Privacy Policy
ASAP Company SNC (hereinafter "ASAP", "we"), a general partnership under Swiss law with its registered office at Chemin de Maillefer 111, 1018 Lausanne, Suisse, operates the ASAP App mobile application (customer and vendor versions), the asap-app.ch website and the associated services (the "Service"). ASAP acts as data controller within the meaning of art. 5 lit. j of the Swiss Federal Act on Data Protection (FADP, revised version in force since 1 September 2023) and, where applicable, art. 4(7) of the GDPR (EU 2016/679).
1. Data controller
ASAP Company SNC, Chemin de Maillefer 111, 1018 Lausanne, Suisse. Data protection and general support contact: asap.app@proton.me.
2. Scope
This policy applies to anyone who creates a customer or vendor account, browses the asap-app.ch website, places an order, operates a registered food truck, or otherwise interacts with our services. It does not cover third-party sites we link to (Stripe, Apple, Google), which have their own policies.
3. Data we collect
Provided directly: identification data (first name, last name, email, phone — optional for customers / mandatory for vendors), password (hashed, never in clear text); vendor data (company name, business ID, address, Stripe Connect details, KYC documents required by Stripe); content (orders, reviews and ratings, optional avatar, favourites). Collected automatically: transactions (amount, card/TWINT method, date, status — card data is never transmitted or stored by ASAP, it passes only through Stripe, PCI-DSS level 1); location (customer: approximate or precise position, only with permission, to display nearby trucks; vendor: truck position when the "online" status is active); technical data (device, OS, Expo/Firebase install ID, language, time zone, IP, error logs); push notification tokens (Expo Push / FCM); strictly necessary cookies on the website and third-party SDKs in the app (Stripe, Supabase, Mapbox). Received from third parties: from Stripe (KYC status, payment events); from Google / Apple for social login (email, name, photo), only with your explicit consent.
4. Purposes and legal bases
Performance of the contract (create the account, process order and payment, deliver the pickup code, order push notifications): contractual performance (FADP art. 31(2)(a); GDPR art. 6.1.b). Display of nearby trucks (customer location): consent, revocable in the OS settings (GDPR art. 6.1.a). Broadcasting the truck position: vendor contractual performance and legitimate interest. Fraud prevention (payment, chargebacks, fake reviews): legitimate interest (FADP art. 31(2)(d); GDPR art. 6.1.f). Anonymised internal statistics and improvement: legitimate interest. Legal obligations (accounting, VAT, authority requests): legal obligation (GDPR art. 6.1.c). Direct email marketing if enabled: consent, easy opt-out in every email. We make no fully automated decisions producing significant legal effects (art. 21 FADP / art. 22 GDPR).
5. Recipients and processors
We never sell your data. The food truck linked to your order receives your first name, the items ordered, any instructions and the 4-digit pickup code — no payment data. Technical processors: Stripe (payments, Connect payouts to vendors, KYC — Ireland/USA); Supabase (database, authentication, storage, server functions — USA); Mapbox (maps — USA); Expo + Google Firebase Cloud Messaging (push — USA); Vercel (website and admin dashboard hosting — global network). All are bound by data processing agreements (DPAs). Transfers to the USA rely on Standard Contractual Clauses and/or the Data Privacy Framework. Public authorities: only upon legally binding request.
6. Retention periods
Active account: as long as you use the Service. Orders and invoices: 10 years (art. 958f CO). Payment data (summaries, Stripe IDs): 10 years. Reviews: kept while the account exists, anonymised after deletion. Technical and security logs: 12 months. Push tokens: disabled on logout, deleted after 6 months of inactivity. Account deleted at your request: profile anonymised immediately, reconnection blocked, definitive deletion after fulfilment of accounting obligations.
7. Your rights
You have the right to access, rectification, erasure ("right to be forgotten"), restriction, portability (GDPR), objection, and withdrawal of consent at any time. You can delete your account directly in the app (Account → Delete account): deletion anonymises the profile immediately and blocks reconnection; historical orders are kept in dissociated form for our accounting obligations. To exercise these rights, write to asap.app@proton.me from the address linked to your account; we respond within 30 days. Complaint: in Switzerland to the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch); in the EU to the authority of your country of residence.
8. Security
Encryption in transit (TLS 1.2+); encryption at rest of Supabase databases; passwords stored only as hashes (bcrypt/argon2); restricted role-based access (Supabase RLS, least privilege); separate administrator authentication verified on every request; monitoring of suspicious connections and audit logs; payment data fully delegated to Stripe (PCI-DSS Level 1). No system is fully secure; in the event of a breach affecting your rights, we will notify you without undue delay (art. 24 FADP).
9. Minors
The Service is intended for persons aged 18 or over (use of payment methods). We do not knowingly collect minors' data. If you believe a minor has registered, contact us: we will delete the account.
10. International transfers
Some processors (Stripe, Supabase, Mapbox, Vercel, Expo, Google) operate from the United States. These transfers are framed by Standard Contractual Clauses (EU Decision 2021/914), where applicable adherence to the EU–US Data Privacy Framework, and a case-by-case assessment of the level of protection (art. 16 FADP).
11. Cookies and trackers
The asap-app.ch website uses only strictly necessary cookies (session, security, language preference). No advertising cookies or marketing tracking pixels. The mobile app collects the technical identifiers described in section 3.
12. Changes
We may amend this policy to reflect legal, technical or Service developments. Any substantial change will be notified to you via the app or by email at least 14 days before it takes effect. The applicable version is the one published at https://admin.asap-app.ch/privacy.
13. Governing law
This policy is governed by Swiss law. For users residing in the European Union, the GDPR also applies under the conditions of its art. 3.
Contact
For any question regarding your data: asap.app@proton.me.
v2026-08-04