Privacy Policy
Last updated: 2025-05-06
1. Introduction
Dinner Surprise ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
This policy is compliant with the General Data Protection Regulation (GDPR) and Swedish data protection laws. By using our service, you consent to the data practices described in this policy.
2. Data Controller
Dinner Surprise is the data controller for personal data collected through our website. If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@dinnersurprise.com3. Information We Collect
3.1 Personal Data
We may collect the following personal data:
- Name
- Email address
- Billing information
- User preferences and dietary restrictions
- Account credentials
3.2 Usage Data
We may also collect information about how you access and use our services:
- IP address
- Browser type
- Pages visited
- Time and date of your visit
- Time spent on pages
- Recipe preferences
- Device information
3.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies to track activity on our website and store certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.
4. Legal Basis for Processing
We process your personal data on the following legal grounds:
- Contract fulfillment: Processing necessary to provide our services to you
- Legitimate interests: To improve and personalize our services
- Consent: Where you have specifically agreed to our use of your data
- Legal obligation: Where we need to comply with a legal or regulatory obligation
5. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process payments and manage your account
- Personalize your experience
- Communicate with you about our services
- Monitor and analyze usage patterns
- Detect, prevent, and address technical issues
- Comply with legal obligations
6. Data Retention
We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal or reporting requirements.
For users with an account, we store personal data until account deletion. Usage data may be kept in an anonymized form for statistical purposes.
7. Data Sharing and Disclosure
We may share your personal information with:
- Service providers: Third parties who provide services on our behalf (payment processors, hosting providers)
- Regulatory authorities: Where required by law
- Business transfers: In connection with a merger, acquisition, or sale of assets
We do not sell your personal data to third parties.
8. Your Data Protection Rights
Under GDPR, you have the following rights:
- Right to access: You can request copies of your personal data
- Right to rectification: You can request that we correct inaccurate data
- Right to erasure: You can request that we delete your data
- Right to restrict processing: You can request that we limit how we use your data
- Right to data portability: You can request that we transfer your data to another organization
- Right to object: You can object to our processing of your data
- Rights related to automated decision making: You can request human intervention for decisions made automatically
To exercise these rights, please contact us at privacy@dinnersurprise.com. We will respond to your request within 30 days.
9. International Data Transfers
Your information may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ.
When we transfer personal data outside the EU/EEA, we ensure a similar degree of protection is afforded to it by using specific contracts approved by the European Commission.
10. Data Security
We have implemented appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
11. Children's Privacy
Our service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we discover that we have collected personal data from a child, we will delete this data immediately.
12. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "last updated" date.
You are advised to review this Privacy Policy periodically for any changes.
13. Complaints
If you have a concern about our privacy practices, including the way we handled your personal data, you can report it to the Swedish Authority for Privacy Protection (IMY):