. Zero Setup Fees 31-Day Free Trial Delivery + Pickup + Reservations Real-Time Dashboard All in one
Skip to main content

MealApp

MealApp GDPR and Data Ownership Policy

Reviewed by MealApp Data Protection Officer + Merchant Operations Belgium. · Last verified: August 15, 2026

We build software. We do not sell your guests. You are the sole owner of your restaurant's data. Here is exactly how we process, protect, and export it.

1. Who Owns the Data: You Are the Controller, We Are the Processor

In clear legal terms: The Restaurant is the Data Controller. MealApp is the Data Processor.

Other reservation platforms, like OpenTable and TheFork, route your guest data into their own marketplace network. They use your hard-earned guests to build their brand, not yours. We operate the exact opposite way. With MealApp, the guest belongs entirely to you. You can see how this structural difference affects your business in our breakdown of MealApp vs TheFork.

[GUEST DATA]
[MARKETPLACE PLATFORM]
[RESTAURANT]
Status: Platform is the Controller. Restaurant is the tenant.
[GUEST DATA]
[RESTAURANT (CONTROLLER)]
Processed securely by [MEALAPP (PROCESSOR)]
Status: You own the guest relationship.

2. What Data We Process, and Exactly Why

We only process what is strictly necessary to run your business. This falls under Article 5(1)(c) of the GDPR (data minimisation). We collect names, emails, phone numbers, and order histories exclusively for operational use. This data powers core functions like your restaurant deposit booking system and strategies on how to reduce restaurant no-shows.

Our tools include Guest CRM, Tagging & Segmentation, Advanced Guest Database Segmentation, and a Duplicate Reservation Control System by Name or Phone.

We do not do AI-driven predictive lifetime value scoring. We do not use algorithms to profile your diners. We process facts, not predictions.

3. Where Your Data Is Hosted

Your data never leaves Europe. Our entire infrastructure is 100% EU-hosted.

We provide an explicit merchant DPA that serves as the technical and legal annex to your contract. Every byte of data flowing between the portal where the guest data lives and the diner-side app your guest interacts with is fully encrypted.

4. Strict Retention Windows: CRM vs. Fiscal Data

You control how long data stays. We apply strict retention rules based on Belgian law:

  • Guest CRM retention: We hold this data for 1 to 3 years after a guest's last interaction.
  • Transactional and Fiscal retention: We hold this for 7 years. This is mandatory to comply with Belgian tax law and the GKS 2.0 / FDM mandates.

We do not hold data one minute past your required retention window. These rules integrate directly into our financial control systems to keep you compliant automatically.

5. Right of Access, Erasure, and Portability

If a diner asks you to delete their data, you must comply. We make this simple through a standard Subject Access Request (SAR) flow.

If a guest invokes their right to erasure, we execute the deletion within the mandatory GDPR 30-day window. You can export everything at any time using our Export of Customer Data in Compliance with GDPR feature. There is zero vendor lock-in.

> INITIATING: SUBJECT_ACCESS_REQUEST (SAR_9942) [GUEST ID] ALICE_VANDERBEEK | ACTION: RIGHT_TO_ERASURE > GATHERING CRM RECORDS (1-3 YR WINDOW)... > GATHERING TRANSACTIONAL RECORDS (7 YR FISCAL HOLD)... > ACTION: CRM DATA PERMANENTLY ERASED. > ACTION: FISCAL ANONYMIZED FOR GKS 2.0 AUDIT. > STATUS: 100% DPA COMPLIANT. EXPORT READY.

6. Belgian DPA Alignment (2026–2028 Enforcement Plan)

The Belgian Data Protection Authority (DPA) is highly proactive. They rely on diner complaints. In 2024, they issued 837 complaints and handled 1,455 breach notifications. Fines are severe: up to €20M or 4% of global revenue. They have established strict precedents, including a €4,920 fine for a single firm's transparency failure.

The strongest defense against a DPA audit is a processor that provides a signed DPA and a clear audit trail. MealApp delivers this baseline compliance standard for every segment-specific vertical we serve.

7. What We Do Not Do: No Resale, No Dark Patterns

We do not resell your guest list. We do not mine your data. We do not profile your guests for external marketing.

Our revenue comes exclusively from providing software and processing services, not from selling your data. You can verify this in our compare plans page and our commission schedule. If you want to see how this translates to your bottom line, review our real commission-savings proof.

Respecting data ownership is the foundation of our entire reservation system pillar.

8. Verified Market Citations

> SYSTEM_LOG: LOADING VERIFIED MARKET CITATIONS... > Our legal and market claims are supported by findings from: Cranium, Hunton, OneTrust DataGuidance Belgium, Improvado 2026, Kiteworks 2026, Legal 500 Belgium, Direct Dine 2026, BDO, Secure Privacy, Eat App 2026, SevenRooms 2026, Vantage Point 2026, Stripe, and Titeca. > Industry reports from SevenRooms and Eat App specifically note that data hoarding by marketplace apps is the primary reason restaurants are switching providers in 2026.

9. Frequently Asked Questions

Q1: Who technically owns the guest data?
You do. The restaurant is the Data Controller. MealApp acts solely as the Data Processor. The guest list belongs entirely to you.
Q2: What happens to my data if I switch to another vendor?
You take it with you. You can pull your data using the Export of Customer Data in Compliance with GDPR feature. We never lock you in.
Q3: How do you handle a guest's right to erasure?
We use a Subject Access Request (SAR) flow. If a guest asks to be removed, we permanently erase their CRM data within the mandatory 30-day GDPR window.
Q4: Where is my data hosted?
All data is securely hosted on 100% EU-based server infrastructure.
Q5: How does this data policy compare to OpenTable or TheFork?
Marketplace platforms route your guests into their own systems to market directly to them. MealApp isolates your data so it serves only your restaurant.
Q6: What happens if the Belgian DPA audits my restaurant?
You are defended by our signed merchant DPA, clear data audit trails, and strict adherence to Article 5 data minimisation laws.
Q7: How long do you retain guest CRM data?
We keep guest CRM data for 1 to 3 years after their last interaction, aligning strictly with GDPR requirements.
Q8: How long do you retain fiscal and transaction data?
We hold financial records for 7 years to ensure full legal compliance with Belgian tax laws and GKS 2.0 / FDM mandates.
Q9: Does MealApp sell or share my guest list?
No. We never sell, share, or mine your guest database. Our business relies solely on software fees, not data brokering.
Q10: Does MealApp use AI to profile my guests?
No. We provide clear CRM segmentation tools, but we explicitly do not use AI-driven predictive lifetime value scoring or profiling algorithms.

Take Control of Your Guest Data

Sign your contract knowing exactly who owns your diners. Take the final step to secure your independence from marketplace data hoarding.