Data protection · GDPR
Privacy Policy
Em português
Resumo da Política de Privacidade
Quem trata os seus dados. Aleksei Rudenko, profissional independente registado em Portugal, NIF 310833019, Av. Duque de Loulé 94, 6.º A, 1050-086 Lisboa, a operar sob a marca Delivery Lift. Contacto: hello@deliverylift.com.
O que recolhemos. Do formulário de contacto: o nome do restaurante, a cidade e o país, o número de WhatsApp ou telemóvel, o email (opcional) e as plataformas onde vende. Se usar a calculadora e enviar o formulário a seguir, seguem também os valores que introduziu. Do próprio acesso ao site, o alojamento regista dados técnicos inevitáveis em qualquer ligação: endereço IP, hora do pedido, página pedida, tipo de navegador e de dispositivo.
Para quê e com que fundamento. Para lhe responder e preparar a sua Baseline — interesse legítimo e diligências pré-contratuais a seu pedido (artigo 6.º, n.º 1, alíneas b) e f) do RGPD). Para medir a utilização do site e para medir e dirigir a nossa publicidade — apenas com o seu consentimento (alínea a)), que pode retirar a qualquer momento.
Cookies, análise e publicidade. Nada é medido antes de escolher no aviso de cookies. O aviso tem três botões com o mesmo peso — Aceitar tudo, Apenas análise e Recusar — e as duas categorias são independentes: a análise carrega apenas o Google Analytics; a publicidade carrega também o pixel da Meta e a etiqueta do Google Ads. Se recusar, nada disto é carregado, não é definido qualquer cookie de análise ou de publicidade, e o site funciona exatamente da mesma forma. Com a análise aceite, o Google Analytics 4 (identificador G-KREGTM22MR) define os cookies _ga e _ga_<id>, conservados até 2 anos; os eventos são guardados 14 meses, tal como os dados associados a um identificador de visitante. As funcionalidades de publicidade da Google só são ativadas se aceitar publicidade.
Google Ads. Carregado apenas se aceitar publicidade. Serve para saber se um clique num dos nossos anúncios deu origem a um pedido. Define o cookie _gcl_au, conservado até 90 dias.
A sua escolha é guardada. Fica no seu navegador com o nome dl_consent durante 6 meses e contém apenas duas respostas e a data — nenhum identificador seu. Guardamo-la para que uma recusa continue a valer na página seguinte. Em todas as páginas existe no rodapé a ligação Preferências de cookies, que reabre o aviso e permite mudar ou retirar o consentimento num clique. Se chegar através de um anúncio, os marcadores do endereço (por exemplo gclid) seguem com o formulário que enviar; só ficam guardados entre visitas, com o nome dl_attr e durante 90 dias, se tiver aceite publicidade.
Pixel da Meta. Apenas depois de aceitar publicidade, o pixel da Meta (identificador 1978591549314055) define o cookie _fbp, conservado até 3 meses, e regista que uma página foi aberta, que um formulário foi enviado ou que uma ligação de WhatsApp foi clicada. Serve para sabermos se a nossa publicidade no Facebook e no Instagram traz pedidos. A correspondência avançada automática está desligada no código, pelo que nenhum campo do formulário chega à Meta. A Meta não é nossa subcontratante: é responsável conjunta connosco pela recolha e transmissão destes dados, nos termos do Adendo de Responsável das Ferramentas de Negócio da Meta, e responsável única por tudo o que faz com eles a seguir, ao abrigo da sua própria política de privacidade. Os dados são transferidos para a Meta Platforms, Inc. nos Estados Unidos.
Nunca enviamos para a Google nem para a Meta o seu nome, email, telefone ou o que escreveu no formulário.
Quem mais vê os dados. A Netlify (alojamento do site e receção do formulário) e o Google (análise, depois da sua aceitação, e o nosso serviço de email). Ambos atuam como subcontratantes, ao abrigo de um contrato escrito nos termos do artigo 28.º do RGPD. Quando envia o formulário, uma cópia do pedido chega também ao nosso Telegram (Telegram Messenger Inc.), para que o vejamos de imediato e possamos responder no próprio dia — é apenas um canal de aviso interno, a mensagem vai para nós e para mais ninguém. Não vendemos os seus dados nem os partilhamos com as plataformas de entrega.
Quanto tempo guardamos. Um pedido que não dá origem a contrato: 24 meses. Registos de cliente: durante o contrato e depois 10 anos, por imposição fiscal e contabilística.
Os seus direitos. Pode pedir-nos acesso aos seus dados, correção, apagamento, limitação do tratamento, portabilidade, e opor-se ao tratamento. Escreva para hello@deliverylift.com e respondemos no prazo de um mês. Tem também o direito de apresentar reclamação à CNPD, a autoridade portuguesa de proteção de dados.
Este resumo cobre o essencial. O texto integral encontra-se abaixo, em inglês; em caso de dúvida sobre qualquer ponto, escreva-nos e explicamos em português.
This page explains what personal data we collect through this website, why we collect it, who else sees it, how long we keep it and what you can ask us to do with it. It is written to be read, not to be survived. If anything here is unclear, write to us and we will explain it in plain words.
Last updated: 28 August 2026
1. Who is responsible for your data
The data controller — the person or organisation that decides why and how your personal data is used — is:
- Aleksei Rudenko, self-employed professional registered in Portugal, trading as Delivery Lift
- Registration number: NIF 310833019
- Registered address: Av. Duque de Loulé 94, 6.º A, 1050-086 Lisbon, Portugal
- Email: hello@deliverylift.com
For anything to do with your personal data — questions, requests, complaints — write to hello@deliverylift.com. We answer within one month, as the GDPR requires, and usually much sooner.
We have offices in Lisbon, Portugal and in Chicago, United States. This matters for your data, and section 6 explains why.
2. What data we collect
Data you give us in the contact form
The form on this website asks for the details we need in order to reply to you and to prepare a baseline calculation for your restaurant:
- restaurant name;
- city and country;
- a phone or WhatsApp number;
- an email address (optional);
- the delivery platforms you sell on.
We also store, together with your message, the page you sent it from, any campaign parameters in the link you arrived by, and the figures you entered into the calculator on the site if you used it. This is so that we can see what you were looking at when you wrote to us, and give you a relevant answer instead of a generic one.
Please do not send us special categories of data (health, political opinions, and so on) — we do not need them and we do not ask for them. We never ask for your platform passwords.
Data you give us when you contact us directly
If you write to us by email or WhatsApp, we receive whatever you choose to send: your name or display name, your number, and the content of your messages. Messages sent over WhatsApp also pass through that service, which handles your data under its own privacy policy.
Technical data, analytics and advertising measurement
When you open this site, our hosting provider processes technical data that is unavoidable in any web connection — your IP address, the time of the request, the page requested, your browser and device type. This is needed to deliver the page to you and to keep the site secure.
Analytics and advertising measurement are different: they run only after you accept them. Until you press "Accept" in the cookie notice, nothing is loaded from Google or from Meta and no measurement data leaves your browser. After you accept, Google Analytics 4 records statistics about how the site is used: the pages viewed, clicks on the main buttons and on the WhatsApp links, use of the fee calculator, and whether a request form was sent. The Meta pixel records far less — that a page was opened, that a request form was sent, and that a WhatsApp link was clicked — and it is there so that we can tell whether our advertising on Facebook and Instagram is working. We deliberately do not pass your name, e-mail address, phone number or anything you typed into a form to either of them: to Google only the page address and the technical details of the action, and to Meta no parameters at all beyond the fact that the action happened.
3. Why we use it, and on what legal basis
Under the GDPR every use of personal data needs a legal basis. Ours are these:
- To answer your enquiry and prepare a free baseline audit. Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
- To perform a contract once you become a client — reporting, invoicing, day-to-day communication. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
- To keep this website secure and working, and to prevent spam and abuse of the form. Legal basis: our legitimate interest in a functioning, non-abused website (Article 6(1)(f) GDPR).
- To measure how the site performs using analytics cookies, and separately to measure and target our advertising using the Meta pixel and the Google Ads tag. These are two independent choices in the cookie notice. Legal basis for both: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time using the Cookie settings link in the footer.
- To remember the choice you made in the cookie notice. Legal basis: our legitimate interest in honouring your decision rather than asking again on every page, and in being able to show that it was honoured (Article 6(1)(f) GDPR). This one record is stored whichever way you choose, including when you decline, because a forgotten refusal is not a refusal.
- To keep accounting and tax records. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
We do not sell your data, we do not rent it, and we do not use it for automated decision-making or profiling that produces legal effects for you.
4. Cookies, analytics and advertising
This site does not set analytics or advertising cookies before you agree to them. When you first open the site, a notice appears at the bottom of the screen with three buttons of equal weight — Accept all, Analytics only and Decline — and nothing is measured until you press one of them.
The two categories are independent and neither is pre-selected:
- Analytics loads Google Analytics 4 and nothing else. It tells us which pages get read and where people give up. It does not load the Meta pixel and it does not enable any advertising feature.
- Advertising additionally loads the Meta pixel and the Google Ads tag, and switches on the advertising features of the Google tag. It is what lets us tell whether an ad we paid for produced an enquiry, and lets us show our ads to people who have visited this site.
If you press Decline, no analytics and no advertising tag is loaded and nothing about your visit is recorded beyond the technical logs described above. Declining does not break anything: every part of the site works the same either way.
We remember your choice, and only your choice. It is stored in your browser under the name dl_consent for six months. The record holds two values — whether you accepted analytics, and whether you accepted advertising — and the date you chose. It contains no identifier for you and is never sent anywhere. We store it for a plain reason: a refusal that is forgotten the moment you open the next page is not a refusal at all.
How to change your mind. Every page has a Cookie settings link in the footer. It reopens the notice, and whichever button you press replaces your previous answer immediately — including switching advertising back off. You can also clear your browser's site data for this domain, which erases the record and makes the notice appear again, or block cookies in your browser settings at any time.
Analytics provider: Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), measurement ID G-KREGTM22MR. Google acts as our processor under its Data Processing Terms, accepted for this account on 18 August 2026. The Google tag is not present in the page at all until you press "Accept": it is only then downloaded, and only then does it set a cookie or send a request.
The cookies it sets once you have accepted:
- _ga — distinguishes one visitor from another. Stored for up to 2 years.
- _ga_<container-id> — keeps the state of the current session. Stored for up to 2 years.
Google’s advertising features follow your advertising choice, not ours. If you accept analytics only, Google Consent Mode denies ad_storage, ad_user_data and ad_personalization, and the tag additionally runs with Google signals and ad personalisation disabled — two separate switches, both off, so nothing measured by Google Analytics reaches Google’s advertising products. If you accept advertising, those same three permissions are granted and both switches are on, which is what makes conversion measurement and remarketing possible.
Retention. Individual event data in Google Analytics 4 is kept for 14 months, after which Google deletes it. Data tied to a visitor identifier is kept for 14 months as well. Aggregated reports that contain no individual events remain available.
Advertising provider: Google Ads (Google Ireland Limited, same address as above). Loaded only if you accept advertising, and from the same point in the code as everything else — never from the page markup. It measures whether a click on one of our ads led to an enquiry, and it makes remarketing lists possible. It sets the cookie _gcl_au, which stores an identifier for the ad click and is kept for up to 90 days. If you have not accepted advertising, the tag is never configured and this cookie is never written.
Where your visit came from. If you arrive from one of our ads, the address carries markers such as gclid or utm_source. Those markers travel with your enquiry when you send the form, because they are part of the message you chose to send us: without them we cannot tell which advertising produced it. Separately, and only if you accepted advertising, we keep those markers in your browser under the name dl_attr for 90 days, so that an enquiry sent on a later visit can still be matched to the click that brought you. The record holds the markers, the date of your first visit and the site you arrived from. If you did not accept advertising, nothing is kept between visits.
Advertising provider: the Meta pixel (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland), pixel ID 1978591549314055. Like the Google tag, it is not present in the page at all until you press "Accept": only then is it downloaded, and only then does it set a cookie or send a request. We use it to see whether the money we spend advertising on Facebook and Instagram actually brings enquiries, and to show our ads to people who have visited this site.
The cookie it sets once you have accepted:
- _fbp — identifies the browser so that a later enquiry can be matched to an ad. Stored for up to 3 months.
Meta is not our processor — it is a joint controller with us. That distinction matters for your rights. For the collection of this data and its transmission to Meta, we and Meta Platforms Ireland Limited decide the purpose together, under Meta’s Controller Addendum to its Business Tools Terms. Everything Meta does with the data afterwards — including using it to improve its own advertising systems — Meta decides alone, under its own Privacy Policy, and we have no control over it and no access to it. You may exercise your GDPR rights against either of us; for anything beyond the collection itself, Meta is the party that can act.
What we deliberately do not send. Meta’s tag can be configured to read the fields of a form on the page and send hashed e-mail addresses and phone numbers back to Meta — what Meta calls automatic advanced matching. It is switched off on this site, in the code, on every page. The pixel is given no parameters at all: it is told that a page was opened, that a form was sent or that a WhatsApp link was clicked, and nothing else.
Transfers. Meta Platforms Ireland Limited transfers data to Meta Platforms, Inc. in the United States. Meta relies on the EU–US Data Privacy Framework and on Standard Contractual Clauses for those transfers. Section 6 below applies to this transfer as it does to the others.
5. Who we share data with
Your data stays with us and with the service providers we need in order to run the business. They fall into four groups, and the difference between them matters for your rights, so we set them out separately.
Processors acting on our instructions. These providers handle your data only for us and only for the purpose we give them, they are not allowed to use it for their own purposes, and each of them is bound by a written data processing agreement under Article 28 of the GDPR:
- Website hosting — serves this site and keeps server logs: Netlify (Netlify, Inc., United States).
- Form and enquiry handling — receives and stores what you submit through the form: Netlify Forms (Netlify, Inc., United States).
- Website analytics — measures how the site is used, only after you accept: Google Analytics 4 (Google Ireland Limited, Ireland; data may be processed by Google LLC in the United States).
A joint controller. One recipient is neither a processor nor fully independent of us, and belongs in a group of its own:
- Advertising measurement — records, only after you accept, that a page was opened or an enquiry sent, so that our advertising can be measured and targeted: Meta Platforms Ireland Limited (Ireland; data transferred to Meta Platforms, Inc. in the United States). Joint controller with us for the collection and transmission of that data, sole controller of everything it does with it afterwards. See section 4.
Independent services you or we use to communicate and to display this site. These are not our processors: they decide for themselves how they handle the data that passes through them, each under its own privacy policy, and we have no control over that:
- Email — we reply to you from a mailbox hosted by Google (Google Ireland Limited / Google LLC, United States), which therefore holds the correspondence between us.
- Messaging apps — WhatsApp (Meta Platforms Ireland Limited), if you choose to write to us through that channel. Your messages pass through the service under its own terms.
- Internal notification of a new enquiry — when the form is sent, a copy of what you submitted is delivered to our own Telegram account (Telegram Messenger Inc.) so that we see it immediately and can reply the same day. The message goes to us and to nobody else; Telegram carries it under its own privacy policy. This is a notification channel only — the enquiry itself is stored with the form provider named above.
Professional advisers. Accountants and, where necessary, lawyers. They see your data only where it is genuinely needed — for example in an invoice — and they are bound by professional confidentiality rather than by a data processing agreement with us.
We also disclose data where the law requires it: to a public authority acting within its powers, or to defend a legal claim. We will not do so more widely than the law obliges us to.
Delivery platforms such as Uber Eats, Glovo, Bolt Food or DoorDash are not our processors. When we work inside a client's own platform accounts, the platform is an independent controller of the data in those accounts, under its own terms and privacy policy.
6. Transfers outside the EEA
We have an office in Chicago, Illinois, United States, and some of the service providers we use are based outside the European Economic Area. This means your data may be transferred to and processed in a country outside the EEA, including the United States. In practice this applies to the hosting and form provider named in section 5 (Netlify, Inc.), to the analytics provider once you have accepted it (Google), to Google Ads and to Meta once you have accepted advertising, to the mailbox provided by Google, and to the messaging app if you choose to use it.
The typefaces on this site are served from our own domain. They are not loaded from Google Fonts or any other third party, so opening a page of this site does not send your IP address anywhere outside our hosting provider.
Where a transfer happens, we rely on one of the safeguards the GDPR allows:
- a decision of the European Commission that the country in question provides an adequate level of protection; or
- Standard Contractual Clauses approved by the European Commission, together with additional technical and organisational measures where these are needed.
You can ask us for a copy of the safeguards that apply to a specific transfer by writing to hello@deliverylift.com.
7. How long we keep data
- An enquiry that does not become a contract: 24 months, after which we delete it.
- Client records: for the duration of the contract and then 10 years, which is set by the accounting and tax law that applies to us.
- Analytics events: 14 months in Google Analytics 4, after which Google deletes them. Data tied to a visitor identifier is kept for 14 months as well.
- Advertising events: the _fbp cookie expires after 3 months and the Google Ads cookie _gcl_au after 90 days. How long Meta and Google keep the event data they receive is decided by them and set out in their own policies; we cannot shorten it and we cannot delete it on your behalf.
- Your cookie choice (dl_consent): 6 months in your own browser, then the notice appears again.
- Where your visit came from (dl_attr): 90 days in your own browser, and only if you accepted advertising. Clearing your browser's site data removes it immediately.
- Server logs: for the short period our hosting provider keeps them for security purposes.
When a retention period ends, we delete the data or anonymise it so that it can no longer be linked to you.
8. Your rights under the GDPR
These rights are yours, they are free to use, and using them costs you nothing in your relationship with us. You can:
- Ask what we hold about you and get a copy of it (right of access).
- Have it corrected if it is wrong or incomplete (rectification).
- Have it deleted where we no longer have a reason to keep it (erasure, the "right to be forgotten").
- Restrict how we use it while a dispute about it is being sorted out (restriction).
- Receive it in a portable format, or have it sent to another provider where this is technically possible (portability).
- Object to our use of it where we rely on legitimate interest (objection).
- Withdraw your consent at any time, where we rely on consent. Withdrawal does not affect what was lawfully done before you withdrew it.
To use any of these rights, write to hello@deliverylift.com. We may need to check who you are before we act, so that we do not hand your data to someone else.
Complaints. If you think we are handling your data wrongly, please tell us first — most problems are a misunderstanding and are fixed quickly. You also have the right to complain to a supervisory authority: in Portugal that is the CNPD — Comissão Nacional de Proteção de Dados (www.cnpd.pt), or the data protection authority of the EU country where you live or work.
9. How we protect data
We keep access to personal data limited to the people who need it to do their work, we use the access controls the tools we work with provide, and this site is served over an encrypted connection. No system is perfectly secure, and we do not claim otherwise — but if a breach affects your rights, we will notify you and the supervisory authority as the GDPR requires.
This website is aimed at restaurant owners and managers. It is not directed at children, and we do not knowingly collect data from anyone under 16.
10. Changes to this policy
When our tools, providers or services change, this page changes with them. The date at the top of the page always shows when it was last updated. If a change matters to you — a new purpose, a new category of recipient — we will make it visible rather than quietly editing the text.
Questions about this policy: hello@deliverylift.com. Company registration details are on the company details page, and the rules for using this website are in the website terms.
Delivery Lift · Restaurant growth agencyPrivacy