Privacy Policy

Website: www.cheffy.lt

Effective Date: February 24, 2026

Website Owner: Dmitri Garo, self-employed individual operating under Individual Activity Certificate No. 1425963 issued in the Republic of Lithuania

Address: Kreivasis skg. 18, Vilnius, Lithuania

Email: team@cheffy.lt

1. General Provisions

1.1. This Privacy Policy (the “Policy”) defines the procedure for collecting, storing, using, transferring, and protecting personal data of users of the website www.cheffy.lt (the “Portal”).

1.2. Personal data is processed in accordance with the General Data Protection Regulation (GDPR), the Law on Legal Protection of Personal Data of the Republic of Lithuania, the EU ePrivacy Directive, and other applicable EU legal acts.

1.3. By using the Portal, the User confirms that they have read and agree to this Policy.

2. Terms and Definitions

2.1. User – any natural or legal person using the Portal.

2.2. Client – a registered User who orders services through the Portal.

2.3. Service Provider – a registered User offering cooking and/or grocery shopping services.

2.4. Personal Data – any information relating to an identified or identifiable person.

2.5. Processing of Personal Data – any operation performed on personal data (collection, storage, use, deletion, etc.).

3. Categories of Data Collected

3.1. Data provided by the User: first name, last name, email address, phone number, service address, billing information.

3.2. Automatically collected data: IP address, cookies, browser data, website activity logs.

3.3. Payment data: processed by Stripe Connect and not stored on the Portal's servers.

3.4. Order and rating data: order history, reviews, and rating scores.

4. Purposes of Processing and Legal Basis

Purpose of ProcessingData CategoryLegal Basis
Account registrationName, email, phoneContract (Art. 6(1)(b) GDPR)
Order fulfillmentContact details, address, order historyContract
Payments and refundsPayment dataLegal obligation (Art. 6(1)(c) GDPR)
Service improvementLogs, website behaviorLegitimate interests (Art. 6(1)(f) GDPR)
Marketing communicationsEmail, nameConsent (Art. 6(1)(a) GDPR)
Dispute resolutionCorrespondence, order historyLegitimate interests

5. Automated Decision-Making

5.1. The Portal uses an automated rating system for Service Providers.

5.2. If the average rating of the last five orders falls below 4.5, the Service Provider's account is temporarily suspended. A manager reviews the case and decides on reinstatement or termination of cooperation within three working days.

5.3. The User has the right to request human review of such a decision.

6. Data Transfers and International Transfers

6.1. Data may be transferred to:

  • Stripe Connect (USA)
  • Analytics services (Google, Meta)
  • Hosting providers

6.2. Transfers outside the European Economic Area (EEA) are carried out using Standard Contractual Clauses (SCC) approved by the European Commission.

7. Retention of Personal Data

Data CategoryRetention PeriodLegal Basis
Account data (name, email, phone)While the account is active + 3 yearsStatute of limitations
Orders and transactions10 yearsTax legislation
Correspondence3 yearsLegitimate interests
Marketing dataUntil consent is withdrawnConsent
Logs and technical data6 monthsSecurity

7.2. After the retention period expires, data is deleted or anonymized.

8. User Rights

The User has the right to:

  • Access, rectify, or erase personal data
  • Restrict processing
  • Data portability
  • Withdraw consent
  • Lodge a complaint with the State Data Protection Inspectorate (VDAI) ( www.ada.lt ) or via the EU ODR platform ( https://ec.europa.eu/odr/ ).

The response period for requests is 1 month (may be extended to 2 months in complex cases).

9. Cookies

9.1. The following types of cookies are used: essential, functional, analytical, and marketing.

CookieTypePurposeRetention PeriodSet By
session_idEssentialAuthenticationSessionmy-chef.eu
lang_prefFunctionalLanguage preference6 monthsmy-chef.eu
_gaAnalyticalGoogle Analytics2 yearsGoogle
_fbpMarketingAdvertising3 monthsMeta

9.3. A cookie consent banner is displayed upon the User's first visit.

9.4. The User may modify or withdraw consent via browser settings or the website's cookie manager.

10. Security Measures

10.1. The following measures are implemented:

  • SSL encryption
  • Restricted access to data
  • Administrative panel access control
  • Regular data backups

11. Changes to the Policy

11.1. We may update this Policy by publishing a new version on the Portal.

12. Contact Information

Dmitri Garo, self-employed individual operating under Individual Activity Certificate No. 1425963 issued in the Republic of Lithuania

Address: Kreivasis skg. 18, Vilnius, Lithuania

Email: team@cheffy.lt