Connection lost
Privacy Policy

Privacy Policy

Last updated: 7 July 2026

Restauranger ("we", "us", or "our") is operated by RiseRank AB, a company registered in Sweden. This Privacy Policy explains how we collect, use, and protect your personal data when you use the Restauranger platform available at restauranger.se.

1. Who We Are

RiseRank AB is the data controller responsible for your personal data. If you have questions about this policy, contact us at hello@restauranger.se.

2. Data We Collect

We collect the following personal data:

  • Account information: first name, last name, email address, phone number, and profile photo.
  • Authentication data: when you sign in with Google, Facebook (Meta), or Apple, we receive your name, email address, and profile picture from those providers.
  • Usage data: pages visited, searches performed, restaurants saved or followed, reviews submitted.
  • Device and technical data: IP address, browser type, operating system, and session identifiers.

3. How We Use Your Data

We use your personal data to:

  • Create and manage your account
  • Provide personalised restaurant recommendations
  • Send transactional notifications (e.g. when a restaurant replies to your review)
  • Improve the platform through analytics and usage insights
  • Comply with legal obligations under GDPR
  • Use aggregated and anonymised data for business analytics, statistics and platform development

We may also use data in anonymised or aggregated form for commercial purposes, including market research and business reporting. Anonymised data does not constitute personal data and falls outside the scope of GDPR.

4. Social Login — Facebook (Meta)

If you choose to sign in using Facebook Login, we receive your public profile data (name, email address, and profile picture) from Meta Platforms, Inc. We use this data solely to create or identify your Restauranger account. We do not post to Facebook on your behalf, access your friends list, or store your Facebook credentials.

5. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR:

  • Contract performance: to provide you with the Restauranger service
  • Legitimate interests: to improve platform functionality, prevent fraud, and send service-related communications to registered users about updates and new features
  • Consent: for marketing emails — you can opt in at registration or at any time through your account settings, and withdraw consent at any time

6. Data Sharing

We do not sell your personal data. We may share data with:

  • Service providers: cloud hosting (AWS), analytics (PostHog, Google Analytics), email delivery (Mailchimp)
  • Authentication providers: Google, Meta, Apple — only to facilitate login
  • Legal authorities: when required by law

All third-party service providers who process personal data on our behalf are engaged under data processing agreements (DPAs) pursuant to Article 28 GDPR. These agreements require processors to handle personal data only on our documented instructions and to implement appropriate technical and organisational security measures.

7. Data Retention

We retain your personal data for as long as your account is active. If you delete your account, your account data is erased within 30 days, except where retention is required by law. Server logs and technical data are retained for up to 12 months. Analytics data collected through PostHog and Google Analytics is retained in accordance with the respective service configurations, subject to applicable data protection law. We periodically review our retention periods to ensure that personal data is not kept for longer than is necessary for its original purpose.

8. International Data Transfers

Some of our service providers are based outside the European Economic Area (EEA). In particular, analytics services (PostHog, Google Analytics), cloud infrastructure (AWS), and email delivery (Mailchimp) may involve transfers of personal data to the United States or other third countries. Where such transfers occur, we ensure that appropriate safeguards are in place — principally the European Commission's standard contractual clauses (SCCs) pursuant to Article 46 GDPR. To request further information about the safeguards applicable to any specific transfer, contact us at hello@restauranger.se.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration, in accordance with Article 32 GDPR. These measures include encrypted data transmission (TLS), access controls, and regular security reviews. Access to personal data is restricted to personnel who require it to perform their duties. No method of transmission over the internet is entirely secure, however, and we cannot guarantee absolute security.

10. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 GDPR.

11. Your Rights

Under GDPR, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Withdraw consent at any time
  • Lodge a complaint with your local data protection authority

To exercise your rights, contact us at hello@restauranger.se.

12. Cookies

We use cookies to maintain sessions and collect analytics data. A cookie consent banner is shown on your first visit. You can manage cookie preferences at any time via the banner or your browser settings.

13. Children's Privacy

Restauranger is not directed at children under the age of 13. We do not knowingly collect personal data from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the platform or sending an email.

15. Marketing Communications

We will only send you marketing emails if you have given your explicit prior consent. You may give consent by ticking the optional opt-in box when creating your account, or at any time through your account settings. You may withdraw consent at any time via the unsubscribe link in any marketing email or through your account settings. Withdrawal of consent does not affect the lawfulness of any processing carried out prior to withdrawal. Service-related communications (such as transaction notifications and account security emails) are not marketing communications and are sent on the basis of contract performance or legitimate interests.

16. Language

This Privacy Policy is published in Swedish and English. The Swedish version is the legally binding version. In the event of any discrepancy or conflict between the two versions, the Swedish version shall prevail.

17. Contact

RiseRank AB
Stockholm, Sweden
hello@restauranger.se