Privacy Policy
Last updated: 12 August 2026 · Version 1.0
1. Who we are
GetEats is an online marketplace for food sold directly by independent farms and small producers, operated at geteats.com. The controller of the personal data described here is:
Global Data Labs LLC · Georgia · identification number 402363321
Registered office: Georgia, Tbilisi, Mikheil Tsinamdzgvrishvili Street, N 52, Attic
Contact: info@geteats.com
Georgia is outside the European Economic Area. Section 7 explains what that means for your data and what safeguards we apply.
2. Who this policy is about
This policy covers three groups, because we process different data about each:
- Buyers — people who browse geteats.com, place orders or create an account.
- Partners — farms and producers that sell through the marketplace, and the people who represent them.
- Business contacts — food businesses we approach with a professional proposal to join the marketplace, whose details we obtained from public sources. Section 4 covers this separately, including where we got them.
A note on roles. GetEats is a marketplace, not the seller. The farm that sells you a product is the seller, and it receives the data it needs to prepare and hand over your order — your name, the delivery address, the order contents. For that use of the data the farm decides for itself and acts as a separate controller.
3. What we collect from buyers and partners
- Name, e-mail, phone number — to create and run your account, confirm and deliver orders, and contact you about a specific order. Legal basis: performance of a contract.
- Password — stored only as a cryptographic hash. We never see or store the password itself.
- Delivery addresses and their map coordinates — to show producers who can actually deliver to you, and to deliver the order. Legal basis: performance of a contract.
- Orders — items, quantities, amounts, status and delivery details, for fulfilment, support, returns and accounting.
- The country your connection appears to come from — to choose which producers to show a first-time visitor. This is a country-level signal from our network provider, not precise location tracking, and we do not build a location history. Legal basis: our legitimate interest in showing a usable catalogue.
- Technical data — IP address, browser type and server log entries, to keep the service available, diagnose faults and prevent abuse. Legal basis: our legitimate interest in security.
- For partners — business details, product listings, prices, photos and published text, plus payout-related information, to run your storefront, settle amounts owed and meet our tax and accounting duties.
Payment card data. We do not receive, process or store card numbers. Online card payment is handled by a specialised payment provider; at the date of this policy that integration is being activated, and until it is live no card data is collected anywhere on the site.
We do not collect special category data such as health or beliefs, we do not profile you for advertising, and we do not make decisions about you by automated means alone (see section 10).
4. Business contacts obtained from public sources
To build the producer side of the marketplace we approach farms and food businesses with a professional proposal. Where we did not receive your details from you directly, the GDPR requires us to tell you so, and this is that notice.
- What we hold — the business name, a professional e-mail address and/or phone number, the website address, the public business-listing link, the region and the product category.
- Where it came from — publicly available sources: the business's own website and its public business listing, such as a maps profile.
- Why — to send a one-off professional proposal to join the marketplace, and one reminder if there is no reply. This is our legitimate interest in business-to-business outreach, weighed against your interests: we write to professional addresses only, about a matter within your trade, and stop immediately when asked.
- How to stop it — reply STOP to any message, or write to info@geteats.com. We delete the contact details and do not write again. No reason is needed.
- How long — up to 12 months from collection if you do not reply, and sooner on request.
5. Cookies
At the date of this policy the site uses two cookies, both strictly necessary:
- session (set by GetEats) — keeps you signed in and keeps your basket attached to your session. HttpOnly and Secure.
- __cf_bm (set by Cloudflare) — distinguishes human from automated traffic, protecting the site from abuse.
We use no analytics, advertising or tracking cookies, and no third-party marketing pixels. That is why you are not asked for cookie consent: strictly necessary cookies do not require it. If we later add analytics or any non-essential cookie, we will ask for your consent first and update this policy before doing so.
6. Who else sees your data
- The partner farm that sells your order — your name, delivery address and order contents.
- Delivery — our logistics partner GetTransfer, for what is needed to collect and deliver.
- Hosting and infrastructure — DigitalOcean for our servers and for object storage of product images, located in the United States; Cloudflare for content delivery and security.
- E-mail — our mail provider for correspondence, and a transactional e-mail service for order notifications and password resets.
- Payment provider — once online card payment is active, to process your payment.
- Address search — mapping services, when you search for an address to choose a delivery point.
- Professional advisers and authorities — accountants, auditors or lawyers where necessary, and public authorities where the law requires it.
We do not sell personal data, and we do not share it for anyone else's marketing.
7. International transfers
The controller is established in Georgia, which the European Commission has not recognised as providing an adequate level of protection, and some of our providers are located in the United States. Where personal data of people in the EEA is transferred to us or to those providers, the transfer is made under Standard Contractual Clauses or another safeguard permitted by Article 46 GDPR, together with the measures described in section 8. You may ask us about the safeguards applying to a specific transfer by writing to info@geteats.com.
8. How we protect data
Access is limited to the people who need it for their role. Traffic to and from the site is encrypted in transit. Passwords are stored only as hashes. Administrative access is restricted and logged, and we keep secrets out of application logs. No system is perfectly secure, but if a breach occurs that is likely to put you at risk, we will inform you and the competent authority as required.
9. How long we keep data
- Account and order data — while your account exists, and afterwards for the periods required by tax and accounting law, or until a related claim is resolved.
- Business contacts from public sources — up to 12 months, or immediately on request (section 4).
- Server and security logs — a short period, sufficient for diagnostics and abuse prevention.
Data no longer needed for any of the purposes above is deleted or irreversibly anonymised.
10. Automated decisions
We do not make decisions about you based solely on automated processing, and we do not profile you. Matching producers to the address or country you provide is a filter that decides what a catalogue page shows — it has no legal effect on you.
11. Your rights
If you are in the EEA or the United Kingdom, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent where processing is based on consent.
Write to info@geteats.com and we will respond within one month, as the GDPR requires. We do not charge for this and we will not treat you differently for asking. You can also complain to a supervisory authority in your country of residence, place of work, or where the issue arose — in France the CNIL, in Italy the Garante per la protezione dei dati personali.
12. Age
The marketplace is intended for adults. We do not knowingly create accounts for children, and no age-restricted goods such as alcohol are sold.
13. Changes to this policy
We will update this page when our processing changes, and we will change the version and date at the top. If a change materially affects you, we will say so clearly rather than only editing the text.
14. Contact
Privacy questions and requests: info@geteats.com. You can also reach us through support. The terms that govern orders are in our terms of use.