Privacy policy

Legal

Privacy policy

Last updated: 2026-05-11

We care about your privacy. This page explains what data we collect, why, how long we keep it and what rights you have. If anything is unclear, just ask — we’re happy to walk you through it.

1. Data controller

Mae Thai Wok is the data controller for the processing of your personal data described in this policy. For questions or to exercise your rights, contact us at support@maethaiwok.se or +46 76 337 25 24.

2. What data we collect

We only collect what we need to respond to you and deliver the service you ask for:

  • Contact details — name, email, phone number.
  • Bookings & catering — date, number of guests, delivery address, any allergies or requests.
  • Communication — content of messages you send us via chat, forms or email.
  • Technical data — IP address, browser, device type and how you use the site, via cookies and analytics tools.

3. Why we process your data

We process your data to:

  • respond to enquiries and handle bookings/catering — legal basis: contract or pre-contractual measures.
  • improve the website, measure how it's used and optimise advertising — legal basis: legitimate interest or consent where required by law.
  • comply with bookkeeping and tax obligations — legal basis: legal obligation.

4. Cookies and analytics

We use cookies to operate the website and analytics/advertising cookies (Google Analytics and Google Ads) to understand how the site is used and reach the right guests with our marketing. You can disable non-essential cookies at any time via your browser settings.

5. How long we keep the data

We don't keep data longer than necessary:

  • Chat and contact tickets are automatically deleted after 90 days if inactive.
  • Bookings and catering requests are kept as long as needed for delivery, follow-up and complaints — normally up to 12 months.
  • Accounting records are kept for seven years under Swedish bookkeeping law.
  • Analytics cookies default to 14 months retention.

6. Who we share data with

Your data is only shared with providers that help us run the business — e.g. booking systems, email (Resend), payment, analytics (Google) and Cloudflare. All partners are data processors and may only use the data according to our instructions. We never sell your personal data.

7. Your rights

Under GDPR you have the right to:

  • request a copy of the data we hold about you,
  • have incorrect data corrected,
  • request deletion of your data (right to be forgotten),
  • object to or restrict the processing,
  • transfer your data to another service (data portability),
  • withdraw consent at any time.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) if you believe we handle your data incorrectly.

8. Security

We use technical and organisational security measures to protect your data against unauthorised access, loss or tampering — including encrypted storage, access controls and DDoS protection via Cloudflare.

9. Contact us

To exercise a right, ask a question about this policy or raise a concern, get in touch:

We normally reply within two business days.