Last updated: 2026-09-02
This Privacy Policy explains what personal data we collect when you use sakurabinche.be (and the Restaurant's mobile app and QR table ordering), why we collect it, how long we keep it and what your rights are. We have tried to write it in plain language. If anything is unclear, contact us at no_reply@asiacuisine.be.
1. Who is responsible for your data
The controller of your personal data is:
Sakura Binche (trading as Sakura Binche)
Av. Charles Deliège 11, 7130 Binche
Company number (KBO/BCE): 0507.707.797
VAT: BE0507707797
E-mail: no_reply@asiacuisine.be · Telephone: 06 484 8418
This is the Restaurant's own website. The Restaurant decides why and how your data is used. The website and ordering system are built, hosted and maintained for the Restaurant by our website developer and hosting provider, which acts as a processor: it only handles your data on the Restaurant's instructions, under a written data-processing agreement, and does not use it for its own purposes.
We are not required to appoint a data protection officer; for all questions about your data, contact no_reply@asiacuisine.be.
2. What data we collect and why
We only collect the data we need to take and fulfil your order. We do not ask for your date of birth, gender or any other data that is not needed for that.
| Data | Why we need it | Legal basis |
|---|---|---|
| Name, telephone number, e-mail address | To confirm your order, prepare it, contact you about it and hand it over to the right person | Performance of the contract (art. 6(1)(b) GDPR) |
| Delivery address | To deliver your order and to check that the address is inside our delivery area | Performance of the contract |
| Your order: dishes, options, amount, delivery or collection time, order note | To prepare the order, print it in the kitchen, and handle complaints | Performance of the contract |
| Table number (QR ordering) | To bring the order to your table | Performance of the contract |
| Payment method and payment status (not your card details, see section 4) | To know whether an order has been paid | Performance of the contract |
| Order amount, VAT, date, invoice details | Bookkeeping and tax obligations | Legal obligation (art. 6(1)(c)) |
| Account data (e-mail, password in hashed form, saved addresses, order history) if you create an account | To let you log in and reorder faster | Performance of the contract |
| Order frequency and spend per customer | To offer loyalty rewards to regular customers and to prevent abuse of vouchers | Legitimate interest (art. 6(1)(f)) — you can object, see section 8 |
| Technical data: IP address, browser type, pages visited, time of request | Security of the website, detecting fraud and automated abuse, error diagnosis | Legitimate interest |
| Language preference, cart contents, table code | To make the website work while you order | Legitimate interest / technically necessary |
"Performance of the contract" means: by placing an order you enter into a contract with the Restaurant, and we need this data to carry out that order. No separate consent is required for it.
Marketing: we do not send newsletters or advertising unless you have given your consent (art. 6(1)(a)). E-mails about your order (confirmation, on its way, ready for collection) and, where the Restaurant offers it, a voucher you have earned through your orders, are not marketing: they are part of the service you asked for.
Automated decisions: we do not take decisions about you based solely on automated processing that have legal or similarly significant effects. The automatic checks described in this policy (delivery area, bot detection) only affect whether an order or registration can be completed technically.
3. Where your data comes from
Everything we hold about you comes from you: what you type when you order or create an account, and the technical data your browser sends automatically. We do not buy data or enrich your profile from other sources.
4. Who receives your data
We do not sell or rent your data. We share it only with the parties needed to fulfil your order:
- our website developer and hosting provider — hosting and maintenance of the website and of the Restaurant's order-receiving system (the screen, printer or app in the Restaurant on which your order appears, and the monthly bookkeeping statement). Servers are located in the European Union.
- The payment service provider (MultiSafepay, Stripe or Mollie, as shown at checkout) — when you pay online. The payment service provider processes your card or bank details itself as an independent controller; the Restaurant never sees or stores your card number. See the privacy policy of the payment service provider concerned for details.
- Google LLC (Google Maps Platform) — when you enter a delivery address, the address (and only the address) is sent to Google's geocoding service to locate it and calculate the distance to the Restaurant, so that we can check the delivery area and delivery charge. Google may process this in the United States under the EU-US Data Privacy Framework.
- Our delivery staff or courier — receive your name, address, telephone number and order for delivery.
- Our accountant and the tax authorities — receive bookkeeping data (amounts, VAT, dates), which is aggregated per month and does not identify you as a customer.
- Authorities — where we are legally required to do so.
5. How long we keep your data
| Data | Retention |
|---|---|
| Completed and refunded orders in the website | 3 years after the order, then automatically anonymised and deleted (name, address, e-mail and telephone are removed) |
| Orders that were cancelled, failed or never paid | Moved to the bin automatically within 1 to 3 days and permanently deleted 30 days later |
| Customer accounts | Deleted after 3 years without any login or order; you can delete your account earlier by asking us |
| Copy of the order in the Restaurant's order-receiving and bookkeeping system | The customer's contact details are kept for up to 6 months after your last order, then removed. The remaining record (dishes, amounts, date) no longer identifies you. |
| Server access logs (IP address, pages requested) | Kept for a short period for security purposes, then deleted |
| Cookies | See section 6 |
Where we have to keep something longer to comply with the law or to handle a dispute, we keep only what is needed for that purpose.
6. Cookies
This website uses only cookies that are needed to make ordering work. We do not use advertising cookies, social-media cookies or third-party analytics cookies on this website, so we do not show a cookie banner: these cookies are exempt from the consent requirement.
| Cookie | Purpose | Duration |
|---|---|---|
WooCommerce session and cart cookies (wp_woocommerce_session_*, woocommerce_cart_hash, woocommerce_items_in_cart) |
Remember what is in your cart while you order | Session / up to 2 days |
WordPress login cookies (wordpress_logged_in_*, wordpress_sec_*) |
Keep you logged in to your account | Session, or 14 days if you tick "remember me" |
| Language cookie | Remember the language you chose | Up to 1 year |
AC_qrtable |
Remember which table you are ordering from after scanning the QR code | 4 hours (up to 14 days in buffet mode) |
billing_*, delivery_method_* |
Remember the address and delivery choice you typed so you do not have to retype it if the page reloads | Session / a few seconds |
Notice cookies (shownotibyasiacuisine, _shopclosednoti_viewed) |
Remember that you have closed an information message (e.g. "we are closed today") | Session |
sidemenu_scroll_top |
Remember your position in the menu | Session |
You can delete cookies at any time in your browser settings; the website may then not remember your cart or login.
7. How we protect your data
The website is served over HTTPS. Passwords are stored in hashed form only. Access to orders is limited to the Restaurant's staff and to the technical staff of our website developer and hosting provider who need it for support and maintenance. Servers and backups are located in the European Union. We use automatic detection of bot registrations and fraudulent orders; this does not involve profiling of individual customers beyond what is described in section 2.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify data that is inaccurate or incomplete (you can change your account details yourself after logging in);
- erase your data, where we no longer need it — note that we may have to keep bookkeeping data that the law obliges us to keep, in which case we will tell you;
- restrict processing while a dispute about the data is being resolved;
- object to processing based on our legitimate interest, including to being included in the loyalty programme;
- data portability: receive the data you gave us in a machine-readable format;
- withdraw consent at any time, where processing is based on consent (for example marketing e-mails), without affecting processing that took place before.
To exercise a right, e-mail no_reply@asiacuisine.be or write to the address in section 1. Tell us the e-mail address or telephone number you used when ordering so that we can find your data; we may ask you to confirm your identity. We answer within one month; if a request is complex we may extend this by two months and will tell you.
You also have the right to lodge a complaint with the Belgian Data Protection Authority: Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35 / Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be, www.dataprotectionauthority.be. We would appreciate the chance to resolve your concern first.
9. Children
This website is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
10. Changes to this policy
We may update this policy when our website or the law changes. The date at the top shows the latest version. Significant changes will be announced on the website.
Questions about your data: no_reply@asiacuisine.be · 06 484 8418