Legal · Privacy

Privacy Policy

How Cevor handles personal data across restaurant discovery, accounts and Cevor Business.

Last updated · 9 September 2026 · Version 3.0

Cevor is a restaurant discovery platform that helps users discover establishments, featured dishes and useful information to choose where to go. Cevor also provides tools for restaurants to manage their presence on the platform.

1. Controller and scope

Cevor operates the service from Brussels, Belgium and is the controller for account, discovery, website, lead and Business-user data described here. No data protection officer has been appointed; the legal contact below is the canonical contact.

2. Account and preference data

  • Account identifier, email, authentication provider and sign-in metadata.
  • Profile details, language, onboarding answers and discovery preferences you provide.
  • Favorites, collections and saved restaurants where these features are used.

3. Discovery, location and personalization

Searches, restaurant and featured-dish interactions, impressions and similar signals may be associated with an account or session to provide requested features, improve discovery and understand aggregate use.

If the app asks for location, permission is optional and is used to prioritize nearby or relevant restaurants. Refusing it does not prevent general discovery, but proximity results may be less relevant. Cevor does not make a blanket promise here about retaining or deleting exact coordinates; the app permission and current implementation govern whether location is processed on-device, transiently or stored.

  • Personalization and ranking help order relevant results; they do not make decisions producing legal or similarly significant effects.

4. Technical, analytics and communication data

  • Device, platform, app/browser version, language, timezone, session and security information, IP address in server logs, and error diagnostics where generated.
  • For website waitlist, demo and pilot forms: name, email, phone where requested, restaurant details, answers, source, timestamps, device/browser details, referral and campaign parameters, completion timing and interaction metadata.
  • Transactional and service emails. Welcome emails may record delivery, opens and tracked-link clicks to measure delivery and engagement; this does not expand the destination of a link.
  • Marketing communications are sent only where an appropriate permission or other lawful basis exists; a contact or demo request is not by itself indefinite marketing consent.

5. Legal bases

  • Contract: accounts, saved features, requested discovery functionality and Cevor Business services.
  • Legitimate interests: service security, abuse prevention, product improvement, proportionate first-party analytics and responding to enquiries.
  • Consent: optional device location permission, non-essential tracking where required, and optional marketing.
  • Legal obligation: tax, accounting, regulatory and lawful authority requests.

6. Restaurants and aggregated analytics

Restaurants may receive aggregated, product-level signals such as profile views, discovery interactions, reservation-link clicks and aggregate interest or engagement. If featured-dish interaction is available, it is also presented in aggregate. Cevor Business does not provide restaurants with an individual user's identity, precise location, favorites history or raw behavioral history through analytics.

7. Providers and transfers

Cevor uses Lovable Cloud infrastructure for the application backend, authentication, database and storage, hosting and content-delivery infrastructure for the public service, and Resend for transactional email. Payment and invoicing providers are described in the Business Billing document when those services are active.

Some providers may process data outside the EEA. Where required, Cevor relies on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. Infrastructure location can vary by service, so Cevor does not claim that every processing operation occurs only in the EU.

8. Retention

Data is kept only for as long as needed for the purpose, account or contract, then deleted or anonymised subject to backup cycles and legal claims. Security, support, form and email-event records use proportionate operational retention periods. Accounting records may be retained for the period required by law. Specific periods may change as systems mature; a legal request can be made at any time.

9. Your rights

You may request access, rectification, erasure, restriction, objection and portability, withdraw consent without affecting earlier lawful processing, and complain to the Belgian Data Protection Authority or another competent authority. Identity may be verified before a request is completed.

10. External links and changes

Cevor may link to a restaurant website or an external reservation service. That third party operates its own service and terms; Cevor does not become the reservation provider merely by providing a link.

This policy may change as the product or law evolves. Material changes are dated here and communicated where required.

Contact

For questions or requests, write to hello@cevor.app

See also