Legal

Privacy Policy

Last updated: June 2, 2026

1. Introduction

Indian Royal Spicy (“we”, “our”, or “us”) operates the Indian Royal Spicy mobile application. This Privacy Policy explains how we collect, use, and protect your personal data when you use our app to place orders, make reservations, or receive push notifications.

We are located at Rue Belliard 189, 1040 Etterbeek, Brussels, Belgium. This policy is compliant with the General Data Protection Regulation (GDPR — EU 2016/679).

By using the app you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use of the application.

2. Information We Collect

Account Information

When you create an account we collect your full name and email address via Supabase Auth. Passwords are managed entirely by Supabase and are never stored in plaintext on our servers.

Order & Transaction Data

When you place an order we record the items and quantities ordered, your delivery address (for delivery orders), order type (delivery/pickup), and payment status as reported by Stripe. We never store card numbers, CVV codes, or any raw bank details.

Usage & Technical Data

We collect device type, operating system version, and app version to diagnose crashes and improve stability. This data does not identify you personally and is aggregated for performance analysis.

3. How We Use Your Information

We use the information we collect to:

  • Process and fulfil your food orders and table reservations.
  • Send order confirmations, preparation updates, and delivery status notifications (via email and push).
  • Manage your reservation history and preferences.
  • Improve the performance and stability of the application.
  • Comply with Belgian tax and legal obligations, including TVA/BTW record-keeping.

We process your data on the legal basis of contract performance (GDPR Art. 6(1)(b)) for orders and reservations, and legitimate interest (Art. 6(1)(f)) for app improvement. Push notifications are based on your explicit consent (Art. 6(1)(a)).

4. Payment Processing

All payment transactions are handled by Stripe, a PCI-DSS Level 1 certified payment processor. We receive only a payment status (succeeded, pending, failed) — we never receive, process, or store card numbers, CVV codes, or bank account details.

Bancontact is the default payment method for Belgian customers, also processed through Stripe’s secure infrastructure.

For full details on how Stripe handles your payment data, please review the Stripe Privacy Policy.

5. Data Sharing

We do not sell, trade, or rent your personal data to third parties. We share data only with the following sub-processors necessary to operate our service:

  • Supabase (EU region — Frankfurt) — authentication and database hosting.
  • Stripe — secure payment processing and Bancontact support.
  • Expo / FCM (Firebase Cloud Messaging) — delivery of opt-in push notifications.

We may disclose your information to competent authorities if required by Belgian or EU law, a court order, or to protect the rights and safety of our users or the public.

6. Data Retention

We retain your data for the following periods:

  • Account data — retained while your account is active, plus 2 years after closure.
  • Order records — retained for 7 years to comply with Belgian accounting and tax law.
  • Reservation data — retained for 1 year after the reservation date.
  • Push notification tokens — retained until you opt out via app settings or uninstall the application.

After applicable retention periods, data is permanently deleted or irreversibly anonymised.

7. Your Rights

As a data subject under GDPR you have the following rights with respect to your personal data:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to correction — request correction of inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”) — request deletion of your personal data where no legal obligation requires us to retain it.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to withdraw consent — opt out of push notifications at any time in your device settings or in-app notification preferences.

To exercise any of these rights, visit Account Settings in the app or email us at info@indianroyalspicy.be. We will respond within 30 days.

8. Children's Privacy

Our application is not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us immediately at info@indianroyalspicy.be and we will promptly delete that data.

9. Security

We implement industry-standard technical and organisational measures to protect your personal data:

  • All data transmitted between the app and our servers is encrypted via HTTPS/TLS.
  • Supabase enforces Row-Level Security (RLS), ensuring users can only access their own data.
  • Stripe is PCI-DSS Level 1 certified — the highest standard for payment security.

No system can guarantee absolute security. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and inform affected users without undue delay (GDPR Art. 34).

10. Changes to This Policy

We may update this Privacy Policy from time to time. When material changes are made, we will notify you via an in-app notification or email before the changes take effect.

The date at the top of this policy reflects the most recent revision. Your continued use of the application after the effective date constitutes your acceptance of the updated policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Indian Royal Spicy

Rue Belliard 189
1040 Etterbeek, Brussels
Belgium
info@indianroyalspicy.be