Skip to content

Privacy Policy

1. Controller

The controller under Regulation (EU) 2016/679 (GDPR) and applicable Romanian data protection law is:

SNB COMMERCE S.R.L., Str. Ploiești nr. 47–49, etaj 1, Mun. Cluj-Napoca, Jud. Cluj, România.

CUI 52191418 · VAT ID RO52191418 · Trade Register J2025053741003 · EUID ROONRC.J2025053741003.

Email: hello@cateringmatch.ro · Website: https://www.cateringmatch.ro

The CateringMatch brand is owned by SNB GROUP S.R.L. (CUI 52065371). The website operator and data controller is SNB COMMERCE S.R.L. only.

No data protection officer is currently appointed. Please contact hello@cateringmatch.ro.

2. Scope

This notice applies to the CateringMatch website and services (including catering inquiries, private status access, file uploads, caterer applications, contact form, and admin/partner areas where relevant).

It does not apply to third-party websites we merely link to.

3. Categories of personal data

Depending on use, we may process: identity and contact data; inquiry details (event type/date, location, guests, catering type, optional budget, notes, locale); caterer application data; communication content; uploaded files; technical/security logs (e.g. IP address, timestamps); consent/cookie status; and local draft data in the browser (localStorage).

4. Purposes and legal bases

Contract / pre-contractual steps (Art. 6(1)(b) GDPR): handling inquiries, status links, matching/intermediation, applications and related offer/booking flows where available.

Legitimate interests (Art. 6(1)(f)): security, abuse prevention, platform operation and reliability (including rate limiting, origin/CSRF controls, audit logs).

Consent (Art. 6(1)(a)): optional marketing (if selected) and Google Analytics 4 only after cookie-banner consent; withdrawable at any time for the future.

Legal obligation (Art. 6(1)(c)): where retention or disclosure duties apply.

5. Recipients and processors

Hosting: Vercel. Database: Neon (PostgreSQL). Transactional email (if enabled): e.g. Resend. File storage (if enabled): S3-compatible storage. Analytics (if consented): Google Analytics 4. Cookieless traffic measurement: Vercel Analytics. Selected published caterers may receive inquiry information needed for matching. Authorities only where legally required. Processor agreements are used where required (Art. 28 GDPR).

6. International transfers

Some providers may process data outside the EEA (including the USA), based on adequacy decisions and/or EU Standard Contractual Clauses and provider safeguards.

7. Retention

Data are kept only as long as needed for the purpose or legal duties: inquiries and related files – until case closure plus 24 months (or longer in case of legal hold, disputes or legal duty); applications – until review completion plus 12–24 months unless longer retention is required; contact messages – 12 months after correspondence ends; security/audit logs – 90–180 days unless longer needed for attack defence; analytics per Google settings and until consent withdrawal; local drafts until submit/delete/browser clear.

8. Cookies and similar technologies

Necessary technologies may be used for operation and security (e.g. admin/partner sessions). Google Analytics 4 loads only after consent. Vercel Analytics measures page views cookieless without advertising IDs. Consent choice is stored locally (cm_consent_v1) and can be changed via Cookie settings in the footer.

9. Private status links

Anyone with the private status link may access the related case status / permitted actions. Keep the link confidential and contact us at hello@cateringmatch.ro if you suspect misuse.

10. No automated decision-making

We do not carry out solely automated decision-making with legal or similarly significant effects (Art. 22 GDPR). Matching may be assisted manually by our team.

11. Your rights

You may request access, rectification, erasure, restriction, portability, objection (where applicable), and withdraw consent. Contact hello@cateringmatch.ro. You may lodge a complaint with ANSPDCP (Romania) or your local supervisory authority.

12. Security

We apply appropriate technical and organisational measures (HTTPS, access controls, origin/rate-limit protections, private status tokens). Absolute security cannot be guaranteed.

13. Minors

Services are not directed at children under 16. If such data are processed inadvertently, we will delete them where legally possible.

14. Changes

We may update this notice when services or law change. The current version is published on this page. Last updated: July 2026.