NovaEat
Order food from businesses near you
Privacy policy
Last updated: 5 September 2026
NovaEat forwards orders to catering businesses. For an order to arrive and be paid we need your name, your phone number and — for delivery — your address. We pass this information to the business you selected. Card payments are handled by Stripe: your card number never reaches the app or our server.
1. Data controller
- Company
- Babala Özdemir (Einzelunternehmen)
- Address
- Unterer Rainweg 22
4414 Füllinsdorf
Schweiz - info@babala.ch
- Phone
- 076 222 45 99
- Company ID
- CHE-322.105.560
- App identifier
-
iOS: ch.babala.novaeat
Android: ch.babala.novaeat
We have not appointed a data protection officer or an EU representative because we do not reach the relevant thresholds. Please address all requests to the contact above.
2. What data we process
| Data | Purpose | Stored where | Retention |
|---|---|---|---|
| Name, phone number, optional e-mail address | Account, order processing, queries from the business | Our server (EU data centre); passed to the selected business | Until you delete your account |
| Password | Login | Our server, as a non-reversible hash only | Until you delete your account |
| Delivery address with coordinates | Delivery and calculation of the delivery fee | Device and our server; passed to the business and its courier | Until you delete your account |
| Address input and — if allowed — location | Converting address to coordinates and back (geocoding) | At the map service OpenStreetMap/Nominatim | Per the map service’s own terms |
| Orders, reviews, favourites, coupon codes, tips | Order history, reordering, rating the business | Our server | Receipts 10 years (accounting duty), other data until account deletion |
| Payment data | Paying for the order | At Stripe; with us only amount, status and payment reference | 10 years (accounting obligation) |
| Device push token | Notifications about your order status | Our server; delivery via Google or Apple | Until you turn notifications off or delete your account |
What we explicitly do not collect
- No card numbers, no CVC codes — we never see them
- No background location tracking
- No advertising, no advertising ID (on Android it is technically removed), no analytics SDK
- No sale or rental of data to third parties
3. Permissions on your device
The app requests only the following permissions. Each of them can be revoked at any time in your device settings; the app remains usable afterwards, with reduced functionality.
- Location while using the app (optional) — Finding nearby businesses and pre-filling the delivery address. You can always type the address manually.
- Notifications — Status updates about your order.
- Camera and photos (iOS only, optional) — Choosing a profile picture and scanning a card for payment.
- Internet — Communication with our server.
4. Legal bases
We process personal data under the Swiss Federal Act on Data Protection (revFADP). Where the GDPR applies, we rely on:
- Performance of a contract (Art. 6(1)(b) GDPR) — everything needed for the app to deliver the function you requested.
- Legitimate interests (Art. 6(1)(f) GDPR) — secure and stable operation, abuse prevention, troubleshooting.
- Consent (Art. 6(1)(a) GDPR) — for anything you actively enable in this app: location while using the app, notifications about your order status and camera and photo picking on iOS. Consent can be withdrawn at any time with effect for the future by revoking the permission in your system settings.
- Legal obligation (Art. 6(1)(c) GDPR) — in particular commercial and tax retention duties for payments.
The catering business you select receives the data needed to fulfil your order (name, phone number, address in case of delivery, order content and notes) and is itself responsible for its further processing.
5. Recipients and third parties
We do not sell data and do not disclose it for advertising purposes. Data is disclosed only to the following parties, and only where required for operation:
| Recipient | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Gunzenhausen (Germany), data centre inside the EU | Operation of our servers. Hetzner processes data solely on our behalf and is contractually bound to confidentiality. |
| Stripe Payments Europe Ltd. / Stripe Inc. | Dublin (Ireland) / San Francisco (USA) | Card payment processing. Card data is collected by Stripe directly; we never receive or store full card numbers, only payment references (tokens), amount, status and the last four digits. |
| Firebase Cloud Messaging (Google Ireland Ltd.) | Dublin (Ireland) | Delivery of push notifications to Android devices. A device token and the message content are transmitted. |
| Apple Push Notification service (Apple) | Cork (Ireland) / USA | Delivery of push notifications to Apple devices. A device token and the message content are transmitted. |
| Google Sign-In (Google Ireland Ltd.) | Dublin (Ireland) | Optional sign-in with a Google account. We receive name, e-mail address and an account identifier. |
| OpenStreetMap Foundation | Cambridge (United Kingdom) | Map rendering. Loading map tiles transmits the IP address to the tile server. |
| Apple Inc. / Apple Distribution International Ltd. | Cupertino (USA) / Cork (Ireland) | App Store distribution, processing of in-app purchases and subscriptions, and crash reports if you have enabled them with Apple. |
| Google Ireland Ltd. / Google LLC | Dublin (Ireland) / Mountain View (USA) | Google Play distribution, purchase processing via Google Play Billing, crash reports according to your Play settings. |
Authorities and courts receive data only where we are legally obliged to provide it.
Transfers abroad
Some of the recipients listed above process data outside Switzerland and the EEA, in particular in the United States. We base such transfers on the European Commission’s Standard Contractual Clauses with the Swiss adaptations recognised by the FDPIC and, where applicable, on the EU-US Data Privacy Framework. We will provide information on the safeguards in place on request.
6. Retention and deletion
Account, address and order data remain until you delete your account. Invoices and payment records are excluded: commercial and tax law require us to retain them for 10 years; after account deletion they are detached from your account. Server logs expire after 14 days. The business you ordered from keeps its own records according to its own retention periods.
Step-by-step instructions are available at Delete data.
7. Children and young people
This app is not directed at children. We do not knowingly collect personal data from children under 16. If we learn that such data has been submitted without parental consent, we delete it without delay.
8. Data security
Wherever the app transmits data at all, connections are encrypted via HTTPS/TLS. On the server side we use access restrictions, tenant separation and regular backups. Nobody can, however, guarantee absolute security for data transmission over the internet.
9. Your rights
- Access to the personal data we process
- Rectification of inaccurate data
- Erasure or destruction of your data
- Restriction of and objection to processing
- Receiving or porting your data in a common format
- Withdrawal of consent with effect for the future
An informal message to info@babala.ch or a call to 076 222 45 99. We normally respond within 30 days. To verify your identity we may request suitable proof. You may also lodge a complaint with a supervisory authority (Switzerland: FDPIC; EU: your competent authority).
10. Changes to this policy
We may adapt this policy when the app or the legal framework changes. The version published on this page, with the date shown above, is the applicable one. We announce material changes inside the app.
← Back to the app overview