Privacy & Cookie Policy

How we handle your data and use cookies

Last updated: 4 September 2026

1. Data Controller

The data controller pursuant to EU Regulation 2016/679 (GDPR) is:

T.E.D. SRL
viale romolo gessi, 16
34123, Trieste
VAT no.: IT01111310320
E-mail: info@ariston-ts.it

2. Data Collected and Purposes

We collect personal data when you actively provide it through the forms on this site, the customer area ("My Account") or the restaurant's mobile app:

SourceData collectedPurposeLegal basis
Table reservation form Name, e-mail, phone, date, time, number of guests, notes, any allergies and intolerances of you and your guests, language chosen for communications Managing your reservation and confirming it by phone or e-mail. Your contact details are also recorded in the restaurant's customer list (name, e-mail, phone, first and last reservation dates, number of reservations), subject to the customer-account retention period Performance of a contract / pre-contractual steps (Art. 6(1)(b) GDPR)
Contact form Name, e-mail, message text Responding to your enquiry Legitimate interest (Art. 6(1)(f) GDPR)
Review form Name, rating, review text Publishing your review on the website (after moderation) Consent (Art. 6(1)(a) GDPR)
Customer account (website and app) Name, e-mail, password (stored only as a non-reversible hash), phone, date of birth, privacy consent, preferences (site theme; whether to receive the newsletter, event and promotion notices), loyalty points and coupons, favourite dishes, saved delivery addresses, any allergies and intolerances you indicate, registration, last login and last visit dates, number of reservations and any internal notes the restaurant keeps about you Creating and managing your account, faster reservations and orders, loyalty programme and personal coupons, age verification Performance of a contract (Art. 6(1)(b) GDPR); for allergies and intolerances, explicit consent given when you enter them (Art. 9(2)(a) GDPR)
Sign-in with Google (website and app), Apple (app) or Facebook (app, where the restaurant enables it) Your account identifier at the provider and your Firebase identifier, name and e-mail returned by the provider (Apple may supply a relay address) Password-less access to your account. On the website, Google sign-in goes directly through Google; in the app, the provider verifies your identity and sends us a token that we validate through Firebase Authentication Performance of a contract (Art. 6(1)(b) GDPR)
Online orders (website and app) Name, phone, e-mail, dishes ordered, notes, coupon code, requested pick-up or delivery time, chosen payment method (cash or card on delivery or on collection), delivery address with floor and intercom (home delivery only), table number (table orders only), language chosen for communications, IP address and the technical identifier of your browser or app (user agent) Receiving, preparing, delivering or handing over your order and keeping you informed about its status; preventing abuse and fraudulent orders Performance of a contract (Art. 6(1)(b) GDPR); for IP address and user agent, legitimate interest (Art. 6(1)(f) GDPR)
Newsletter E-mail, optional name Sending promotional communications after you confirm your subscription (double opt-in); you can unsubscribe from every message Consent (Art. 6(1)(a) GDPR)
Job applications ("Work with us") Name, e-mail, phone, attached CV Assessing your application. The CV is forwarded by e-mail to the restaurant and is not stored on the website's server Pre-contractual steps (Art. 6(1)(b) GDPR)
Server access logs IP address, browser type, pages visited, date/time Security, fraud prevention and server diagnostics Legitimate interest (Art. 6(1)(f) GDPR)

We do not collect financial or biometric data: orders are paid on delivery, on collection or at the table, and no payment details pass through the website or the app. Information about allergies and intolerances, which you may enter in your profile, in a reservation or in an order, is health-related data: it is optional, it is used only to prepare and serve your dishes correctly, and it is processed on the basis of the explicit consent you give when you enter it, which you can withdraw at any time by removing it from your profile; information already sent with a reservation or an order remains in the notes of that reservation or order for the retention periods in section 3. We do not carry out profiling or automated decision-making.

3. Data Retention

  • Reservations: kept for 12 months from the date of the reservation; older reservations are periodically deleted by the restaurant. If you delete your account, past reservations are anonymised.
  • Contact messages: kept for as long as needed to reply and in any case no longer than 6 months from receipt, then deleted by the restaurant; they are deleted immediately if you delete a customer account with the same e-mail address.
  • Reviews: kept for as long as they are published; you can request removal at any time.
  • Customer account: kept until you delete it (from the website or the app). After prolonged inactivity (by default 12 months without logins, reservations or orders) and only if the restaurant has enabled this procedure, the account may be deleted after an e-mail warning, a reminder and a notice period (60 days by default).
  • Online orders: kept for as long as needed to handle the order and to meet legal obligations; when the account is deleted, the personal data attached to past orders is anonymised.
  • Security log (sign-ins, account deletions and merges) and e-mail sending log: kept for a limited period set by the restaurant. For that period the security log also keeps a record of the account deletion itself (date and e-mail address).
  • Server logs: kept for 30 days, then automatically overwritten.

4. Data Sharing

Your data is not sold, rented or disclosed to third parties for marketing purposes. Data may be disclosed only to:

  • Hosting and infrastructure providers (data processors under GDPR Art. 28), bound by data processing agreements;
  • Google Ireland Ltd — Firebase Authentication and Firebase Cloud Messaging: to validate sign-in tokens for Google or Apple sign-in from the app; where the restaurant enables it, for phone-number verification by SMS (the number is sent to Google, which delivers the code and associates the number with your Firebase sign-in identity until your account is deleted; Google may also run automated abuse checks); where the restaurant enables push notifications, for delivering them to the app and to browsers that have accepted them (only the technical push token and the device or browser type are stored). For these services Google acts as a data processor;
  • Google, Apple Inc. and, where enabled, Meta Platforms Ireland Ltd as identity providers: sign-in with Google (directly through Google on the website, through Firebase in the app), Sign in with Apple and, where enabled, Facebook login are services for which Google, Apple and Meta are independent controllers, processing the data of your account with them under their own privacy policies;
  • Public authorities, where required by law.

Data is stored on servers within the European Economic Area (EEA). Google's and Apple's services may involve a transfer of data outside the EEA, covered by the safeguards of GDPR Art. 44 et seq. (EU–US adequacy decision and standard contractual clauses).

5. Your Rights

Under GDPR Articles 15–22 you have the right to:

  • Access — obtain confirmation of whether we process your data and receive a copy;
  • Rectification — correct inaccurate data;
  • Erasure ("right to be forgotten") — request deletion;
  • Restriction — limit processing in certain circumstances;
  • Data portability — receive your data in a structured, machine-readable format;
  • Objection — object to processing based on legitimate interest;
  • Withdrawal of consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, write to info@ariston-ts.it. We will respond within 30 days. You also have the right to lodge a complaint with the Italian supervisory authority: Garante per la Protezione dei Dati Personali.

Self-service, without writing to anyone: from the customer area of the website ("My Account") and from the app you can at any time download a copy of your data and delete your account. Deletion removes your profile, saved addresses, favourites, points and coupons, your newsletter subscription and the messages you sent through the contact form; it anonymises past orders and reservations; reviews already published stay online without your name (you can ask for their removal). It cannot be undone. If you used sign-in with Google or Apple and you delete from the app after a recent sign-in, the app also asks Firebase to delete your sign-in identity; otherwise the identity at Firebase is removed on request at the address above, and in any case you can revoke the app's access from your Google or Apple account settings. If you created two accounts (for example one with e-mail and password and one with Google) you can merge them from your profile: the data is moved to the account you are signed in to and the other one is deleted, after you confirm through a link sent to the e-mail address of the account being merged in (valid for one hour).

This site uses only technically necessary cookies. No profiling, advertising or third-party tracking cookies are set. The mobile app uses no cookies. It keeps on the device, in the app's protected area, your access token (removed when you sign out), your cart, the last delivery address you used, your preferences (language, theme, dismissed notices) and a temporary copy of the website's public content for offline use; if you request an export of your data, the file is saved in the app's private folder on your device. This local data stays on the device until you empty the cart or uninstall the app.

NameTypePurposeDuration
PHPSESSID Technical / Session Maintains your PHP session (flash messages, CSRF token, reservation state) Session (deleted when you close the browser)
cookieConsent Technical / Preference (localStorage) Stores your cookie consent preferences so the banner is not shown on every visit 1 year (localStorage — not a cookie, not transmitted to the server)

Technically necessary cookies are exempt from prior consent under Article 122 of the Italian Privacy Code and Recital 25 of the ePrivacy Directive. Nevertheless, this banner informs you transparently of their use.

If you wish to withdraw your consent or delete stored preferences, you can clear this site's localStorage via your browser's developer tools, or use the button below:

7. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. These include CSRF token validation on all forms, server-side input sanitisation and HTTPS in production.

8. Changes to This Policy

We may update this policy to reflect changes in our practices or applicable law. The date at the top of this page indicates the latest revision. Continued use of the site or the app after an update constitutes acceptance of the revised policy.

9. Mobile App

This policy also covers the restaurant's mobile app, which uses the same services and the same data as the website. In particular:

  • the app does not collect the device's location, does not access contacts, photos or the microphone, and contains no advertising or third-party analytics;
  • sign-in with Google or Apple and, where enabled, phone-number verification by SMS go through Firebase Authentication (see section 4);
  • the app embeds Google's Firebase Cloud Messaging: on installation the device obtains from Google a technical registration identifier, which is not sent to the restaurant nor linked to your account. The current version of the app sends no push notifications. Should the restaurant enable them in a future version, they will be sent through Firebase Cloud Messaging using only that identifier and the device type, with no other personal data, and you will be able to switch them off in your phone settings;
  • reviews written from the app are published only after the restaurant approves them and carry your account name until you delete your account, after which they remain without a name;
  • account deletion is available in the app's Account section (also before completing your profile) and has the effects described in section 5.