Last updated: 30 July 2026
This Privacy Policy explains how Grabilio processes your personal data when you use our website and ordering service, in accordance with the EU General Data Protection Regulation (GDPR).
Grabilio is the controller responsible for your personal data. For any privacy question, contact us at privacy@grabilio.com.
Account details (name, email), order information (items, table or pickup slot, payment status), and technical data such as your approximate location and device information. Payments are processed by Stripe; we never store your full card details. If you ask us to notify you when an order is ready, we store the push endpoint your browser gives us — an address for that browser install, nothing about you.
To create and manage your orders, process payments, show nearby venues, provide customer support, and meet our legal obligations.
Essential cookies keep you signed in and remember your preferences (such as language, location and your cookie choice). They are required for the service to work and cannot be switched off. If you arrive through a campaign link, we also store which link brought you here for 30 days. You can review or withdraw your analytics choice at any time via “Cookie settings” in the footer.
With your consent we use Plausible Analytics, a privacy-friendly tool hosted in the European Union, to understand how the service is used and to improve it. Plausible does not use cookies and does not collect personal data or track you across websites or devices. It records only aggregated statistics, such as the pages visited, the referring website, country, and device type. You can accept or decline analytics from the cookie banner at any time.
We share your data with the venue fulfilling your order, and with the service providers we use to run Grabilio: payment providers (Stripe, and Square or Revolut where a venue uses them) to take your payment; Resend to send order emails and invoices; the WhatsApp Business Platform (Meta) if you give a phone number and the venue sends status updates that way; your browser's push service if notifications are enabled; Vercel for hosting, image storage and server logs; Neon for our database; Upstash for abuse protection; Sentry for error monitoring; Plausible for analytics, only after you consent; Google Maps for city search; and Google or Facebook only if you choose to sign in with them. Which of these apply depends on the venue and the features you use. We never sell your personal data.
We keep order records for as long as required for accounting and legal purposes, and account data until you ask us to delete it. A push subscription for an order is deleted as soon as that notification has been sent, and in any case together with the order it belongs to.
Under the GDPR you have the right to access, correct, delete or export your data, and to object to or restrict its processing. To exercise these rights, contact privacy@grabilio.com and we will reply within one month. Where an order carries a tax invoice, the law requires us to keep that invoice: in that case we remove or anonymise everything else and retain only the invoice for the statutory period.
For any question about this policy or your personal data, email privacy@grabilio.com.