Effective Date: 14th May 2026
Last material amendment: 5th June 2026 (addition of driver data subject access request procedure in Section 6 and Google Drive sub-processor disclosure in Section 12.1).
Business Name: Virtuous Restaurants Ltd
Website: www.virtuousrestaurants.com
Virtuous Restaurants (“we,” “us,” or “our”) values your privacy and is committed to protecting the personal information of our customers, restaurants, and delivery drivers. This Privacy Policy explains how we collect, use, store, and share personal data when you use our website, our ordering sites at virtuousrestaurants.co.uk and its restaurant subdomains, our mobile apps, our delivery driver app, or our ordering widgets (“Platform”), and your rights regarding that information.
This Privacy Policy applies to users of our websites, mobile applications, and related services.
Our Privacy Policy explains how we collect, use, store, and protect your personal data, and your rights under UK GDPR and the Data Protection Act 2018.
Customers:
Name, email, delivery address, order history, phone number (for account authentication via one-time passcode — OTP verification is required to create an account and place orders through the Platform), and a tokenised reference maintained by Stripe to at least one payment card linked to the customer’s account, which is required before an order can be placed. The Platform does not collect, view, or store full card details at any time; these are held exclusively within Stripe’s secure infrastructure.
Device and browser information, IP address, and cookies used in the ordering widget.
Location information if applicable for order tracking.
Loyalty and rewards data: points balance, points transaction history, and redemption records where a customer participates in a Partner Restaurant’s loyalty programme through the Platform (processed by the Platform as that restaurant’s data processor, see Section 5A).
Order history and recommendations: recent and common orders, and items predicted or suggested at checkout, generated from your order history (see Sections 2 and 11.3).
Restaurants:
Business information, contact details, menu items, payment information, and tax documents.
Login credentials and device/browser data.
Names and contact numbers of staff reachable during live orders (Accountability Policy Section 4.35).
Order acceptance, preparation, sealing and collection-PIN verification records generated in the Console (Accountability Policy Sections 3.16 and 4.14B), and records of refunds issued in the Console, including the staff member who issued the refund, the amount and the time (Accountability Policy Section 4.27A).
Allergen-update requests and responses (Accountability Policy Section 31.21.A.6).
Delivery Drivers:
Name, email, phone number, vehicle details, licences and insurance documentation, background check information.
Location data collected during deliveries via the driver app.
Device identifiers, IP address, and app usage data.
Timestamped photographs captured through the driver app at collection and at delivery.
Bank and payment details, delivery fees earned, and records of any payment adjustments.
Customer ratings of deliveries.
Messages and participation records from the optional Registered Drivers WhatsApp group (see Section 14).
Right-to-work records, including share-code checks and expiry reminders.
App event records: arrival, collection, collection-PIN, collection-anomaly and handover logs.
Payment adjustment notices and your responses (Accountability Policy Section 3.25).
Records of technology-access decisions (Accountability Policy Section 31.21.A.2).
Automatically Collected Information:
IP addresses, browser type, device identifiers, operating system, and usage analytics from the website, apps, and widgets.
Cookies and tracking technologies for functionality, performance, and analytics.
User-Generated Content:
Reviews, ratings, messages, and photos submitted through the Platform.
We use the information to:
Facilitate orders, deliveries, and payments.
Communicate with users regarding orders, account activity, service updates, and marketing (if consented) and to inform existing customers about the Virtuous Restaurants marketplace and partner restaurants in accordance with the Platform’s legitimate interests and Regulation 22(3) of the Privacy and Electronic Communications Regulations 2003, where the customer has not opted out. Customers are given a simple way to opt out at checkout, when their contact details are collected, and in every message.
Verify identity, eligibility, right to work (including share-code checks and expiry reminders), licences, and insurance for restaurants and drivers.
Improve and optimise the Platform’s functionality, performance, and security.
Comply with legal obligations, audits, and regulatory requirements.
Complaints, refunds, disputes and evidence handling: We process personal data (including messages, photos, videos, location/GPS data, and order records) for the purposes described in Section 30.13 of the Accountability Policy, in accordance with our Delivery Responsibility, Risk Allocation and Accountability Policy (incorporated into the Terms of Use). This includes forwarding evidence and messages to the relevant restaurant (or driver) when requested, processing food refunds only on the restaurant’s prior written authorisation, and deciding remedies for failures of our own delivery service (Accountability Policy Section 30.13(b)). We use such data only to make the operational determinations listed in Section 30.13 of the Accountability Policy, including decisions about our own delivery service. Decisions on remedies for the food remain the sole responsibility of the relevant restaurant (subject always to non-excludable statutory consumer rights under UK law, including the Consumer Rights Act 2015).
Where the Platform operates autonomous delivery mechanisms, delivery location data, GPS coordinates, and delivery confirmation data from autonomous systems are processed on the legal basis of performance of contract (UK GDPR Article 6(1)(b)) to confirm delivery and document the completion of the order for risk allocation and dispute resolution purposes. No human driver accesses customer personal data in connection with autonomously delivered orders. Autonomous delivery confirmation data is retained in accordance with the retention periods set out in Section 10 of this Policy.
PIN confirmation data, including the timestamp and GPS coordinates at the point of delivery confirmation, is processed on the legal basis of performance of contract to document the completion of delivery and the transfer of risk in accordance with the Delivery Responsibility, Risk Allocation and Accountability Policy. Where an alternative confirmation method is used in place of PIN confirmation, the same legal basis and retention periods apply to the alternative confirmation record.
Essential cookies: Required for login sessions, ordering widget functionality, and cart/session management.
Non-essential cookies: Used for analytics, performance monitoring, and optional marketing.
Driver tracking: GPS/location data collected during active deliveries for routing and delivery documentation; retained as set out in Section 10.2.
Non-essential cookies that require consent (including marketing cookies) are set only after you opt in through the cookie banner. Where the law allows certain analytics cookies to be used without prior consent, you can object to them at any time through the cookie settings.
Disabling essential cookies may limit Platform functionality.
We implement appropriate technical and organisational measures to safeguard your personal data:
Encryption: TLS encryption for sensitive data, including payment information
Access Control: Only authorised personnel can access personal data
Data Retention: Personal data is retained only as necessary or as required by law
Regular Audits: Security audits and risk assessments to maintain compliance
Data Hosting and Infrastructure: The Platform’s ordering, delivery, and driver application services are hosted on Google Firebase, a cloud infrastructure platform operated by Google LLC. Where a Firebase service supports regional configuration, the Firebase project is configured to store personal data in United Kingdom and/or European Economic Area data centre regions. Some Firebase services (for example sign-in and authentication, push-notification delivery, and crash or performance reporting) may process data in other locations, including the United States; these transfers are protected by the safeguards described in Section 7. Google LLC acts as a sub-processor on our behalf under Google’s standard data processing terms, which incorporate the EU Standard Contractual Clauses with the UK Addendum (or the UK International Data Transfer Agreement) as applicable.
Our technology infrastructure provider is contractually bound to process personal data exclusively on our documented instructions and may not access, use, disclose, or exploit personal data for any purpose of their own. Payment data is processed separately by Stripe and is never stored within the Firebase infrastructure. No system is completely secure, and users acknowledge that we cannot guarantee absolute security. Where applicable, we ensure appropriate technical and organisational measures are in place commensurate with the risk to data subjects.
Customer and Driver accounts on the Platform are for people aged 18 and over only (restaurant staff using Virtuous Restaurants Console must be at least 16 and authorised by their restaurant). You must be at least 18 years old to create a customer account or place an order through the Platform. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that a user is under 18 we will immediately suspend their account and delete their personal data. If you believe a person under 18 has created an account please contact support@virtuousrestaurants.com immediately.
We do not sell personal information to third parties.
We may share personal information with:
Restaurants and drivers to fulfil orders. Drivers receive the customer’s name, delivery address, contact number, order reference and the items in the order for the active delivery only, and customer contact details are removed from the driver app within 72 hours (Accountability Policy Section 31.21.A.3). Customers receive their assigned Driver’s name and a contact number for the active delivery only. Partner Restaurants receive the assigned Driver’s name and the collection verification details for each order, to verify collection (Accountability Policy Sections 3.2B and 4.14B).
WhatsApp (Meta Platforms): where Platform support sends a delivery-confirmation message by WhatsApp to the number you gave at checkout (Accountability Policy Section 1.4B), or where a marketplace service message is sent by WhatsApp (Accountability Policy Section 31.21.A.13). Meta processes this as an independent controller.
Partner Restaurants, for fraud prevention: where the Platform has verified that a customer made a fraudulent claim, relevant records may be shared with Partner Restaurants to prevent further fraud (Accountability Policy Section 15.3A).
Partner Restaurants, for complaints: delivery evidence and handover records relevant to a complaint about their order (Accountability Policy Section 30.13(a)).
Insurers and professional advisers: where needed to handle or defend a claim, including our insurer and, where a Driver caused a loss, the Driver’s insurer (Accountability Policy Section 5.5).
Electronic signature provider: Legalesign, used to send and sign driver registration forms and agreements (messages from notifications@legalesign.com).
You, for a court claim: if you bring a statutory claim against a Partner Restaurant, copies of your own order and delivery records on written request (Accountability Policy Section 17.4).
Payment processors, delivery-management software providers, and other service partners: customer payments on the Platform’s ordering interface are processed via Stripe’s payment infrastructure, which supports card payments, Apple Pay, and Google Pay. Apple Pay and Google Pay transactions are processed through Stripe’s underlying payment infrastructure. For Stripe’s data processing terms and privacy practices, see stripe.com/gb/privacy.
Account verification (SMS/OTP) provider: to verify a customer’s mobile number and secure their account, the mobile number is shared with the Platform’s SMS/OTP delivery provider for the sole purpose of transmitting the one-time passcode, currently operating under the sender name “GCloudApps.” This provider does not use the mobile number for any other purpose and is bound by data processing terms consistent with this Policy.
Law enforcement or regulatory authorities as required by law.
In connection with mergers, acquisitions, or business transfers.
Aggregated or anonymised data for analytics or research purposes.
Analytics Providers: For Platform system performance monitoring, operational infrastructure analytics, and service optimisation. No analytics provider receives or processes data for the purpose of monitoring individual driver activity, acceptance rates, availability, or engagement patterns.
Cloud infrastructure and hosting providers: The Platform uses Google Firebase (operated by Google LLC) as its cloud hosting infrastructure. Google LLC processes personal data as a sub-processor under binding data processing terms. Google LLC’s data processing is governed by Google’s Cloud Data Processing Addendum, which incorporates the EU Standard Contractual Clauses with the UK Addendum (or the UK IDTA) as applicable. Google LLC does not use personal data processed through Firebase for Google’s own advertising or commercial purposes.
Marketplace App Data Processing:
Where a Partner Restaurant is included in the Marketplace App (a standard condition of the Platform Services Agreement, subject to the restaurant’s right to opt out), the Platform will host, display, and make publicly available that restaurant’s menu content — including item names, descriptions, pricing, images, allergen summaries, and availability — for the purpose of enabling customer discovery and ordering. This constitutes processing of the restaurant’s operational content data and, where such content includes personal data, processing of personal data.
Customer personal data relating to Marketplace App orders is handled under the controller map in Section 5A. The Platform is an independent controller for platform accounts, delivery and platform compliance. The Partner Restaurant is an independent controller for preparing and fulfilling the order. The Platform is the restaurant’s processor for its loyalty programme. The Platform processes restaurant content data on the legal basis of: (a) performance of the contract with the Partner Restaurant, specifically the content licence granted in their Platform Services Agreement; and (b) the restaurant’s acknowledgement of the mandatory standard condition set out therein.
Partner Restaurants may withdraw from the Marketplace App at any time by written notice to admin@virtuousrestaurants.com, subject to any applicable notice period in their Platform Services Agreement. Following confirmed withdrawal, the Platform will remove the restaurant’s content from the Marketplace App within a reasonable operational period. Withdrawal does not affect any other processing activities described in this Policy.
When a customer places an order through the Marketplace App, the personal data collected at checkout (name, delivery address, email, phone number, payment details) is processed in the same manner as any other order placed through the Platform, as described in Section 1 and Section 2 of this Privacy Policy. No additional data categories are collected solely by reason of the order originating from the Marketplace App.
Partner Restaurants participating in the Marketplace App must ensure that their own customer-facing privacy notices and terms of service disclose that orders placed through their menus may be facilitated through a shared marketplace platform operated by Virtuous Restaurants Ltd, and that customer data will be processed as described in this Privacy Policy and in the restaurant’s own privacy notice (Section 5A). This is required to satisfy the restaurant’s own transparency obligations as data controller under UK GDPR Article 13.
Payment data processing: Payment data is processed by Stripe in accordance with Stripe’s own privacy policy and data processing terms. The Platform does not store raw payment card data. As between the Platform and a Partner Restaurant, liability for a Stripe system failure, data breach or processing error caused by Stripe’s systems is governed by the Platform Services Agreement. Nothing in this paragraph limits any right you have as a customer. Partner Restaurants are directed to Stripe’s own terms for their data processing obligations as Stripe Connect account holders.
5A. Who Is Responsible for Your Data
Virtuous Restaurants Ltd is an independent data controller for:
– your platform account and sign-in (including one-time passcodes and the tokenised payment card reference);
– the delivery service it provides (delivery address and contact details used for delivery, driver assignment, GPS, delivery PIN and confirmation records, and delivery evidence);
– complaints about the delivery service (Accountability Policy Section 30.13(b)) and records of your acceptance of the Platform’s terms at checkout (Accountability Policy Section 31.2);
– fraud prevention and compliance monitoring;
– marketplace service communications;
– any optional dietary/allergen profile and date of birth saved to your account;
– device, cookie and usage data from the Platform’s websites, apps and ordering widgets; and
– personal data about Drivers and about restaurant staff who use the Platform (a Partner Restaurant is a separate controller for its own driver collection records, as described in its Privacy Policy).
Each Partner Restaurant is an independent data controller for:
– preparing and fulfilling your order (including order contents, special instructions and the allergen information needed to prepare it);
– decisions on complaints and refunds about its food; and
– its own marketing, where you have consented.
Virtuous Restaurants Ltd acts as the Partner Restaurant’s data processor for that restaurant’s loyalty programme (points, rewards and redemption records), processing that data only on the restaurant’s documented instructions under the Platform Services Agreement.
Where both the Platform and a Partner Restaurant hold the same information (for example your name and order details), each is responsible for its own use of it. You can exercise your rights with either; if you contact the wrong one, it will tell you who to contact.
You have the right to:
Access: Request a copy of your personal data
Rectification: Correct inaccuracies in your data
Erasure: Request deletion of your data (“right to be forgotten”)
Restriction of Processing: Limit how your data is used
Data Portability: Receive your data in a machine-readable format
Object to Processing: Object to processing for legitimate interests or marketing
Withdraw Consent: Withdraw consent where applicable
To exercise any rights, contact us at support@virtuousrestaurants.com. Registered independent drivers may submit rights requests to driver.support@virtuousrestaurants.com.
Data Subject Access Requests (DSARs) — Response Timeframe and Exemptions
We will respond to any data subject access request or other rights request without undue delay and in any event within one calendar month of receipt. Where a request is complex or we receive a high volume of requests simultaneously, we may extend this period by a further two months. Where an extension applies, we will inform you of the extension and the reasons for it within the first month of receiving your request.
Where we decide not to take action on a request, we will inform you without undue delay and in any event within one calendar month of receipt, explaining our reasons and your right to lodge a complaint with the ICO.
Where the Platform is conducting an active fraud investigation or compliance review in connection with your account, and where disclosure of the information requested in a DSAR would be likely to prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of any tax or duty, we may apply the relevant exemptions under Schedule 2, Part 1 of the Data Protection Act 2018 to withhold or restrict the specific information that forms part of that active investigation. Where such an exemption is applied, we will inform you that an exemption has been applied and identify the relevant Schedule 2 provision, to the extent that doing so does not itself prejudice the investigation. This exemption is applied on a case-by-case basis and does not affect your right to access information unrelated to an active investigation, nor does it affect your right to complain to the ICO.
Where the ICO is succeeded, merged or replaced into a successor data protection authority, references to the ICO in this Policy shall be read as references to the successor body exercising equivalent regulatory functions.
Registered independent drivers requesting access to their personal data held by the Platform will receive access to their individual compliance records held securely in the Platform’s driver compliance system, shared directly with the requesting driver in a commonly used format within one calendar month of a valid request (extendable in accordance with the paragraph above) submitted to driver.support@virtuousrestaurants.com.
Customers bringing a statutory claim against a Partner Restaurant may also request copies of their order and delivery records by writing to resolutions@virtuousrestaurants.com. These are provided free within 10 business days (Accountability Policy Section 17.4).
Your personal data may be transferred or stored outside your country of residence. We ensure such transfers comply with GDPR using appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses, as applicable, in accordance with UK GDPR.
Where our technology services involve processing outside the UK, we ensure appropriate safeguards including the UK IDTA are in place.
Where personal data is processed through Google Firebase infrastructure, the EU Standard Contractual Clauses with the UK Addendum (or the UK International Data Transfer Agreement), as incorporated in Google’s Cloud Data Processing Addendum, govern any transfers of personal data from the United Kingdom to Google LLC’s corporate structure. The Platform configures Firebase data storage and processing to remain within UK and/or EEA regional boundaries to the maximum extent technically available. Users may request further details on the transfer safeguards in place by contacting support@virtuousrestaurants.com.
Customer and Driver accounts are not intended for anyone under the age of 18; if we become aware that we have collected information from anyone under 18, we will promptly delete it. Personal data, including order history, account information, and driver location data, is retained only for as long as necessary to provide services, comply with legal obligations, or for legitimate business purposes, with specific retention periods applied where applicable (e.g., 7 years for tax documents and for order and transaction records; see Section 10.2). Promotional marketing, including marketing on behalf of Partner Restaurants, is sent only to users who have opted in, and users may withdraw consent at any time. Marketplace service communications are sent on the basis described in the next paragraph.
Informational communications about the Platform’s marketplace and partner restaurants may also be sent to existing customers on the basis of the Platform’s legitimate interests under Regulation 22(3) of the Privacy and Electronic Communications Regulations 2003. Customers are offered a simple opt-out at checkout, when their contact details are collected, and each such communication includes a clear opt-out mechanism. Customers who opt out will not receive further marketplace communications.
For users outside the UK, all data processing and transfers comply with applicable data protection laws, including GDPR and equivalent international privacy regulations, and users retain all rights granted under their local laws. By continuing to use the Platform, all users acknowledge and accept these practices regarding data collection, retention, tracking, and marketing communications.
Certain processing activities (promotional marketing, non-essential cookies, the optional dietary/allergen profile and date of birth) rely on your consent. You can withdraw consent at any time without affecting core services. See section 6 for your rights and how to opt out.
We may update this Privacy Policy from time to time. Where changes are material — including any changes that affect how we process your personal data, the purposes for which we process it, your rights under this Policy, or our legal obligations — we will notify you via email or a prominent in-app or on-site notice before those changes take effect, in accordance with Section 12.14 below. Minor corrections, clarifications, and updates that do not affect the substance of how we process your personal data may be posted without advance notice. The Last Material Amendment date at the top of this Policy will be updated on each material revision.
10.1 Principles of Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including order fulfilment, account management, administration, audits, dispute resolution, and legal obligations.
When retention is no longer necessary, we securely delete, anonymise, or overwrite data, unless further retention is required by law (e.g., tax, accounting, litigation).
We apply the principle of least retention: keeping data only as long as necessary to meet legal and business needs.
10.2 Typical Retention Periods
Below are the standard retention durations we apply (subject to legal requirements and internal needs). These are aligned with best practices used in online restaurant and food-ordering platforms:
Order and transaction records: retained for 7 years for tax, accounting, and audit purposes.
Continuous location and route data from the driver app: retained for 30 days after delivery completion, unless required longer for dispute resolution, investigation, or legal compliance.
Delivery evidence (photographs, and the GPS coordinates and timestamps recorded with arrival, collection, pre-seal photograph and handover events): retained under Section 10.9 (up to 180 days, extended only for open disputes or legal holds).
Customer contact details in the driver app: removed within 72 hours of delivery confirmation or cancellation (Accountability Policy Section 31.21.A.3).
Marketing consent and communication preference data: retained until consent is withdrawn, plus an additional 1 year to maintain evidence of consent history.
Usage, device, and analytics data: retained for between 1 and 3 years, after which any personal identifiers are removed or anonymised so that individuals cannot be identified.
Note that Partner Restaurants, as separate independent data controllers, retain their own records of orders in accordance with their own retention schedules and legal obligations, which may differ from this Platform retention schedule. Please refer to the relevant Partner Restaurant’s Privacy Policy for their retention periods.
10.3 Deletion, Anonymisation & Overwriting
After the relevant retention period ends, we securely delete data from active systems.
If full deletion is not feasible (e.g., due to backup systems or logs), we overwrite or pseudonymise personal identifiers so that individuals can no longer be identified.
For transactional records that must remain for legal compliance, we remove or mask personal identifiers wherever possible while preserving essential non-identifying details for accounting and audit purposes.
10.4 Right to Request Deletion / Erasure (“Right to be Forgotten”)
You may request erasure of your personal data at any time, subject to the constraints of this retention scheme and legal obligations.
If your request relates to data that is still required for a legal or operational purpose (e.g., tax records, open disputes), we will comply to the maximum permissible extent by removing what can be removed or masking identifiers.
We will respond to a deletion request without undue delay and within one calendar month, extendable by up to two further months for complex requests as set out in Section 6.
10.5 Backup & Archive Retention
Backups or archives may retain historical snapshots for a limited period, generally between 90 days and 1 year, depending on system architecture.
Data in backups or archives is subject to the same deletion or anonymisation rules once the retention period in the live system has expired.
Access to backups and archives is restricted, encrypted, and read-only, except for necessary recovery operations.
10.6 Legal Holds / Exceptional Retention
In the event of litigation, regulatory investigation, or legal obligation, we may place a “legal hold” on specific records, temporarily suspending deletion until obligations have been met.
Legal holds are limited to the minimum necessary scope and duration.
10.7 Recordkeeping & Audit Trails
We maintain internal logs of all deletion, anonymisation, or overwriting actions, including timestamp, data category, and responsible system or agent.
Audit trails (with minimal metadata) are retained for at least 3 years to demonstrate compliance with our retention policy.
10.8 User Notification & Transparency
When you request erasure, or when we anonymise or delete your data, we will inform you of which data was removed or anonymised, unless doing so would compromise other users’ privacy or legal obligations.
If we cannot fully erase data due to legal or technical constraints, we will explain the reasons for partial retention or masking.
10.9 Complaints and Dispute-Related Data
Data relating to complaints, refunds, disputes, or delivery evidence (including photographs, videos, messages, and location data) is retained only for as long as necessary for the purposes in Accountability Policy Section 30.13, to meet legal obligations, or to support audits — no longer than 180 days from the date of delivery. Where a complaint or dispute remains open at that date, or a legal hold applies under Section 10.6, the relevant evidence is kept until 30 days after the complaint or dispute is closed or the legal hold ends. This is the single retention rule for delivery evidence; Accountability Policy Section 25.1 applies it. Once the dispute is resolved or the retention period ends, such data is securely deleted, anonymised, or overwritten in accordance with our formal data retention schedule. The Accountability Policy governs how complaints and disputes are handled; this Privacy Policy governs how the related personal data is processed (Accountability Policy Section 1.3(b)).
For the avoidance of doubt, records relating to commercial invoices issued to Partner Restaurants, including the order details, refund amounts, and payment confirmation that form the basis of such invoices, constitute financial and transactional records and are retained for 7 years in accordance with Section 10.2 of this Policy and applicable tax and accounting obligations, regardless of whether they also relate to a customer complaint or delivery dispute. The 180-day dispute-data retention period applies to operational evidence (photographs, videos, GPS data, messages) and does not reduce the retention period applicable to financial records.
11.1 Third-Party Links and Integrations
Our Platform may contain links to, or integrate with, third-party websites, APIs, or services (including but not limited to payment processors, mapping services, social media platforms, and analytics providers).
These third parties operate independently and have their own privacy policies. We are not responsible for the content, security, or data handling practices of third-party sites or services.
We recommend users review the privacy policies of any third-party services they interact with through our Platform.
11.2 Embedded Content
Content embedded from third-party platforms (such as videos, maps, or widgets) may collect information about your interactions, devices, or IP address.
Embedded content providers may use cookies, tracking pixels, or other technologies, which are outside our direct control.
We advise users to review embedded content providers’ privacy policies to understand how they process data.
11.3 Automated Decision-Making and Profiling
Our Platform may use automated systems, algorithms to assist with delivery routing optimisation, fraud prevention and risk assessment, personalised recommendations and content suggestions, and operational analytics for efficiency and service improvements.
We comply with the updated rules on automated decision-making under the Data (Use and Access) Act 2025.
Where these processes involve solely automated decision-making that may have legal or similarly significant effects on individuals and involve special category data, we apply the stricter requirements of UK GDPR. For non-special category data, such processing is generally permitted subject to appropriate safeguards.
Users have the right to request meaningful information about the logic involved, to request human review of any automated decision affecting them, to make representations, and to contest the decision.
The Platform operates a compliance monitoring system that automatically analyses claim patterns, delivery GPS records, evidence submission records, and order data across user accounts over time to identify patterns consistent with systematic or repeated fraud, as described in the Delivery Responsibility, Risk Allocation and Accountability Policy Section 15.3B. This automated monitoring may result in a user’s account being escalated for enhanced compliance review, which may include requiring additional verification steps before further claims are processed, or may ultimately result in the Platform exercising its right to cease providing technology access to a verified fraudulent user under Section 15.3A of the Accountability Policy. These outcomes may constitute automated decisions with a significant effect on the relevant user. Users subject to any such automated determination have the right to request human review of that determination by contacting support@virtuousrestaurants.com, to make representations to the Platform regarding the assessment, and to request meaningful information about the logic and data underlying the automated conclusion. Such requests will be responded to within one calendar month, subject to any applicable exemptions under Schedule 2 of the Data Protection Act 2018 where an active fraud investigation is ongoing. Health information, including reports of allergic reactions, is never used as an input to this automated monitoring. Permanent refusal of access is never decided solely by automated means: it follows the written notice, 14-day response and internal review procedure in Accountability Policy Section 15.3A.
For Drivers: delivery opportunities are offered by an algorithm based only on current proximity and real-time demand. It does not use acceptance history, availability, response times, ratings or branded-item purchases (Accountability Policy Sections 31.21.A.1, 31.21.A.3 and 31.21.A.9). Payment adjustments are never made solely by automated means; the Driver is notified in writing and may respond within seven days (Accountability Policy Section 3.25).
11.4 Transparency and User Rights
Where automated processing is used to make decisions impacting users’ experience, we ensure:
Transparency about the purpose and logic of the processing
Opportunity for human intervention, correction, or objection
Compliance with all applicable UK GDPR and DPA 2018 requirements regarding fairness, accuracy, and accountability
11.5 Data Minimisation in Third-Party Use
We only share or process data with third-party providers to the extent necessary for operational purposes.
Personal identifiers are pseudonymised or anonymised wherever possible.
11.6 Third-Party & Risk Mitigation
All third-party providers are carefully vetted for GDPR compliance, data security, and reliability.
Contracts with third-party service providers include binding data protection obligations, confidentiality agreements, and audit rights.
Any automated system used is regularly monitored, updated, and tested to ensure compliance with privacy, security, and ethical standards.
11.7 User Consent and Opt-Out
Users retain full control over optional data shared with third-party services.
Users may withdraw consent for optional processing at any time without affecting core services.
Users can withdraw cookie consent at any time through the cookie settings.
11.8 Liability Disclaimer
While we enforce strict contractual and technical safeguards, we cannot guarantee the practices of independent third-party services or embedded content providers.
Users acknowledge and accept that interactions with third-party content or upsell recommendations are at their own discretion.
11.9 Separate Programs
Data collected through the Referral & Affiliate Program and the Virtuous Delivery Platform (driver registration) are processed separately and solely for the purposes of the respective program. Participation in one program does not imply consent, access, or rights to the other program.
11.10 The Platform’s ordering, menu management, and application services are provided through third-party technology infrastructure and development service providers acting as data processors under binding Article 28 data processing agreements. Such providers are contractually prohibited from accessing, using, or disclosing personal data except strictly as required to provide the technical services to the Platform. The categories of these providers are: ordering and menu-management software, application development and maintenance, cloud hosting, and SMS delivery. The Platform’s principal service providers include Google LLC (Firebase and Google Workspace), its SMS/OTP provider and Legalesign (electronic signatures); payments are handled by Stripe. A current list of all sub-processors is available on request from support@virtuousrestaurants.com.
12.1 Legal Basis for Processing
We process your personal data only when we have a valid legal basis under UK GDPR:
Performance of contract: for orders, the delivery service, payments, and our agreements with Drivers and Partner Restaurants.
Legal obligation: for tax, audit, or regulatory compliance.
Consent: for promotional marketing, non-essential cookies, date of birth, and (as explicit consent) the optional dietary/allergen profile.
Vital interests: responding to a medical emergency at the delivery address (Section 2).
We document and regularly review the legal basis for all processing activities.
Criminal records and background check data: Where the Platform collects background check information from delivery drivers for the purpose of right-to-work verification and platform safety compliance, such data is processed on the basis of the Platform’s legitimate interests in platform safety and in verifying that Drivers are legally permitted to carry out delivery work (and on the basis of legal obligation only where a statutory duty to carry out the check applies to the Platform) and, where it constitutes criminal convictions data as defined under UK GDPR Article 10, under Schedule 1, Part 2, paragraph 10 of the Data Protection Act 2018 (preventing or detecting unlawful acts), supported by an appropriate policy document as required by Schedule 1, Part 4. Background check data is processed solely for the purposes of driver registration compliance and is retained in accordance with Section 10.2 of this Privacy Policy. It is not shared with third parties except where required by law or where the driver’s consent has been obtained.
Sub-processor authorisation: In this Policy, “sub-processor” means a provider that processes personal data on our behalf, directly or through our technology provider; where we act as a Partner Restaurant’s processor (Section 5A), these providers are sub-processors of that restaurant’s data. The Platform has authorised Google LLC (operating Google Firebase cloud infrastructure) as a sub-processor for the purposes of hosting and operating the Platform’s ordering and delivery technology. This authorisation is documented in the Platform’s Article 28 data processing agreement with its technology infrastructure provider. All sub-processors are bound by data processing obligations no less protective than those imposed on the Platform under UK GDPR.
The Platform additionally uses Google Drive, provided under a Google Workspace business account and Google’s Cloud Data Processing Addendum, as secure cloud storage for driver onboarding and compliance documentation. Google LLC processes this data as a sub-processor under the same binding data processing terms applicable to Firebase, and does not use such data for Google’s own purposes.
The Platform has also authorised an SMS/OTP delivery provider, currently operating under the sender name “GCloudApps,” as a sub-processor for the sole purpose of transmitting one-time passcodes to customer mobile numbers for account verification. This sub-processor is bound by data processing terms no less protective than those imposed on the Platform under UK GDPR.
The Platform also uses Legalesign as a sub-processor to send driver registration forms and agreements and to record electronic signatures on them.
12.2 Data Protection Contact / Privacy Contact
We have appointed a Data Protection Contact to oversee compliance. You may contact our Data Protection Contact at: vaibhav@virtuousrestaurants.com for any questions or concerns regarding your personal data.
12.3 ICO / Regulatory Complaint Instructions
If you are unsatisfied with our handling of your personal data, you may lodge a complaint with the UK Information Commissioner’s Office (ICO) at https://ico.org.uk/concerns/ or by calling 0303 123 1113.
12.4 Children’s Privacy: Customer and Driver accounts are for people aged 18 and over only (restaurant staff using Virtuous Restaurants Console must be at least 16 and authorised by their restaurant). We do not knowingly collect personal data from anyone under the age of 18. If we become aware that a user is under 18 we will immediately suspend their account and delete their personal data. For the purposes of UK GDPR data protection obligations we additionally confirm that we do not offer information society services directly to children under the age of 13 and will delete any such data immediately upon discovery.
12.5 Data Breach Notification
In the event of a personal data breach, we will notify affected users without undue delay and the ICO within 72 hours, where required. Notifications will include the nature of the breach, potential impacts, and recommended actions for users.
12.6 Data Minimisation & Purpose Limitation
We collect only the minimum personal data necessary for the purposes outlined in this Privacy Policy. Data is used exclusively for order processing, account management, delivery, legal compliance, operational optimisation, or marketing where consent has been provided.
12.7 Data Accuracy & User Responsibility
Users are responsible for providing accurate and complete information. We make reasonable efforts to maintain data accuracy and will promptly correct errors upon request.
12.8 Data Transfer & Safeguards
Where personal data is transferred outside the UK or EEA, we implement safeguards such as the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses, encryption, and access restrictions, in compliance with UK GDPR to ensure data protection compliance.
We use the ICO’s three-step test to identify restricted transfers and apply safeguards such as the UK International Data Transfer Agreement (IDTA) or UK Addendum where required.
12.9 Automated Decision-Making & Profiling
We may use automated systems and algorithms to optimise delivery routing, prevent fraud, provide personalised recommendations, or conduct operational analytics.
These processes do not create legal effects or similarly significant effects, except the fraud monitoring described in Section 11.3.
Users have the right to request human review, contest automated decisions, and receive meaningful information about the logic, significance, and consequences of automated processing affecting them.
12.10 Third-Party & Embedded Content
Our Platform may integrate with third-party websites, APIs, or embedded content (e.g., payment processors, maps, videos).
Third parties operate independently and have their own privacy policies.
Interactions with third-party content are at your own discretion.
We conduct due diligence and contractual safeguards to mitigate risk, but we cannot guarantee third-party practices.
12.11 Retention, Deletion, & Consent Management
Personal data is retained only as long as necessary for legal, tax, or operational purposes.
Users may request deletion, and we will comply unless legal obligations prevent full erasure.
Withdrawn consents are immediately enforced for optional processing, marketing and cookies.
12.12 Audit & Accountability
We maintain audit logs of all data processing, sharing, deletion, and access events. Logs are regularly reviewed to ensure accountability and compliance with UK GDPR and other applicable laws.
12.13 Security & Liability Disclaimer
We implement industry-standard technical and organisational safeguards, but no system can be completely secure. Users acknowledge and accept residual risk when using the Platform.
12.14 Updates to the Privacy Policy
Material changes to this Privacy Policy will be notified to users via email or a prominent notice on the Platform before changes take effect. The effective date will be updated accordingly.
12.15 Additional Clauses
Force Majeure / System Failures: We are not liable for data loss or interruptions caused by events beyond our reasonable control, except where the law provides otherwise.
Governing Law / Jurisdiction: This Privacy Policy is governed by the laws of England and Wales. If you are a consumer resident in Scotland or Northern Ireland, you may also bring proceedings in the courts of your home jurisdiction.
Severability: If any provision of this Privacy Policy is invalid or unenforceable, the remaining provisions remain in full effect.
13.1 Platform Applications
The Platform operates or will operate three distinct applications. Each collects different categories of personal data appropriate to its function.
Virtuous Restaurants — Customer Facing
Data collected includes name, email address, delivery address, phone number for OTP verification, order history, a tokenised reference to at least one payment card secured by Stripe — mandatory before an order can be placed, with the Platform never collecting, viewing, or storing full card details — date of birth where optionally provided, any optional dietary/allergen profile, loyalty data, delivery confirmation records, device identifiers, IP address, and location data where provided for order tracking. Camera access is not required. Push notification permission may be requested for order status updates. This application is intended for users aged 18 and over only.
Virtuous Restaurants Console — Restaurant Facing
Data collected includes restaurant staff login credentials, order data, order acceptance, preparation and sealing timestamps, collection-PIN verification records, refund records including the issuing staff member, amount and time, device identifiers, IP address, and app usage data. Location data is not collected through this application. Push notification permission may be requested for incoming order alerts. This application is intended for authorised restaurant staff only and is not a consumer-facing application.
Virtuous Restaurants Driver — Driver Facing
Data collected includes driver name, contact details, GPS and location data collected continuously during active delivery periods for routing and delivery documentation purposes, timestamped photographic evidence captured through the application at the point of collection and delivery, arrival, collection-anomaly and handover logs, device identifiers, and app usage data. Camera access is required to capture pre-seal photographic verification and delivery evidence in accordance with the Platform’s delivery documentation obligations. Location data is collected only during active delivery sessions. Continuous route data is retained for 30 days after delivery completion; GPS coordinates recorded with delivery events form part of delivery evidence and are retained under Section 10.9. Push notification permission is required for delivery opportunity alerts. This application is intended for registered independent drivers only.
13.2 Device Permissions
Location — required by Virtuous Restaurants Driver during active delivery sessions. Optional in Virtuous Restaurants for order tracking. Not collected by Virtuous Restaurants Console.
Camera — required by Virtuous Restaurants Driver for delivery documentation. Not required by Virtuous Restaurants or Virtuous Restaurants Console.
Push Notifications — may be requested by all three applications for order and delivery alerts. Users may disable notifications through device settings. In Virtuous Restaurants and Virtuous Restaurants Console this does not affect core functionality; in Virtuous Restaurants Driver, Drivers who disable notifications will not be alerted to delivery opportunities but can still view them in the App.
All data collected through each application is processed in accordance with the legal bases and retention periods set out in this Privacy Policy.
13.3 App Store and Google Play Compliance
Data collected through each application is processed solely for the purposes described in this Privacy Policy. No data collected through any application is used for purposes inconsistent with what is disclosed here.
For iOS users: The Platform complies with Apple’s App Tracking Transparency framework. Where device-level identifiers are used for analytics purposes, the Platform will request permission through the system prompt before accessing the IDFA. Users may withdraw this permission at any time through their device settings without affecting access to core application functionality.
For Android users: The Platform’s data collection and use practices for each application are disclosed in the respective Google Play Data Safety sections in accordance with Google Play Developer Programme Policies. The information provided in each Data Safety section is consistent with this Privacy Policy.
The Platform does not share personal data collected through any application with data brokers. The Platform does not use data collected through any application for interest-based advertising without explicit user consent.
Virtuous Restaurants and Virtuous Restaurants Driver are not intended for anyone under the age of 18. Virtuous Restaurants Console may be used only by authorised restaurant staff aged 16 or over. For the purposes of UK GDPR data protection obligations we additionally confirm that no application is directed at children under the age of 13. If we become aware that a child under 13 has created an account or provided personal data through any application, we will delete it immediately.
For any questions about data practices in connection with any of the Platform’s applications contact support@virtuousrestaurants.com.
14.1 Introduction
Virtuous Restaurants® (“the Company,” “we,” “us”) uses WhatsApp solely as an optional communication channel to provide onboarding support, share general updates, and notify drivers of official delivery opportunities. Participation in WhatsApp communications is entirely voluntary, and drivers may leave the group at any time without consequence. All delivery assignments must be accepted and recorded through the official App, which serves as the only system of record. WhatsApp messages do not create any obligation, employment relationship, or entitlement to work or compensation.
We use WhatsApp (owned by Meta) as a communication channel. Meta acts as an independent controller for its own processing. Please review Meta’s privacy policy.
14.2 Virtuous Restaurants® Registered Independent Drivers WhatsApp Support Channel – for approved drivers eligible to receive delivery opportunities.
Presence in the group is voluntary and does not guarantee access to jobs, work, or income.
14.3 Data Collected
We process only the data necessary for WhatsApp group operations:
Messages sent from phone numbers within the official group such as questions or comments
Participation logs, engagement, and admin interactions
First and last name for recognition or official communications
Documents submitted for registration, verification, or approval
Any operational data required for compliance, auditing, or dispute resolution
14.4 Legal Basis for Processing
Legitimate interests – for operating the optional group, including the visibility of your name, phone number and messages to other members, which is inherent in how WhatsApp groups work. The group is optional: all delivery opportunities are available in the official App, so you can receive work without joining the group or after leaving it.
Legitimate Interests – for onboarding, operational management, compliance, auditing, dispute resolution, and official group communications.
14.5 Voluntary Participation & No Guarantee
Participation in Registered Drivers group is voluntary.
Completing the registration form does not guarantee invite to the Registered Drivers group or access to any delivery opportunities.
Membership does not create employment, agency, or contractual rights.
14.6 Visibility & Communications
By participating, you acknowledge:
Public display of your phone number, messages, announcements or any recognition posts sent by the Admin.
Logging of messages and participation solely for operational, compliance, auditing, or dispute resolution purposes. You may leave the group at any time, or ask to be removed via driver.support@virtuousrestaurants.com. Leaving the group has no effect on your access to delivery opportunities in the App.
14.7 Security Responsibilities
Drivers are solely responsible for securing their WhatsApp accounts and devices.
Virtuous Restaurants® applies technical and organisational measures to protect your data.
The Company is not liable for losses caused by compromised accounts, devices, unofficial contacts, or actions outside official channels.
14.8 Official Channels & Scam Protection
Admin will only communicate publicly in official WhatsApp group.
Any DM, WhatsApp, SMS, or unofficial contact claiming to be admin is a scam — block and delete immediately.
Only official Driver Registration Form links sent from driver.support@virtuousrestaurants.com or notifications@legalesign.com are valid.
No registration fees, charges, or offers outside the official channels are valid. Do not engage with anyone contacting you privately claiming to be an Admin, as such messages are fraudulent. The authorised Admin communicates exclusively through public broadcasts to the group and will never contact drivers via private message or phone call.
14.9 Audit & Monitoring
All communications may be logged or monitored solely for:
Compliance
Operational integrity
Auditing and dispute resolution
No other surveillance is intended or authorised.
14.10 Data Retention
Data is retained only as long as necessary for onboarding, operational, compliance, recognition, auditing, or dispute-resolution purposes.
Once no longer required, data is securely deleted or anonymised.
WhatsApp messages and participation logs are retained for a maximum of 5 years. Registration and verification documents are retained for 6 years after the end of the relationship in accordance with Section 10.2.
14.11 Withdrawal & Complaints
You may leave the Registered Drivers WhatsApp group at any time, or ask to be removed by contacting driver.support@virtuousrestaurants.com.
Complaints may be submitted to the UK Information Commissioner’s Office (ICO).
14.12 Termination & Group Management
Virtuous Restaurants® may suspend or remove participants from the Registered Drivers group at any time, with or without notice, for:
Continued participation does not grant employment, agency, or worker rights.
14.13 Liability Disclaimer
Virtuous Restaurants® is not liable for:
Missed earnings or delivery opportunities
Disputes between drivers
Actions taken outside official channels
Losses caused by unsecured devices or unauthorised communications.
All work, postings, and communications are voluntary and optional, and do not guarantee income or assignments. Drivers are paid per accepted delivery (Accountability Policy Section 31.21.A.1).
14.14 Governing Law
This Policy is governed by the laws of England & Wales.
14.15 Acknowledgement
By registering and participating in the WhatsApp group, drivers:
Confirm they have read, understood, and agreed to this Policy.
Understand participation is voluntary and independent.
Acknowledge that their first and last name may appear in official communications and admin messages.
Agree to use official channels only and ignore all unauthorised/unofficial communications.
Understand that all work, postings, and communications are optional and do not guarantee income or assignments.
Understand that amendments to this Policy will be notified to them by email in advance, and that they may leave the group at any time.
In the unlikely event of a data breach affecting your personal information, we will notify affected users without undue delay and, where required, the ICO within 72 hours. We will provide information on the nature of the breach, potential impacts, and steps you can take to protect yourself.
If you are unsatisfied with our handling of your personal data, you may lodge a complaint with the UK Information Commissioner’s Office (ICO) at https://ico.org.uk/concerns/ or by calling 0303 123 1113.
For questions or concerns regarding your personal data or this Privacy Policy:
Virtuous Restaurants Ltd (registered in England and Wales, Company No. 16314621)
Registered office: 27 Streatfield Road, Harrow, HA3 9BP
ICO registration number: ZB964052
Email: support@virtuousrestaurants.com
Virtuous Restaurants Ltd — Company No. 16314621
This Privacy Policy is governed by the laws of England and Wales and complies with the UK General Data Protection Regulation and the Data Protection Act 2018. For correspondence regarding this Policy or to exercise your data rights contact support@virtuousrestaurants.com.
Related documents:
Terms Of Use — virtuousrestaurants.com/terms/
Accountability Policy — virtuousrestaurants.com/accountability/
Authorised Communications — virtuousrestaurants.com/authorised-communications/
© 2026 Virtuous Restaurants Ltd. All rights reserved.