Privacy at a glance
- Who we are: edrink P.C., an Athens-based company. We are the controller for the edrink app and website. More
- What we collect: account and reservation details, payment data (handled by Stripe; we never see your full card number), device and usage data, and GPS location only if you allow it. More
- Allergies & dietary needs: health-related data. We process and share these notes with the venue only with your explicit consent; they are kept so venues can serve you correctly on future visits, and you can have them deleted at any time. More
- Why we use it: every purpose is mapped to a legal basis in one table, with no vague "improving our services" catch-alls. More
- Venues: when you book, we send the venue only what it needs to host you. From that moment the venue is independently responsible for its copy of your data. More
- Who else gets it: a named list of our service providers, what they do, and where they process data. We never sell your personal data. More
- Where it lives: our servers are in Frankfurt, Germany (EU). Transfers outside the EEA are covered by named safeguards, vendor by vendor. More
- How long: concrete retention periods per data category; see the table. More
- Your rights: access, correction, deletion, portability, objection, and consent withdrawal. Requests are free, answered within one month, and you can start deleting your account from the app. More
- Marketing: only with your consent, with one-tap unsubscribe. You can object to personalisation at any time. More
1. Who we are
edrink Private Company (Ι.Κ.Ε.), 11-13 Aristotelous St, Athens 104 32, Greece (Tax ID: 802281720, General Commercial Registry (GEMI) no. 173565201000) is the data controller for the personal data described in this policy, which means we decide how and why that data is processed.
For anything relating to your personal data, contact us at support@edrink.gr or by post at the address above. Our designated privacy lead handles all data protection requests.
2. What this policy covers
This policy covers personal data we process when you use the edrink mobile app or the edrink website (including reservations made on the website or through a venue's edrink booking link or widget, also when it is embedded on the venue's own website), when you book an edrink venue through Reserve with Google or through a partner app or website integrated with edrink, when you use edrink Manager on behalf of a venue (Section 6.4), and when you contact our support team or receive our communications.
It does not cover:
- What venues do with your data after you book. Restaurants, bars and other venues on edrink are independent businesses. Section 6 explains exactly what we send them and where our responsibility ends and theirs begins.
- Cookies in detail. Our Cookie Policy, available on our website, lists every cookie and similar technology we use. Section 10 below summarises how consent works.
3. The data we collect
3.1 Data you give us
- Account data: name, email address, phone number, and password (stored hashed).
- Reservation data: venue, date and time, party size, and the status of your booking (confirmed, seated, cancelled, no-show).
- Special requests: free-text notes you add to a booking, for example a birthday, a stroller, or dietary needs. See the box below for how we treat allergy and dietary information.
- Payment data: where a venue requires a deposit or prepayment, payment is processed by Stripe. Your full card details go directly to Stripe and never touch our servers; we receive only a payment confirmation, the last four digits, and the card brand.
- Support conversations: messages you exchange with our support team (via Intercom chat or email).
3.2 Data collected automatically
- Device and technical data: IP address, device model and OS, browser or app version, language, and device identifiers (including the mobile advertising identifier, only where you have consented; see Section 10). To stop abuse of SMS verification, we also keep your IP address and a device fingerprint in our abuse-prevention system for up to 48 hours; security logs are kept as set out in Section 9.
- Crash reports: if the app crashes, technical details about the crash (device model, operating system and app version, the error), without your name or contact details, only after you consent (see Section 10).
- Usage data: pages and screens viewed, searches, taps, and session length, collected through Google Analytics on the website and in the app, only after you consent (see Section 10).
- Precise location (GPS): only if you grant the app location permission, and only while you use the app, to show venues near you. This is optional: you can always search by area instead, and you can revoke the permission in your device settings at any time. The map in the app and the booking widget is provided by Mapbox, which receives the map area shown on your screen, which may be centred on your location.
3.3 Data from third parties
- Social login: if you sign in with Google, Apple or Facebook, we receive your name and email address (or Apple's private relay address) from that provider.
- Reserve with Google: if you book an edrink venue through Google, we receive your name, contact details, reservation details and any special requests you write from Google in order to place and manage the booking. This policy applies to that data from the moment we receive it.
- Partner apps and websites: if you book an edrink venue through an app or website integrated with edrink (for example a travel or discovery app), we receive your name, contact details and reservation details from that partner in order to place and manage the booking, and we send the partner the status of that booking. This policy applies to that data from the moment we receive it.
Allergies, dietary and religious dietary needs: special category data. Notes about allergies or intolerances are health data, and notes about halal, kosher or similar needs can reveal religious beliefs. Under EU law (GDPR Article 9) these are special categories of data that require extra protection. We handle them as follows:
- The special request field exists so we can pass your requests to the venue you are booking. Everything you write there is shared with that venue, and only with that venue, so it can host you.
- Include health-related or dietary information only if you want the venue to know it. By writing such information in your note and submitting the booking, you give your explicit consent for us to share it with that venue and for the note to be kept, by us with your reservation history and by that venue in its guest records, solely so that you are served correctly on this and future visits (for example, so the venue remembers an allergy even if you forget to mention it next time).
- We never use these notes for marketing, advertising, profiling or recommendations, and venues may not use them for anything other than serving you.
- You can have any note deleted at any time: edit or remove it on an upcoming reservation in the app, or contact us at support@edrink.gr and we will delete it and instruct the venue to do the same.
- Venues can also record allergy, dietary or accessibility information you give them directly, for example by phone or at the table, in their own guest records on edrink. The venue is responsible for that information (Section 6.3).
3.4 What you must provide, and what is optional
To create an account and make a booking we need your name, email address and phone number; without these we cannot provide the service, because venues need to know who is coming and how to reach you. Everything else (special requests, dietary notes, location access, marketing preferences) is optional, and declining it never affects your ability to book.
4. Why we use your data, and our legal basis for each purpose
Under the GDPR we must have a legal basis for every use of your personal data. This table is the complete list; we do not use your data for purposes that are not on it.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and managing your account | Account data | Contract (Art. 6(1)(b)) |
| Taking, changing, cancelling and honouring your reservations, and sending you booking confirmations and reminders (email and push), including linking your booking to the venue's own record of you when the email address and phone number match, and declining your requests at a venue that has chosen not to take bookings from you | Account, reservation and contact data | Contract (Art. 6(1)(b)) |
| Sending your booking details to the venue you chose | Name, phone number, email address, party size, date/time; booking status; non-sensitive special request notes (e.g. a birthday or a stroller) | Contract (Art. 6(1)(b); the transmission is the service you asked for) |
| Passing allergy / dietary / other sensitive notes to the venue, and keeping them so you are served correctly on future visits | Special requests containing special category data | Explicit consent (Art. 9(2)(a), together with Art. 6(1)(a)), given by writing the information in your note and submitting the booking, as explained in this policy; withdrawable at any time |
| Processing deposits and prepayments | Payment data (via Stripe) | Contract (Art. 6(1)(b)) |
| Answering your support requests | Support conversations, account and reservation data | Contract (Art. 6(1)(b)) |
| Showing venues near you | Precise GPS location | Consent (Art. 6(1)(a)), via the device location permission |
| Personalising venue rankings, recommendations and coupons inside the app | Reservation history, searches, saved venues and in-app activity (never your special request notes) | Legitimate interests (Art. 6(1)(f)): showing you relevant venues rather than a random list. We assessed that this limited, in-app personalisation does not override your rights; it involves no sensitive data and has no legal or similarly significant effect on you. You can object at any time (see Section 5). |
| Marketing emails and push notifications about edrink offers | Contact data, marketing preferences | Consent (Art. 6(1)(a)) |
| Product and website analytics (understanding how the app and the website are used, and, on the website, which visits lead to a reservation) | Usage and device data | Consent (Art. 6(1)(a)), given through the cookie banner on the website or the consent screen in the app (see Section 10) |
| Keeping the app working: finding and fixing crashes | Crash reports (Section 3.2) | Consent (Art. 6(1)(a)), given in the app's consent screen together with analytics |
| Measuring which campaigns work: app-install attribution, and, where we run advertising for the website, whether a visit or a reservation followed an advertisement | Advertising identifier, install source; on the website, campaign and click identifiers | Consent (Art. 6(1)(a)), via the consent banner or screen and, on iOS, App Tracking Transparency. Website advertising measurement is not in use today; it will be listed in the Cookie Policy before it starts. |
| Preventing fraud and abuse (including automatic booking limits and blocking abuse of SMS verification), enforcing our no-show policy, and securing our systems | Device data including a device fingerprint, logs, reservation history | Legitimate interests (Art. 6(1)(f)): protecting our platform, our venues and other diners from abuse. Balancing assessment available on request. |
| Recording and honouring your cookie and consent choices | Consent records (Section 9) | Legal obligation (Art. 6(1)(c), Art. 7(1) GDPR: we must be able to demonstrate consent) |
| Keeping accounting and tax records | Transaction and invoice records | Legal obligation (Art. 6(1)(c), Greek tax and accounting law) |
| Establishing, exercising or defending legal claims | The data relevant to the claim | Legitimate interests (Art. 6(1)(f)) |
5. Personalisation, marketing and automated decisions
Personalisation. We may use your reservation history, searches, saved venues and in-app activity, including through automated and machine-learning models, to order venues, suggest places you might like and, from time to time, offer you coupons. This is a limited form of profiling. It never uses your special request notes or other sensitive data, no venue can pay to be shown to you this way, and no decision with legal or similarly significant effects is made about you through it.
Your right to object. You can object to personalisation and profiling at any time by emailing us at support@edrink.gr. If you object to personalisation for direct marketing purposes, we stop immediately and unconditionally. The app keeps working; you simply see non-personalised results.
Marketing. We send marketing emails and push notifications only if you have opted in, and every marketing message tells you how to stop them. Push notifications can also be turned off in the app or your device settings.
Automated decisions. To run bookings fairly and protect venues, some decisions are made automatically:
- a reservation is recorded as a no-show if the venue has not recorded your arrival within 6 hours after the reservation ends; under the venue's cancellation policy, this can mean the venue keeps some or all of a prepaid amount;
- an account with repeated no-shows or cancellations, or too many reservations created or left open, may be temporarily unable to book;
- phone numbers, IP addresses or devices used to abuse our SMS verification are blocked.
These decisions are necessary for our contract with you (GDPR Art. 22(2)(a)). You can ask for any of them to be reviewed by a person, give your view and contest it at support@edrink.gr or through our live chat; if a no-show was recorded wrongly, we correct it and any amount retained is refunded (Terms of Use, Section 6). A venue can also choose not to take bookings from you; the app then declines your requests at that venue, and that is the venue's decision.
6. edrink and venues: who is responsible for what
6.1 When you book
To fulfil your reservation, we send the venue: your first and last name, phone number, email address, party size, the date and time, your booking status, and any special request notes. Where a note contains sensitive information (allergies, dietary needs), we send it only on the basis of your explicit consent, given as described in Section 3; the venue may keep it in its guest records solely to serve you on future visits, until you withdraw your consent or request deletion. We do not send the venue your location or your activity on edrink, including your bookings at other venues.
From the moment the venue receives this data, it processes it as an independent data controller under its own responsibility and its own privacy policy, for example to prepare your table or comply with its own legal obligations. Our agreements with venues allow them to use data received through edrink only to manage and honour your reservations, contact you about them and your visit, handle cancellations, no-shows and refunds, keep their own reservation history and guest records for their own venue(s), and meet their legal obligations. They may not sell it or pass it to other businesses, other than their own service providers, and may not use it for marketing unless you opt in (Section 6.2). We are not responsible for a venue's own processing. Ask the venue directly about its privacy practices.
6.2 Venue marketing
Venues may not use the contact details they receive through edrink for their own marketing unless you separately opt in to that venue's communications. If you do opt in, the venue is solely responsible for that marketing and for honouring your opt-out.
6.3 Where we work for venues
We provide venues with reservation-management tools (their digital reservation book). When we host and maintain a venue's guest records in those tools, we act as the venue's processor under a data processing agreement (GDPR Art. 28): the venue decides what happens to its guest book, and we act on its instructions.
Where a venue moves to edrink from another reservation system, we may, at the venue's request, import the venue's existing guest and reservation records into that venue's own records on our platform. The venue is responsible for ensuring it may lawfully transfer this data and for informing the people concerned. We act only as the venue's processor for these records and for the records a venue enters itself: they are never used for our own purposes, never feed our recommendations, are never shared with any other venue, and no marketing to you results from them. The venue decides how long it keeps its guest records. Two things do happen within that venue only: when you book it on edrink with the email address and phone number held in a record in its guest book, we link the two so the venue sees one guest history, including any notes it keeps about you; and if the venue has chosen not to take bookings from you, we decline your requests at that venue.
6.4 Venue owners and staff
If you use edrink Manager on behalf of a venue, we process your name, work email address, phone number, login credentials, activity logs and crash reports from the edrink Manager app to provide the venue with the service, keep the account secure and meet our legal obligations (contract with the venue, Art. 6(1)(b), and our legitimate interest in security, Art. 6(1)(f)). We keep this data for the term of the venue's agreement with edrink and for the limitation periods that follow. The recipients, transfers, security measures and rights described in this policy apply to you in the same way. The venue's own guest records are a separate matter: for those, the venue is the controller and we act as its processor (Section 6.3).
7. Who else receives your data
We never sell your personal data. Beyond venues (Section 6), your data is handled by the providers below. Most act as processors on our instructions under GDPR Art. 28 contracts; the ones marked † act as independent controllers under their own privacy policies.
| Provider | What it does for us | Processing location | Transfer safeguard |
|---|---|---|---|
| DigitalOcean | Hosting of our servers and databases | Frankfurt, Germany (EU) | EU processing; Standard Contractual Clauses in our data processing agreement for any access from outside the EEA |
| Stripe † | Payments, deposits, payouts to venues (independent controller for its own regulatory obligations, e.g. anti-fraud and financial compliance) | EU / US | EU-US Data Privacy Framework; SCCs |
| Google Ireland Ltd (Firebase, Google Analytics 4) | App infrastructure (sign-in, push notifications) and, only with your consent, crash reports and analytics for the app and the website | EU / US | EU-US Data Privacy Framework; SCCs |
| Google (Reserve with Google) † | Bookings you start on Google (independent controller for your interaction with Google's own services) | EU / US | EU-US Data Privacy Framework |
| Partner booking apps and websites † | Where you book through a partner app or website integrated with edrink: the status of that reservation (confirmed, changed, cancelled), so the partner can show it to you | EU; where a partner processes data outside the EEA, one of the safeguards in Section 8 | Not applicable (EU processing), or as stated in Section 8 |
| Usercentrics A/S (Cookiebot) | Consent management on the website: shows the cookie banner, applies your choice and keeps the record of it | Denmark (EU) | Not applicable (EU processing) |
| Twilio / SendGrid | Twilio: SMS verification codes. SendGrid: booking emails (confirmations, reminders) | US | EU-US Data Privacy Framework; SCCs |
| BulkerSMS | SMS verification codes (Greece) | Greece (EU) | Not applicable (EU processing) |
| ClickSend | SMS verification codes | Australia | Standard Contractual Clauses |
| Intercom | Support chat | US | EU-US Data Privacy Framework; SCCs |
| Mapbox | Maps in the app and the booking widget: the map area shown (which may be centred on your location), IP address and device information | US | EU-US Data Privacy Framework |
| Apple and Google (Apple Wallet, Google Wallet) | Your digital booking pass, if you add it (name, venue, date and time, booking code) | US | EU-US Data Privacy Framework |
| AppsFlyer | Mobile install attribution (only with your consent) | EU / Israel | European Commission adequacy decision for Israel |
| Apple / Google / Meta † | Social login, if you choose it (independent controllers for the sign-in service itself) | US | EU-US Data Privacy Framework |
| Accountants, auditors, lawyers † | Professional services under confidentiality (independent controllers by law) | Greece (EU) | Not applicable (EU processing) |
We may also disclose data where the law requires it (for example to tax authorities, courts, or the police on a valid legal order), and, in the event of a merger, acquisition, corporate restructuring or sale of assets, to the parties and advisers involved; see Section 13.
8. International data transfers
Your data is stored on servers in Frankfurt, Germany, inside the EU. Some of the providers listed in Section 7 process data in the United States, Israel or Australia. Where that happens, the transfer is protected by one of the GDPR's approved mechanisms, as listed per provider in the table above: the European Commission's adequacy decisions (including the EU-US Data Privacy Framework for certified US providers, and the adequacy decision for Israel), and/or the Commission's Standard Contractual Clauses together with supplementary measures where needed. You can request a copy of the relevant safeguards by contacting us.
9. How long we keep your data
| Data | How long | Why |
|---|---|---|
| Account data | While your account is active. | Providing the service |
| Reservation history (no payment involved) | While your account is active; deleted or pseudonymised when you delete your account. Venues keep their own copy in their guest records (see below). | Providing the service; no-show enforcement |
| Reservations and notes in a venue's guest records on edrink, including reservations made without an edrink account (Reserve with Google, partner apps and websites, a venue's booking link or widget) | For as long as the venue keeps them: the venue decides as controller (Section 6.3). We delete them when the venue does, when you withdraw consent for a sensitive note, or when the venue stops using edrink | Hosting the venue's records on its instructions |
| Transaction and invoice records (deposits, prepayments) | 5 years, or up to 10 years where Greek tax law requires it, with identifiers accessible only on a need-to-know basis | Greek tax and accounting law |
| Special request / dietary notes | Kept with your reservation history, and in the guest records of the venue(s) you shared them with, until you delete them, withdraw consent, or delete your account | Your explicit consent |
| Support conversations | 2 years after the ticket closes | Service quality, dispute handling |
| Analytics data (website and app) | 14 months | Product improvement |
| Crash reports | 90 days | Keeping the app working |
| System and security logs | 12 months | Security, fraud prevention |
| Backups | Rolling ~90 days | Disaster recovery |
| Website cookie consent records (Cookiebot) | 12 months from your choice; a new record is created each time you change it or the banner asks again | Demonstrating consent (Art. 7(1)) |
| Other records of consent given and withdrawn (marketing, dietary notes, app permissions) | 5 years after withdrawal | Demonstrating compliance (Greek limitation periods) |
Where we must keep transaction records for tax law after you delete your account, we pseudonymise them: your name, contact details and any notes are removed from operational systems and the retained record is accessible only for the legal purpose. We are transparent that this is pseudonymisation: the retained record remains subject to the GDPR and to the protections in this policy until it is finally deleted.
10. Cookies, SDKs and consent
We use cookies and similar technologies (including mobile SDKs) as described in our Cookie Policy, available on our website. Strictly necessary cookies run without consent. Everything else (analytics, crash reporting, attribution and any advertising technology) runs only after you consent through our consent banner (web) or consent screen (app), as required by Greek Law 3471/2006. On the website, consent is managed through Cookiebot with "Accept" and "Reject" given equal weight, and we use Google Consent Mode in basic mode: no Google analytics or advertising script loads until you accept. You can change your choices at any time via the "Cookie settings" link in the website footer or the app's settings, and on iOS we additionally respect your App Tracking Transparency choice.
11. Your rights
Under the GDPR you have the right to:
- Access your data and get a copy (Art. 15);
- Correct inaccurate data (Art. 16); you can edit most of it yourself in account settings;
- Delete your data (Art. 17); see Section 12 for the self-serve path;
- Restrict processing while a dispute or verification is pending (Art. 18);
- Portability: receive the data you gave us in a machine-readable format, or have it sent to another provider (Art. 20);
- Object (Art. 21); see the box below;
- Withdraw any consent at any time (Art. 7(3)), as easily as you gave it, without affecting past processing.
Right to object (Article 21 GDPR). Where we process your data on the basis of legitimate interests (personalisation, fraud prevention), you have the right to object at any time, on grounds relating to your particular situation. Where your data is used for direct marketing, you can object at any time, without giving any reason, and we will stop immediately.
How to exercise your rights: in your account settings, or by emailing support@edrink.gr. We respond within one month (extendable by two further months for complex requests; if so, we will tell you within the first month). Exercising your rights is free; we may ask you to verify your identity so we do not hand your data to someone else. We will only refuse or charge for requests that are manifestly unfounded or excessive, and we will explain why (Art. 12(5)).
Complaints. You can lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, www.dpa.gr, contact@dpa.gr, +30 210 6475600, or with the supervisory authority of the EU country where you live or work. We would appreciate the chance to resolve your concern first, but you do not have to contact us before going to the authority.
12. Deleting your account and data
You can delete your account in three ways: from the app (account settings), via the account-deletion form on our website, or by emailing us at support@edrink.gr.
When you delete your account we erase your profile, preferences, saved venues, dietary notes and support history from our live systems within 30 days; copies in encrypted backups expire automatically within roughly 90 days. Transaction records that Greek tax law obliges us to keep are pseudonymised as described in Section 9 and deleted at the end of the statutory period. If you signed in with Apple, Google or Facebook, we also revoke the connection on our side. Upcoming reservations stay valid with the venue unless you cancel them. Venues you booked with keep their own record of your reservations; we pass your deletion request on to them.
13. Security, age limits, and corporate changes
Security. All traffic is encrypted in transit (TLS); passwords are stored hashed; access to personal data is limited to people who need it; our processors are bound to equivalent standards. If a personal data breach occurs, we will notify the Hellenic DPA within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to you. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay.
Age limits. edrink is a service for booking venues that serve alcohol; you must be 18 or older. We do not knowingly collect data from anyone under 18, and we delete such data if we become aware of it.
Corporate changes. If edrink is involved in a merger, acquisition, corporate restructuring (including a change of the group parent company) or sale of assets, your data may be transferred to the successor entity. Any successor remains bound by this policy, and your data remains protected by the GDPR regardless of where the new controller is established. If the controller of your data changes, we will inform you prominently, in the app and by email, before the change takes effect, and remind you of your rights, including deletion.
14. Changes to this policy
When we change this policy, we will post the new version here with a new date. For material changes (new purposes, new categories of recipients, changes to your rights) we will notify you in the app or by email before the change takes effect, and where a new processing purpose requires consent, we will ask for it rather than assume it. Previous versions are available on request.
Language. This policy is published in English and in Greek. In case of any discrepancy between the two versions, the English version prevails; your rights under the GDPR are not affected by this.
15. Contact us
edrink Private Company (Ι.Κ.Ε.)
11-13 Aristotelous St, Athens 104 32, Greece
support@edrink.gr
Supervisory authority: Hellenic Data Protection Authority, Kifissias 1-3, 115 23 Athens. Website: www.dpa.gr. Email: contact@dpa.gr. Phone: +30 210 6475600.