Privacy policy
Panolo — order fresh bread where you are staying
Last updated: 24 August 2026
Controller for this policy: Johannes Nevels, trading as Panolo,
KVK 42139085, Verlengde J.A. Feithstraat 11, 9725 AS Groningen, the Netherlands — privacy@panolo.eu
Who is responsible for what
Panolo is used in two ways, and that changes who is responsible.
- If you are a guest ordering bread at a campsite, park or holiday rental: that venue decides what is collected about your order and why. The venue is the controller; Panolo runs the software on their behalf as processor.
- If you run a venue and have a Panolo account: Panolo is the controller for your account data.
To have guest data corrected or deleted, the fastest route is your venue, whose contact details are shown in the app. You can also write to privacy@panolo.eu and we will act on the venue's instruction.
What we collect from guests
You are not asked to create an account. Scanning the code at reception signs you in anonymously — no name, no password.
| What | Why | Required? |
|---|---|---|
| An anonymous account identifier | Links your orders to you so you can see and cancel them | Created automatically |
| The pitch, berth or room you are staying in | So the venue knows where the bread goes | Yes |
| Your arrival and departure dates | Sets which mornings you can order, and means we only remind guests actually on site | Yes |
| Your email address | Optional. Used only to remind you before the order cutoff | No |
| A notification token, if you allow notifications | Sends the order reminder and tells you when your bread is ready | No |
| Your orders — items, quantities, prices, which morning | The order itself, and the list the baker works from | Yes |
We do not collect your name, phone number, home address, payment card details, location, advertising identifiers, contacts or photos. Panolo contains no advertising, no analytics SDK and no third-party trackers. We do not track you across other apps or websites.
Dietary information
Some items are marked gluten-free, vegan or vegetarian. If you order one, that choice is part of your order and is visible to your venue so they pack it correctly. We do not build a dietary profile about you, we do not ask you to declare allergies, and this is never shared beyond the venue you are staying at.
What we collect from venue owners
Your email address and password (for signing in), your venue's name and type, the contact details you choose to show guests, and optionally your baker's email address so the daily order list can be sent there.
Payment
Venues choose whether guests pay cash at pickup or online.
Where a venue has enabled online payment, the payment is taken by Stripe on a page hosted by Stripe, and the money goes to the venue's own Stripe account. The venue is the seller. Panolo never receives, sees or stores your card or bank details. We keep only the fact that a bill was settled, its amount, and Stripe's reference for it. Stripe's own privacy notice governs what they hold: stripe.com/privacy.
Why we are allowed to use it
- Performing the service you asked for — taking your order and having it ready is the contract; the pitch number, stay dates and order contents are necessary for it.
- Your consent — the optional reminder email, and push notifications. Withdraw either at any time: delete the address, or turn notifications off in your device settings.
- Our legitimate interest — keeping the service secure and working.
Who else sees it
- Your venue, and only your venue. Guests at one venue cannot see another venue's data, and within a venue a guest cannot see another guest's orders. This is enforced by server-side security rules, not only by the app.
- Google Firebase, which hosts the service (authentication, database, notifications, hosting) as our processor.
- Stripe, where a venue has enabled online payment.
- Our email provider, which delivers reminder and order-list emails.
We do not sell your data. We never will.
Where it is stored
In the European Union. The database region is
europe-west4 (Netherlands) and functions run in
europe-west1 (Belgium). The region is fixed at creation and was
chosen for this reason.
How long we keep it
| What | How long |
|---|---|
| Guest profiles — pitch number, stay dates, optional email | Deleted 30 days after your departure date, automatically, by a scheduled job |
| Orders | Kept by the venue as their own trading record. They are stored against the pitch number, not against you, so once your profile is deleted they no longer identify anyone |
| Notification tokens | Removed when you turn notifications off, when the token stops working, or with your profile |
| Emails we send | The queued message is deleted once delivered |
You do not have to wait 30 days. Delete my data in the app removes your profile, email and stay dates immediately and cancels any upcoming orders.
Your rights
You can ask for a copy of your data, correct it, have it deleted, restrict or object to its use, and withdraw consent. Contact your venue or privacy@panolo.eu. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Children
Panolo is not directed at children and we do not knowingly collect data from them. A parent ordering bread for a family gives us no data about the children.
Changes
We post changes here and update the date above. Material changes are notified in the app.