Privacy Policy — Today is Greenday

Last updated: 30 June 2026

Today is Greenday ("we", "us") values your privacy. This policy explains what personal data we collect through our website and mobile app, why we collect it, and what rights you have. We process data in accordance with the General Data Protection Regulation (GDPR) and the Dutch Implementation Act (UAVG).

1. Who We Are

Today is Greenday B.V.
Ceintuurbaan 113-115
1072 EZ Amsterdam, The Netherlands
KVK: 95103171
Email: hello@todayisgreenday.com

Today is Greenday B.V. is the data controller responsible for your personal data.

2. What We Collect

CategoryExamples
Account dataName, email address, password (stored hashed)
Order & loyalty dataOrder history, pickup/delivery choices, loyalty points and rewards
Usage dataPages and screens visited, features used, crash reports, device model and OS version
Communication dataMessages sent via our contact form or support chat
Push notification dataDevice push token (only if you enable notifications)
Cookie & analytics dataIP address, session data, browser type (website only — see section 6)

3. Why We Process Your Data

PurposeLegal basis (Art. 6 GDPR)
Providing the service (accounts, orders, loyalty)Performance of a contract
Improving & securing our productLegitimate interest
Sending push notifications & marketing emailsConsent (opt-in required)
Analytics & non-essential cookiesConsent (cookie banner)
Complying with legal obligationsLegal obligation

4. Sharing Your Data

We do not sell your data. We share data only with:

  • Processors that help us run the service — including hosting and infrastructure, online ordering, loyalty programme management, analytics and crash reporting, email delivery, and push notification delivery. Each acts on our instructions under a data processing agreement (verwerkersovereenkomst).
  • Authorities — only when legally required.

Some features (such as online ordering and the loyalty programme) are operated through third-party platforms that may act as independent controllers for their own services. When you use those features you are also subject to their privacy policies. A current list of our processors is available on request via hello@todayisgreenday.com.

If data is transferred outside the European Economic Area (EEA), we rely on EU Standard Contractual Clauses (SCCs) or another lawful transfer mechanism.

5. Retention

  • Account data: for as long as your account is active, and up to 12 months after you delete it (after which it is erased or anonymised).
  • Order & loyalty data: for the lifetime of your account; financial transaction records are kept for 7 years (see below).
  • Support & contact data: up to 24 months after our last contact.
  • Analytics data: up to 14 months.
  • Push tokens: until you disable notifications or delete the app or your account.
  • Financial records: 7 years (statutory obligation under Dutch tax law).

6. Cookies & the App

Our website uses cookies. Non-essential cookies (analytics, marketing) require your consent via our cookie banner, in line with Article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet).

Our app collects usage and crash data to improve performance and stability. No cookies are placed in the app; device identifiers are used only for technical purposes (such as crash diagnostics and delivering push notifications) and are not used for cross-app tracking or advertising.

7. Your Rights

Under the GDPR and UAVG you have the right to access, rectify, erase, restrict, or port your data, and to object to processing. You can also withdraw consent at any time (for example by turning off notifications or unsubscribing from marketing emails).

Deleting your account: you can delete your account and associated personal data at any time directly in the app (via your account settings) or by emailing hello@todayisgreenday.com. When you delete your account we erase or anonymise your personal data, except where we are legally required to retain it (e.g. financial records).

To exercise any of these rights, email hello@todayisgreenday.com. We respond within one month.

You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl / 0900-2001201.

8. Security

We apply appropriate technical and organisational measures, including encryption in transit (TLS), access controls, and regular security reviews. In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.

9. Children

Our services are not intended for children under 16 (the threshold under Dutch law, UAVG Art. 8). We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact us and we will delete it.

10. Changes

We may update this policy. Material changes will be communicated via email or a notice in the app. The "Last updated" date at the top of this page always reflects the latest version.

Have a nice greenday.

Hier komt de tekst