NovaShop
Ordering app for guests of a NovaKasse business
Privacy policy
Last updated: 5 September 2026
NovaShop is the lightweight ordering app for guests. It has no user account and no login: only what is needed for the order is transmitted. Payment runs through Stripe’s payment sheet, which opens inside the app. Your card details go straight to Stripe from there; our server never sees them and stores only the amount, the status and a payment reference.
1. Data controller
- Company
- Babala Özdemir (Einzelunternehmen)
- Address
- Unterer Rainweg 22
4414 Füllinsdorf
Schweiz - info@babala.ch
- Phone
- 076 222 45 99
- Company ID
- CHE-322.105.560
- App identifier
-
iOS: ch.babala.shop.swiftui
Android: ch.babala.shop
We have not appointed a data protection officer or an EU representative because we do not reach the relevant thresholds. Please address all requests to the contact above.
2. What data we process
| Data | Purpose | Stored where | Retention |
|---|---|---|---|
| Name, optional phone number, note | Assigning the order and asking back about it | Our server; passed to the selected business | Records 10 years (accounting duty) |
| Delivery address (street, postcode, town) — delivery only | Delivering the order | Our server; passed to the business and the courier | Records 10 years (accounting duty) |
| Payment data | Paying for the order | At Stripe; with us only amount, status and reference | 10 years (accounting obligation) |
What we explicitly do not collect
- No account, no password, no e-mail address required
- No location access — the app requests only the internet permission
- No advertising, no analytics, no trackers, no push notifications
3. Permissions on your device
The app requests only the following permissions. Each of them can be revoked at any time in your device settings; the app remains usable afterwards, with reduced functionality.
- Internet — Loading the menu and submitting the order. The app requests no other permissions.
4. Legal bases
We process personal data under the Swiss Federal Act on Data Protection (revFADP). Where the GDPR applies, we rely on:
- Performance of a contract (Art. 6(1)(b) GDPR) — everything needed for the app to deliver the function you requested.
- Legitimate interests (Art. 6(1)(f) GDPR) — secure and stable operation, abuse prevention, troubleshooting.
- Consent (Art. 6(1)(a) GDPR) — this app requests no special system permissions, so no separate consent is required.
- Legal obligation (Art. 6(1)(c) GDPR) — in particular commercial and tax retention duties for payments.
5. Recipients and third parties
We do not sell data and do not disclose it for advertising purposes. Data is disclosed only to the following parties, and only where required for operation:
| Recipient | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Gunzenhausen (Germany), data centre inside the EU | Operation of our servers. Hetzner processes data solely on our behalf and is contractually bound to confidentiality. |
| Stripe Payments Europe Ltd. / Stripe Inc. | Dublin (Ireland) / San Francisco (USA) | Card payment processing. Card data is collected by Stripe directly; we never receive or store full card numbers, only payment references (tokens), amount, status and the last four digits. |
| Apple Inc. / Apple Distribution International Ltd. | Cupertino (USA) / Cork (Ireland) | App Store distribution, processing of in-app purchases and subscriptions, and crash reports if you have enabled them with Apple. |
| Google Ireland Ltd. / Google LLC | Dublin (Ireland) / Mountain View (USA) | Google Play distribution, purchase processing via Google Play Billing, crash reports according to your Play settings. |
Authorities and courts receive data only where we are legally obliged to provide it.
Transfers abroad
Some of the recipients listed above process data outside Switzerland and the EEA, in particular in the United States. We base such transfers on the European Commission’s Standard Contractual Clauses with the Swiss adaptations recognised by the FDPIC and, where applicable, on the EU-US Data Privacy Framework. We will provide information on the safeguards in place on request.
6. Retention and deletion
We keep no profile about you. Your order stays with the business and in our records; invoices and payment records are kept for 10 years due to statutory duties. Server logs expire after 14 days.
Step-by-step instructions are available at Delete data.
7. Children and young people
This app is not directed at children. We do not knowingly collect personal data from children under 16. If we learn that such data has been submitted without parental consent, we delete it without delay.
8. Data security
Wherever the app transmits data at all, connections are encrypted via HTTPS/TLS. On the server side we use access restrictions, tenant separation and regular backups. Nobody can, however, guarantee absolute security for data transmission over the internet.
9. Your rights
- Access to the personal data we process
- Rectification of inaccurate data
- Erasure or destruction of your data
- Restriction of and objection to processing
- Receiving or porting your data in a common format
- Withdrawal of consent with effect for the future
An informal message to info@babala.ch or a call to 076 222 45 99. We normally respond within 30 days. To verify your identity we may request suitable proof. You may also lodge a complaint with a supervisory authority (Switzerland: FDPIC; EU: your competent authority).
10. Changes to this policy
We may adapt this policy when the app or the legal framework changes. The version published on this page, with the date shown above, is the applicable one. We announce material changes inside the app.
← Back to the app overview