1. Who we are
The data controller for everything described in this policy is:
- Registered seat
- 12 Voulgaroktonou, Kalamaria, Thessaloniki 55133, Greece
- VAT (ΑΦΜ)
- 803307830
- GEMI no.
- 194266606000
- biteodelivery@gmail.com
- Phone
- +30 697 044 5873
In this policy, "Biteo", "we", "us" and "our" mean BITEO DELIVERY E.E. — the company that operates the Biteo delivery fleet, engages couriers, and works with partner restaurants and marketplaces.
Our software — the driver app, the dispatch engine, and the web portals — is developed, hosted and operated for us by DEMFI (Belgrade, Serbia), our technology provider. DEMFI processes personal data only on our behalf and on our instructions, as our data processor under a data processing agreement (see sections 7 and 8).
2. What this policy covers
This policy explains how we process personal data in connection with:
- the Biteo driver app (Android and iOS), used by couriers who deliver on our fleet;
- the courier application and onboarding process, including the online application form we send to candidates;
- the Biteo websites, including this site (biteodelivery.com);
- the restaurant portal and operations console — partner restaurants log in from our website and are redirected to the portal at biteo.demfi.app, which is our portal hosted on DEMFI infrastructure; and
- the delivery orders we fulfil, which contain limited data about order recipients.
3. Data we collect from couriers
When you apply to join the fleet
Our application form collects the information Greek law and our courier engagement require: first and last name, date of birth, phone number, email address, home address, tax identification number (ΑΦΜ), social security number (ΑΜΚΑ), driving licence number and expiry date, vehicle type and licence plate, bank account (IBAN) for payouts, and the verification status of your identity, licence, insurance, and proof-of-address documents.
When you submit the application, we also record a consent and agreement record: the version of the agreement you accepted, the date and time of acceptance, the IP address the submission came from, and your typed full-name signature. This record is kept unchanged as proof of the agreement, even if you later update your application details.
When you work with the driver app
- Account data — your name, phone number, email address (if provided), and your driver status (online, available, active).
- Device data — a random device identifier that the app generates the first time it runs and stores in your phone's secure storage. It is not derived from your hardware, your phone number, or any advertising ID; it exists only to bind your account to one device so nobody else can log in as you. We also store a push-notification token so we can send you delivery offers, and basic device information (manufacturer, model, operating system version) attached to crash reports.
- Location data — described in detail in section 4.
- Work and earnings data — the deliveries you complete, the offers you receive and accept, your per-delivery earnings, your cash-on-delivery balance, and records of cash and bank settlements.
- Diagnostics — if the app crashes or an error occurs, a technical report is sent to our error-monitoring service. These reports identify you only by your internal driver ID; they do not include your name, and telephone numbers are actively removed from them before they are sent.
4. Location data
Prominent disclosure. The Biteo driver app collects location data to dispatch deliveries, navigate routes, share live courier position with the ordering customer, and detect fraud, even when the app is closed or not in use — but only while you have set yourself online in the app. Going offline stops all location collection.
How it works in practice:
- While you are online, the app sends your position (coordinates, accuracy, speed and heading) to our servers approximately every 10 seconds, including in the background. Android shows a persistent notification whenever this background collection is running.
- While you are actively navigating a delivery, the app additionally refreshes your position on screen more frequently (roughly every 3 seconds) for turn-by-turn accuracy.
- Your live position is stored as a single current value that is overwritten by each update — we do not build a permanent movement history from it.
- During an active delivery, the route points of that delivery are recorded as a trail and kept for 30 days. We use these trails to verify deliveries, resolve disputes, and detect GPS spoofing and fraud. After 30 days they are automatically deleted.
- When you deliver an order placed through Wolt, we send your coordinates only (no name, no phone number) to Wolt for the duration of that order, so the customer can see their courier approaching on the map. We do not send courier location to e-food.
- Coordinates are sent to our routing provider, Mapbox, to calculate routes, travel times, and the maps you see in the app.
The app cannot dispatch deliveries to you without location access, so location permission is required to go online. You can stop collection at any time by going offline or revoking the permission in your phone's settings.
5. Other people's data
Order recipients (customers)
When a restaurant hands us an order for delivery, we receive the delivery details the marketplace or restaurant collected: the recipient's name, delivery address, and, where provided, a phone number and delivery notes. We use this data solely to perform and document the delivery, and we show it to the assigned courier only for the orders they deliver. Customers' data is otherwise governed by the privacy policy of the marketplace or restaurant where the order was placed.
Restaurant partners and portal users
For partner restaurants we process business contact details and the account credentials of staff who use the restaurant portal. Our operational consoles keep audit records of significant actions (for example, who settled a cash balance).
Website visitors
Our websites set no analytics or advertising trackers (see the Cookie Policy). If you contact us through a form or by email, we receive what you send and use it only to reply to you. Our web servers keep standard technical logs (IP address, request, timestamp) for security and abuse prevention.
6. Why we process data, and on what legal basis
- Running the fleet — dispatching offers, navigation, proof of delivery, customer live-tracking, calculating your earnings, and settling cash balances. Legal basis: performance of our agreement with you (GDPR Art. 6(1)(b)).
- Onboarding and compliance — verifying identity, licence, insurance, and tax and social-security details before you can deliver. Legal basis: performance of the agreement and our legal obligations (Art. 6(1)(b) and (c)).
- Accounting and tax — keeping earnings, settlement, and ledger records. Legal basis: legal obligation under Greek tax and accounting law (Art. 6(1)(c)).
- Fraud prevention and platform integrity — delivery route trails, GPS-spoofing detection, device binding, and rate limiting. Legal basis: our legitimate interest in preventing fraud and keeping the service safe (Art. 6(1)(f)).
- Service quality and stability — crash and error reports, and operational event logs. Legal basis: legitimate interest in running a reliable service (Art. 6(1)(f)).
- Communication — push notifications with delivery offers and status updates, and replies to your messages. Legal basis: performance of the agreement (Art. 6(1)(b)).
We do not sell personal data, we do not use it for advertising, and we do not use any third-party analytics or marketing trackers in the driver app or on our websites.
7. Who we share data with
We use a small number of service providers (processors), each receiving only what its function requires:
| Recipient | Purpose | Data involved |
|---|---|---|
| DEMFI (Belgrade, Serbia) | Development, hosting and operation of the Biteo software platform, under a data processing agreement | All service data, on our instructions only |
| Hetzner Online GmbH | Server hosting (Falkenstein, Germany) | All service data, stored in the EU |
| Mapbox | Routing, travel times, maps | Coordinates and waypoints |
| Wolt | Live courier tracking for the ordering customer | Courier coordinates only, per active Wolt order |
| Google (Firebase Cloud Messaging) | Delivering push notifications | Push token, notification payload (order and restaurant references — no location) |
| Sentry | Crash and error monitoring | Technical reports with internal IDs; names excluded, phone numbers scrubbed |
Beyond processors, we disclose data only where the law requires it (for example to tax or social-security authorities), to professional advisers under confidentiality, or to establish or defend legal claims. e-food receives order status updates for its own orders but no courier location or courier personal data.
8. International transfers
Our servers and database are located in Germany (EU). Our technology provider, DEMFI, is based in Serbia, which is outside the EEA and not covered by an EU adequacy decision; DEMFI's access to personal data is therefore governed by the European Commission's Standard Contractual Clauses, incorporated in our data processing agreement, and limited to what operating the platform requires.
Some providers listed above (Google, Sentry, Mapbox) may process limited technical data in the United States. Where that happens, the transfer is protected by the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses, as implemented in each provider's data processing agreement.
9. How long we keep data
| Data | Retention |
|---|---|
| Live courier position | Overwritten by each update; buffered copies expire within about 2 minutes |
| Delivery route trails | 30 days, then deleted automatically |
| Dispatch and offer event logs | 90 days, then deleted automatically |
| Application and consent records | Duration of the engagement, plus the limitation period for legal claims |
| Earnings, settlements, ledger and cash records | As long as Greek tax and accounting law requires (generally at least five years) |
| Order and delivery records | Duration required for accounting, dispute resolution and legal claims |
| Crash reports | Per our error-monitoring provider's rolling retention (typically 90 days) |
| Contact messages | As long as needed to handle your enquiry |
When a retention period ends, we delete the data or anonymise it so it can no longer be linked to you.
10. Security
All traffic between the app, the websites and our servers is encrypted (TLS). Courier accounts are bound to a single device using a randomly generated key held in the phone's secure storage. Access to operational systems is restricted to authorised staff behind authenticated, rate-limited consoles, and sensitive actions are logged. Our infrastructure runs in an EU data centre with access controls and firewalls.
11. Your rights
Under the GDPR you can ask us for access to your data, a copy of it in a portable format, correction of inaccurate data, deletion, restriction of processing, and you can object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting past processing.
To exercise any of these rights — including deleting your courier account — email biteodelivery@gmail.com from the address or phone number we have on file. We respond within one month. Note that some records (for example earnings and settlement history) must by law be kept for the statutory retention period even after an account is deleted; we delete or anonymise everything we are not legally required to keep.
If you believe we have mishandled your data, you can lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), www.dpa.gr, Kifissias 1-3, 115 23 Athens.
12. Automated dispatch
Delivery offers are generated by an automated dispatch system that considers courier position, availability, route efficiency and order readiness. An offer is exactly that — an offer: you choose whether to accept it, and not responding to an offer is not treated as a rejection. No decision producing legal or similarly significant effects about you is taken solely by automated means; account decisions such as suspension are made by a person.
13. Children
The driver app and courier engagement are available only to adults (18+). We do not knowingly process children's data.
14. Changes to this policy
If we change this policy, we will publish the new version on this page with a new version number and effective date, and for material changes we will notify active couriers through the app or by direct message before the change takes effect.
15. Contact
For anything related to this policy or your personal data: biteodelivery@gmail.com · +30 697 044 5873 · BITEO DELIVERY E.E., 12 Voulgaroktonou, Kalamaria, Thessaloniki 55133, Greece.