin area admin.hfoods.de and to our business relationships with restaurants, referral partners and prospective customers. For these, Karam Ali Murad-Murad, trading under the business name hfoods, is the controller within the meaning of the GDPR.

For the ordering websites and ordering apps of the restaurants, the respective restaurant is the controller, even where an app is published under the developer name hfoods. We process the data of guests there solely as a processor on the instructions of the restaurant. What data is processed, who receives it, how long it is stored and what rights guests have is set out in the privacy policy of the restaurant, which is linked in the shop and in the app. Section 10 tells you who to contact about a guest account.

Personal data is any data that can be used to identify you personally.

2. Controller

Karam Ali Murad-Murad, trading under the business name hfoods
Birkenweg 34
51503 Rösrath
Germany

Email: info@highfoods.de

We have not appointed a data protection officer; the conditions of Art. 37 GDPR and section 38 BDSG are not met. For questions about data protection and about exercising your rights you can contact us using the details above.

3. When you use hfoods.de and the admin area

a) Delivery, hosting and places

The website hfoods.de is delivered by Google Ireland Limited through Firebase Hosting. When a page is accessed, your IP address, browser type, operating system, referrer address and the time of access are recorded.

The admin area admin.hfoods.de runs at Vercel Inc.; its server functions are currently executed in the United States of America. Our database (Cloud Firestore, Frankfurt am Main region) and our own server functions are located with Google in the European Union. Sign in through Firebase Authentication and Identity Platform is processed by Google in the United States of America. Push messages are delivered by Firebase Cloud Messaging on Google's worldwide infrastructure. We send emails through the provider named in section 7. We check delivery addresses and address entries through the Google Maps Platform.

Legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is secure and reliable operation. For transfers outside the European Union see section 8.

b) Access to the admin area

For the admin area we process your email address, your encrypted password, your name, your role in your business and the times of your sign ins. Legal basis is Art. 6 (1) (b) GDPR.

c) Storage in your browser

This website sets no cookies. It stores in your browser only what you triggered yourself.

The web storage keeps your language choice in the language notice and the fact that you dismissed the notice pointing to the chat. If you sign in to the admin area, Firebase Authentication also stores your sign in there so that you stay signed in. If a consent banner were ever shown to you, the choice you made there would be added as a further entry; we would ask you beforehand.

The session storage, which your browser clears when you close the tab, holds the draft of your booking with the details you have already entered in the booking flow. It makes sure that going one step back or reloading does not discard your input.

Language choice, chat notice and booking draft do not leave your browser; we transmit the details from the booking flow only once you submit the booking. We verify your sign in through Firebase Authentication, see sections 3 b and 8. The basis for all these entries is section 25 (2) no. 2 TDDDG: they are strictly necessary for us to provide the service you have expressly requested.

The Cookie settings link at the bottom of every page opens a plain overview of what this website stores in your browser, so that you can check this for yourself at any time.

4. Advertising and measurement

We do not use any advertising or analytics service on this website. No provider is embedded, no advertising or analytics script is loaded, and no identifier is set for these purposes. There is therefore nothing here that would require your consent, and we do not ask you for one. This is why you will not find a consent banner on this website.

Should we introduce ad measurement at a later point, it would run solely on the basis of your consent (Art. 6 (1) (a) GDPR and section 25 (1) TDDDG). We would ask you beforehand, and this policy would name the provider, the data involved and the storage periods in advance.

5. Contacting us

Contact form

If you send us an enquiry through the contact form, we store your details including your contact data in order to handle the enquiry and for follow up questions. We do not pass this data on without your consent. Legal basis is Art. 6 (1) (b) GDPR for pre contractual measures and otherwise Art. 6 (1) (f) GDPR.

For enquiries made through the referral link of a referral partner, the part on the referral programme in section 6 applies in addition.

Email and telephone

If you write or call us, we store your enquiry including all personal data arising from it in order to handle it. We do not pass this data on without your consent.

WhatsApp

If you write to us on WhatsApp, WhatsApp Ireland Limited processes your phone number and the content of your messages under its own terms. We have no influence on that processing. If you want to avoid it, send us an email.

Chat on this website

This website offers a chat that answers questions about our products automatically. The answers are generated by a language model. We state this inside the chat window itself, as required by Art. 50 (1) of Regulation (EU) 2024/1689. Answers can contain errors and are not a binding quote.

We process the content of your messages and the history of the running conversation. This data goes to our server function in the European Union (Google Cloud Functions, Netherlands region) and from there to Anthropic PBC, San Francisco, United States of America, which operates the language model. Your IP address is processed in memory only, in order to limit the number of requests and prevent abuse; it is not stored.

We do not store conversation content permanently. We only record daily counts of how many requests were processed, in order to keep track of cost. These counts cannot be linked to a person. Legal basis is Art. 6 (1) (f) GDPR, our legitimate interest being to answer product questions quickly, and Art. 6 (1) (b) GDPR where the conversation serves to prepare a contract.

Please do not enter special categories of personal data or any credentials into the chat. For a personal conversation, reach us by phone or email.

6. Customers, referral partners and prospective customers

Booking and customer account

If you book a package, we process your company and contact data, the details of your business, the time of your consents, the versions of the terms, the data processing agreement and this privacy policy, the IP addresses of the connection and the identifier of your browser. Legal basis is Art. 6 (1) (b) GDPR, and for securing evidence Art. 6 (1) (f) GDPR, our legitimate interest being to be able to prove the content and the time of your consent later on.

Providing this data is neither required by law nor by contract; you are not obliged to provide it. It is, however, necessary for concluding the contract: without your company and contact data, without the details of your business and without a stored payment method we cannot conclude the contract and cannot provide the ordering system to you. There is no other consequence.

Payment method and direct debit

For the collection of our invoices, your bank details are recorded by our payment service provider Stripe directly on a page of Stripe. We receive the last four digits of the IBAN, the mandate reference and the identifiers of your customer account at Stripe. Legal basis is Art. 6 (1) (b) GDPR. Stripe may process data in the United States of America; details are in section 8.

Invoices and accounting

We create and send invoices by email and transfer them to Lexware Office of Haufe-Lexware GmbH und Co. KG, Freiburg im Breisgau. We keep invoices and accounting records for eight years (section 14b UStG, section 147 (1) no. 4 and (3) AO) and commercial letters of tax relevance for six years (section 147 (1) no. 2 and 3 and (3) AO), in each case from the end of the calendar year. Legal basis is Art. 6 (1) (c) GDPR.

Contract file

For every contract we keep a contract file with the events of the contract, such as consent, booking, invoices, changes and termination. We keep it until the end of the third calendar year after the contract ends, and parts of tax relevance for six years. Legal basis is Art. 6 (1) (b), (c) and (f) GDPR.

Partner application

If you apply to become an integration partner or a referral partner, we process the details from your application, such as company, contact person, email address, telephone number, address, VAT identification number and your message, in order to review the application and prepare the contract, on the basis of Art. 6 (1) (b) GDPR. For referral partners, the following part on the referral programme applies in addition.

If we reject your application, we delete it six months after the rejection or, if you applied again afterwards, six months after your last renewed application. Together with it we delete the consent to the agreement you gave when registering, including the contract file for it, and your account, as long as it is only an applicant account. If you become a partner, the details form part of your contract.

If you apply as an integration partner through the referral link of another partner, we assign your application to that partner. While your application is open, they see in their partner area the name of your company and the date and status of your application. Once you are approved, they see whether your partner account is active, the number of your active restaurants and the commission they receive from us for them. If you did not state a company, they see only the date instead of a name. We do not pass on your email address, telephone number or address to them. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is to pay the referring partner correctly and verifiably. The referring partner processes these details as a controller in its own right. You can object to the assignment under Art. 21 (1) GDPR (section 9). If you apply as a referral partner, the referring partner does not see your application.

Referral programme

In the referral programme, referral partners recommend hfoods to restaurants. Private individuals and businesses can take part. If a contract with a restaurant is concluded, the referral partner receives a commission on the invoices the restaurant pays to us. For this we process data of the referral partners and data of the recommended businesses.

a) Data of referral partners. The part on partner applications applies to your application. When you conclude the referral partner agreement or confirm your conditions sheet, we keep a contract file: the version and the fingerprint of the text you agreed to, the time, the IP addresses of the connection, the identifier of your browser, your user ID, your email address and the type of participation you stated (private individual or business). If you participate as a private individual, we do not store the IP addresses and the identifier of your browser.

If you take part as a natural person, that is as a private individual or as a sole trader, we ask for your date of birth when you register. We use it to check that you are of age, because only adults can take part; if you are under 18, registration is not possible. We also carry it over into the setup of your payout account so that you do not have to enter it there again. If there are justified doubts about your age, we may ask for proof; we do not store a copy of an identity document. The legal basis is Art. 6 (1) (b) GDPR. If we reject your application, we delete the date of birth together with it (part on partner applications). Otherwise we keep it for as long as you take part and delete it at the end of the third calendar year after your participation ends.

For settlement we process your master data (name, company, legal form, type of participation, address and the email address for statements), the commission you earn and the documents with which we settle it. If you take part as a business, we also process your tax details (tax number or VAT identification number, as a small business your small business identification number where applicable, and your VAT status) and settle by self-billed credit note (section 14 (2) sentence 5 UStG). If you take part as a private individual, we do not collect tax details and settle by a commission statement without VAT; if you tell us that you have become a business for VAT purposes, we store this together with the day from which it applies. We send you credit notes and commission statements by email, show them in your partner area and transfer them to Lexware Office with your name as supplier.

Payouts are made to your payout account with our payment service provider, Stripe Payments Europe, Limited, Dublin, Ireland. You set it up once through your partner area; Stripe creates an account connected to us for this purpose. So that you do not have to enter details twice, we transmit to Stripe your name, your email address, your address, your telephone number if you have given it, your date of birth, whether you take part as a person or as a company, a short description of your activity as a referral partner and the identifier of your partner account; later, for each payout, the amount and the number of the credit note or commission statement. You can check and change the transmitted details at Stripe before you confirm them. Stripe records your identity and your bank details directly on a page of Stripe and checks them as a controller in its own right; the privacy policy of Stripe applies to this. From Stripe we only store the identifier of the account and its status, for example whether payouts are possible or details are missing, not your identity document data.

We only store bank details ourselves if you request a bank transfer because Stripe has rejected or closed your payout account, you cannot complete the setup or using it cannot reasonably be expected of you for good cause, if we ask you for them because we pay you by bank transfer, or if you participate under an earlier version of the agreement that provides for entering them in the partner area. We then store your bank details with IBAN, BIC and account holder and use them for the transfer order to our bank.

We use your details as a referral partner exclusively to fulfil our obligations under the agreement, that is for activation, assignment, settlement and payout, and to meet legal obligations, and for no other purpose. We do not send you advertising, such as a newsletter, based on these details.

Your display name (your company, otherwise your name) is shown as your recommendation to anyone who opens your referral link. We also name it to businesses that enter themselves through your link in the email for confirming their enquiry, and to businesses you report yourself as the source of their data. The legal basis is Art. 6 (1) (b) GDPR, for naming you as the source Art. 6 (1) (c) GDPR together with Art. 14 (2) (f) GDPR.

The legal basis for application, contract, settlement and payout is Art. 6 (1) (b) GDPR. For credit notes, commission statements, accounting records and their retention it is Art. 6 (1) (c) GDPR together with the retention obligations under section 257 HGB, section 147 AO and section 14b UStG; we keep them for eight years from the end of the calendar year. If you participate as a business, Art. 6 (1) (f) GDPR applies in addition to the contract file, with our legitimate interest in being able to prove the conclusion, content and time of your consent later. If you participate as a private individual, we keep the contract file only to perform the contract and to meet our legal obligations (Art. 6 (1) (b) and (c) GDPR). Recipients are Stripe Payments Europe, Limited for the payout account and the payouts, Haufe-Lexware GmbH und Co. KG for accounting in Lexware Office and the provider named in section 7 for sending the emails.

We keep your contract file as long as commission can still arise from your agreement. After that we count from the latest of these days: end of the agreement, last commission, last credit note and end of the last assignment of a business. At the end of the third calendar year after that we delete from the file the IP addresses, the identifier of your browser, your email address and your user ID, because by then claims under the agreement are generally time barred (sections 195 and 199 BGB). At the end of the eighth calendar year we delete the file itself; until then it proves the agreed self-billing procedure, for as long as we keep the credit notes. If we reject your application, the period in the part on partner applications applies.

b) Data of recommended businesses. If you enter your business yourself through the referral link of a referral partner, we process the details from the form: name of the business, contact person, email address, telephone number, town and, where given, postcode and message.

After you submit the form, we send you an email with which you confirm your enquiry. Your enquiry and your consent only take effect with this confirmation; before that we do not contact you, and the referral partner does not see the enquiry. If you do not confirm within 7 days, we delete the enquiry after this period has expired. If the email cannot be sent, we delete the enquiry immediately. At most one such email goes to the same email address within 24 hours. For your consent we store its wording, its version, the time of the enquiry and the time of the confirmation.

If a referral partner reports your business, we receive the details from them: name of the business, contact person, email address, town and, if they state them, telephone number, postcode and a note about your business. In doing so they declare to us that you consented to them beforehand in text form, and state by which channels (email, telephone) we may contact you, on which day and in which form (email, messenger message or signed form) you consented and who consented for your business. We store these details together with the wording they confirmed for this. We contact you only by the channels they stated. We inform you about the report immediately by email to the reported address. If it does not arrive, we inform you at the first contact and send the information in text form afterwards, at the latest one month after the report.

To prevent abuse we count the enquiries through referral links per connection and day. For this we store your IP address (for IPv6 its /64 range) only as a check value together with the day, never in plain text, and delete it after three days at the latest. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is to protect the form against mass and abusive enquiries.

We use the details to contact you about your enquiry, to assign it to the referral partner through whose link or report it came, to recognise duplicate reports of the same business and, if you become a customer, to settle the referral partner's commission. The legal basis for contacting you is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time with effect for the future. For the assignment, the check for duplicate reports and the notice to the referral partner it is Art. 6 (1) (f) GDPR; our legitimate interest is to pay our referral partners correctly and traceably. For the confirmation email, keeping unconfirmed enquiries until they are deleted and the details of your consent it is also Art. 6 (1) (f) GDPR; our legitimate interest is to be able to prove that the enquiry and the consent come from your business (Art. 7 (1) GDPR). We need the details in the form and in the report to contact you about your enquiry; without them we cannot process the enquiry. There is no other consequence. If you become a customer, the part on booking and customer account applies to your data as a customer in all other respects.

By way of exception to section 5, the referral partner learns that your business came to us through their link or report. In their partner area they see the name and town of your business and the status of the enquiry, for example whether it is being reviewed, has been declined or has expired, or whether you have become a customer and since when. If you become a customer, they see, in order to settle their commission, for each paid invoice to hfoods the invoice number, the period, the day of payment, the net amount and the commission calculated from it with its status. This includes whether the commission is held back or lapses because one of your payments has been disputed or reversed. They are not told whether any other invoice is outstanding. Invoice number, period and net amount also appear on their credit notes. We do not pass on your contact person, your email address or your telephone number to them. The referral partner processes these details as a controller in its own right.

If no contract is concluded, we delete the details of your business twelve months after the enquiry was received. If you become a customer, we delete the contact person, email address, telephone number and message from the enquiry as soon as the referral partner's commission for your business ends. We keep the assignment to the referral partner with the name and town of your business until the end of the third calendar year after the commission ends, so that we can prove their settlement, and the details in credit notes and accounting records for the statutory periods (eight years, section 147 AO, section 14b UStG). Your rights under section 9 apply here as well. You can object to the assignment and to the notice to the referral partner under Art. 21 (1) GDPR, and to being contacted for advertising purposes at any time and without giving reasons under Art. 21 (2) GDPR.

Register “No contact wanted”. If you object to being contacted or tell us that you do not want to be contacted, we enter your email address and your telephone number in a blocking register, only as a check value, not in plain text, with the type of detail and the day of entry, without the name of your business and without the referral partner. At the same time we decline open enquiries about your business and delete the contact person, email address, telephone number and message from all enquiries about your business. If a referral partner reports you later, we compare their details with the register: if there is a match, we do not create the report, and they learn only that your business does not want to be contacted by us. If someone enters themselves with your email address through a referral link, we do not accept the enquiry; if only your telephone number is in the register, we note this on the enquiry and do not call you.

The purpose of the register is to respect your objection permanently. The legal basis is Art. 6 (1) (c) GDPR together with Art. 21 (3) GDPR, because after an objection to advertising we may no longer process your data for it, and without a comparison we could not ensure this for a new report. If you do not want to be contacted without expressly objecting, it is Art. 6 (1) (f) GDPR; our legitimate interest is not to approach you against your recognisable wishes (section 7 (1) sentence 2 UWG). We keep the entry as long as your wish applies; there is no fixed deletion period, because otherwise we could no longer respect it. If you later confirm an enquiry through a referral link yourself by email, we delete the entry for your email address. Otherwise we delete it when you tell us that you want to be contacted again.

7. Recipients

We pass data only to the recipients below. The role is stated for each provider individually: with the processors we have concluded an agreement under Art. 28 GDPR; a provider that is a controller in its own right decides about its processing itself and informs you about it in its own privacy policy.

ProviderPurposePlace of processingRole
Google Ireland Limited, Dublin, Irelanddelivery of hfoods.de through Firebase Hosting, database (Cloud Firestore) and server functions, sign in through Firebase Authentication and Identity Platform, push messages through Firebase Cloud Messaging, address checks and distance calculation through the Google Maps PlatformFrankfurt am Main, Belgium and the Netherlands; sign in in the United States of America; push messages on Google's worldwide infrastructureprocessor
Vercel Inc., Walnut, California, United States of Americaoperation of the admin area admin.hfoods.deserver functions currently in the United States of Americaprocessor
Stripe Payments Europe, Limited, Dublin, Ireland, and Stripe, Inc., United States of Americarecording your payment method, the SEPA direct debit mandate and the collection of the monthly invoice; payout of commission to referral partners to their payout account, an account with Stripe connected to usIreland and the United States of Americacontroller in its own right for payment processing, verifying the identity of referral partners, fraud prevention and its own legal obligations
Haufe-Lexware GmbH und Co. KG, Freiburg im Breisgau, Germanyaccounting, invoices as well as self-billed credit notes and commission statements to referral partners (Lexware Office)Germanyprocessor
[mail provider, still to be released by the owner]sending our emails, such as confirmations, invoices, credit notes and commission statements[mail provider, still to be released by the owner]processor
Anthropic PBC, San Francisco, United States of Americalanguage model behind the chat on this websiteUnited States of Americaprocessor
OpenStreetMap Foundation, United Kingdommap tiles in the admin areaUnited Kingdom and European Unioncontroller in its own right for delivering the tiles
WhatsApp Ireland Limited, Dublin, Irelandmessages you send us on WhatsAppIreland, United States of Americacontroller in its own right under WhatsApp's own terms
The referral partner through whose referral link or report a business came to usnotice that the business came through them, with name, town and status of the enquiry and the details needed to settle their commission (section 6, referral programme)Germanycontroller in its own right
The partner through whose referral link you applied as an integration partnername of your company, date and status of your application and, once you are approved, the number of your active restaurants and their commission for them (section 6, partner application)registered office of the partnercontroller in its own right

Beyond that we pass data to tax advisers, authorities and courts where we are obliged to do so (Art. 6 (1) (c) GDPR).

8. Transfers to countries outside the European Union

As section 3 a and the table in section 7 show, individual processing activities regularly take place outside the European Economic Area, in particular sign in through Firebase Authentication, the delivery of push messages and the server functions of the admin area at Vercel.

The basis for transfers to recipients in the United States of America is the adequacy decision of the European Commission on the EU US Data Privacy Framework (Implementing Decision (EU) 2023/1795), as long as the recipient is certified and the decision is in force, and otherwise the standard contractual clauses under Implementing Decision (EU) 2021/914 from the data processing terms of the respective provider. For Anthropic PBC the basis is the data processing agreement concluded with it, including the standard contractual clauses.

If one of these bases ceases to apply, we review the transfer again and adapt this policy.

9. Your rights

Under the GDPR you have the following rights:

  • Access (Art. 15 GDPR): you can request information about the data we hold about you.
  • Rectification (Art. 16 GDPR): you can request the correction of inaccurate data.
  • Erasure (Art. 17 GDPR): you can request the deletion of your data, provided that no statutory retention obligations prevent this.
  • Restriction (Art. 18 GDPR): you can request that the processing of your data is restricted.
  • Data portability (Art. 20 GDPR): you can receive your data in a machine readable format.
  • Withdrawal of consent (Art. 7 (3) GDPR): you can withdraw a consent you have given at any time with effect for the future.

To exercise your rights, write to info@highfoods.de.

Right to object under Art. 21 GDPR

Where we process data on the basis of Art. 6 (1) (f) GDPR, you can object at any time on grounds relating to your particular situation. An informal message to info@highfoods.de is enough. We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

Where we process data to present our ordering system to you (direct marketing), for example after a referral by a referral partner, you can object at any time without giving reasons (Art. 21 (2) GDPR). An informal message to info@highfoods.de is enough. We will then no longer use your data for this purpose (Art. 21 (3) GDPR).

There is no automated decision making in individual cases, including profiling, within the meaning of Art. 22 GDPR. Your booking, the contract, the price and any termination are always decided by a person. The chat on this website does not decide anything about your contract either; it answers questions.

10. Questions about a guest account or an order

Please address questions about your account or your orders in an ordering shop or an ordering app to the restaurant. It is the controller for these, and its privacy policy is linked in the shop and in the app. If such an enquiry reaches us, we forward it to the restaurant without undue delay and act on its instructions.

You can delete a guest account yourself in the account settings of the ordering website of the respective restaurant.

11. Retention periods

Unless a specific period is stated above, we store your data until the purpose of the processing no longer applies. In detail:

  • We delete contact enquiries three years after the end of the calendar year of the last message.
  • If the enquiry leads to a contract, we keep commercial letters of tax relevance for six years and invoices and accounting records for eight years from the end of the calendar year (section 147 AO, section 14b UStG).
  • We keep the contract file until the end of the third calendar year after the contract ends, and parts of tax relevance for six years.
  • We delete the details of businesses recommended to us by a referral partner twelve months after the enquiry was received if no contract is concluded. If the business becomes a customer, we delete the contact details from the enquiry when the commission ends and the assignment to the referral partner at the end of the third calendar year after that.
  • We delete enquiries through a referral link that you do not confirm as soon as the 7 days for confirmation have expired.
  • We delete the check value of your IP address used to protect the referral page after three days at the latest.
  • We keep entries in the register “No contact wanted” as long as your wish applies (section 6).
  • We delete rejected partner applications six months after the rejection or the last renewed application.
  • We delete the date of birth of a referral partner together with a rejected application, otherwise at the end of the third calendar year after the end of their participation.
  • From the contract file of a referral partner we delete IP addresses, browser identifier, email address and user ID at the end of the third calendar year, and the file itself at the end of the eighth calendar year after the latest of the days named in section 6.
  • We delete logs of the server functions after 30 days.
  • We overwrite backups after 98 days; until then, deleted data can still be contained in backups, but it is no longer used.
  • The entries in the web storage of your browser stay there until you delete the data of this website in your browser; the stored sign in ends when you sign out.
  • Your browser discards the draft of your booking in the session storage as soon as you close the tab.

12. Data security

We use technical and organisational measures to protect your data:

  • TLS encryption for all data transmissions
  • Encrypted storage of passwords
  • No storage of card data with us; we store complete bank details only for transfers to referral partners
  • Access restricted databases with role based access control
  • Data is kept separately for each restaurant
  • Backup of the database at least once a week, kept for 98 days

13. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2 bis 4
40213 Düsseldorf
www.ldi.nrw.de

14. Typefaces

The typefaces of this website are embedded locally. No connection to servers of Google is established when you open this website.

15. Changes to this privacy policy

We adapt this policy when the law or our services change. The version that applies is always on this page, with the date at the top.

Cookie settings

At the moment we do not use any services on this website that need your consent, so there is nothing to choose here.

Without consent

This website does not set any cookies of its own. In your browser's storage we only keep what carries out a choice you made. None of it is sent to us or to anyone else.

  • hfoods_lang_pref: your language choice in the language notice. 180 days.
  • hfoods_chat_teaser: that you closed the message pointing to the chat. 30 days, 180 days after the second time.

Controller: hfoods, Karam Ali Murad-Murad, Rösrath, Germany. Legal basis: section 25 (2) no. 2 TDDDG.

More in our privacy policy