Privacy Policy
Last updated 19 August 2026
Who we are
Restaurants from Spain is a global directory of Spanish restaurants outside Spain, operated by Relevant Audience Digital Services Pte. Ltd. (UEN 201734242K), 158 Simei Road, #03-254, Singapore 520158. We are the data controller for the personal data described in this policy.
As a Singapore company we are bound by the Personal Data Protection Act 2012 (PDPA). Our Data Protection Officer is [DPO NAME], reachable at privacy@restaurantsfromspain.com — write there for any question, request or complaint about your personal data. Where you are in the EEA or UK, the GDPR also applies to our handling of your data, and the table below sets out our lawful basis under it.
What we collect
- Account data — your name, email address, an encrypted (hashed) password, and optionally your city. We never store your password in readable form.
- Reviews you write — your rating, review text, the date of your visit, any photos you choose to upload, and the display name shown alongside them.
- Newsletter data — your email address plus a record of your consent: when you gave it, and which page you gave it on. We keep this to prove the subscription was genuine.
- Booking requests — the name, phone number, email, party size and any notes you submit when requesting a table.
- Technical data — IP address, browser and device type, and the pages you visit. We use this to keep the site secure and to detect fraudulent or automated activity.
Why we use it, and our legal basis
| What we do | Legal basis (UK/EU GDPR) |
|---|---|
| Create and operate your account | Performance of a contract |
| Publish your review after moderation | Performance of a contract |
| Pass a booking request to the restaurant | Performance of a contract |
| Send you the newsletter and offers | Your consent, withdrawable at any time |
| Moderate content, prevent fake reviews and abuse | Our legitimate interest in a trustworthy directory |
| Keep the site secure and measure how it is used | Our legitimate interest in a safe, working service |
What is public
Approved reviews are public. Your review text, rating, visit date, any photos and your display name can be seen by anyone and may appear in search engines. Your email address, password and IP address are never published. Choose a display name you are comfortable showing publicly, and do not include personal details in review text.
Who we share it with
We do not sell your personal data. We share it only as follows:
- With the restaurant, when you submit a booking request — they need your name, contact details and party size in order to hold the table. The restaurant is a separate controller for what it does with that information.
- With service providers who process data on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Website hosting and delivery | United States / global edge |
| Neon | Database hosting | Singapore (ap-southeast-1) |
| Resend | Transactional email and newsletter delivery | United States |
| Maps embeds and publicly available business information | Global |
We may also disclose data where the law requires it, or to establish or defend legal claims.
International transfers
Our database is hosted in Singapore, and we operate globally, so your data may be processed outside your own country — chiefly in Singapore and the United States. Where we transfer data out of Singapore we take steps to ensure it receives a standard of protection comparable to the PDPA, as the Transfer Limitation Obligation requires. Where data leaves the UK or EEA, we rely on Standard Contractual Clauses or an equivalent safeguard with each provider.
How long we keep it
- Account data — while your account is open, then up to 12 months.
- Published reviews — indefinitely, as part of the public record of the directory. If you delete your account we can anonymise your reviews on request.
- Newsletter data — until you unsubscribe, plus a consent record for 3 years.
- Booking requests — 24 months, for dispute resolution.
- Technical logs — up to 12 months.
Your rights
Depending on where you live, you have the right to access your data, correct it, delete it, receive a portable copy, object to or restrict how we use it, and withdraw consent at any time. Withdrawing consent does not affect anything we did before you withdrew it.
Under the Singapore PDPA you may additionally ask us for an account of how your data has been used or disclosed in the past year, and you may withdraw consent to any use of it.
To exercise any of these, email our Data Protection Officer at privacy@restaurantsfromspain.com. We respond within 30 days. Every newsletter also carries a one-click unsubscribe link. If you are not satisfied with our answer you may complain to Singapore’s Personal Data Protection Commission (PDPC), or — if you are in the EEA or UK — to your local data protection authority instead.
Cookies
We use cookies that are strictly necessary to run the site — chiefly to keep you signed in and to protect forms from abuse. We do not use advertising cookies or sell data to advertisers. You can block cookies in your browser, but you will not be able to stay signed in.
Children
This service is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
Security
Passwords are stored hashed, data is encrypted in transit, and access to the administration system is limited to named staff. No system is perfectly secure, so please use a unique password and tell us immediately if you suspect a problem with your account.
Changes
If we change this policy materially we will update the date above and, where the change affects how we use your data, tell you by email.