MIAMMIAM.LU · GDPR
Privacy Policy
Websites & applications

MIAMMIAM SERVICES

Privacy Policy

This Privacy Policy explains how MiamMiam processes personal data when you use the MiamMiam website, customer application, MiamMiam Partner, MiamMiam Manager, MiamMiam Driver, courier-partner portal, application forms, support channels and related services (together, the Services). It should be read together with any more specific notice displayed in a Service.

1. Scope and people covered

This Policy applies to website visitors, customers, order recipients, restaurant and business partners and their authorised users, courier-partner applicants, approved independent delivery providers, companies providing delivery services, their representatives and authorised users, and each individual driver attached to such a company. In this Policy, Driver means any individual aged at least eighteen (18) who physically performs a delivery mission, whether independently or for a company delivery provider.

2. Data controller and contact

The controller responsible for the processing described in this Policy is:

IWEB SOLUTIONS S.à r.l., trading as MiamMiam
1, Avenue de Luxembourg
L-4950 Bascharage
Luxembourg
RCS Luxembourg: B298678
VAT: LU36781163
Email: support@miammiam.lu

Questions and data-protection requests may be sent to the address above with the subject Data protection. We may request information reasonably necessary to verify identity and protect the account concerned.

Restaurant partners, company delivery providers, payment providers, banks and other organisations may act as separate controllers when they process data for their own purposes. Their own privacy information applies to that processing.

3. Personal data we collect

Depending on the Service used, we process the following categories:

  • Customers and recipients: identity and contact details; account and sign-in data; delivery address, coordinates, access details and instructions; order contents, restaurant, value, fees, discounts, status, messages, complaints and feedback; and limited payment, wallet and refund information.
  • Restaurant and business partners: business identity, registration, addresses, representatives, authorised users, contracts, bank and invoice details, catalogue and opening information, orders, preparation, delivery method, support, claims and account activity.
  • Delivery-provider applicants: identity, date of birth, address, contact details, languages, vehicle and experience, identity documents, establishment authorisation or business permit, application status, review information and correspondence.
  • Approved providers and Drivers: profile and account status; company relationship; vehicle, registration, permit, inspection and insurance; device, session, IP address and security data; availability, selected zone and delivery radius; offers, acceptances and refusals; pickup and delivery events; routes and location; codes and delivery photographs; incidents, ratings and support; remuneration, deductions, invoices, tax information, IBAN, BIC and payout status.
  • Technical and communication data: timestamps, error and security logs, browser or application version, language, network and device information, push tokens, notification status, emails, SMS, notifications and support exchanges. Where an email contains an open-tracking element, we may record whether and when it was loaded together with associated technical request information. If a future in-app chat is activated, its messages may also be processed after users have been informed.

Payment-card information entered through Stripe is processed by Stripe. MiamMiam does not receive or store the complete card number or card security code.

4. How we obtain data

We obtain data directly from you; automatically from your browser, application or registered device; from customers, recipients, restaurant partners, delivery providers and authorised company users where necessary for an order or business relationship; from payment, communications, hosting and security providers; and from public registers or competent authorities where verification or compliance requires it.

5. Purposes and legal bases

We process data to create and secure accounts; prepare and perform contracts and orders; review applications and verify eligibility; organise preparation, pickup and delivery; propose and monitor delivery missions; calculate distances, waiting, cancellations, remuneration and payouts; issue invoices and refunds; provide support; handle complaints and incidents; prevent fraud and misuse; protect people, orders, accounts and systems; improve reliability; establish, exercise or defend legal claims; and comply with accounting, tax, commercial, regulatory, court and law-enforcement requirements.

Depending on the purpose, the legal basis is the performance of a contract or pre-contractual steps, compliance with a legal obligation, or MiamMiam's legitimate interests in operating and improving the Services, ensuring security, preventing fraud, resolving disputes and defending rights. Consent is used only where a feature is genuinely optional and the law requires it, for example optional marketing or non-essential technologies. An operating-system permission controls technical access to a device feature and is not necessarily consent under the GDPR.

IWEB SOLUTIONS S.à r.l. is registered as a Platform Operator under Luxembourg's DAC7 law. Where a Partner or delivery provider is a Reportable Seller, MiamMiam collects and verifies the legally required identification, residence, tax, VAT, business-registration and financial-account information and reports the number of relevant activities, consideration paid or credited, and related fees, commissions or taxes to the Luxembourg Inland Revenue. The authority may exchange that information with the tax authorities of the relevant EU Member States. Each Reportable Seller receives, no later than 31 January of the following year, the DAC7 information reported about that Seller. DAC7 reporting does not itself create a new tax.

6. Driver availability and location

MiamMiam Driver collects precise location from the time a Driver personally selects Available for delivery until that Driver selects Unavailable, and during any mission that must first be completed. Collection may continue in the background or while the screen is locked when the required device permission is enabled. When enabling location for the first time, the Driver must expressly acknowledge the information and grant the required device permission. A persistent device notification remains visible while location is active. The device permission is a technical requirement and is not relied upon as GDPR consent.

Location is necessary to identify compatible nearby requests, estimate distance and time, organise dispatch, monitor operational progress, confirm arrival, pickup and delivery, calculate waiting or cancellation, protect people and orders, detect fraud and investigate incidents. Customers and restaurant Partners currently have no access to a Driver's location. An authorised company delivery-provider user may access only the limited current-location view described in section 9. Any future customer map feature must be reassessed and this Privacy Policy updated before activation. Location records may include latitude, longitude, accuracy, heading, speed, device and server timestamps, device identifier, update source, availability events and indicators that the device reports a mocked location.

A Driver who has no active mission may switch to unavailable at any time. Continuous availability tracking then stops. MiamMiam does not track private movement outside periods of availability and active missions. Location is not used for behavioural advertising or to monitor compliance with road speed limits. Refusing or withdrawing the required device permission prevents the Driver from becoming available, receiving nearby mission offers and performing a mission.

7. Dispatch and automated processing

Automated operational rules assist mission proposals, distance and time estimates, remuneration calculations, anomaly detection, fraud prevention and incident prioritisation. Relevant parameters may include current position and its accuracy, selected zone and radius, vehicle, availability, current assignments, route compatibility, pickup timing, mission constraints, relevant technical history and security signals. Drivers remain free to accept or decline an offer.

An anomaly or suspected misuse causes the account to be flagged for an administrator; an authorised person takes the final decision on any lasting pause, suspension, deactivation, lasting restriction or definitive refusal of payment. The Driver is informed of that decision and its reason by email. The email contains a link to a response form whose submission is automatically assigned to the relevant case, allowing the Driver to submit observations and request human review. Separately, repeated failed login attempts may cause a fully automated temporary security lock lasting from five (5) minutes to no more than forty-eight (48) hours, depending on the number of attempts. A reasoned response is provided without undue delay and no later than fourteen (14) calendar days; an erroneous decision is corrected without delay.

8. Delivery contacts and proof

Only when a Driver is travelling from pickup towards the customer may the customer's telephone number be temporarily displayed to that Driver for a direct telephone call. The Driver's personal number is not shown to the customer. Voice calls do not pass through MiamMiam Driver and MiamMiam does not record their audio content. The customer's number ceases to be accessible to the Driver when the mission is completed and may not be used for any other purpose.

Where an authorised doorstep deposit is required after the customer remains absent and the five-minute procedure has been followed, the Driver may take a photograph directly in MiamMiam Driver. The image must be limited to the order, deposit location and necessary address elements. Age-restricted products may never be left at the door. Delivery photographs must not be stored in a personal gallery, copied, published or shared.

9. When we disclose data
  • Restaurant and business partners receive customer, recipient, order and delivery information necessary to prepare, manage and, where applicable, deliver an order, together with relevant assignment and status information.
  • Assigned Drivers receive the restaurant, order, pickup and customer-delivery information necessary for an accepted mission. The customer's number is visible only while the Driver is travelling towards that customer.
  • Customers and recipients currently receive relevant status and estimated-arrival information but cannot access the Driver's location. A future map feature, if activated after prior reassessment and information, will be limited to the period during which the Driver is travelling towards the customer. Customers will not see the Driver's first name or surname, photograph, vehicle type, registration number or personal telephone number.
  • Company delivery-provider access: an authorised company user can see only the most recent location ping of a Driver currently attached to that company while the Driver is available or on a mission. No route, route history or earlier location sequence is disclosed. Access ends immediately when the Driver becomes unavailable or the attachment ends, and never includes later activity for another company or as an independent provider.
  • Authorised MiamMiam personnel access data according to their role for administration, application review, dispatch, support, payment, security, compliance and claims.
  • Service providers support hosting, storage, payment, email and SMS, push notifications, accounting, diagnostics and security. Amazon Web Services hosts the database, including stored location records, in its Frankfurt region (eu-central-1; availability zone eu-central-1a). MiamMiam operates its own OSRM routing and Nominatim geocoding servers on AWS in the same region and zone, so no external mapping provider receives Driver location for those functions. Google Firebase and Apple Push Notification service are used only to deliver push notifications in MiamMiam Driver. They receive the push token, necessary technical delivery data and a generic notice such as New order available, but no location, restaurant, customer, address or order details. The application then retrieves the request through MiamMiam's protected API. Stripe processes customer card payments but does not receive Driver location data.
  • Banks, advisers, insurers, courts and authorities receive data where necessary to process payments, obtain advice, protect rights or comply with law. Data may also be disclosed under confidentiality safeguards in a merger, financing, reorganisation or sale of all or part of the business.
  • Tax authorities under DAC7 receive the identification, residence, tax, financial-account and transaction information that MiamMiam is legally required to report. The Luxembourg Inland Revenue may exchange it with the competent tax authorities of other EU Member States.

We do not sell personal data. Each recipient receives only data necessary for its role. Providers acting on our behalf are subject to contractual and security obligations.

10. Payments and financial data

Stripe processes online card payments. MiamMiam receives limited transaction information such as reference, amount, status, payment-method category and refund result. For Driver payouts, we process account-holder name, IBAN, BIC, VAT number where applicable, payout frequency, earned amounts and payment references for payment administration, accounting, compliance, fraud prevention and related support.

11. International transfers

Our primary hosting infrastructure is located in the European Union. Some international service providers may process data or permit support access from outside the European Economic Area. Where required, we use an adequacy decision, approved Standard Contractual Clauses with supplementary measures where appropriate, or another transfer mechanism permitted by the GDPR. Information about relevant safeguards may be requested using the contact details above.

12. Retention
  • Account and contractual data are retained during the relationship and afterwards only for legal obligations, unresolved transactions, security, fraud prevention and legal claims.
  • Orders, invoices, payouts, refunds and accounting records are retained for the periods required by tax, accounting and commercial law.
  • Information and evidence used for DAC7 due diligence and reporting are retained for the legally required period and restricted to tax-compliance and evidentiary purposes.
  • An application that is refused is automatically deleted after seven (7) days. An application that remains unprocessed, with neither an acceptance nor a refusal decision, is automatically deleted after one (1) month. If the application is accepted, the necessary eligibility and contractual records are retained during the resulting relationship and afterwards only for applicable legal obligations and claims.
  • Detailed Driver positions and routes are automatically deleted on the first day of each month. If a claim concerning the delivery is still open, the detailed records may be retained until that claim is closed, but never for more than two (2) months; they are automatically deleted at closure or, at the latest, when the two-month limit is reached.
  • Orders and the minimal delivery records archived with them — the pickup time and delivery time — are retained for ten (10) years to support invoices and comply with Luxembourg accounting and tax obligations. Archived orders contain no Driver GPS points, route or travelled-distance record and do not permit reconstruction of the Driver's movements.
  • Delivery codes are set to NULL immediately after the delivery is completed.
  • Doorstep delivery photographs are automatically deleted after ninety (90) days. Where a specific legal obligation, claim or proceeding requires longer retention, the relevant photograph is isolated, access-restricted and retained only for the necessary period.
  • Data necessary for a specific incident, fraud inquiry, accident, complaint or proceeding may be isolated, access-restricted and retained until final closure and for applicable legal limitation periods. This does not extend the two-month maximum applicable to detailed Driver positions and routes.
  • Access and security logs are normally retained for fourteen (14) days and then deleted or overwritten. If a specific security incident occurs, the relevant extract may be isolated, access-restricted and retained only as long as necessary to investigate the incident and protect legal rights.
  • Other support and communication records are retained only while necessary for account protection, incident handling, quality follow-up and legal claims. AWS Lightsail automatic database backups are rotated after seven (7) days. We do not routinely create manual database snapshots; an exceptional snapshot used for restoration is deleted immediately after restoration.

Customer address, contact details and exchanges cease to be accessible to the Driver immediately after mission completion. When retention is no longer justified, data are deleted, irreversibly anonymised or isolated and restricted where deletion must legally be delayed.

13. Cookies, local storage and mobile technologies

The website uses cookies and similar technologies required for sessions, security, baskets, sign-in, language and interface preferences, application detection and, where applicable, referral attribution. A non-essential cookie or similar technology is used only after any consent required by law. Mobile applications store limited authentication, device-registration, language and preference information locally and use notification services supplied by Google Firebase and Apple.

Mobile operating systems may request permissions for notifications, precise and background location, camera or photo access. Camera and photo access are used only when a user chooses to capture or select a required image or document. Permissions may be changed in device settings, although disabling one may make the related function unavailable.

14. Security

We use measures appropriate to risk, including HTTPS/TLS network transmission, AWS-managed encryption of the database and backups at rest, password hashing, access controls, device-bound authentication tokens, token and device revocation, authenticator-based two-factor authentication for administrative access, restricted administrative access, logging, monitoring, backups and incident management by trained IT personnel. No internet service can guarantee absolute security. Users must protect credentials and devices and notify MiamMiam promptly of suspected unauthorised access.

15. Your data-protection rights

Subject to GDPR conditions and exceptions, you may request access, rectification, erasure, restriction and portability of data you provided; object to processing based on legitimate interests; object at any time to direct marketing; withdraw consent where processing is based on consent; and obtain information and human intervention concerning any significant automated decision. Rights are not absolute where law, unresolved transactions, security, third-party rights, an investigation or legal claims require continued processing.

Send a request to support@miammiam.lu. Email requests are normally answered and resolved within a few days and, in all cases, within the applicable GDPR deadline. Where legally permitted for a complex or numerous request, the one-month period may be extended by two further months after notice to you.

16. Account deletion and required data

Customers and Drivers may request access to their data or account deletion directly in the application, where the request is processed automatically. Deleting an account does not immediately erase records that must be retained for accounting, tax, fraud prevention, unresolved orders, payouts, disputes or legal claims; those records are restricted to the applicable purpose.

Required information must be provided so that we can create an account, process an order, assess an application, offer and perform deliveries or make a payout. If it is not provided, the corresponding Service may be unavailable. Drivers cannot remain available or eligible for nearby mission proposals without required notification and location permissions.

17. Children

The Services are not directed at children who cannot lawfully enter the relevant transaction. Delivery-provider applications and Driver profiles are available only to adults meeting the legal and contractual requirements. MiamMiam does not knowingly invite minors to apply as Drivers.

18. Complaints

Please contact us first at support@miammiam.lu so that we can investigate. You may also lodge a complaint with the Commission nationale pour la protection des données (CNPD) in Luxembourg or the competent authority in your habitual residence, place of work or place of the alleged infringement, without affecting any other remedy. Information and the CNPD complaint form are available at cnpd.public.lu.

19. Changes to this Policy

We update this Policy when the Services, processing activities or legal obligations change. The current version is published with its last-updated date. Where a change materially affects how personal data are processed, we provide an additional notice before it takes effect where required.

Last updated: 8 August 2026