Privacy Policy
Last updated:
Who we are and what this covers
This Privacy Policy explains how Baland Tech, SL ("Foodium", "we") collects and uses personal data. It covers both the Foodium mobile app and this website, including the business portal where venue owners manage their subscription. Our identity and registry details are in the Legal notice above.
We are the data controller. For any privacy question or to exercise your rights, contact privacy@foodium.app. Because we offer services to people in the European Union from Andorra, an EU representative for data-protection purposes will be named here; until then, please use privacy@foodium.app.
We handle personal data under Andorran Llei 29/2021, qualificada de protecció de dades personals (supervised by the Andorran Data Protection Agency, APDA) and, where it applies, the EU General Data Protection Regulation (GDPR).
The data we collect
Account and identity. You sign in with Google or Apple — we don't hold passwords. We receive and store your email, name and profile photo from that provider, along with the provider's account identifiers and technical timestamps. If you sign in with Apple's Hide My Email, we work with the private relay address. We also derive a device identifier from your device's technical attributes (model, make, operating system) to help keep accounts secure.
Profile. Your username (public) and, if you choose to add them, your contact name and email, date of birth, gender, home city, address and avatar. Date of birth and gender are optional.
What you create and do. Reviews, ratings, notes and the photos you upload; the places you save, bookmark or mark as visited (including which contacts you visited with); your swipe history; your in-app contacts and the messages, places and reviews you share with them. We also build an interest profile from your activity (the areas, categories and dishes you engage with) to personalise discovery — this is profiling, and you can object to it (see Your rights).
Location. When you allow it, the app uses your device location while you're using it to sort places by proximity; this precise location stays on your device and is not sent to our servers. Separately, on each signed-in session the app determines your approximate location from your internet (IP) address via a third-party IP-geolocation service and keeps a periodic snapshot (IP address, network provider and coarse location) for a limited period. This approximate, IP-based location runs even if you decline the device-location permission.
Business and billing data (venue owners). Your plan and subscription status, the places you claim, the photos and venue details you publish, and the billing details you enter for invoicing (legal name, tax ID, address). Aggregated statistics about how diners interact with your venue are prepared for you (see How we share data).
If you contact us or express interest before creating an account — for example a venue enquiry, a waiting-list entry, feedback or a support request — we keep what you send us (which may include your email and message).
How and why we use your data
To provide the service (the legal basis is performance of our contract with you): run your account, show and personalise discovery, enable reviews, saving, contacts and sharing, operate venue subscriptions, and provide customer support.
To meet legal obligations: issue and keep invoices and tax records, and respond to lawful requests.
For our legitimate interests, balanced against your rights: keep the service secure and prevent abuse; understand product usage; and prepare aggregated, non-identifying statistics for venue owners about how people interact with their listing. We rely on legitimate interest for the interest-profile that personalises discovery — you can object to it at any time.
Direct marketing (venue owners). If you have a business account, we may occasionally email you about our own similar services — for example, an invitation to come back after your trial or subscription ends. This is the so-called soft opt-in: we tell you about it when we collect your details, every such email carries a one-click unsubscribe link, and you can object at any time (see Your rights). We never send marketing email to diners.
With your consent: website analytics and, in the app, the notification categories that are off by default. You can withdraw consent at any time.
AI features (venue owners). When enabled, we use a third-party AI provider (Anthropic) to translate business-authored text and to generate written performance summaries from your venue's aggregated statistics and your own business photos. These features use business content only — never a diner's identity — and any AI-generated insight is advisory.
How we share data
We do not sell your personal data. We share it only with service providers who process it on our behalf, and only as needed to run Foodium. These include: our cloud, database, storage, authentication and messaging provider (Google Firebase, hosted in the EU); our payment provider (MONEI) for subscriptions; our email provider (Resend) for account and invoice emails; an IP-geolocation service; a search provider; the AI provider named above (when those features are enabled); and internal operational alerting. A current list of the categories of providers is kept available and updated as it changes.
How venues see diner activity. When you interact with a venue on Foodium — including venues that haven't joined yet — that activity feeds statistics we prepare for businesses. These statistics are aggregated and cannot identify you; a venue never sees your identity or your individual actions.
When you share a message, place or review with another user, the recipient keeps their own copy, which stays under their control. We may also disclose data where the law requires it, or to protect our rights, users or the service.
International transfers
Your data is stored primarily in the European Union. Some of our providers are based in, or transfer data to, the United States. Where they are, we rely on an appropriate safeguard for each provider — an adequacy decision, the EU-US Data Privacy Framework where the provider is certified, or the European Commission's Standard Contractual Clauses. Andorra, where we are based, holds an EU adequacy decision, which covers transfers of EU personal data to Andorra.
How long we keep your data
We keep your account and content for as long as your account is open, and afterwards only as described here. Behavioural signals that carry a time limit are kept for a limited period and then removed. Invoices and tax records are kept for at least six years, as Andorran law requires, and are not deleted when an account is closed.
When you delete your account, we remove your ability to sign in and strip identifying fields from your account record. Your email is kept so we can recognise a returning owner and handle business disputes. We also keep an internal copy of your pre-deletion record for up to 12 months for security, fraud-prevention, dispute and audit purposes — and longer where we are required to, or where it is necessary for legal reasons. Some content you shared with other people, and copies other users hold, may remain in their accounts.
Your rights
You can ask us to access, correct, or delete your personal data; to restrict or object to certain processing (including the interest-profile and any direct marketing); and to receive a copy of data you provided. To make a request, email privacy@foodium.app.
Deleting your account in the app is a first step (it removes your sign-in and profile fields). You can also ask us to fully erase your data at any time, and we will do so except for the limited records we must keep for legal, tax, dispute or fraud-prevention reasons. We handle these requests manually, so allow us a reasonable time.
If you believe we've mishandled your data, you can complain to the Andorran Data Protection Agency (APDA) or, if you are in the EU/EEA, to your local data-protection authority.
How we protect your data
We host data in the European Union on Google Cloud infrastructure, encrypt it in transit, and rely on Google and Apple for sign-in so we never hold your password. Billing operations are handled server-side, and card details are entered on our payment provider's page and never reach us. No service can be perfectly secure, but we work to protect your data and to detect and respond to problems.
Children
Foodium is not intended for children. You must be at least 16 years old to use it. We do not knowingly collect personal data from children under this age; if you believe a child has provided us data, contact privacy@foodium.app and we will remove it.
Notifications and messages
With your permission, we send push notifications (for example, activity that involves you or, for venue owners, insights about your venue). You can turn notifications off at any time in your device's settings. By email, we send service messages about your account, trial, subscription and invoices — these are part of running the service, not marketing. The only marketing email we send is the occasional win-back invitation to venue owners described above, always with a one-click unsubscribe.
Changes and contact
We may update this policy; we'll change the date above and, for significant changes, tell you in the app or on the site. Questions or requests: privacy@foodium.app.