Skip to content

Privacy Policy

Last updated: February 6, 2026

1. Introduction and Data Controller

We respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the German Telecommunications and Telemedia Data Protection Act (TTDSG). This privacy policy explains how we collect, use, store, and safeguard your personal information when you visit our website or use our services. It also informs you of your privacy rights and how the law protects you.

Data Controller

CookiWise GmbH (Dal Rotti Frankfurt)
Taunusstraße 25, 60329 Frankfurt am Main, Germany
Email: info@dalrotti.com
Phone: +49 69 30036126
VAT ID: DE3684844483 | Tax ID: 204/123/70008
Owner: Dhara Tushar Moradiya

2. Personal Data We Collect

We may collect, use, store and transfer different kinds of personal data about you:

  • Identity Data: First name, last name, username or similar identifier, date of birth (if provided for special offers)
  • Contact Data: Billing address, delivery address, email address, and telephone numbers
  • Financial Data: Payment card details (processed by our payment provider Stripe), transaction information
  • Transaction Data: Details about payments, orders, delivery preferences, special dietary requirements, order history
  • Technical Data: IP address, browser type and version, time zone setting, geolocation data, operating system, device information, cookies and similar technologies
  • Usage Data: Information about how you use our website, including pages visited, time spent on pages, links clicked
  • Marketing and Communications Data: Your preferences in receiving marketing from us and your communication preferences

3. Legal Basis for Processing

We process your personal data on the following legal bases under GDPR Article 6:

  • Performance of Contract (Art. 6(1)(b) GDPR): To process your orders, reservations, and payments
  • Legal Obligation (Art. 6(1)(c) GDPR): To comply with tax, accounting, and food safety regulations
  • Legitimate Interests (Art. 6(1)(f) GDPR): To improve our services, prevent fraud, and maintain security
  • Consent (Art. 6(1)(a) GDPR): For marketing communications and non-essential cookies (you may withdraw consent at any time)

4. How We Use Your Data

We use your personal data for the following purposes:

  • To process and fulfill your online orders and reservations
  • To process payments securely through our payment provider Stripe
  • To coordinate delivery services with our delivery partners
  • To send order confirmations, updates, and customer support responses
  • To send promotional offers and newsletters (only with your consent)
  • To analyze website usage via Google Analytics (with anonymized IP addresses)
  • To comply with legal obligations including tax laws and food safety regulations
  • To improve our website functionality and customer experience

5. Cookies and Tracking Technologies

We use cookies and similar tracking technologies in accordance with the TTDSG. Cookies are small text files stored on your device.

  • Essential Cookies: Required for website functionality (e.g., shopping cart, user session). These do not require consent.
  • Analytics Cookies: Google Analytics to understand website usage. We anonymize IP addresses and have disabled data sharing with Google. You can opt out via cookie settings.
  • Marketing Cookies: Used only with your explicit consent for personalized advertising
  • Social Media Integration: Instagram feed integration (Instagram may set cookies when you view our embedded content)

You can manage cookie preferences at any time through our cookie banner or browser settings. Rejecting non-essential cookies will not affect basic website functionality.

6. Third-Party Data Sharing

We share your personal data only with trusted third parties and only to the extent necessary:

  • Payment Processing: Stripe (US-based, GDPR-compliant via Standard Contractual Clauses) processes payment card data. We do not store full card details.
  • Delivery Services: We share delivery addresses and contact details with our delivery partners to fulfill your order
  • Google Analytics: Website analytics with IP anonymization enabled. Data is processed in accordance with Google's data processing agreement.
  • Google Maps: Address validation and delivery area calculation. Used only when you enter a delivery address.
  • Hosting Provider: Our website is hosted on secure servers. Hosting provider has access to server data for maintenance purposes.

We do not sell your personal data to third parties for marketing purposes.

7. Data Retention

We retain personal data only as long as necessary:

  • Order Data: 10 years to comply with German tax and accounting laws (§ 147 AO)
  • Marketing Consent: Until you withdraw consent or 3 years of inactivity
  • Technical Data: Automatically deleted after 26 months (Google Analytics retention period)

After retention periods expire, we securely delete or anonymize your data

8. Your Legal Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of Access (Art. 15 GDPR): Request a copy of your personal data we hold
  • Right to Rectification (Art. 16 GDPR): Request correction of inaccurate data
  • Right to Erasure (Art. 17 GDPR): Request deletion of your data (subject to legal retention requirements)
  • Right to Restriction (Art. 18 GDPR): Request limitation of data processing
  • Right to Data Portability (Art. 20 GDPR): Receive your data in a structured, machine-readable format
  • Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests
  • Right to Withdraw Consent (Art. 7(3) GDPR): Withdraw consent for marketing and non-essential cookies at any time

Right to Lodge a Complaint: You can complain to your local data protection authority (for Frankfurt: Hessischer Beauftragter für Datenschutz und Informationsfreiheit; for Zwickau: Sächsischer Datenschutzbeauftragter)

To exercise these rights, please contact us using the details in Section 10.

9. Data Security

We implement comprehensive technical and organizational security measures:

  • TLS/SSL encryption for all data transmission
  • Secure payment processing via PCI-DSS compliant Stripe
  • Access controls limiting data access to authorized personnel only
  • Regular security audits and software updates
  • Staff training on data protection and security

In case of a data breach affecting your rights, we will notify you and the relevant data protection authority within 72 hours as required by GDPR Article 33

10. Changes to This Privacy Policy

We may update this privacy policy to reflect changes in our practices or legal requirements. The 'Last Updated' date at the top indicates the most recent revision. We encourage you to review this policy periodically. For material changes, we will provide prominent notice on our website.

11. Contact and Data Protection Officer

For privacy-related questions, to exercise your rights, or to contact our data protection officer:

Email: info@dalrotti.com
Phone: +49 69 30036126
Address: Taunusstraße 25, 60329 Frankfurt am Main, Germany

Data Protection Officer: Available upon request via the contact details above