Operator details
- Legal name
- Faraday Web Services Ltd
- Company registration number
- 13228535
- 12 George Road
- Suite 5, The Cloisters
- Birmingham B15 1NP
- West Midlands
- United Kingdom
1. Who is the data controller
The data controller is Faraday Web Services Ltd (registered company number 13228535), with registered office at 12 George Road, Suite 5, The Cloisters, B15 1NP Birmingham, West Midlands, United Kingdom. Please use the Contact form on this website for privacy questions, data-protection requests, or any other enquiry about this Policy; choose the Privacy or related subject so we can route your message correctly. Where we act as a data processor on behalf of restaurant owners (for example, hosting the Content they publish), the relationship is governed by these terms together with our Terms of Service.
2. What personal data we collect
We collect: (a) account data — name, email address, password (hashed), preferred language and country, role, and account status; (b) owner & subscription data — restaurant claim evidence, billing name and address, VAT number where applicable, and payment metadata returned by Stripe (we never see or store your full card number); (c) listing data — public information you submit about a restaurant (address, hours, menu links, photos, halal information); (d) user-generated content — reviews, ratings, photos, reports of incorrect information; (e) usage data — IP address, device, browser, language, pages viewed, search terms, referrer, and timestamps; (f) location data — only when you explicitly press "near me" or grant geolocation permission, processed in real time to return nearby restaurants and not stored against your account; (g) communications — messages you send to support, claim verifications, and email engagement (open/click) for transactional and (where you opt in) marketing emails; (h) cookies & similar identifiers — see section 8 below.
3. Where the data comes from
Most data is collected directly from you when you visit the Service, create an account, claim a restaurant, post a review, or subscribe to a paid plan. Some data is collected automatically through your browser or our analytics tools. A small portion comes from third parties: Stripe (payment confirmations and billing metadata), restaurant owners (when they update a Listing), other users (when they review or report a restaurant), and public sources (publicly listed contact details, business registries, and publicly shared photos used to seed initial Listings).
4. Why we use your data and on which legal basis
We process personal data: (i) to operate, secure and improve the Service — based on our legitimate interest in running a useful, safe directory; (ii) to provide the directory and search experience to visitors — legitimate interest; (iii) to create and manage your account, claim flow and subscription — performance of a contract; (iv) to process Premium Subscription payments through Stripe and prevent fraud — performance of a contract and legal obligation; (v) to publish restaurant Listings, photos and reviews — legitimate interest in running a directory and (where applicable) consent of the submitter; (vi) to send transactional emails (claim status, payment receipts, security alerts) — performance of a contract; (vii) to send marketing emails about the Service to owners who have opted in — your consent, withdrawable at any time; (viii) to comply with legal obligations such as accounting, tax, fraud-prevention and responding to lawful requests — legal obligation; (ix) to defend or exercise legal claims — legitimate interest.
6. International transfers
We are based in the European Economic Area / United Kingdom but serve users worldwide. Some of our sub-processors (notably Stripe and global hosting / email providers) may process data outside the EEA or UK, including in the United States. When that happens we rely on appropriate safeguards approved by the European Commission and the UK Information Commissioner — chiefly the Standard Contractual Clauses, the EU-US Data Privacy Framework where the recipient is certified, and the UK Addendum. A copy of these safeguards is available on request.
7. How long we keep your data
We keep personal data only as long as necessary for the purposes for which it was collected. Account data is kept for the lifetime of your account and deleted (or anonymised) within 12 months of account closure unless we are legally required to keep it longer. Subscription and billing records are kept for the period required by tax and accounting law (typically 10 years in France, 6 years in the UK). Server logs are kept for up to 13 months. Reviews remain associated with the displayed name you chose at the time of posting; you can request anonymisation or removal at any time. Backups are rotated and overwritten automatically; data may persist there for a short additional period for resilience purposes.
8. Your rights
Subject to applicable law, you have the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased ("right to be forgotten"); restrict or object to certain processing, including direct-marketing profiling; receive a portable copy of data you provided to us; withdraw consent at any time where processing is based on consent (without affecting prior processing); and lodge a complaint with your local data-protection authority (such as the CNIL in France, the ICO in the United Kingdom, the GBA in Belgium, the AP in the Netherlands, the BfDI in Germany, the OPC in Canada, the OAIC in Australia, or your state Attorney General in the United States). To exercise any of these rights, submit a request through the Contact form on this website from the email address linked to your account where possible, and choose the privacy / data-rights subject; we may ask for proof of identity before responding, and will reply within the legal deadline (one month under the GDPR, extendable by two months for complex requests).
10. Security
We take the security of your data seriously and use technical and organisational measures including encryption in transit (TLS), hashed passwords, role-based access controls, audit logging, regular dependency updates, and monitoring. No internet service can be guaranteed 100% secure; if you believe your account has been compromised or you spot a vulnerability, please use the Contact form on this website and choose the security subject.
11. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe that a child has provided us with personal data, please submit a report through the Contact form on this website and we will delete it.
12. Automated decision-making
We do not use solely automated decision-making (including profiling) that produces legal or similarly significant effects on you. Our ranking signals (featured placement, sort order, search relevance) are guided by aggregate, non-individual factors such as ratings, review counts, recency, and Premium status.
13. Changes to this Policy
We may update this Policy from time to time. The current version is always the one published on this page; we update the "Last updated" date above when we make changes. If a change is material we will notify registered users by email or in-product notice before it takes effect.
14. Contact
We do not publish a public support email address. For any privacy-related question, request, or complaint — or for general, legal, or security matters — please use the Contact form on this website and pick the subject that best matches your request. Postal mail can be sent to Faraday Web Services Ltd, 12 George Road, Suite 5, The Cloisters, B15 1NP Birmingham, West Midlands, United Kingdom.
Last updated: May 2026
