top of page

Last updated 14 September 2026

Privacy Policy
 

Daily Pot AS · Org.nr 917 104 611 · Vaskerelven 21, 5014 Bergen · post@dailypot.no

Daily Pot AS runs the Daily Pot app. This page explains what personal data the app collects, why, how long we keep it, and what you can do about it. We are the data controller for that data.

 

1. What we collect, and why
 

Your account

When you create an account we store your name, email address and an encrypted form of your password. You may optionally add a phone number and birthday. If you sign in with Google, we receive your name and email address from Google instead of a password.

Why: to give you an account and let you sign back into it.


Legal basis: performance of a contract— GDPR Art. 6(1)(b).


Orders and payments

When you order, we store what you ordered, the amount, the time, the payment method, whether it was paid, and a payment reference from the payment provider.

We never see or store your card number. Card and Apple Pay payments are handled entirely by Stripe, and Vipps payments by Vipps MobilePay. They send us only a reference and a result.

Why: to take your order, take payment, and issue a receipt.

Legal basis: performance of a contract — Art. 6(1)(b); and, for keeping the sales record afterwards, a legal obligation — Art. 6(1)(c). See section 4.


Loyalty points and perks

We store your points balance and history, your total spend and tier, your member code, which loyalty cards you have tapped and when, and any perks you have redeemed or used.

We record the time of each card tap per member so the same person cannot collect from the same card repeatedly within a short window.

Why: to run the loyalty programme and prevent abuse of it.

Legal basis: performance of a contract — Art. 6(1)(b); abuse prevention is our legitimate interest — Art. 6(1)(f).


Table reservations

If you book a table we store the date, time, number of guests, any notes you add, and the phone number and email you give for the booking. This is shared with Wix, which runs our reservation system and sends your confirmation email.

Why: to make and confirm your booking.

Legal basis: performance of a contract — Art. 6(1)(b).


Push notifications

If you allow notifications, we store a push token identifying your device, so we can tell you when your order is ready.

Why: to send you notifications you asked for.

Legal basis: your consent — Art. 6(1)(a). You can withdraw it at any time in your device settings; we delete the token when you sign out.


Crash and error reports

If the app crashes, we receive a crash report containing your account's internal ID, your device model, OS version, and technical details of the fault. We have deliberately configured this not to include your name, email, or order contents.

Why: to find and fix faults.

Legal basis: our legitimate interest in a working app — Art. 6(1)(f).
 

Browsing without an account

You can browse the menu without creating an account. In that mode we collect no personal data at all — no name, no email, no device identifier. You only give us data if you choose to create an account, order, or book a table.


What we do not do

We do not use advertising trackers, we do not build marketing profiles, we do not sell or rent your data to anyone, and we do not collect your location.

 

2. Who else processes your data

Each of these acts as our processor, handles only what its job requires, and is bound by a data processing agreement.

  • Supabase — database and sign-in. Ireland (EU).

  • Stripe — card and Apple Pay payments. EU/US, under EU Standard Contractual Clauses.

  • Vipps MobilePay — Vipps payments. Norway/EEA.

  • Wix — table reservations and confirmation emails. EU/US, under EU Standard Contractual Clauses.

  • Expo — delivers push notifications to your device. US, under EU Standard Contractual Clauses.

  • Sentry — crash reports. EU/US, under EU Standard Contractual Clauses.

  • Google — optional “Sign in with Google”. EU/US, under EU Standard Contractual Clauses.

  • Apple — Apple Pay. EU/US, under EU Standard Contractual Clauses.
     

Your account data, orders and loyalty history are stored in the EU (Ireland).

We may also disclose data where the law requires it — for example to tax authorities, or in response to a valid legal order.


3. Legal bases, summarised

  • Account, orders, reservations, loyalty — contract, Art. 6(1)(b).

  • Keeping sales records for five years — legal obligation, Art. 6(1)(c).

  • Crash reporting and preventing loyalty abuse — legitimate interests, Art. 6(1)(f).

  • Push notifications — consent, Art. 6(1)(a).


4. How long we keep it

  • Account details (name, email, phone, birthday) — until you delete your account, at which point they are erased immediately.

  • Sales records (orders, payments, receipts) — five years after the end of the financial year, because the Norwegian Bookkeeping Act (bokføringsloven § 13) requires it. GDPR Art. 17(3)(b) permits us to keep these despite a deletion request.

  • Reservations, push tokens, loyalty passes — deleted when you delete your account.

  • Crash reports — kept for up to 90 days, then deleted automatically.


What deleting your account actually does

Your name, email, phone and birthday are erased, your loyalty balance is cleared, and your login stops working — immediately and permanently.

Your past sales records are kept for the five years the law requires, but with the link to you removed. They can no longer be traced back to a named person.
 

5. Your rights

Under the GDPR you may:

  • See what we hold about you (Art. 15).

  • Correct anything wrong (Art. 16).

  • Delete your account and personal data (Art. 17) — you can do this yourself in the app, under Profile → Delete Account, without contacting us.

  • Get a copy of your data in a portable format (Art. 20).

  • Restrict or object to processing based on our legitimate interests (Art. 18 and 21).

  • Withdraw consent for notifications at any time, without affecting anything we did beforehand.
     

Write to us at post@dailypot.no and we will respond within one month.

If you think we have handled your data wrongly, you can complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no), or to the supervisory authority where you live.
 

6. Security

Passwords are never stored in readable form. Data is encrypted in transit. Access to the database is restricted per-user at the database level, so one customer's account cannot read another's. Payment credentials never reach our systems at all.
 

7. Children

The app is not aimed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
 

8. Changes to this policy

If we change how we use your data, we will update this page and change the date at the top. Significant changes will be announced in the app.
 

9. Contact

Questions about anything on this page, or about your own data, come straight to us.
 

Daily Pot AS
Vaskerelven 21, 5014 Bergen, Norway
Org.nr 917 104 611
post@dailypot.no
 

Goodness, served round.

bottom of page