Who We Are
Royal Palace (“we”, “us”, “our”) operates the website https://royalpalacefr.com and related services for browsing the menu, placing orders (delivery or pickup), and reserving tables.
Address: Your Company Address, France. Contact: royalpalacefr@gmail.com.
Data We Collect
- Account & Contact: name, email, phone, password (hashed), OTP codes for verification.
- Order & Booking: items, preferences, special instructions, date/time of bookings, party size.
- Addresses & Location: delivery address, postcode/city; if you allow, approximate location for branch finding or delivery availability.
- Payment Details: processed by our payment partners (e.g., Stripe). We do not store full card numbers.
- Device/Usage: IP, browser/OS, pages viewed, clicks, timestamps, referring URLs.
- Cookies: session cookies, preferences, analytics, and (optional) marketing cookies.
- Support: messages you send us and related metadata.
How We Use Data
- To create and maintain your account; verify your email/phone via OTP.
- To process orders, take payments, provide delivery/pickup, and manage table bookings.
- To personalize content (e.g., show nearby branches, remember your cart).
- To send transactional messages (order status, receipts, OTP, booking confirmations).
- To improve our website, menu, and services via analytics and feedback.
- To detect, prevent, and respond to fraud or abuse.
- With your consent, to send offers, promotions, or newsletters (you can opt out anytime).
Legal Basis (EU/EEA)
If you are in the EU/EEA (including France), we process personal data under these bases:
- Contract: to provide the services you request (orders, payments, bookings).
- Legitimate Interests: site security, service improvement, customer support.
- Consent: marketing emails/notifications; certain cookies/analytics.
- Legal Obligation: tax and accounting recordkeeping.
Analytics & Advertising
We may use analytics tools (e.g., Google Analytics) to understand site usage and performance. If marketing cookies are enabled, we may use remarketing tags to measure campaign effectiveness. Data is generally aggregated and does not identify you directly.
Payments
Card payments are handled by our payment partner (e.g., Stripe) in compliance with PCI-DSS. We receive a payment confirmation/identifier but do not store full card details on our servers. Please review your payment provider’s privacy policy for more information.
Data Retention
We keep data only as long as necessary for the purposes above, including legal, tax, and accounting obligations. You can request deletion of your account and associated personal data (subject to lawful exceptions).
Security
We implement safeguards such as encryption in transit (HTTPS), access controls, and periodic reviews. No method of transmission or storage is 100% secure; we work to protect your data continuously.
International Transfers
Where data is transferred outside your country (e.g., to service providers), we take steps to ensure appropriate protections (e.g., standard contractual clauses where applicable).
Your Privacy Rights
Depending on your location, you may have rights to:
- Access, correct, or delete your personal data.
- Object to or restrict processing, and request portability.
- Withdraw consent where processing is based on consent (e.g., marketing).
- Lodge a complaint with a supervisory authority (e.g., CNIL in France).
To exercise rights, contact us at royalpalacefr@gmail.com. We may need to verify your identity.
Children’s Privacy
Our services are not directed to children under the age required by local law. If we learn we’ve collected personal data from a child without appropriate consent, we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date.
Contact Us
If you have questions about this Policy or your data, contact: Royal Palace, Your Company Address — royalpalacefr@gmail.com.