Privacy policy
Last updated: 1 October 2026
1. Controller
Rakesh Murthy
SR Digital
Jevenstedter Str. 33 a
22547 Hamburg
Germany
Email: [email protected]
Contact form: https://topfoodspot.com/en/contact
We have not appointed a data protection officer, as there is no legal obligation to do so.
2. Overview
TopFoodSpot is a public directory of restaurants, cafés and other eateries. You can browse it without an account.
- Browsing TopFoodSpot sets no cookies and stores nothing on your device.
- We do not use advertising or tracking tools such as the Meta Pixel or Google Analytics.
- Fonts are delivered from our own server; your browser does not contact Google Fonts.
- Restaurant and café owners who create a listing need an account. Only then do we process further data, as described below.
3. Hosting and server logs
The website is hosted by DigitalOcean, LLC, USA, on servers in the EU (Frankfurt, Germany). DigitalOcean routes the website's traffic through the global content delivery network of Cloudflare, Inc., USA, which also protects it against attacks. When you open a page, the server processes technical data that your browser sends: IP address, date and time, requested address, referring page and browser type (user agent). This is necessary to deliver the website securely.
Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in operating a secure website). We have concluded a data processing agreement with DigitalOcean that includes the EU standard contractual clauses; DigitalOcean is also certified under the EU-US Data Privacy Framework. We do not store or evaluate these server logs ourselves; DigitalOcean and Cloudflare keep them only as long as needed to deliver and secure the website.
4. Domain and email routing (Cloudflare)
Our domain is managed by Cloudflare, Inc., USA. Cloudflare answers name queries for topfoodspot.com and forwards emails sent to [email protected] to our mailbox. Website traffic is not routed through our own Cloudflare account (for the delivery of the website see section 3).
Legal basis: Art. 6 (1) (f) GDPR. Cloudflare is certified under the EU-US Data Privacy Framework.
5. Visit and click counters
We show public counters for website visits, clicks on listings and visitors currently online. We count without cookies and without storing anything on your device:
- Our server combines your IP address and browser type with a secret key that changes every day and turns this into a pseudonymous value. The IP address itself is not stored.
- This value is stored for at most two days, so that each visitor is counted only once per day. For the "online now" display, a page you have open sends a short signal about once a minute; these signals are deleted after one day.
- Obvious automated traffic such as search engine bots is not counted.
Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in showing simple, privacy friendly usage figures).
6. Links to Instagram profiles, websites and Google Maps
"Visit on Instagram", "Visit website" and "Open in Google Maps" buttons lead through our server, which counts the click as described above and then forwards you. Nothing from Instagram, Google or the listed website is loaded before you click. After forwarding, the privacy policy of the respective website applies.
7. Contact form and email
If you contact us via the contact form or by email, we process your email address, your message and, if provided, your name, to answer your request.
- Contact form messages are delivered to us by email via Resend, Inc., USA, using servers in the EU (Ireland). Resend is our processor; transfers to the USA are covered by the EU-US Data Privacy Framework or standard contractual clauses.
- Emails reach our mailbox at Google (Gmail), Google Ireland Ltd.
- We do not store contact form messages on the website.
Legal basis: Art. 6 (1) (b) GDPR if your request relates to a contract, otherwise Art. 6 (1) (f) GDPR (answering enquiries). We delete messages when they are no longer needed, unless business letters must be kept under commercial or tax law (up to 6 or 10 years).
8. Account and sign in for owners
Owners sign in with their email address; we send a sign in link, no password is stored.
- Account data (email address) and listings are stored with Supabase, Inc., on servers in the EU (Frankfurt, Germany). Supabase is our processor; we have concluded a data processing agreement. Possible access from the USA is covered by the EU-US Data Privacy Framework or standard contractual clauses.
- Sign in emails are sent via Resend (see section 7).
- After signing in, Supabase sets cookies that keep you signed in. They are strictly necessary for the service you request and therefore need no consent (§ 25 (2) no. 2 TDDDG).
- While you fill in the listing form, your unfinished input is kept in your browser's session storage for this tab, so that it survives a reload or a language switch. It never leaves your device, is removed when you submit the form, is no longer used after 30 minutes and is deleted when you close the tab. This too is strictly necessary for the function you use (§ 25 (2) no. 2 TDDDG).
Legal basis: Art. 6 (1) (b) GDPR (providing the service).
9. Listings
The information you enter for a listing (name, short description, city, country, Instagram profile, website, Google Maps link) is published on TopFoodSpot and visible to everyone. Please do not enter personal data of other people.
Legal basis: Art. 6 (1) (b) GDPR.
10. City suggestions (Geoapify)
Only on the form for creating a listing: when you type in the city field, your input and your IP address are sent to Geoapify (KEPTAGO LTD, Paphos, Cyprus, EU) to show city suggestions based on OpenStreetMap data. Nothing is sent before you start typing, no cookies are set, and Geoapify is not used anywhere else on the website.
Legal basis: Art. 6 (1) (f) GDPR (convenient and correct city entry).
11. Payments and invoices (Stripe)
Payments are processed by Stripe Payments Europe, Ltd., Ireland (part of Stripe, Inc., USA). On Stripe's payment page you enter your payment details and billing address and, if you buy as a business, your company name and VAT ID. We do not receive your full card details. Stripe calculates the VAT (Stripe Tax) and creates an invoice for every payment.
- We store the payment records needed for accounting: amount, date, the listing concerned, and Stripe's references to the payment and invoice, plus the time you accepted our terms.
- Billing details are stored by Stripe, not by us.
Legal basis: Art. 6 (1) (b) GDPR (contract) and Art. 6 (1) (c) GDPR (tax and accounting obligations). Stripe also processes data as an independent controller, for example to prevent fraud: https://stripe.com/privacy
12. How long we keep data
- Visit and click counter values: at most two days; "online now" signals: at most one day.
- Account and listings: as long as you use TopFoodSpot. You can delete single listings or your whole account at any time (section 13); a deleted listing is hidden at once and its description and links are removed.
- Listings that were never paid for: deleted automatically after 90 days.
- Payment records and invoices: 10 years from the end of the year of payment, as required by German tax and commercial law (§ 147 AO, § 14b UStG, § 257 HGB). After an account is deleted, they are kept without any link to the person and then deleted automatically.
- Contact messages: see section 7.
The automatic deletions run once a day.
13. Deleting your account
You can delete your account yourself at any time in your dashboard under "Delete account", or ask us to do it via the contact form or [email protected]; we then delete it within 30 days. Your listings are removed from TopFoodSpot immediately and their content is deleted, together with your account and email address. Payment records and invoices are kept as described in section 12, as the law requires.
14. Our Instagram profile
We run the Instagram profile @srdigital0626, on which we may also present TopFoodSpot. When you visit it, Meta Platforms Ireland Ltd. processes your data under its own responsibility, including in the USA; for some processing, such as page statistics (Insights), we are jointly responsible with Meta (Art. 26 GDPR). We only receive anonymous statistics.
Legal basis: Art. 6 (1) (f) GDPR (presenting our business). You can best exercise your rights directly with Meta: https://privacycenter.instagram.com/policy and https://www.facebook.com/legal/terms/page_controller_addendum
15. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). Contact us via [email protected] or the contact form.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg, https://datenschutz-hamburg.de
Bot protection (Cloudflare Turnstile)
To protect the sign in and contact forms against automated abuse, we use Cloudflare Turnstile, a service of Cloudflare, Inc., USA. Only when you open one of these forms, Turnstile is loaded from Cloudflare's servers and checks, mostly without any action on your part, whether the request comes from a person. For this, Cloudflare processes your IP address and technical information about your browser and device.
Legal basis: Art. 6 (1) (f) GDPR (protecting our services against abuse and spam). Cloudflare, Inc. is certified under the EU-US Data Privacy Framework.
16. Other information
We do not use automated decision making or profiling. Providing data is voluntary; without an email address, however, we cannot create an account, and without payment a listing cannot be published. We may update this privacy policy when our service changes; the current version is always available here.