What we keep about you, why, and what you can do about it.
Up by Friday provides this website and the screens around it. You can reach us at hallo@upbyfriday.com. That address is for everything on this page, including the requests at the bottom.
For your guests' data you are the controller and we are the processor. That is not a formality: it means we only use that data to do what you ask us to, and never for anything of our own. For your own data, such as your login address, we are the controller.
Your email address, so you can log in. The name of your business and whatever you put on your own site. Nothing else, we don't ask for a date of birth, a gender, or things we'd do nothing with.
What is needed for an order or a question, and nothing beyond that. For pickup: name, email address, phone number if they fill it in, and what they ordered. At the table a guest fills in nothing, only if they want a receipt after paying do they give an email address, and we use it only to send that receipt. Through the contact form: whatever they type, including their message. If they pay online, their card details go through Stripe and not through us; we see the amount and whether it worked. All of that data is yours, not ours. We use it for nothing else and sell it to no one.
Our database runs at Supabase, the site at Vercel. Email goes via Resend: an order confirmation, a receipt, a login link. Online payment runs through Stripe, and then through the business's own Stripe account: the money goes straight there and we are not in between. For reading in an existing site and for translating a menu we use a Google language model; only the public content of the site and the text of the menu go there, never any guest data.
As long as you're a customer. If you stop, we delete your data within thirty days, except what we're legally required to keep for the books.
Access, correction or deletion. One email is enough and we do it within a month.
For your own data: because we have an agreement with you and have to carry it out. For your guests' data: because you engage us to. For the visit figures: because you and we both have an interest in knowing whether your site works, and because we collect them in a way that identifies no one.
Three kinds, and none of them is for advertising. One to keep you signed in. One to remember which language you want to read the dashboard or a site in. And one short-lived technical one, to hold an order in a basket while someone is still ordering. There are no third-party trackers on your site.
We count visits to your site so you can see how many people come and where from. That happens on our own servers, without a cookie for that purpose and without a profile per visitor. Nothing goes to Google Analytics or anything like it.
Our database and the site are in Europe. Two services are American: Stripe for payments and Resend for email, plus the Google language model we use for an import and for translations. The European Commission's standard clauses apply to all three, and no guest data goes to the language model.
Everything travels over an encrypted connection. Anyone who can sign in can only reach their own business: that is not a rule in our code but a lock in the database itself, and we test with every change that the lock holds. There are no passwords, you sign in with a code by email, so there is none to steal.
If you disagree with something, email us first. If we can't work it out, you can go to your national data protection authority.
We put the new date at the top. If it's something you ought to know, we email it rather than hoping you notice.
Last updated: August 2026