Privacy policy
Last updated: 11 September 2026
This notice explains which personal data we collect when you use myprivatechef.it and the MyPrivateChef services, why we use it, who we share it with and what rights you have. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) and the Italian Privacy Code (Legislative Decree 196/2003). In case of doubt, the Italian version prevails.
1. Data controller
The data controller is MyPrivateChef S.r.l.s., Piazza dell’Erba 11, 05018 Orvieto (TR), Italy, VAT no. IT01760940559. For any question about this notice or to exercise your rights, write to [email protected].
2. Which data we process
If you request a chef (guest)
- Contact details: name, email address, phone number.
- Request details: address where the service takes place, date and time, number of guests, type of occasion, cuisine preferences, kitchen equipment, chosen price range, any notes. For holidays: dates, number of adults and children, meals requested.
- Dietary restrictions: allergies, intolerances and preferences (for example vegetarian, gluten-free, halal, kosher). This information may reveal health data or religious beliefs: we collect it only if you provide it, use it exclusively to prepare the service safely and store it encrypted.
- Proposal and payment: proposed menu, amount, payment status. Payment happens on Stripe: we never see or store your card details, we only receive the outcome and the transaction identifier.
- Review: the rating and text you choose to leave after the service.
- Communications: emails and messages exchanged with our team, requests sent through the support and sommelier forms.
- Request source: if you arrive from a campaign, the campaign parameters in the address (for example
utm_source) are saved with the request to understand where bookings come from. They do not identify you.
If you sign up as a chef
- Account: name, email, profile photo, identifier of the sign-in account (Google, or email and password through Firebase Authentication). We never see your password.
- Professional profile: biography, working area, specialities, photos, dishes and menus, documents uploaded to activate the profile (CV and HACCP certificate, PDF), VAT number if you have one, details to receive your payouts (IBAN or PayPal email).
- Activity on the platform: requests you open among the opportunities, proposals sent, bookings and related payouts, reviews received, acceptance of the terms with date and version.
- Support: the tickets you open and the messages exchanged with the team, stored encrypted.
If you are a partner or supplier
Organisation name, contact person, contact details and notes on the business relationship, kept in our partner archive together with the messages exchanged.
If you visit the site
- Technical data: IP address, browser and device type, pages requested, date and time, generated by server logs and by the site protection services (Cloudflare). They keep the site running and protect it from abuse.
- Request flow: the answers you give in the request form stay in your browser (sessionStorage) until you submit. We also record, in pseudonymous form and without cookies, which steps of the flow you reach (a random identifier stays in your browser only for the duration of the tab, no personal data): it helps us understand where users stop and improve the form.
- Statistics and advertising: only with your consent we use Google Analytics and Google Ads (see the Cookies section).
You are not obliged to provide data, but without the fields marked as required in the forms we cannot handle the request, create the account or reply to you.
3. Purposes and legal bases
| What we do | Data used | Legal basis |
|---|---|---|
| Receive your request, propose a chef and a menu, manage booking, payment and service | Contact details, request details, proposal and payment | Performance of a contract or pre-contractual steps (Art. 6.1.b GDPR) |
| Prepare the service respecting allergies, intolerances and dietary preferences | Dietary restrictions | Your explicit consent (Art. 9.2.a GDPR), given when you provide them; you can withdraw it by writing to us |
| Create and manage your chef profile, verify it, offer you opportunities and manage the bookings assigned to you | Account, professional profile, activity on the platform | Performance of a contract (Art. 6.1.b) |
| Send you service notifications: confirmations, proposals, reminders, payment outcomes, review invitations, ticket replies | Email, phone | Performance of a contract (Art. 6.1.b) |
| Answer support requests and contacts | Communications | Pre-contractual steps and legitimate interest in replying to those who write to us (Art. 6.1.b and 6.1.f) |
| Publish reviews about the service | Review, name (abbreviated) | Your consent (Art. 6.1.a) |
| Manage relationships with partners and suppliers | Partner data | Performance of a contract and legitimate business interest (Art. 6.1.b and 6.1.f) |
| Comply with tax and accounting obligations and defend our rights | Booking and payment data | Legal obligation (Art. 6.1.c) and legitimate interest (Art. 6.1.f) |
| Keep the site running securely, prevent abuse and fraud, limit automated requests | Technical data | Legitimate interest (Art. 6.1.f) |
| Measure the use of the site and of advertising campaigns | Flow statistics, Google Analytics and Google Ads data | Your consent (Art. 6.1.a and Art. 122 Italian Privacy Code), which you can withdraw at any time |
We do not take decisions based solely on automated processing that produce legal effects on you. We do not profile you for commercial purposes.
4. Who we share data with
Data is processed by our team and by the people who work with us, instructed on confidentiality. We share it only with those needed to deliver the service:
- The chefs: when we assign the service, the chef receives the details needed to carry it out (name, address, date and time, number of guests, dietary restrictions and notes). Chefs undertake to use this data only for the service.
- Stripe Payments Europe Ltd (Ireland), for card payments. Stripe is an independent controller of payment data: Stripe privacy policy.
- Google Ireland Ltd, for sign-in to the chef area and back office (Firebase Authentication) and, with your consent, for statistics and advertising (Google Analytics, Google Ads): Google privacy policy.
- Cloudflare Inc., for protection, content delivery and certificates of the site.
- Hetzner Online GmbH (Germany) and OVH SAS (France), which host our servers in the European Union; uploaded documents and photos are stored on these servers.
- DigitalOcean LLC, for the managed database, hosted in the Frankfurt data centre.
- Zoho Corporation (servers in the European Union), for delivering service emails.
- Telegram (Telegram FZ-LLC), only for our team's internal alerts: when a request or a ticket arrives, the team receives a message with reference, city, date, number of guests and occasion, never the customer's contacts or notes.
- Advisers, authorities and insurers where the law requires it or to enforce a right.
Providers processing data on our behalf are appointed as processors under Art. 28 GDPR. We do not sell your data and do not pass it to third parties for marketing purposes.
5. Transfers outside the European Union
Our main systems are hosted in the European Union. Some providers (Google, Stripe, Cloudflare, Telegram) may also process data in non-EU countries, in particular the United States. In those cases the transfer relies on adequacy decisions of the European Commission, including the EU-US Data Privacy Framework for certified providers, or on standard contractual clauses with additional safeguards. You can ask us for a copy of the safeguards applied.
6. How long we keep data
- Requests that do not become bookings: up to 24 months from the last contact, so we can follow up on the same request.
- Bookings, proposals and payments: for the duration of the relationship and then for 10 years, as required by tax and accounting rules and to protect rights in case of disputes.
- Dietary restrictions and notes: deleted or anonymised at the end of the retention of the booking they belong to, or earlier on your request once the service is over.
- Chef account and profile: while the account is active; after closure we keep only what is needed for tax obligations and defence of rights, for the period set by law.
- Reviews: while the service is published, unless you ask for removal.
- Support communications, tickets and partner archive: up to 24 months from the last exchange.
- Notifications and technical identifiers: sent notifications, expired sessions and temporary Telegram identifiers are deleted automatically within 30 days.
- Technical and security logs: up to 12 months.
- Statistics: Google Analytics data kept for 14 months; request flow statistics are pseudonymous.
7. How we protect data
The site and the APIs are reachable only over encrypted connections (HTTPS). Dietary restrictions, notes, message contents and partner data are encrypted in the database. Documents uploaded by chefs are stored in a private space that is not publicly accessible. Back office sessions expire after a few hours and access is limited to authorised team members. We apply request limits to prevent abuse and keep encrypted backups.
8. Your rights
At any time you can ask us to:
- access your data and receive a copy;
- rectify inaccurate or incomplete data;
- erase data, when we no longer have a legitimate reason to keep it;
- restrict processing while a check is pending;
- receive data in a structured format (portability) for processing based on contract or consent;
- object to processing based on legitimate interest;
- withdraw consent where processing relies on it, without affecting the lawfulness of prior processing.
To exercise your rights write to [email protected]. We reply within one month; for complex requests we may extend the deadline by two months, letting you know. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante) or with the authority of the country where you live.
9. Cookies and similar tools
A cookie is a small file the site saves in your browser. We also use the browser’s local storage and session storage, which work in a similar way. Here is the full list.
Technical tools, always active
They are necessary for the site to work and do not require consent (Art. 122 Italian Privacy Code).
| Name | Purpose | Duration |
|---|---|---|
__Host-mpc_csrf | Protects forms from forged submissions (CSRF) | 1 hour |
__Host-mpc_session | Keeps the session of back office users | 8 hours |
__Host-mpc_client | Keeps the session of whoever opens a personal link received by email (proposal, payment, review) | 8 hours |
idToken (local storage) | Keeps you signed in to the chef area | Until you sign out of the chef area |
| Firebase Authentication data (IndexedDB and local storage) | Handles sign-in with Google or email and password in the chef area and back office | Until sign-out |
| Request flow state (session storage) | Remembers the answers given in the request form until you submit it | Closing the tab |
mpc_analytics_consent (local storage) | Remembers whether you consented to statistics | 12 months |
mpc_attribution and mpc_key_* (session storage) | Remember the campaign parameters you arrived with and the keys that prevent duplicate form submissions | Closing the tab |
mpc_analytics_sid (session storage) | Random session identifier for the internal measurement of the booking form; not a cookie, does not identify you | Duration of the tab |
Cloudflare cookies (for example __cf_bm) | Tell legitimate visits from automated traffic and protect the site | Up to 30 minutes |
| Stripe cookies (on the checkout.stripe.com domain) | Make the payment page work and prevent fraud | Set by Stripe |
Statistics and advertising, only with consent
| Service | Purpose | Main cookies and duration |
|---|---|---|
| Google Analytics 4 (Google Ireland Ltd) | Aggregate statistics on visits: pages viewed, source, devices | _ga 2 years, _ga_* 2 years |
| Google Ads (Google Ireland Ltd) | Measures conversions of advertising campaigns | _gcl_au 3 months, IDE 13 months |
These tools stay off until you give consent. The site currently shows no banner to collect it: statistics and advertising tools are therefore active only for those who consented earlier. When we reintroduce the consent request, you will be able to accept or refuse just as easily and change your mind at any time.
How to manage cookies
You can delete or block cookies from your browser settings (Chrome, Firefox, Safari, Edge). Blocking technical cookies may prevent access to the chef area and to payment. To withdraw consent to statistics you can also write to [email protected] and clear the site data from your browser.
10. Minors
MyPrivateChef services are intended for adults. We do not knowingly collect data from children under 14; if you believe a minor has provided us with data, write to us and we will delete it.
11. Changes to this notice
We may update this notice when services or rules change. The version in force is always published on this page with its update date; in case of significant changes we will notify registered users by email.