Policies
Privacy Policy
Last updated 3 September 2026
LocalBites is the data controller for accounts created on localbites.ie. We process personal data under the GDPR and Irish data-protection law. Contact: localbitesie@gmail.com.
What we collect when you join or shop
We ask only for what we need to create your account and run the neighbourhood shop. We do not collect a street address at join.
- Name and email
- Role: food lover, home cook, or both
- Town or neighbourhood from our list (with map coordinates for that place — not your home address)
- Irish mobile number (optional until you contact a kitchen)
- Your consent to these terms and this policy (we store when you agreed)
- Home cooks also: kitchen name, HSE registration status (self-reported), and dishes you cook
- Food lovers (and “both”) also: dishes you would like to find nearby, and shopping areas
- When you use the shop: cart lines, WhatsApp enquiry introductions to kitchens, and orders you place through LocalBites (when in-app checkout is available)
Sign-in uses a short email or SMS code — we do not ask you for a password on join. After you confirm, we mark the account as verified.
Contact form
If you write to us from the site we store your name, email, subject, and message so we can reply.
Why we use it
We use this data to create your account, confirm your email or mobile, send product emails (codes, welcome, order updates), introduce you to home kitchens you contact, and operate the shop. Legal bases: contract (running your account and any orders), consent (when you agree to these policies), and legitimate interests (keeping accounts honest and answering messages).
How we keep it secure
We treat account data as confidential. In practice that means:
- The site is served over HTTPS, so data is encrypted in transit
- Account and shop data live in our product database (PostgreSQL), encrypted at rest with our host
- Join and shop sign-in use one-time codes — we do not store a food-lover password. Staff tools use separate controls
- Access is restricted: when you are signed in you can read your own profile; other people’s profiles are not publicly listed
- Server-only keys stay on our servers and are never sent to your browser
- We take backups and limit who on the LocalBites team can reach production data
No security setup is perfect, but these are the controls we rely on today.
Sharing
We run accounts and the shop on our own API and database. We send product email through our mail host (SMTP), and we host the public site with our website provider. Optional visit counts (only if you accept cookies) are processed by that host. When you tap Contact, WhatsApp opens with a prefilled message — that chat is between you and the cook, outside LocalBites. When a cook sells through Pay in LocalBites, we may share identity and completed-sale data with Revenue under Irish / EU DAC7 (AEOI) platform-operator rules where they apply. We do not sell your details. We may share data if Irish law requires it. Some processors are outside Ireland, including the United States, under standard contractual clauses.
Retention and your rights
We keep profiles and shop history for as long as we need them to run accounts, fulfil orders, or meet legal duties. You can ask for access, correction, deletion, or a copy of your data, and you can withdraw consent for marketing-style emails where we rely on consent. You may complain to the Data Protection Commission in Ireland.
Cookies and similar storage
Account details live in your profile, not in cookies. Essential cookies keep sign-in secure (including the shop session). Optional page-view counts on our host run only if you accept them in the cookie banner. You can change that choice from the Cookie Policy. Related terms: Terms and Conditions.