Bitebooker

Legal

How we handle your data

What we ask you, when, who receives it and what stays on your device. Written by reading the code, not a template.

Last updated
12 September 2026
Data controller
BITEBOOKER S.R.L.
Registered office
Via Vincenzo Nardi 101, 51100 Pistoia (PT), Italia
VAT number
IT02042780474
For your rights, write to
privacy@bitebooker.it
Certified mail (PEC)
posta@pec.bitebooker.it

This page describes the public Bitebooker site: the restaurant listings, the search, the forms to book or request a table, the reviews and your personal area. It does not describe the software restaurants use internally, which is a different thing with its own rules.

What we ask you, and only when it is needed

Browsing requires nothing. You can look at every listing, filter by city and cuisine and read the reviews without telling us who you are and without any account.

We ask for data at four moments, and at each one only what that thing needs:

  • Booking a table — name, phone, email, day and time, how many people (adults, children, pets), and any note you want to leave the restaurant. Consent to the processing is required: without it we cannot pass your name to the restaurant, so there is no booking. Consent to marketing messages is separate and optional, and is not needed to book.
  • Requesting a table at a place that does not use Bitebooker — name, one contact (phone or email), day, time and how many people. It lets us pass the request along and tell you how it went.
  • Reporting something wrong on a listing — the reason, and an optional note. We do not ask for any contact details: telling us a place has closed should not cost a sign-up.
  • Writing a review — the rating, the text, a title if you want one, and the name to sign it with. This needs an account, because a review is tied to a booking: that is why we can say every review is verified.

If you sign in with Loonar ID we receive your identifier, name and email address from the sign-in service. We never receive or store your password: that stays with Loonar.

Who receives your data

The restaurant. It is the most important line on this page, and it is the only recipient that makes sense: you book to have dinner somewhere, and that somewhere needs to know who is coming, how many of you and at what time.

From that moment the restaurant has your details in its own customer records and answers for what it does with them — its own messages, its own follow-ups, its own mailing list. Requests about that (removing you from its records, finding out what it holds) go to the restaurant, and we cannot make them on your behalf.

We do not sell your data and we do not pass it to anyone unrelated to your booking. If that ever changed, changing this page would not be enough: the product would have changed.

If you link a booking to your account

Linking a booking to your account does not move it and does not change who answers for it: the record stays in the restaurant's files, exactly as if you had never signed in. The link is ours, kept separately, and it does one thing: it lets you find that booking again from another phone.

Three consequences, and they are the reason it is built this way:

  • the restaurant does not see the link. To it you are the name you typed when booking, no more and no less. It does not know whether you have an account, nor whether you have booked elsewhere;
  • you link one booking at a time, and you choose. We link nothing automatically even where we could: the list this browser remembers may hold bookings made by someone else who used the same device;
  • unlinking or deleting your account removes the link, not the booking. That stays with the restaurant, which needs it: it is its evening, its books, its dining room.

It is also why “my bookings” is a *view*, not an archive. We keep the thread; the data stays where it has always been.

What stays on your device

Two things, and neither reaches us.

  • The «My bookings» list — it lives in your browser's storage, under the key bb:portale:mie-prenotazioni. It holds only what is needed to reopen a page: the type, the booking code, the place, the day and the time. It does not hold your name, phone, email or how many of you were coming. It keeps at most twenty entries and each one disappears by itself sixty days after the booked day. You can empty it at any time from the page itself, and on a shared device you probably should.
  • Two cookies, only if you sign inbb_sessione holds the session (up to thirty days) and bb_giro lasts ten minutes and exists only to complete the sign-in safely. Both are technical, readable only by our server, and without an account they are never even written.

There are no profiling cookies, no advertising and no banner to accept, because there is nothing to accept.

No third party receives your visit

Measured across ten pages of the site, including the ones where you book and sign in: the browser made 218 requests and every one of them to our own address. None to an analytics service, an ad network, a map, a font archive or a social button. The fonts are served by us, the images are ours.

It means that opening this page tells nobody else that you opened it.

Reviews are public, and can be withdrawn

A published review shows the rating, the text, the title if there is one, the first name only and the date. It does not show the surname, the email, the phone, or which booking made it possible. If you leave the signature empty it appears as «a guest».

You can withdraw it whenever you like from your personal area: from that moment it no longer shows on the listing.

Your rights

You can ask what data we hold, have it corrected or deleted, restrict its use, receive it in a readable format and object to a given use. You can withdraw a consent at any time, and withdrawing it does not make what happened before unlawful.

You can also complain to the Italian data protection authority (Garante per la protezione dei dati personali).

For requests about what the restaurant did with your data after the booking — its records, its messages — the recipient is the restaurant: we cannot reach into its customer database.

How long

What stays on your device lasts as long as written above: sixty days from the booked day for the list, thirty days for the session cookie, ten minutes for the other one.

On our server there is no automatic deletion. A booking, a table request, a review and the link between a booking and your account stay until somebody deletes them: there is no expiry that removes them by itself. We write it because that is how it is.

Three things are yours to do, and they take effect at once:

  • withdraw a review from your personal area: it disappears from the restaurant's page;
  • unlink a booking from your account: the booking stays, the link goes;
  • empty the list this device remembers, from its own page.

Cancelling a booking is not deleting it: the table is freed and the restaurant sees the cancellation, but the booking stays on record — the restaurant needs it to know what happened that evening.

To have us delete your data, write to the address at the top of this page. The copy the restaurant holds in its own records is theirs, and has to be asked of them.

If this page changes

The date at the top says when the text you are reading is from. If anything changes that concerns your data — a new recipient, an analytics tool, one more cookie — this page changes first.