Skip to content
Drif FoodDRIF FOOD

Privacy policy

Last updated: August 2026

Courtesy translation — in the event of any discrepancy, the French version prevails.

1. Data controller

Data collected on driffood.ma and through the Drif Food app is processed by DRIF FOOD, Al Wafae 2, Bloc 14, Av. Allal El Fassi, Oujda, Morocco. For any question about your data or to exercise your rights: 0707-80-0404 or driffood@gmail.com.

2. Data we collect

Depending on how you use the service, we may process:

  • Identity and contact details: name, phone number, email address (if you create an account), delivery address.
  • Location: GPS coordinates of the delivery point, when you set them on the map to be delivered (see section 6).
  • Orders: content of your orders, amounts, service mode (delivery, pickup, dine-in), any remarks, and history.
  • Account: login identifier, language, password (stored encrypted, never in plain text).
  • Loyalty: indicators computed from your orders (see section 4) and rewards granted to you.
  • Consent: your agreement (or refusal) to receive commercial offers, and its date.
  • Use of the website and app: pages and products viewed, items added to the cart, abandoned checkouts, promotions displayed and clicked (see section 13).

No banking data is collected: payment is made upon delivery or pickup, in cash or by card at the restaurant's terminal.

3. Purposes and legal bases

  • Processing, preparing, delivering and tracking your orders, and managing your account — performance of the contract.
  • Contacting you about an order — performance of the contract.
  • Loyalty programme: granting rewards and promotional codes (section 4) — legitimate interest.
  • Promotions and personalised offers: determining which offers you qualify for (section 4) — legitimate interest.
  • Measuring how the service is used and improving our menu (section 13) — legitimate interest.
  • Prevention of fake delivery orders (section 5) — legitimate interest.
  • Sending you offers, news about new dishes and your reward codes — your consent (section 7).
  • Compliance with our accounting and legal obligations — legal obligation.

4. Loyalty, personalised promotions and profiling

To reward loyal customers, we automatically compute, from your order history, indicators such as the number of orders and total spend. These indicators determine a loyalty level (from Bronze to Diamond). This processing constitutes profiling; it is used solely to grant you rewards and promotional codes based on your level and spend, and does not lead to any decision producing legal effects concerning you. You may object to it by contacting us.

If you order online with an account, we also maintain a loyalty points account: each eligible order earns points computed from its amount, and every movement (earning, conversion into a discount voucher, claw-back after a refund, expiry, adjustment) is recorded in a ledger you can consult from your account. Points convert into personal, single-use discount vouchers with a limited validity period. The detailed, up-to-date rules (rate, thresholds, voucher validity, expiry after inactivity) are published on the "Loyalty programme" page of the website and app; points and vouchers already earned are never removed without prior notice.

Some promotions are reserved for groups of customers: for example an offer aimed at new customers, at a given loyalty level, or at customers who have not ordered for some time. To determine whether an offer applies to you, we use only information derived from your orders: number of orders, date of your last order, average basket, loyalty level, and whether or not you have installed the app. This processing is also profiling. It is used solely to offer you promotions and produces no legal effect concerning you: the standard price always remains available and no order is refused on this basis. You may object to this profiling by contacting us; you will then continue to order normally, without receiving targeted offers.

Two further uses rely on the same information. Firstly, we show you dish suggestions on the home page and in the cart, based on what you have already ordered and on what our customers order in general; they never change any price. Secondly, when we send you a notification (section 7), we choose the time at which it is sent according to the time of day you usually order, so as to disturb you as little as possible. You may object to both of these uses by contacting us.

5. Prevention of fake orders

To protect ourselves against fake orders("ghost orders") — for example an order placed and delivered while the customer then becomes unreachable — we may record an internal flag associated with a phone number, together with the reason. This mechanism is used solely to prevent delivery-order fraud; this information is strictly internal, accessible only to restaurant staff, and is reviewed periodically.

6. Geolocation

When you choose delivery, you can set your position on a map: the corresponding GPS coordinates are used solely to locate the delivery point (a marker for the courier). They are kept with the related order and your saved addresses, and you can delete them at any time.

7. Notifications and commercial communications

Our messages fall into four categories, which you control separately from your account (the "Notifications" section):

  • Order tracking (confirmation, preparation, delivery) — necessary to fulfil your order, these messages are not advertising;
  • Loyalty (points about to expire, voucher earned, change of level) — information about your own benefits, which you can turn off;
  • Offers and promotions — sent only if you have expressly consented (checkbox not pre-ticked);
  • New arrivals (new dishes) — also subject to your consent.

These messages reach you as notifications on the app or the browser where you signed in. Some are automatic: for example a reminder if you have not ordered for a long time, or an invitation to leave a review after an order. They follow limits we impose on ourselves: never between 9 pm and 9 am, at most one message per day and two per week, and we stop insisting with people who do not open them.

You may withdraw your consent at any time, category by category, from your account — without this affecting the processing of your orders. Your successive choices are kept so that we can show we have respected them.

Our general offers are also published on our social networks. Unless you ask us to, they are not sent by message to your personal number.

8. Recipients

Your data is accessible to restaurant staff and, for a delivery, to the courier in charge of your order (name, phone, address and location marker shown on the delivery slip). It is neither sold nor transferred to third parties for commercial purposes.

We use technical service providers (processors):

  • Supabase — hosting of the database, authentication and files;
  • Vercel Inc. — website hosting;
  • Google— "Sign in with Google" (if you use it);
  • OpenStreetMap / Nominatim — map display and address conversion;
  • Google (Firebase Cloud Messaging) — technical delivery of notifications to your device or your browser;
  • WhatsApp / Meta — occasional contact channel, if you write to us or ask us to send you a code there.

9. Hosting and transfers outside Morocco

Our technical providers host data on servers located outside Morocco. The detail matters, because Law No. 09-08 distinguishes countries by the level of protection they afford:

  • Germany: the database, accounts and files, as well as delivery route calculation. Germany appears on the list of States recognised by the CNDP as affording sufficient protection.
  • United Kingdom: map tiles and address lookup (OpenStreetMap). Also on that list.
  • United States: website hosting, notification delivery, guiding the courier to your address, and WhatsApp exchanges if you write to us. That country is not on the list: these transfers rest on the performance of your order — delivering requires knowing where to go — or, for promotional notifications, on your consent, which you may withdraw at any time.

The bulk of your data — everything you entrust to us when ordering — therefore stays in a country recognised by the CNDP.

10. Retention periods

  • Orders: identifying data (name, phone, address, GPS position, remarks) is deleted or anonymised 3 years after the order — including on the restaurant's till; accounting records may be archived longer to meet our legal obligations.
  • Data passed to the courier (name, phone, address, delivery point): erased 30 daysafter the run. The delivery record itself is kept without a name, for the courier's accounts.
  • Proof-of-delivery photo, where enabled: deleted after 30 days, and removed from the courier's phone as soon as it is uploaded.
  • Route calculation: the result is cached to avoid recomputing, then deleted as soon as it expires.
  • Reviews: your name and phone are stripped after 90 days; the rating and comment are kept, attached to no one.
  • Promotion usage (so an offer is not claimed twice): the phone number and device identifier are erased after 1 year.
  • Account, addresses and loyalty profile: deleted after 2 years without an order or login — and at any time upon your request (section 11).
  • GPS position: kept with the related order or your saved addresses (same periods as above), deletable at any time.
  • Marketing consent: kept until withdrawn.
  • Usage data (section 13): deleted after 90 days; only anonymous daily totals per product are kept beyond that.
  • Rewards: deleted after use or expiry, following a short retention period.
  • Loyalty points: the balance and movement ledger are kept as long as your account exists, and deleted with it (on your request or after prolonged inactivity — see above). Points also expire under the programme rules, always with prior notice.

11. Your rights

In accordance with Law No. 09-08, you have rights of access, rectification, objection and deletion of your data:

  • View and correct your information from your account area.
  • Delete your account and associated data from your account or via the account deletion page.
  • Object to commercial prospecting, to profiling (section 4) or to usage measurement (section 13), and exercise any other right, by writing to driffood@gmail.com or calling 0707-80-0404.

12. Security

Exchanges with our servers are encrypted (HTTPS). Access to data is restricted to authorised staff, and each customer can only access their own information. Passwords are stored in encrypted form.

13. Measuring use of the website and app

To understand what interests our customers and improve our menu, we record certain actions you take on the website and in the app. The list is exhaustive:

  • opening the app;
  • viewing a category or a product;
  • adding or removing an item from the cart, viewing the cart;
  • starting checkout, abandoning checkout, placing an order;
  • a promotion being displayed or clicked, clicking a suggestion, clicking a notification.

These records contain the action, its date and, where applicable, the product or category concerned. No free-text content is recorded. If you are signed in to your account, they are linked to it; otherwise they are associated with a random session identifier, kept by your browser for the duration of the visit, which cannot identify you.

They serve only three purposes: improving our menu and our service, measuring how effective our promotions are, and offering you relevant suggestions and offers (section 4). They are neither sold nor shared with advertisers, and are never used for targeted advertising outside our own services. We use no third-party advertising tracker.

These records are deleted after 90 days. Beyond that we keep only anonymous daily totalsper product (for example: "this sandwich was viewed 120 times yesterday"), which relate to no individual and cannot be traced back to you. You may object to this usage measurement by contacting us (section 11).

14. Cookies and local storage

The site only uses technical cookies necessary for its operation (for example remembering your language and your cart). No advertising or tracking cookies are used.

The website and the app also use your device's local storage to keep your cart, your language, your display theme and the session identifier mentioned in section 13. You can clear it at any time from your browser settings or by uninstalling the app.

15. Contact and updates

This policy may be updated; the date of the last revision appears at the top of the page. For any question: driffood@gmail.com.