Privacy Policy
Last updated: 1 June 2026
1. Who we are
This service is operated by Evabits, reachable at inkoop@evabits.com. Evabits acts as the data controller for all personal data processed through the Luncheon application (“the Service”).
2. What data we collect
We collect and process the following categories of personal data:
Account data
- Name and email address
- Hashed password (credentials login) or Google account identity (OAuth login)
- Role within the application (user or administrator)
- Company affiliation
Profile data
- Avatar image, if uploaded (stored in Vercel Blob)
Attendance data
- Daily lunch attendance records linked to your account
- Dates of any manually skipped or retroactively added lunches
Payment data
- Monthly billing totals based on recorded attendance
- Payment status (paid / unpaid) linked to Mollie payment links
- No raw card numbers or bank details are stored by us; Mollie handles all payment processing
Technical data
- Session cookies (
next-auth.session-token) to keep you signed in - Kiosk device tokens (
kiosk_token) stored as a SHA-256 hash — only used to authenticate shared lunch-kiosk devices - No analytics, advertising trackers, or third-party cookies are used
3. Legal basis for processing
- Contract performance (Art. 6(1)(b) GDPR) — processing your account, attendance, and payment data is necessary to deliver the lunch-registration and billing service.
- Legitimate interest (Art. 6(1)(f) GDPR) — retaining historical attendance records for accurate reporting and audit purposes. Our interest does not override your rights; you may object at any time (see section 5).
4. Who we share data with
We use the following sub-processors. Data is only shared to the extent necessary to operate the Service.
- Neon — PostgreSQL database hosting (EU region). Stores all structured application data.
- Vercel — Application hosting and Blob storage (EU region). Serves the application and stores avatar images.
- Mollie — Payment processing. Receives billing amounts and manages payment links. Mollie's own privacy policy governs data it processes as a controller.
We do not sell, rent, or trade your personal data to any third party.
5. How long we keep data
- Account data — retained for the duration of your active membership, and deleted within 12 months of account deactivation upon request.
- Attendance records — retained indefinitely to preserve historical cost reports. Records are soft-linked to anonymised participant IDs if an account is deleted.
- Kiosk device tokens — automatically expire after 1 year.
- Session cookies — expire when you sign out or after the session lifetime configured in NextAuth.
6. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data where no overriding legal ground applies.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to limit processing while a dispute is resolved.
- Objection — object to processing based on legitimate interest; we will stop unless we can demonstrate compelling legitimate grounds.
To exercise any of these rights, email inkoop@evabits.com. We will respond within 30 days.
7. Supervisory authority
If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Dutch data protection authority: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
8. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email to registered users. The “Last updated” date at the top of this page always reflects the current version.
9. Contact
Questions about this privacy policy? Contact us at inkoop@evabits.com.