2. What we use and why
To handle your request, confirm availability and arrange delivery, we use your restaurant name, contact person, email or phone number, selected trays and quantities, their prices, delivery interval and preferred date. We also use the delivery address and any notes you choose to add. We do not collect card details or process payments on this website.
When you are the person placing the contract, we use these details to take steps at your request and perform the contract. When you act for a restaurant, our legitimate interest is to manage that business relationship and communicate with its representative. We need the required fields and at least an email address or phone number to process an order. The delivery address is required; notes are optional.
After ordering, you can tell us whether you were looking for other crops or products. Answering is optional. We use your response to handle your enquiry and improve the range, based on our legitimate interest in providing and improving the service. Please avoid including sensitive information or unnecessary details about other people.
The services that host and protect the website receive the technical information needed for a connection, such as your IP address and request information. Our legitimate interest is to keep the service secure, diagnose faults and prevent duplicate or abusive requests. We also retain information required by applicable legal, tax or accounting obligations.
We do not sell your data or share it so other companies can advertise to you. This website does not use advertising trackers. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
Only with your consent, we use PostHog to understand usage of this website: pages and crops viewed, clicks, filters, scrolling, selection changes, order steps and errors. A random browser identifier links these actions without linking them to your name, email or customer account. You can separately allow session replay, which lets us review browsing to identify difficulties. Analytics must be enabled for replay to work. We hide form fields and exclude account, sign-in, order confirmation and restaurant suggestion areas. We do not send passwords, codes, tokens, coordinates, contact details, addresses or the text you type. This usage data is processed in the United States. Declining both options does not stop you browsing or ordering. You can withdraw or change consent through “Privacy settings” in the footer; withdrawal stops new collection and removes optional identifiers from this browser without affecting earlier lawful processing.
3. Restaurant search and location
Once you type at least three characters in the restaurant name, we send that search and the selected language through our server to Amazon Location to suggest restaurants, cafés and bars. Names and addresses come from the provider’s place data. This assistance serves our legitimate interest in making it easier to place orders with accurate details. You can ignore suggestions and enter the details yourself. If you select a suggestion, its name and address may become part of your draft and order.
“Use my location” is optional. We only request your position when you press the button and allow access in your browser. With your consent, we send the coordinates to our server and Amazon Location to obtain an address. We do not save those coordinates in the order, local storage or our application logs. The address you accept may be saved. You can deny or revoke the browser permission and type the address yourself; revoking permission does not erase an address already submitted.
4. Providers and processing outside Europe
Amazon Web Services (AWS) hosts the website, API and order database. Amazon Location receives restaurant searches and, if you allow it, coordinates to suggest an address. The main order database is in Germany, in the Frankfurt region. The website is delivered through AWS’s global network.
Slack receives order notifications and follow-up answers so the MicroVerdes team can handle them. Notifications may contain restaurant and contact details, the address, notes, selection, total and delivery dates. Access is intended for the team handling orders. This involves an external service provider, even though we do not share your details for advertising.
If you allow analytics or session replay, we use PostHog Cloud in the United States to process that browsing data on behalf of MicroVerdes, under the provider’s processing terms. See PostHog’s privacy policy and its data processing agreement, including the safeguards it sets out for international transfers.
These services may process data outside the European Economic Area. AWS incorporates the European Commission’s standard contractual clauses into its processing terms for transfers to which they apply; Slack offers these clauses through its data processing agreement. See AWS’s terms and data processing at Slack. You can ask our privacy contact about the safeguards that apply to your data. We may also disclose information when required by law.
5. Storage in your browser
We use localStorage to remember your language, restore a selection and manage order confirmation. This browser storage is different from a cookie. We use sessionStorage to keep your menu filters and, when you sign in, your account session in this tab. We remember your privacy choice, including a decision to reject analytics. Optional PostHog storage is allowed only after your consent. We do not use this information for advertising or to follow you across other websites.
| What we save | Purpose and how long it stays |
|---|
Chosen languagelocalStorage | Your Spanish or English preference. It stays until you change it or clear this website’s data, with no fixed expiry date. |
|---|
Menu preferencessessionStorage | We save your crop search, selected filters and list order in sessionStorage to keep them when you visit other pages. This record contains no order details, credentials or language choice. It lasts for the tab session; browsers may restore it according to their settings. You can clear the filters or delete this website’s data. |
|---|
Order draftlocalStorage | Your selection, form step and the details you enter, including unfinished fields. It is removed after successful confirmation of your order submission or when you start a new selection. Until then, it stays without a fixed expiry so you can return after reloading. |
|---|
Pending requestlocalStorage | A copy of the submitted order, its identifier and a follow-up key, so the same request can be checked if the connection is lost. For an account order, it includes the user identifier to prevent retrying as another account. It stays until the confirmation is saved in this browser. If the response or storage fails, it is kept to recover the order. |
|---|
Latest order confirmationlocalStorage | A minimal reference containing the order identifier, total, and follow-up key and status, plus the user identifier for account orders. It does not contain the full checkout form. It stays until another confirmation replaces it or you clear this website’s data. It has no fixed expiry. |
|---|
Customer sessionsessionStorage | Amazon Cognito keeps session tokens in sessionStorage, separately from the order draft. They are removed when you sign out or the tab session ends; browsers may restore tabs according to their settings. Access and identity tokens last 15 minutes and can be refreshed for up to 7 days. We do not store passwords or codes in localStorage. Unfinished sign-in steps may temporarily use sessionStorage. |
|---|
Privacy choicelocalStorage | In localStorage, we save whether you accept or reject analytics and replay, and when you decided. Your choice is valid for 180 days. We will ask again afterwards; you can change it earlier through the footer. This record contains no order details. |
|---|
Optional analytics identifierslocalStorage / sessionStorage | Only with your permission, PostHog uses localStorage and sessionStorage to link visits and actions in this browser through a random identifier and a session. We do not store order fields or sign-in details here. Withdrawing permission removes these optional identifiers; you can also delete them in your browser settings. An expired choice does not permit new collection. |
|---|
You can remove this information in your browser settings. This deletes drafts and recovery references on that device, but not orders already received in our systems. If you block local storage, some recovery features will be unavailable and we cannot send a new order from this form. On a shared device, clear this website’s data when you finish.
6. How long we keep information
We keep orders and communications for as long as needed to arrange deliveries, maintain a recurring order relationship and handle issues. After that, we retain them only for applicable legal retention periods or as needed to establish, exercise or defend legal claims. Optional answers are kept while useful for handling the enquiry and reviewing the range. There is currently no single automatic deletion period for all orders.
These criteria also apply to operational copies and team notifications. Erasure may require reviewing the database, Slack notifications, notification delivery archives and backups. Technical records are kept according to their security and diagnostic purpose. Erasure requests are assessed with these systems and any requirement to retain particular records in mind.
Session replay retention is configured for 30 days in PostHog. Usage events are kept according to the project’s retention settings and service plan, and only while needed to analyse and improve the website. Withdrawing consent prevents new collection; it does not by itself erase data already received. You can ask our privacy contact about these periods or request erasure.
7. Your rights
You can request access, correction or erasure of your data, restriction of processing and, where applicable, data portability. You can also object to processing based on legitimate interests for reasons relating to your situation. Where we rely on consent, you can withdraw it without affecting the lawfulness of processing already carried out.
Send your request to the privacy contact above. Describe what you need and include an order reference if you have one; please do not send identity documents initially. If identity checks are needed, we will ask only for the information necessary. We respond without undue delay, normally within one month; if a lawful extension is needed, we will explain the reason and timing.
You can also complain to the Spanish Data Protection Agency (AEPD) or the competent supervisory authority where you live, work or where an alleged infringement occurred.
8. Customer accounts
You can create an account to view your orders and deliveries, or continue to order as a guest.
Accounts use Amazon Cognito on AWS in Frankfurt, Germany, with a verified email and a unique identifier. You can sign in with a password or a passkey you have registered. Amazon Cognito sends email-verification and password-recovery codes. Cognito manages authentication data and passkey public keys. The private key and biometric data stay under the control of your device or credential manager and are not sent to MicroVerdes. We store links between the account and its orders and deliveries so you can view them. Earlier guest orders are linked only at your request where email and ownership checks permit it. Providing the requested service and our legitimate interest in protecting accounts are the bases for this processing. Account data is kept while you use the account and afterwards where needed for legal obligations or claims; there is no general automatic deletion period. Order notifications to Slack do not include passwords, codes or access tokens.
9. Changes to this policy
We will update this page when the services or use of data change and show the revision date. If a change requires additional information or your consent, we will provide or request it before applying the change. The Spanish and English versions describe the same processing.