Privacy Policy

Last updated: 27 June 2026

This Privacy Policy describes how GudFood Work collects, uses, stores, shares, and protects your personal data when you use the GudFood Work mobile application and related services (collectively, the "Service"). We are committed to protecting your privacy and handling your personal information in a transparent, lawful, and proportionate manner. Please read this document carefully. If you have any questions, you may contact us at any time using the details provided below.

1. Who We Are and How to Contact Us

GudFood Work operates across two jurisdictions — Poland (European Union) and Ukraine — under separate legal entities. Your data is processed by the entity corresponding to the region you selected when creating your account.

Data Controller for Poland (GDPR-regulated):

GudFood Work / IULIIA GUDKOVA
ul. Solinska 19A lok. 79
02-142 Warszawa, Poland
NIP: 5223248372
Email: [email protected]

Data Controller for Ukraine:

ФОП ГУДКОВА ЮЛІЯ МИКОЛАЇВНА (sole trader HUDKOVA YULIIA MYKOLAIVNA)
Individual Tax Number (ITN): 3111719760
Ukraine, Kyiv
Email: [email protected]

We have not appointed a formal Data Protection Officer (DPO), as we do not meet the thresholds for mandatory DPO appointment under Article 37 GDPR. However, all data protection enquiries, requests, and concerns are handled directly by the data controller through the contact address above: [email protected].

We aim to respond to all privacy-related communications within 30 calendar days of receipt. For complex or high-volume requests, we may extend this period by a further 60 days, in which case we will notify you of the extension within the initial 30-day window.

2. What Data We Collect

We collect personal data that is necessary to provide the Service to you and your employer. We do not collect data beyond what is reasonably required for the purposes described in this Policy. The categories of personal data we process are as follows:

2.1 Identity and Account Data

When your employer onboards you onto GudFood Work, or when you complete your profile, we collect:

2.2 Order Data

Every meal order you place through the app generates the following records:

2.3 Payment Data

We process payment data in order to charge any user-paid portion of meal costs. The specific data we hold is limited to:

We do not store, transmit, or have access to full card numbers, CVV codes, PINs, or any other sensitive authentication data. All such data is handled exclusively by the respective payment provider under their own PCI DSS-compliant infrastructure.

2.4 Reviews, Ratings, and Meal Photos

2.5 Device and Technical Data

2.6 Crash Logs and Diagnostics

If the app crashes or encounters an unhandled error, Firebase Crashlytics automatically collects:

Crash logs do not contain your name, email, order history, or payment information. They may contain your device's advertising identifier (IDFA/GAID) in anonymised form depending on your device privacy settings.

2.7 Analytics Events

Firebase Analytics collects the following categories of behavioural data to help us understand how the app is used and improve the Service:

Analytics events are associated with a pseudonymous Firebase installation ID, not your name or employee ID. We do not use analytics data to make individual decisions about you.

2.8 Push Notification Interaction Data

We track whether push notifications we send to you are opened (tapped). This helps us assess whether our notifications are useful and relevant. We do not track the content of your interactions once you are inside the app following a notification.

2.9 Support Messages

If you contact us via email at [email protected] for support purposes, we retain the content of your messages and our replies. This data is used solely to resolve your query and is not used for any other purpose.

2.10 Session Tokens

3. Legal Basis for Processing

Under the General Data Protection Regulation (GDPR), all processing of personal data must be justified by one of the lawful bases set out in Article 6. The table below maps each processing activity to its legal basis.

Processing Activity Legal Basis (GDPR Article) Notes
Account creation and login Art. 6(1)(b) — Performance of a contract Necessary to provide you access to the Service contracted by your employer
Order processing and delivery Art. 6(1)(b) — Performance of a contract Core service delivery cannot function without processing order data
Payment processing Art. 6(1)(b) + Art. 6(1)(c) — Contract + Legal obligation Payment processing is required to fulfil orders where a user-paid portion exists; transaction records are legally required under applicable tax law in Ukraine and Poland
Transactional push notifications (order status updates) Art. 6(1)(f) — Legitimate interest Keeping you informed of your order status is a core part of the service; our legitimate interest is not overridden by your interests
Marketing push notifications Art. 6(1)(a) — Consent We send marketing notifications only where you have actively enabled them in the app's notification settings
Analytics and crash reporting Art. 6(1)(f) — Legitimate interest Improving app reliability and user experience; data is pseudonymous and does not support individual profiling decisions
Customer support communications Art. 6(1)(f) — Legitimate interest Resolving user issues and maintaining service quality; our legitimate interest in providing good support is not overridden
Review photos uploaded by users Art. 6(1)(a) — Consent Users actively choose to upload photos; the system requests camera/photo library permission explicitly and separately
Loyalty and rewards programme tracking Art. 6(1)(b) — Performance of a contract The loyalty programme is a contractual feature of the Service; tracking points and rewards is required to deliver it
Retention of financial records after account closure Art. 6(1)(c) — Legal obligation Ukrainian and Polish law require retention of financial and tax records for a minimum of 5 years

4. Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The table below sets out our retention periods for each category of data.

Data Type Retention Period Reason
Session tokens (access + refresh) 30 days maximum (refresh token lifespan); access tokens expire in 15 minutes Security — tokens are invalidated on logout or expiry
Order history 5 years from the date of the order Ukrainian and Polish tax law requirements for financial record-keeping
Payment records (transaction ID, amount, status) 5 years from the date of the transaction Financial record-keeping obligations under applicable tax law
Review photos Until the user deletes the photo or the account is closed User-controlled content; the user retains full control over deletion
Text reviews and star ratings Until deleted by the user or account closure; anonymised aggregate data retained indefinitely Anonymised averages (e.g., average dish rating) have no personal data dimension
Crash logs and analytics events 90-day rolling window Operational necessity for bug diagnosis; older data has no utility for current app versions
Push notification tokens Until the token is revoked by the device, the user unregisters from notifications, or the account is closed Required for service delivery of push notifications
Customer support messages 2 years from the date of the communication Dispute resolution and follow-up support requirements
Account identity and profile data Deleted within 30 days of a verified deletion request User's right to erasure under Art. 17 GDPR; note that financial records are retained per tax law even after account deletion
Device and technical data 90 days from collection (via Firebase) Technical diagnostics and compatibility monitoring

5. Third-Party Data Processors

We share personal data with the following third-party processors, each of whom processes your data only on our behalf and under contractual terms that require them to protect it appropriately. We have carried out a proportionality assessment for each processor relationship.

Processor Purpose Data Transferred Privacy Policy / Terms
Google Firebase (Analytics, Crashlytics, FCM) App usage analytics, crash and error reporting, delivery of push notifications Pseudonymous device identifiers, event data, crash traces, push tokens policies.google.com/privacy
Monobank (Ukraine payments) Processing payments for Ukrainian-region users Transaction amount, order reference; card data handled directly by Monobank monobank.ua/legal
Przelewy24 (Poland payments) Processing payments for Polish-region users Transaction amount, order reference; card data handled directly by Przelewy24 przelewy24.pl/regulamin
Apple Inc. (Apple Pay) Tokenised payment processing for iOS users who choose Apple Pay Tokenised payment credential; Apple does not share card details with us apple.com/legal/privacy
Google LLC (Google Pay) Tokenised payment processing for Android users who choose Google Pay Tokenised payment credential; Google does not share card details with us Google Pay Privacy Notice
Contabo GmbH (Server hosting) Infrastructure and server hosting for the GudFood Work API backend (api.gudrouting.com) All data processed by our API; Contabo provides infrastructure only and does not access application-level data contabo.com/en/legal/privacy

We do not sell, rent, or trade your personal data to any third party. We do not share your data with advertisers, data brokers, or any entity for their own independent marketing or commercial purposes.

6. Your Rights as a Data Subject

If you are located in the European Economic Area (EEA), or if you are a Ukrainian user whose data is protected under Ukrainian data protection law, you have a number of rights with respect to your personal data. We take these rights seriously and provide mechanisms to exercise each of them.

6.1 Right of Access (GDPR Article 15)

You have the right to obtain confirmation of whether we process personal data about you, and if so, to receive a copy of that data along with information about: the purposes of processing; the categories of data concerned; the recipients or categories of recipients; the retention period; and the source of the data (if not collected directly from you). We will provide this information in a commonly used electronic format such as PDF or JSON upon request.

6.2 Right to Rectification (GDPR Article 16)

If you believe that personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it. We will act on verified rectification requests within 30 days. Note that certain data — such as your employee identifier — is linked to your employer's legacy system and may require your employer's HR department to update the source record.

6.3 Right to Erasure — "Right to be Forgotten" (GDPR Article 17)

You have the right to request the deletion of your personal data when: the data is no longer necessary for the purposes for which it was collected; you withdraw consent (where processing was based on consent); you object to processing and no overriding legitimate grounds exist; or the data has been unlawfully processed. We will process your erasure request within 30 days. Note that financial and tax records (order history and payment records) are retained for 5 years under applicable law even after account deletion — this is a legal obligation we cannot waive on your behalf.

6.4 Right to Restriction of Processing (GDPR Article 18)

You have the right to request that we restrict (i.e., suspend) processing of your data in the following circumstances: you contest the accuracy of the data (for the period while we verify it); the processing is unlawful but you prefer restriction over erasure; we no longer need the data but you require it for legal claims; or you have objected to processing and we are assessing whether our legitimate grounds override your objection.

6.5 Right to Data Portability (GDPR Article 20)

Where processing is based on consent or a contract and is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly used, machine-readable format (JSON or CSV), and to transmit that data to another controller. Upon request, we will provide your account data, order history, and preference settings in JSON format.

6.6 Right to Object (GDPR Article 21)

You have the right to object at any time to processing of your personal data that is based on our legitimate interests (Art. 6(1)(f)), including for direct marketing purposes. Where you object, we will cease that processing unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims.

6.7 Right to Withdraw Consent (GDPR Article 7(3))

Where we process your data based on your consent (e.g., marketing push notifications, or uploading meal photos), you may withdraw your consent at any time without detriment. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. You can withdraw consent for push notifications via your device's notification settings or within the app's profile settings. You can withdraw consent for photo uploads by revoking camera/photo library permissions in your device settings at any time.

6.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority at any time if you believe your rights have been violated:

We encourage you to contact us first to resolve any concerns, but you are always free to contact the supervisory authority directly.

How to Exercise Your Rights

To exercise any of the rights listed above, please email us at: [email protected]

Subject line: Data Subject Request

Please include: your registered name, the email address or login associated with your account, and a clear description of the right you wish to exercise. We may ask you to verify your identity before processing the request. We will respond within 30 calendar days.

7. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you within the meaning of Article 22 GDPR. Specifically:

8. Personal Data Breach Notification

In the event that we discover a personal data breach — defined as a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data — we will take the following steps:

9. International Transfers of Personal Data

Our primary API server infrastructure is hosted by Contabo GmbH in Germany (within the EEA). However, certain services we use may process data on servers located outside the EEA:

9.1 Google Firebase

Google Firebase services (Analytics, Crashlytics, FCM) may process data on servers located in the United States and other countries outside the EEA. Google has implemented adequate safeguards for these international transfers through:

A list of Google's sub-processors is available at policies.google.com/privacy.

9.2 Payment Processors

Monobank (UA) operates within Ukraine. Przelewy24 (PL) operates within Poland. Apple Pay and Google Pay may process tokenised credentials through international infrastructure; however, as these processors handle only tokenised data (not your full card details), the residual risk of international transfer is minimal. Both Apple and Google maintain GDPR-compliant transfer mechanisms including SCCs.

9.3 Ukraine-Specific Note

Ukraine is not a member of the EEA. For Ukrainian users whose data is transferred to EEA-based servers (e.g., our Contabo infrastructure in Germany), this transfer is handled within the scope of our legitimate operational necessity and applicable Ukrainian data protection requirements. We apply equivalent protections to Ukrainian users' data regardless of where it is processed.

10. App Permissions We Request

The GudFood Work app requests the following permissions from your device. We request only the permissions we actually need:

Permission Platform Purpose Can You Deny It?
INTERNET Android, iOS Required for all core app functionality — communicating with our API at api.gudrouting.com, loading menus, placing orders, processing payments No — the app cannot function without internet access
POST_NOTIFICATIONS Android 13+ (API 33+) Required to deliver push notifications about order status, loyalty rewards, and (if enabled) marketing messages Yes — denying this permission means you will not receive push notifications, but all core ordering and payment features remain functional
Notifications permission iOS Same as POST_NOTIFICATIONS above; iOS prompts you during onboarding Yes — you may deny this during onboarding or revoke it later in iOS Settings
Camera iOS and Android Requested only when you choose to take a new photo for a food review; not requested at any other time Yes — you may deny or revoke this permission at any time. You can still submit reviews without photos.
Photo Library / Gallery access iOS and Android Requested only when you choose to upload an existing photo from your gallery for a food review Yes — you may deny or revoke this permission at any time

11. Local Data Storage

GudFood Work uses encrypted local storage for all sensitive data stored on your device. We do not use traditional browser cookies or unencrypted local storage mechanisms.

12. Children and Age Restriction

GudFood Work is a professional corporate meal ordering service intended exclusively for employed adults. Use of the Service requires a valid corporate account linked to an employer that has contracted GudFood Work. We require users to be at least 18 years of age.

We do not knowingly collect personal data from children under the age of 16. If you are a parent, guardian, or employer representative and you believe that a child under 16 has provided personal data to GudFood Work, please contact us immediately at [email protected]. We will promptly investigate and delete the data if confirmed.

13. Account Deletion

You have the right to request deletion of your GudFood Work account and associated personal data at any time. To do so:

  1. Send an email to [email protected]
  2. Use the subject line: Delete my account
  3. Include in the body: your full registered name and your employee identifier (visible in your Profile screen within the app)
  4. We will verify your identity and confirm receipt within 5 business days
  5. We will complete account deletion within 30 calendar days of your verified request

Important note on data retained after deletion: Even after your account is deleted, we are required by Ukrainian and Polish tax law to retain financial records — specifically your order history and payment transaction records — for a period of 5 years from the date of the relevant transaction. This retained data is held in a restricted-access archive and is not used for any service-delivery or marketing purpose. All other personal data (name, device tokens, push notification history, support messages beyond 2 years, analytics identifiers) will be erased within the 30-day window.

14. Force Majeure — Armed Conflict Disclosure (Ukraine Operations)

Our Ukrainian operations, including data processing activities related to Ukrainian-region users, may be affected by the ongoing armed conflict in Ukraine. We operate under conditions of significant uncertainty with respect to infrastructure continuity, staff availability, and regulatory accessibility.

As a result of active military operations, infrastructure damage, power outages, or government-imposed emergency measures, the following disruptions may occur:

We will communicate any material disruptions to the Service via in-app notifications where technically feasible. We will restore normal operations — including full data protection compliance — as quickly as circumstances permit. This disclosure is provided in a spirit of transparency and does not constitute a waiver of our data protection obligations.

15. Security Measures

We implement technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:

No security system is completely impenetrable. We cannot guarantee the absolute security of your data, particularly in the context of threats outside our reasonable control. We will however notify you promptly in the event of any breach as described in Section 8.

16. US Privacy Rights (California & Other States)

This section applies to residents of California and other US states with applicable consumer privacy laws. It supplements the rest of this Privacy Policy.

California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
Cal. Civ. Code §§ 1798.100–1798.199.100

If you are a California resident, you have the following rights under the CCPA/CPRA:

How to submit a CCPA/CPRA request: Email [email protected] with the subject line "CCPA Request". We will respond within 45 calendar days. We may extend this period by an additional 45 days where reasonably necessary, with prior notice.

Categories of personal information collected (Cal. Civ. Code § 1798.110(c)):

CategoryExamplesCollected
IdentifiersName, email address, login, employee ID, device IDYes
Commercial informationOrder history, payment method typeYes
Internet or network activityApp interactions, crash logsYes
InferencesMeal preferences derived from order history (internal only)Yes
Sensitive personal informationFinancial account informationPartial — payment method type only; full card data held by payment provider
Geolocation dataPrecise locationNo
Biometric dataFingerprints, face scansNo
Audio / visualPhotosOptional — only if you add a review photo

California Online Privacy Protection Act (CalOPPA)

This Privacy Policy is publicly accessible and linked from within the GudFood Work app. We update the "Last updated" date whenever this Policy changes. We do not currently respond to Do Not Track (DNT) signals because there is no universally accepted standard for DNT; we will re-evaluate this position as industry standards develop.

Children's Online Privacy Protection Act (COPPA)
15 U.S.C. § 6501 et seq.

GudFood Work is a professional B2B service requiring a valid corporate account. Users must be at least 18 years old. We do not knowingly collect personal information from children under 13. If we discover that we have inadvertently collected personal information from a child under 13, we will delete it immediately. Contact us at [email protected] if you believe a child has submitted data.

CAN-SPAM Act (15 U.S.C. §§ 7701–7713)

We do not send commercial marketing emails. Any emails we send are transactional (order confirmations, payment receipts, account notices) and are exempt from CAN-SPAM opt-out requirements. Push notifications can be disabled at any time in app Settings or your device's notification settings.

Digital Millennium Copyright Act (DMCA) — 17 U.S.C. § 512

If you believe content in GudFood Work infringes your copyright, you may submit a takedown notice to our designated agent:

DMCA Designated Agent:
Email: [email protected]
Subject line: DMCA Takedown Notice

Your notice must include: (1) identification of the copyrighted work; (2) identification of the allegedly infringing material and its location in the app; (3) your contact information; (4) a statement of good faith belief that the use is not authorised; (5) a statement under penalty of perjury that the information is accurate and you are authorised to act on behalf of the copyright owner.

Repeat copyright infringers may have their access to content features permanently terminated.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes — meaning changes that significantly affect your rights or the way we process your data — we will:

Your continued use of the GudFood Work app after the effective date of any changes constitutes your acknowledgement of the updated Privacy Policy. If you do not agree with the changes, you may contact us to request account deletion as described in Section 13.

We recommend reviewing this Policy periodically. You can always access the current version of this Policy within the app or at this URL.

Questions about this Privacy Policy?

Contact us at: [email protected]

We are committed to responding to all privacy enquiries within 30 calendar days.