FEASTY

Privacy Policy

Last updated: 26 June 2026

The binding version is the Polish one (Terms §14.4). EN/DE are courtesy translations.

Version: privacy:0.4.0 | Last updated: 26 June 2026

This document covers the Feasty consumer app. Personal data of restaurateurs collected through the B2B Claim verification flow and the Feasty Business panel is governed by a separate privacy policy — it will be available at business.feasty.com.pl once published (planned before the first B2B monetisation). Until the dedicated B2B privacy policy is published, restaurateurs may contact the Controller at contact@feasty.com.pl regarding the processing of their data in the B2B Claim procedure — we respond individually with the full scope of information required by Art. 13 GDPR.

Definitions

For the purposes of this Privacy Policy, the following terms have the meanings set out below:

1. Data Controller

The controller of your personal data is Radosław Rodak, a natural person operating under the Polish "non-registered business activity" scheme (Art. 5(1) of the Act of 6 March 2018 — Entrepreneurs' Law), correspondence address: ul. Boya-Żeleńskiego 34, 20-435 Lublin, Poland. The Application currently operates in an early-access, free phase and does not generate revenue. Upon exceeding the non-registered business threshold or commencing registered business activity, this Privacy Policy will be updated with registration numbers (NIP, REGON, KRS) along with a version bump requiring renewed consent.

For matters relating to the protection of personal data, please contact us at: contact@feasty.com.pl.

Data Protection Officer (DPO). The Controller has not appointed a Data Protection Officer because none of the conditions under Art. 37(1) GDPR are met: the Controller is not a public authority; the core processing activities do not consist of operations requiring regular and systematic monitoring of data subjects on a large scale, nor large-scale processing of special categories of data (Art. 9) or data on criminal convictions (Art. 10). This determination will be reassessed when the non-registered business threshold is crossed or when features that change the scale of processing are launched.

2. Data we collect

Depending on how you use the Feasty app, we process the following categories of data. For each item we indicate whether providing the information is mandatory (required to create an account or use the feature) or optional (you can use the Application without providing it — Art. 13(2)(e) GDPR).

Account data

Activity data

Technical data

Location data

Your approximate GPS location — only at the moment when you search for nearby restaurants or start a Matchmaker session. We do not store a history of your location.

Contacts from your phone's address book (optional)

If you use the "Find friends" feature we will ask for one-time permission to access your phone's address book. You can revoke this permission at any time in your device's system settings (iOS Settings → Feasty → Contacts / Android Settings → Apps → Feasty → Permissions).

Once permission is granted:

Purpose: to show you which of your address-book contacts are already on Feasty so you can follow them without manually searching. The feature is fully optional — the Application works without this permission, the only consequence being the absence of the "Find friends from contacts" screen.

Legal basis: Article 6(1)(a) GDPR (User consent expressed by granting the system permission). Revoking the permission in system settings is equivalent to withdrawing consent — from that moment the feature stops working and any earlier matches are no longer displayed.

Analytics data (what we do NOT collect)

Feasty intentionally does NOT use behavioral analytics tools such as Google Analytics for Firebase, Mixpanel, Appsflyer or Adjust. We do not profile your habits, do not build marketing behavior models, do not sell data to third-party advertisers.

We collect only:

No behavioral tooling means we do NOT ask you for cookie/tracking-SDK consent banners (ePrivacy / Polish Electronic Communications Law (PKE) art. 399). Should we enable analytics in the future, we will ask for your explicit consent before activation.

Anonymous metrics for B2B partners

When you tap "Call", "Reserve", "Directions", "Menu", "Share", a delivery link or add a place to your "Saved" list, we increment an anonymous counter of how many such actions happen per restaurant per day. The counter:

Restaurateurs who have claimed their venue in Feasty Business (B2B Claim procedure, manually reviewed by an administrator) see daily aggregated statistics of THEIR restaurant in their dashboard panel:

Under the Premium plan, restaurateurs additionally see anonymised industry comparisons — the median score and tag distribution across a set of at least 5 similar venues in the same cuisine and area. The restaurateur NEVER sees the names of competitors. We do not disclose the composition of the comparison set either — we only show "compared with 5-9 / 10-19 / 20+ similar venues". Your venue may be used in comparisons presented to other B2B partners in your category and location — but only as an anonymised median, never by name.

If a category (tag) would contain fewer than 5 unique review authors, the owner panel shows "Insufficient data" instead of a percentage — this protects authors of individual reviews from identification (k-anonymity threshold, Art. 4(5) GDPR).

Legal basis: counters are anonymous aggregates within the meaning of GDPR Recital 26 — without person-level identifiers they do not allow direct or indirect identification of a User (k-anonymity threshold of 5 applies to tag distribution). To the extent that the moment of the tap might be momentarily linked to your session on the server side before the counter is incremented, the legal basis is Art. 6(1)(f) GDPR (legitimate interest of the controller in metric integrity + interest of restaurateurs in receiving aggregated traffic).

Right to object (Art. 21 GDPR): you may object at any time to your anonymous taps being counted in B2B metrics by writing to contact@feasty.com.pl. Once your objection is recorded, future interactions stop being counted (we flag the account so the server honours the objection on every subsequent counter increment). The objection cannot apply retroactively — the counters are already anonymous and contain no identifier that could be removed.

Matchmaker

Matchmaker is a feature for choosing a restaurant together — you and your friends join a single session via a 6-character code and swipe through 20–30 nearby venues to quickly pick a place for a shared meal.

Session data processed:

Sessions are stored as single documents in the database and automatically closed after 24 hours of inactivity. A complete session (members + swipes) is deleted within 30 days of being closed. You can manually delete any session you have created.

We do not use Matchmaker data for profiling or to train any models — it operates strictly in real time for session participants.

Legal basis: Art. 6(1)(b) GDPR (contract performance — providing the social feature you knowingly joined).

Feasty AI — generated restaurant summaries

The Application uses a generative AI model (Vertex AI Gemini, hosted exclusively in the europe-west1 region — Belgium) to produce two types of summaries visible on the restaurant screen:

Guarantees enforced by our processing:

Audit logs: every generation is recorded in an internal audit collection (aiOutputAudits) with the SHA-256 hash of the model instruction (the raw instruction is never stored), a truncated result (≤ 4096 chars), model metadata and a 90-day retention period. Purpose: internal quality audit and documentation for defending against potential restaurateur claims (AI Act §11.2).

Legal basis for Level A generation (restaurant summary from public community reviews): Art. 6(1)(f) GDPR — legitimate interest of the controller and Users in receiving a synthetic overview of content that Users publish as public Content in the application. Reviews passed to the model come from already-public Content; the Art. 21 objection (described above) excludes a given person's contribution from the aggregate.

Legal basis for Level B generation (personalised intro for you, built from placeholder tokens representing people in your social network and their public activities): Art. 6(1)(f) GDPR — legitimate interest of the User (you) in receiving a personalised recommendation based on the public activities of your network + legitimate interest of the people in your network in having their publicly expressed opinions help other Users choose restaurants (consistent with the inherently public nature of reviews and follows in the app). Data of people in your network is passed to the model only as placeholder tokens (e.g. friend_1, friend_2) — Vertex AI never receives their names or identifiers. Any such person may at any time exercise the Art. 21 objection against their contribution — their data is then excluded from both Level A and Level B.

Legal basis for audit logging: Art. 6(1)(c) GDPR (legal obligation arising from AI Act Art. 50 — origin transparency for AI-generated content) and Art. 6(1)(f) GDPR (legitimate interest of the controller in defending against claims related to AI-generated content).

Photos in reviews

Photos you attach to restaurant reviews are stored in Cloud Storage in the European-region bucket. To clarify:

Split the bill

The "Split the bill with friends" feature helps you divide the cost of a shared meal. Within it we process:

Legal basis: Art. 6(1)(b) GDPR (performance of the contract — providing a feature you knowingly use). We do not use this data for profiling or to train models.

Feasty Events — group outings

The "Feasty Events" feature ("Propose an outing") helps you plan a get-together with friends. Within it we process:

Legal basis: Art. 6(1)(b) GDPR (performance of the contract — providing a social feature you knowingly use).

Venue Faces

A venue owner may invite you to appear on their listing as a "Venue Face" — e.g. head chef, owner or manager. The feature works only with your consent:

Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 81 of the Polish Act on Copyright and Related Rights (dissemination of likeness with authorisation).

Shared lists

Your own lists (other than the default "Favorites" and "Want to go") can be shared with friends:

Legal basis: Art. 6(1)(b) GDPR (performance of the contract). The recipients of data visible on a shared list (e.g. your name as the author of an entry) are the other co-authors of that list. The notice-and-action mechanisms are described in Art. 16 DSA.

3. Purposes and legal bases of processing

Service delivery (Art. 6(1)(b) GDPR — contract performance)

Security and abuse prevention (Art. 6(1)(f) GDPR — legitimate interest)

Product communication (Art. 6(1)(a) GDPR — consent)

Pre-registration waitlist (Art. 6(1)(a) GDPR — consent)

If, before creating an account, you leave your email on the "Request access" screen, we process this data for a single purpose: sending you one notification with an invitation to the app when we open the next access wave. Data collected: email address, timestamp of the entry, timestamp and version of this Privacy Policy at the moment of consent, source of the request, hashed (SHA-256 with a server-side pepper) IP address for spam-source auditing, truncated user-agent. Legal basis: your explicit consent (Art. 6(1)(a) GDPR). Without ticking this consent in the form, we do not store your email at all — server-side validation rejects the request.

Waitlist data is not combined with registered users' data, is not used for analytics or profiling, and is not transferred to any third parties. The invitation email is sent personally from the Controller's address.

Retention: until (a) we send you an invitation code and you register — the entry is then deleted and the consent migrates to the consent log tied to your account; OR (b) a decision not to grant access — the entry is manually deleted; OR (c) at most 12 months from the entry date without an invitation being sent. You may withdraw consent and request deletion at any time by writing to the address in section 1 — the entry will be deleted within 30 days.

4. Recipients of data

Your data may be transferred to the following categories of recipients (processors operate under data processing agreements concluded with us):

5. Transfers outside the European Economic Area

Some of our service providers, including Google LLC, Sentry and Resend, as well as selected infrastructure providers (e.g. Expo), are based or operate infrastructure outside the EEA, in particular in the United States. Personal data may therefore be transferred outside the EEA. Transfers are made in accordance with Chapter V of the GDPR, in particular on the basis of:

6. Retention periods

We retain your data for the following periods:

After account deletion, we delete or fully anonymize your data according to the scenario you select (see section 7). Maximum erasure request fulfillment time: up to 30 days. In practice most operations complete within seconds (a cascading server-side process triggered after Firebase Auth deletion); the 30-day window covers edge cases (backups expire after 14 days, the last technical markers after 30 days).

Exception: consent logs (GDPR Art. 17(3)(e))

We retain anonymized consent logs (e.g. exclusion of reviews from Feasty AI summaries, objection to B2B counters, acceptance of Terms and Privacy Policy at a given version) for 6 years after the last change. This is required by GDPR Art. 7(1) ("the controller shall be able to demonstrate that the data subject has consented") and falls under the right-to-erasure exception of GDPR Art. 17(3)(e) (data necessary for the establishment, exercise, or defense of legal claims). After account deletion only the bare event metadata remains in the log (consent type, granted/withdrawn status, timestamp, policy version) — the last identifying field (IP hash) is stripped. The 6-year period matches the limitation period for consumer claims under Polish law (KC art. 118).

7. Your rights

In connection with the processing of your personal data, you have the following rights:

Anonymize reviews (default)

Your account is deleted, while your reviews are anonymized (author changed to "Former user"). The profile photo is removed immediately; photos within the review body remain visible as social content. Social content remains visible to the community but cannot be linked back to you.

> ⚠️ Important caveat — limits of anonymization. The system automatically removes only the link between the review and your profile (author, identifier). We do NOT automatically redact the review text itself or photo contents — if you placed identifying information inside the body of a review (e.g. "I, Jan Kowalski…", "I was here with my wife Anna", your face on the photo), it remains visible despite the author label change. Within the meaning of GDPR Art. 4(5) the operation will then be pseudonymization (identifiers embedded in Content), not full anonymization. Recommendation: if full unidentifiability matters to you, before closing your account manually delete the specific reviews containing identifying information, or choose the Full erasure scenario below — in both cases Content is permanently deleted.

Full erasure (Art. 17 GDPR)

Your account and all related reviews, photos (profile + review), lists are permanently deleted.

Response deadlines

Under Art. 12(3) GDPR we respond to every request concerning your rights within 1 month of receipt. In complex cases or when we receive a large volume of requests we may extend this deadline by a further 2 months (up to 3 months in total), informing you of the extension with justification within the initial one-month period.

Exception: for account-deletion requests, the technical execution of data deletion takes up to 30 days (in practice — seconds, see section 6).

To exercise any of these rights, contact us at contact@feasty.com.pl.

8. Right to lodge a complaint

You have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO) if you believe that the processing of your data violates GDPR:

Urząd Ochrony Danych Osobowych
ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland
www.uodo.gov.pl

9. Data security

We apply adequate technical and organizational measures to protect your data against unauthorized access, loss or modification:

Personal data breach notification (Art. 34 GDPR)

In the event of a personal data breach likely to result in a high risk to your rights and freedoms (e.g. leak of identifying data, unauthorised access to your private data), we will inform you without undue delay — via a push notification in the app and/or an email to the address associated with your account. The information will describe the nature of the breach, the likely consequences, the measures we have taken or propose to take, and the contact details of the Controller's point of contact (contact@feasty.com.pl). No Data Protection Officer is appointed — see section 1.

Independently of notifying users, we report every breach to the President of the Personal Data Protection Office (PUODO) within 72 hours of becoming aware of it (Art. 33 GDPR).

10. Minimum age

Feasty is available to persons aged 16 and over. We do not knowingly collect data from persons under 16. If we discover an account belongs to a person under that age, we will delete it immediately.

11. Automated decisions and profiling

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

For fair restaurant ranking, every review is weighted by an aggregation algorithm. Your review's weight depends on (a) account age and review history, (b) your prestige rank (Standard / Elite / Connoisseur), (c) whether the visit was verified (geo-tagged photo or confirmed stamp), and (d) the review's own age (reviews older than two years count for about 15% of fresh ones). These weights affect only restaurant ranking — never decisions about your account, access to the service, or any legal consequences. Full ranking parameters are publicly disclosed to restaurant owners as required by P2B Regulation (EU 2019/1150) Art. 5.

Prestige-rank qualifying criteria (Art. 13(2)(f) GDPR — meaningful information about the logic of profiling)

The prestige rank is computed fully rule-based (NOT using AI or statistical models), based on deterministic thresholds applied per city, separately:

Quality gate (entry condition for any tier above Standard, both required):

City threshold: if fewer than 50 qualifying Users exist in a given city (meeting both quality criteria above), nobody in that city receives a rank above Standard — this protects badge meaning in low-activity cities.

Recompute cycle: the rank is re-evaluated once per week (Sunday cron). Promotion to a higher rank is immediate upon first exceeding the threshold. Demotion (loss of rank) only takes effect after a 14-day grace period — protects against weekly fluctuations in city ranking position.

Notification: we notify you of grace-period start via a push message; demotion at grace expiry is silent. Promotions are silent on the push channel (the UI surfaces the new pill anyway).

Current thresholds (200 / 10 / 50 / 14 days) are the defaults and may be tuned by the Controller in the config/prestige Firestore document. Any change that materially alters the qualification logic triggers an update of this Policy (version bump + re-consent).

12. Policy changes

This privacy policy may be updated periodically to reflect changes in how the Application works, in the law, or in how data is processed. The version and last-updated date are shown at the very top of this document. Material changes (changes to the scope of data, legal bases, categories of recipients or mechanisms for exercising your rights) will be communicated with appropriate advance notice via the Application, email or another available channel. Where applicable law requires your consent or confirmation that you have read the changes, we will ask you to take the appropriate action before continuing to use certain features of the Application. The current version accepted by you is stored in the consent log (section 6, "Exception: consent logs") — you can request an extract at any time by writing to contact@feasty.com.pl.