reservations.fiest.ioContact

Fiest Reservations

Fiest Reservations and Catering privacy notice

How Fiest Oy handles personal data on reservations.fiest.io and catering.fiest.io: as controller for the site, analytics, security and the demonstration, and as processor for group requests made to a restaurant.

About this notice

reservations.fiest.io · catering.fiest.io · Fiest Oy · Updated 11 September 2026. This notice explains how Fiest Oy processes personal data on reservations.fiest.io and catering.fiest.io. A group request is the responsibility of the restaurant it goes to; the restaurant's own notice is on its ordering form. Fiest handles the request on the restaurant's behalf and runs the site.

1. Controller

Fiest Oy (business ID 3438254-5), Sähkötalo, Kampinkuja 2, 00100 Helsinki. Privacy matters: info@fiest.io, +358 40 440 7518.

2. Two roles

As controller, Fiest is responsible for use of the site: the cookie choice, analytics, abuse prevention, restaurant suggestions on the homepage and the public demonstration at /test. As processor, Fiest stores and forwards group requests made to a restaurant on that restaurant's behalf. The restaurant is the controller: it decides what the data is used for and how long it is kept, and it is responsible for the lawfulness of its processing, for its own notice and for answering requests about your data. Fiest is responsible only for the technical processing described in this notice. Fiest and the restaurant have a data processing agreement. The restaurant's notice is the restaurant's own; it tells you who represents the restaurant and how it handles your request.

3. What we process as controller

Cookie choice and appearance setting: stored in your browser. The choice lasts 180 days, the appearance setting until you remove it. Analytics, only with consent: page views and form steps sent to PostHog's EU service through k.fiest.io. Form contents, contact details and order details are never sent. Sessions are not recorded. Abuse prevention: the number of requests is limited per network address. The address is stored as a salted hash in an hourly counter that is deleted within a day. Cloudflare's edge network limits requests further without storing anything. Restaurant suggestions on the homepage: the restaurant name and message you enter. The demonstration at /test: the example menu, group size and time you choose, without contact details. If you give a @fiest.io address for a test message, it is used only to send that message and is not stored. Legal bases: consent for analytics, and legitimate interest in running and securing the site and in handling suggestions and the demonstration.

4. How a group request is handled technically

The request is stored in a database in the EU (Frankfurt). Only Fiest staff who need access for operations can reach it. The restaurant receives the request by email, and you receive a confirmation. The emails contain the request details and are sent through Resend. The confirmation carries a private link to your request. Only a hash of the link's key is stored, and the link expires 30 days after the event. Opening it changes nothing. The restaurant decides the retention period. Fiest keeps the request on the restaurant's behalf for the term of the agreement and deletes it at the restaurant's request or when the agreement ends. Copies in the restaurant's own systems are the restaurant's responsibility.

5. Providers and transfers outside the EU

We use these sub-processors, which act on our instructions: Cloudflare: running the site and API, and limiting requests at the edge. Neon: the database, on AWS in Frankfurt (EU). Resend: email delivery. PostHog: analytics in its EU service, only with consent. Data is not sold or used for marketing. Where a provider processes data outside the EU or EEA, the transfer relies on standard contractual clauses approved by the European Commission.

6. Retention as controller

Analytics events: at most 12 months. Rate-limit counters: deleted within a day. Restaurant suggestions and demonstration records: for the pilot, at most 12 months.

7. Your rights

You have the right to access your data, to have it corrected or deleted, to restrict or object to processing, to data portability and to withdraw consent. You can change the cookie choice under Cookie settings in the page footer. Requests about your group request go to the restaurant, whose contact details are in its notice and in your confirmation. If such a request reaches Fiest, we pass it on to the restaurant. Requests about the site, analytics, suggestions and the demonstration go to Fiest at info@fiest.io. We reply within a month. You can also complain to the Office of the Data Protection Ombudsman (tietosuoja.fi). (https://tietosuoja.fi/en/home)

8. Changes

We update this notice when processing changes. Fiest's general privacy policy is at fiest.io/en/privacy-policy. (https://fiest.io/en/privacy-policy)