Connection lost
Cookie Policy

Cookie Policy

This page explains how RiseRank AB collects, uses, and protects your personal information on the website restauranger.se, and covers the cookies we use. You can change your cookie preferences at any time via the Cookie Settings link in the footer or the More menu.

1. Introduction and organizational information

RiseRank AB, company registration no. 559177-2875, Textilgatan 43, 120 30 Stockholm, Sweden ("RiseRank", "we", or "us"), is the data controller and is dedicated to serving our customers and contacts to the best of our abilities. Part of this commitment involves the responsible management of personal information collected through the website restauranger.se and any related interactions. Our primary goals in processing this information include:

  • Enhancing the user experience on our platform by understanding customer needs and preferences.
  • Providing timely support and responding to inquiries or service requests.
  • Improving our products and services to meet the evolving demands of our users.
  • Conducting necessary business operations, such as billing and account management.

It is our policy to process personal information with the utmost respect for privacy and security. We adhere to all relevant regulations and guidelines to ensure that the data we handle is protected against unauthorized access, disclosure, alteration, and destruction.

We have a designated Data Protection Officer (DPO). If you have any questions or require further information about how we manage personal information, please contact us at max@riserank.com. Personal information processed under this policy is retained only for as long as necessary for the purposes described below, to comply with legal obligations, or until you withdraw your consent.

2. Scope and application

This policy is designed to protect the personal information of all our stakeholders, including website visitors, registered users, and customers on restauranger.se. Whether you are just browsing the website, using our services as a registered user, or engaging with us as a valued customer, we ensure that your personal data is processed with the highest standards of privacy and security.

3. Data collection and processing

3.1. Types of personal information we process

We collect personal information through various interactions, including when you use restauranger.se to discover restaurants, leave reviews, or book a table, or when you provide information to us directly. The following list details the types of personal information we may process:

  • First and last name
  • Email address and/or phone number
  • Device ID, IP address, browser information and language, operating system and version
  • Real-time location (e.g., GPS) and IP-based approximate location
  • Interaction logs (e.g., clicks, time spent on pages) and browsing history

We only process information that is essential for delivering our services, complying with legal obligations, or enhancing your user experience.

3.2. How we use personal information

The data we collect serves multiple purposes: customizing user experience, authentication and security, content delivery, communication, analytics and performance tracking, marketing and advertising, customer support, fraud prevention and risk management, and research and development.

3.3. Legal basis for processing

We process your personal information on the basis of the following legal grounds under Art. 6 GDPR, depending on the purpose:

  • Performance of a contract (Art. 6(1)(b) GDPR): to provide our services to you, e.g. account management, bookings, and customer support.
  • Legitimate interest (Art. 6(1)(f) GDPR): for analytics, performance tracking, fraud prevention, and improving our services, following a balancing test that ensures your rights do not override our interest.
  • Consent (Art. 6(1)(a) GDPR and the Swedish Electronic Communications Act (LEK), Chapter 6, Section 18): for non-essential cookies, marketing, and targeted advertising. Consent can be withdrawn at any time.
  • Legal obligation (Art. 6(1)(c) GDPR): for matters such as accounting and compliance with statutory requirements.

4. Data storage and protection

4.1. Data storage

  • Personal information is stored on secure servers located in the following countries: the United States and Sweden. As a general rule, account information is retained for as long as you have an active account and thereafter for up to 24 months to address any claims; accounting records are retained for 7 years in accordance with Swedish accounting law; and analytics and marketing data based on consent are retained until consent is withdrawn, but no longer than the retention period specified for the relevant cookie under section 7.3 below.
  • Data hosting partners: We partner with reputable data hosting providers committed to using state-of-the-art security measures.

4.2. Data protection measures

  • Access control: Access to personal information is strictly limited to authorized personnel with a legitimate business need.
  • Security audits and monitoring: Regular security audits are conducted to identify and remediate potential vulnerabilities.

5. Data sharing and disclosure

5.1. Sharing personal information

We may share your information with third-party service providers who perform services on our behalf. These partners are prohibited from using your personal information for any purpose other than to provide these services to RiseRank AB.

Service / ProviderPurpose(s)Collected personal data typesPrivacy policy link
PostHogAnalytics and performance trackingAddress and city, IP address, Device IDposthog.com/privacy
Google Analytics (Google Ireland Limited)Marketing and advertising, analytics and performance trackingEmail (only if logged in), address and city, device ID, IP address, operating system, browser fingerprint, location, browsing historybusiness.safety.google/privacy
Google Fonts (Google Ireland Limited)Customizing user experienceIP address, browser fingerprintbusiness.safety.google/privacy
Google Tag Manager (Google Ireland Limited)Tag managementAggregated data about tag firingbusiness.safety.google/privacy
reCAPTCHA (Google Ireland Limited)Fraud preventionDevice ID, IP address, operating system, browser fingerprintbusiness.safety.google/privacy
Amazon Web Services / CloudFront (AWS EMEA SARL)Cloud computing, content deliveryEmail, address, device ID, IP address, operating systemaws.amazon.com/privacy
Mailchimp (The Rocket Science Group LLC)Marketing and advertisingName, email, device ID, IP addressmailchimp.com/legal/privacy

5.2. Data processing agreements

When we share your data with third-party service providers, we do so under Data Processing Agreements (DPAs) ensuring your information is managed in accordance with the GDPR.

5.3. Transparency and control

You will always be informed of any significant changes to our sharing practices. Please contact us at max@riserank.com with any questions.

6. Your rights and choices

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), to object (Art. 21), and to withdraw consent (Art. 7(3)). You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection, IMY (Art. 77). To exercise any of these rights, please contact us at max@riserank.com. We will respond to your request within the timeframes stipulated by law.

7. Cookies and tracking technologies

7.1. About cookies and tracking technologies

Our use of cookies is based on the Swedish Electronic Communications Act (LEK), Chapter 6, Section 18, the EU ePrivacy Directive, and, where applicable, the GDPR. Cookies are small data files placed on your device that enable us to remember your preferences and collect information about your website usage.

7.2. How we use these technologies

  • Essential cookies: Necessary for the website's functionality. They do not require consent.
  • Performance and analytics cookies: Collect information about how visitors use the website.
  • Functional cookies: Enable enhanced functionality and personalization.
  • Advertising and targeting cookies: Used to deliver relevant advertisements and measure campaign effectiveness.

7.3. Cookies used on restauranger.se

Below are examples of the cookies used on the website. Exact cookie names and retention periods are shown where established; others are shown as estimates pending confirmation.

Provider / categoryExample cookie name(s)PurposeRetention period
PostHog (analytics)ph_*Analytics and performance trackingPlaceholder – typically up to 1 year
Google Analytics (analytics/marketing)_ga, _ga_*Analytics, marketing, and advertisingPlaceholder – typically up to 13 months
Google Fonts (functional)No cookie set when self-hostedFont displayPlaceholder
Google Tag Manager (functional)Does not set its own cookiesTag managementNot applicable
reCAPTCHA (essential/security)_GRECAPTCHAFraud preventionPlaceholder – typically up to 6 months
Amazon CloudFront (essential)PlaceholderContent deliveryPlaceholder
Essential cookies (session/login) (essential)Placeholder, e.g. session_idAuthentication and securityDuration of session or up to 30 days

7.4. Your choices and consent

Upon your first visit, our website will present a cookie consent banner where you can accept all cookies, reject non-essential cookies, or customize your preferences. If you do not make an active choice, only essential cookies are set. No cookie requiring consent is set before you have provided your consent.

You can change or withdraw your consent at any time via the "Cookie Settings" link in the footer or the More menu. Your choice is stored for up to 12 months, after which you will be asked to make a new choice. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

7.5. Changes to our cookie use

We may update our use of cookies to improve our services or comply with legal requirements. We will notify you of any significant changes and seek your consent where necessary.

8. International data transfers

We may transfer your personal information to locations outside the EU/EEA, including to the United States, to the extent we use providers such as Amazon Web Services, Google, and Mailchimp that are established or process data there. Any such transfers are always carried out under a valid transfer mechanism under Chapter V GDPR, primarily the European Commission's Standard Contractual Clauses (SCCs) or, where applicable, reliance on a recipient's certification under the EU-U.S. Data Privacy Framework (DPF). You may request a copy of the safeguards applied by contacting us at max@riserank.com.

9. Direct marketing and communications

We may use your personal information to send direct marketing communications about our products, services, and promotions, in compliance with the GDPR and the ePrivacy Directive. We will obtain your explicit opt-in consent before sending direct marketing where required by law. Every communication includes clear instructions on how to unsubscribe. Direct marketing may be sent via email, push notifications, and in-app messaging. You can manage your preferences via the unsubscribe link in our emails or text messages.

10. Data breach notification procedures

If a data breach is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Art. 33 GDPR. If a data breach poses a high risk to your rights and freedoms, we will notify you without undue delay, in accordance with Art. 34 GDPR, providing clear information about the breach and the steps you can take to protect yourself.

Point of contact: If you have any questions about a data breach, please contact us immediately at max@riserank.com.

11. Policy updates and changes

We may update this policy from time to time to reflect changes in legal requirements, industry standards, or our business operations. For material changes we will notify you via email, website notifications, or other appropriate channels, and indicate the effective date at the top of the document. For material changes requiring your consent under the GDPR, we will seek your explicit opt-in consent before implementing the changes.

12. Contact us

If you have any questions or concerns about this policy, please contact us at max@riserank.com.

RiseRank AB (company registration no. 559177-2875)
Textilgatan 43
120 30 Stockholm, Sweden
www.restauranger.se