Privacy policy

Last updated: 18 August 2026

This English version is provided for convenience. The legally binding version is the German one: Datenschutzerklärung.

1. Scope

This privacy policy applies to the website hfoods.de, to the associated ordering websites of our partner restaurants and to all mobile applications developed and provided by us (together the „services“) that are published in the Google Play Store and the Apple App Store.

All applications published under the developer name „hfoods“ or „Karam Ali Murad-Murad“ in the Google Play Store and the Apple App Store are developed, operated and maintained by us. This privacy policy applies uniformly to all of these applications.

It equally applies to all mobile ordering apps of our partner restaurants that are based on the hfoods platform and are technically operated by us, regardless of whether they are published under the name „hfoods“, under the name of the respective partner restaurant or under the name of its owner in the Google Play Store or the Apple App Store. In all cases the technical data processing is carried out by hfoods.

Personal data is any data that can be used to identify you personally.

2. Controller and app developer

The controller for data processing within the meaning of the GDPR and the developer of all apps published under „hfoods“ is:

Karam Ali Murad-Murad
Birkenweg 34
51503 Rösrath
Germany

Phone: +49 1556 0830004
Email: info@highfoods.de

For questions about data protection, about the processing of your personal data or about exercising your rights as a data subject, you can contact us at any time using the details above.

3. Overview of processing activities

We only process personal data where this is necessary to provide our services. The individual processing activities are described below.

a) Hosting

Our website and web apps are provided through a cloud hosting service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). When a page is accessed, your IP address, browser type, operating system, referrer URL and time of access are recorded automatically.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in reliable provision of the service). Google may process data in the USA on the basis of the EU US Data Privacy Framework.

b) User account and registration

To use the ordering functions in our apps and web apps you can create a user account. For this purpose we process:

  • Email address and password (encrypted)
  • Name
  • Phone number
  • Delivery address or addresses

Authentication is handled by a cloud based authentication service provided by Google. Your account data is kept separately for each restaurant.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract, provision of the ordering service).

c) Order data

When you place an order, we store the following in a Google cloud database:

  • Order content (items, quantities, extras, notes)
  • Time of the order and requested delivery or pickup time
  • Delivery address or pickup selection
  • Payment method and payment status
  • Order status (accepted, in preparation, completed and so on)

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). Order data is stored for as long as this is necessary to process and trace the order. Retention for accounting purposes is the responsibility of the respective partner restaurant as a separate controller.

d) Payment processing (Stripe)

For online payments we use the payment service provider Stripe, Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA, and Stripe Payments Europe, Ltd., Dublin, Ireland). Depending on the payment method chosen, Stripe processes:

  • Credit card or debit card: card number, expiry date, CVC
  • Apple Pay or Google Pay: tokenised payment data (no card numbers)
  • Klarna: name, email, address (forwarded to Klarna)

We do not store complete card data ourselves. Stripe is certified under PCI DSS Level 1. Transmission is encrypted.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). Stripe may process data in the USA on the basis of the EU US Data Privacy Framework and standard contractual clauses.

Privacy policy of Stripe: https://stripe.com/privacy

e) Local storage on your device

Our apps store certain data locally on your device in order to improve usage:

  • Basket contents and user settings
  • Cached menu data for faster loading times
  • Cookie consent and language settings

This data does not leave your device and is deleted automatically when the app is uninstalled.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest) and section 25 (2) TDDDG (technically necessary storage).

f) Network connectivity check

Our apps check the network status of your device (online or offline) in order to inform you about connection problems. No personal data is collected or transmitted in the process.

4. Cookies and web storage

Our websites use cookies and local web storage. Cookies are small data packages that are stored on your device.

Technically necessary cookies and storage: these are required to operate the website, for example session handling and storing your cookie decision. They are used on the basis of Art. 6 (1) (f) GDPR and section 25 (2) TDDDG.

Any storage that is not technically necessary takes place solely on the basis of your consent (Art. 6 (1) (a) GDPR and section 25 (1) TDDDG). You can withdraw your consent at any time with effect for the future.

5. Consent based ad measurement

We advertise our platform online. With your consent we measure which advertisement led to an enquiry, so that we can assess whether our advertising budget is well spent. For this purpose we use the following providers:

  • Google Ads, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
  • Microsoft Advertising, provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland

Legal basis: Art. 6 (1) (a) GDPR and section 25 (1) TDDDG (consent). Providing consent is voluntary and it is not required in order to use this website.

Nothing is loaded before you consent

The scripts of these providers are only loaded after you have given your consent. Until then the consent signals on this website are set to „denied“ and no request is sent to Google or Microsoft, so no data leaves your browser. If you reject consent, the scripts are never loaded.

What is processed after consent

Once you consent, the providers set cookies and similar identifiers in your browser (for example _gcl and _gac for Google, _uet and MUID for Microsoft) and process in particular:

  • Pseudonymous identifiers from cookies and similar technologies
  • IP address, browser and device information
  • Pages visited on this website and actions such as sending an enquiry
  • Referring advertisement or click identifier

This allows an enquiry to be attributed to a specific advertisement. The retention periods for this data are determined by the respective provider. Further information is available in the privacy notices of Google and Microsoft.

Both providers are part of groups with parent companies in the USA, so data may be transferred to the USA. The transfer is based on the adequacy decision of the European Commission under the EU US Data Privacy Framework and on standard contractual clauses.

How your decision is stored

Your decision is stored in the local storage of your browser under the key hfoods_consent, together with a timestamp and a version number, so that we can demonstrate when and to what you consented. The entry remains valid for 180 days. After that, and whenever the purposes or providers change, we ask you again. The entry stays in your browser and is not transmitted to us.

Withdrawing your consent

You can withdraw your consent at any time with effect for the future using the link at the bottom of every page. When you withdraw, the consent signals are set back to „denied“ and the cookies set by these providers are deleted from your browser. Data that was processed lawfully before the withdrawal remains unaffected. You can also delete or block cookies in your browser settings at any time.

6. Contacting us

Contact form

If you send us enquiries via the contact form, your details including the contact data you provide are stored by us in order to process the enquiry and in case of follow up questions. We do not pass this data on without your consent.

Legal basis: Art. 6 (1) (b) GDPR (pre contractual measures) and Art. 6 (1) (f) GDPR (legitimate interest).

Enquiry by email or phone

If you contact us by email or phone, your enquiry including all personal data arising from it is stored by us for the purpose of processing the request. We do not pass this data on without your consent.

AI chat on this website

This website offers a chat that answers questions about our products automatically. The answers are generated by an AI language model. We state this inside the chat window itself, as required by Art. 50 (1) of the AI Act (EU) 2024/1689. Answers can contain errors and are not a binding quote.

We process the content of your messages and the history of the running conversation. This data goes to our server function in the European Union (Google Cloud Functions, Netherlands region) and from there to Anthropic PBC, San Francisco, USA, which operates the language model. Your IP address is processed in memory only, in order to limit the number of requests and prevent abuse; it is not stored.

We do not store conversation content permanently. We only record daily counts of how many requests were processed, in order to keep track of cost. These counts cannot be linked to a person.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in answering product questions quickly) and Art. 6 (1) (b) GDPR where the conversation serves to prepare a contract. For the transfer to the USA see section 7.

Please do not enter special categories of personal data or any credentials into the chat. For a personal conversation, reach us by phone or email.

The chat sets no cookies. If you dismiss the message that points you to the chat, your browser stores that decision locally (web storage, key “hfoods_chat_teaser”) so the message does not appear again. Nothing is stored until you act, and it is stored only to carry out that decision.

7. Transfers to third countries

We use cloud services provided by Google and the payment service provider Stripe, which partly process data in the USA. With your consent, ad measurement data may also be transferred to Google and Microsoft in the USA (see section 5). The European Commission has adopted an adequacy decision for the USA under the EU US Data Privacy Framework, and the providers named are certified under it.

For the AI chat (section 6) we transfer message content to Anthropic PBC in the USA. The transfer is based on the data processing agreement concluded with the provider, including the European Commission’s standard contractual clauses.

In addition, we have concluded data processing agreements pursuant to Art. 28 GDPR with these providers to safeguard your data.

8. Your rights as a data subject

Under the GDPR you have the following rights:

  • Access (Art. 15 GDPR): you can request information about the data we hold about you.
  • Rectification (Art. 16 GDPR): you can request the correction of inaccurate data.
  • Erasure (Art. 17 GDPR): you can request the deletion of your data, provided that no statutory retention obligations prevent this.
  • Restriction (Art. 18 GDPR): you can request that the processing of your data is restricted.
  • Data portability (Art. 20 GDPR): you can receive your data in a machine readable format.
  • Objection (Art. 21 GDPR): you can object to processing that is based on Art. 6 (1) (f) GDPR.
  • Withdrawal of consent (Art. 7 (3) GDPR): you can withdraw a consent you have given at any time with effect for the future.

To exercise your rights, please contact: info@highfoods.de

9. Account and data deletion

You can delete your user account and the personal data linked to it yourself at any time via the ordering website of the respective restaurant. The deletion function is located in your account settings.

If deleting the account yourself is no longer possible, for example because the restaurant has ceased operations, you can instead contact us by email at info@highfoods.de. We will then delete your account and all associated data within 30 days.

Past order data can also be deleted on request, provided that the order has been fully completed.

10. Retention periods

Unless a more specific retention period is stated, your personal data remains with us until the purpose of the processing no longer applies. In detail:

  • Account data: until the account is deleted by the user
  • Order data: until the order is fully completed, deletable on request afterwards
  • Contact enquiries: until the enquiry has been fully handled, at most 3 years
  • Local app data: until the app is uninstalled
  • Cookie consent: 180 days in the local storage of your browser

11. Data security

We use technical and organisational measures to protect your data:

  • SSL and TLS encryption for all data transmissions
  • Encrypted storage of passwords
  • No storage of credit card data on our servers
  • Access restricted databases with role based access control
  • User data is kept separately for each restaurant

12. Right to lodge a complaint with a supervisory authority

In the event of infringements of the GDPR you have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2 to 4
40213 Düsseldorf
www.ldi.nrw.de

13. Plugins and tools

Google Fonts (hosted locally)

This site uses Google Fonts for a consistent presentation of typefaces. The fonts are hosted locally, so no connection to Google servers is established.

Further information: https://developers.google.com/fonts/faq

14. Changes to this privacy policy

We reserve the right to amend this privacy policy so that it always reflects current legal requirements or changes to our services. The current version is always available on this page.