Privacy Policy
Last updated: 7 July 2026
This Privacy Policy explains how personal data is processed in connection with Toorliefer, a delivery operations and dispatch platform that connects restaurants and other merchants, delivery drivers, and the customers receiving their orders. We are committed to processing personal data lawfully, transparently, and only for the purposes described below.
1. Who operates Toorliefer
Toorliefer is a product of and operated by RILZ Germany GmbH. For the personal data described in this policy, RILZ Germany GmbH acts as the controller (or, where it processes data on behalf of a connected merchant, as a processor for that merchant).
RILZ Germany GmbHGraeffstr 1
50823 Köln, Germany
Represented by: Rohi Rusanov
Commercial register: HRB 114200, Köln
Email: rohirusanov@rilz-germany.com
2. What personal data we process
Depending on your role, we may process the following personal data:
- Restaurant / merchant account details — the account and contact information used to set up and operate a merchant on the platform.
- Driver account details — the account and contact information of delivery drivers using the platform.
- Customer delivery name — the name of the person receiving a delivery.
- Delivery address — the address an order is delivered to.
- Telephone and contact information — where provided, used to coordinate and complete a delivery.
- Delivery instructions — notes provided to help complete a delivery.
- Order identifiers — references that link an order to its delivery.
- Location and delivery-status data — pickup and drop-off locations, driver location during an active delivery, and the status of the order and delivery.
- Technical logs and security data — records generated when the applications are used, kept for security, auditing, and troubleshooting.
3. Where the data comes from
We receive personal data from the following sources:
- Restaurants and merchants — when they set up their account and when orders are entered or generated on their behalf.
- Authorised marketplace integrations — such as Uber Eats, when a merchant connects a marketplace store so that its orders are imported for fulfilment.
- Drivers — when they register and while they carry out deliveries.
- The Toorliefer applications — technical and status data generated as the platform is used.
4. Why we process personal data
We process personal data for the following purposes:
- Importing merchant orders into the platform.
- Creating and dispatching deliveries.
- Assigning deliveries to drivers.
- Route planning and delivery tracking.
- Communicating with customers about their delivery.
- Fraud prevention, security, auditing, and providing support.
5. Legal bases for processing (GDPR)
We rely on the following legal bases under Article 6 of the General Data Protection Regulation (GDPR):
- Performance of a contract (Art. 6(1)(b)) — to import, create, dispatch, and complete deliveries and to provide the platform to the parties involved in an order.
- Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve the platform, prevent fraud and misuse, and keep audit records.
- Compliance with legal obligations (Art. 6(1)(c)) — where we are required by law to process or retain certain data.
- Consent (Art. 6(1)(a)) — where processing requires consent, in which case it may be withdrawn at any time with effect for the future.
6. Who we share data with
We share personal data only as needed to fulfil deliveries and operate the platform, with:
- The connected restaurant or merchant whose order is being fulfilled.
- Drivers authorised for that restaurant to carry out the delivery.
- The marketplace provider (for example Uber Eats) where delivery status must be synchronised back for a marketplace order.
- Infrastructure and technical service providers that help us run the platform, acting on our instructions.
- Authorities where disclosure is legally required.
7. Use of marketplace data
Where order data is received from an authorised marketplace integration such as Uber Eats, that data is used only for the operational fulfilment of the relevant merchant order — importing it, creating and dispatching the delivery, assigning a driver, tracking it, and synchronising its status back to the marketplace. It is not used for unrelated advertising, customer acquisition, or competitive analysis.
8. Data retention and deletion
We keep personal data only for as long as it is needed for the purposes set out in this policy — in particular to fulfil and account for the relevant delivery — and for as long as we are required to keep it to comply with applicable statutory retention obligations. When data is no longer needed and no retention obligation applies, it is deleted or irreversibly anonymised. Technical logs and security data are retained for the period necessary for security and auditing.
9. International transfers
Personal data is processed within the European Union / European Economic Area where possible. Where personal data is transferred to, or accessed from, a country outside the EU/EEA, we put appropriate safeguards in place as required by the GDPR — such as an adequacy decision or the European Commission’s Standard Contractual Clauses — so that the data remains protected. You can request more information about the safeguards used by contacting us at the address in Section 12.
10. Data security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss, and misuse. Access to personal data is limited to what is necessary to operate the platform and fulfil deliveries, and platform activity is logged for security and auditing purposes.
11. Your rights under the GDPR
Subject to the conditions in the GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (right to erasure).
- Restrict processing of your data.
- Object to processing based on our legitimate interests.
- Data portability — receive certain data in a structured, commonly used, machine-readable format.
- Lodge a complaint with a data-protection supervisory authority. Given our registered seat in North Rhine-Westphalia, the competent authority is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW); you may also contact the supervisory authority of your own place of residence.
Where our processing is based on consent, you may withdraw that consent at any time with effect for the future.
12. Contact for privacy requests
To exercise any of the rights above, or for any question about this policy or how your personal data is processed, contact us at:
RILZ Germany GmbHGraeffstr 1, 50823 Köln, Germany
Email: rohirusanov@rilz-germany.com
13. Changes to this policy
We may update this Privacy Policy from time to time, for example to reflect changes to the platform or to legal requirements. The date at the top of this page shows when it was last updated. The current version published here always applies.
Toorliefer is a product of RILZ Germany GmbH.