Privacy Policy

Last updated: August 2026

Protecting your personal data matters to us. This privacy policy explains which personal data we process in connection with our website mrbrunch.ch and our services, for which purposes we do so, and which rights you have. The Swiss Federal Act on Data Protection (FADP) applies.

1. Controller

The controller responsible for data processing within the meaning of the FADP is:

MrBrunch AG, Unterrohrstrasse 3, 8952 Schlieren, Switzerland

Email: info@mrbrunch.ch · Phone: +41 44 244 80 90 · UID: CHE-159.354.843

For any privacy-related requests, you can reach us at info@mrbrunch.ch.

2. Scope and Principles

This privacy policy applies to the use of our website, to orders placed in our online shop and to the further services described here. We process personal data in accordance with the principles of the FADP: lawfully, proportionately, for specified purposes and transparently.

You are not obliged to provide us with personal data. However, without certain information (e.g. delivery and billing address or email address) we cannot fulfil orders or offer certain website features.

A separate, internal privacy notice additionally applies to employees of MrBrunch AG.

3. Customer Account, Registration and Guest Checkout

When you create a customer account, we process the data you provide: email address, name, optionally your phone number, and your password (stored exclusively as an encrypted hash). You can optionally enable two-factor authentication.

When you order without registering (guest checkout), we also create a customer record with the data entered at checkout in order to process the order. No login is created in this case.

In your account we additionally store your order history, saved addresses and your language preference.

4. Orders and Checkout

To process your order we handle:

  • Delivery and billing address (name, company, street, postal code, city, phone, email)
  • Geo-coordinates of the delivery address for delivery planning, determined via the Google Places address search
  • Order contents, delivery date and time slot, number of people, comments, tip
  • Payment status and payment method (payment itself is processed by Stripe, see section 10)

Address details are stored as a snapshot within the order so that receipts and delivery documents remain correct later on. For subscription orders (recurring deliveries) we additionally store the delivery frequency and the next delivery date.

We need this data to perform the contract, for delivery, invoicing and the statutory retention of business records.

5. Vouchers and Greeting Cards

If you order a voucher or greeting card for another person, we process the recipient data you provide (name, email address, personal message) solely to create and deliver the voucher or greeting card.

Please only provide data of persons who agree to this. As the person placing the order, you are responsible for informing the recipient.

6. Quotes, Business Customers and Relationship Management (B2B)

For quote requests we process your contact details (name, email, phone), event details (date, number of people, location, requested services) and any files you upload. We also record whether a quote sent to you has been opened via its personal link so we can track its status.

For business customers we process the company name, billing and contact details, information on contact persons and commercial terms (e.g. collective billing, discounts).

To manage business relationships, we keep internal notes on enquiries, conversations and prospects. These serve customer care and sales.

7. Contact and Callback

If you contact us via a form, by email or by phone, or request a callback, we process your details (name, contact details, content of the enquiry) to respond to your request.

We use Google reCAPTCHA to protect our forms from abuse (see section 16).

8. Newsletter and Marketing Emails

Newsletter

We send our newsletter through our own in-house system. Your data (email address and, where available, name, phone number, company and address details) stays with us. For the technical delivery of the emails we use Amazon SES, a service of Amazon Web Services (AWS), operated in the Zurich, Switzerland data center. You can sign up for the newsletter via the form on the website, during checkout or in your customer account.

We use a double opt-in process for sign-ups: after you register, you receive a confirmation email with a link. We only add you to the mailing list once you click this link. As evidence of your consent, we store the time of your sign-up and confirmation as well as the IP address used.

Our newsletters contain a tracking pixel and individualized links that are redirected via our website. This lets us record whether and when you opened a newsletter and which links you clicked. We use this information to measure the success of our newsletters and to better tailor the content to our recipients' interests. If you do not want this tracking, you can disable the loading of images in your email client or unsubscribe from the newsletter.

You can unsubscribe at any time with one click via the unsubscribe link contained in every email, or in your customer account settings. Unsubscribing takes effect immediately.

We store your data for as long as your subscription is active. After you unsubscribe, if your email address becomes permanently undeliverable or if a complaint is received, we place your email address on an internal suppression list so that you no longer receive newsletters from us.

Reminder and Win-back Emails

If you abandon a checkout or have not ordered for a longer period, we may send you reminder emails, sometimes including voucher codes. We evaluate whether such emails are opened and links are clicked in order to manage sending and measure success.

Each of these emails contains an unsubscribe link. After unsubscribing you will no longer receive marketing emails; order and service messages are not affected.

Attribution

To understand through which channels visitors find us, we store origin information (e.g. referring website, campaign parameters) in your browser's local storage on your first visit and associate it with your customer record when you place an order or register.

9. Cookies, Tracking and Web Analytics

On your first visit, a cookie banner asks for your consent to analytics and advertising cookies. We use technically necessary cookies without consent. You can change or withdraw your choice at any time via the "Cookie Settings" link in the website footer.

Analytics and Advertising Services (only with consent)

With your consent we use the following services. Cookies may be set and data such as your IP address, device information and usage behaviour may be transferred to the providers:

ServiceProviderPurposeCategory
Google Analytics 4Google Ireland Ltd. / Google LLC (USA)Reach and usage analyticsAnalytics
Google Tag ManagerGoogle Ireland Ltd. / Google LLC (USA)Management of tracking servicesTechnical
Google Ads Conversion and RemarketingGoogle Ireland Ltd. / Google LLC (USA)Conversion measurement and advertisingAdvertising
Meta PixelMeta Platforms Ireland Ltd. (Ireland/USA)Conversion measurement and advertising on Facebook/InstagramAdvertising
Meta Conversions APIMeta Platforms Ireland Ltd. (Ireland/USA)Server-side transmission of purchase events for conversion measurement (only with advertising consent)Advertising
LinkedIn Insight TagLinkedIn Ireland Unlimited Company (Ireland/USA)Conversion measurement and advertising on LinkedInAdvertising
HotjarHotjar Ltd. (Malta, part of the Contentsquare group)Usage behaviour analytics (e.g. heatmaps)Analytics

Meta Conversions API (server-side transmission)

If you have consented to the advertising category, we additionally send a server-side purchase event to Meta (Meta Conversions API) when an order is completed. This includes the order value, the ordered products and contact and address data exclusively in hashed form (SHA-256). The event is deduplicated with the Meta Pixel so purchases are not counted twice. Without your consent, no server-side transmission takes place.

Technically Necessary Cookies and Local Storage

  • Login session for your customer account (up to 30 days)
  • Security cookie protecting against cross-site request forgery (24 hours)
  • Language preference (1 year)
  • Short-lived cookie identifying the referring website (30 minutes)
  • Browser local storage: shopping cart, delivery postal code and delivery date, cookie consent, attribution information

Vercel Analytics and Speed Insights

To measure website performance we use Vercel Analytics and Speed Insights (Vercel Inc., USA). These services operate without cookies and without cross-device profiling.

10. Payment Processing

Payments are processed by Stripe (Stripe Payments Europe Ltd., Ireland, and Stripe Inc., USA). Your email address, the order amount and the order items are transferred to Stripe. You enter your card or payment details directly with Stripe; we do not receive or store full card details.

Stripe uses its own fraud prevention checks and processes device and connection data for this purpose. Further information can be found in Stripe's privacy policy.

11. Delivery

For deliveries we use the logistics platform Onfleet (Onfleet Inc., USA). Name, phone number, delivery address including coordinates, delivery notes and the ordered items are transferred to Onfleet so that our delivery team can complete the delivery.

We use the Google Distance Matrix (Google) to calculate delivery distances. If you use the location feature in the address input field, your device coordinates are transferred to the Nominatim map service of the OpenStreetMap Foundation to determine your address.

12. Accounting and Invoicing

We use Bexio (Bexio AG, Switzerland) for accounting and invoicing. Contact and billing data of customers and business customers as well as invoice line items are transferred there.

We retain accounting-relevant records for 10 years in accordance with the statutory requirements of the Swiss Code of Obligations.

13. Communication (Email, WhatsApp, Chat Assistant)

Email

We send transactional emails (e.g. order confirmations, quotes, invoices) via Microsoft 365 (Microsoft Ireland Operations Ltd., EU/USA) and Hostpoint (Hostpoint AG, Switzerland). For troubleshooting we keep a sending log containing the recipient address, sender, subject and time of sending.

These emails contain a tracking pixel and links that are redirected via our website. This lets us record whether and when an email was opened and which links were clicked. We use this solely to check the deliverability and clarity of our order and service messages; it is not used for profiling or advertising. Security-related emails (e.g. password reset, login codes, email address confirmation) and internal staff emails are sent without this measurement. You can prevent the tracking pixel by disabling the loading of images in your email client; click measurement only applies if you click a link in the email.

We delete the sending log after 7 days. For emails with open and click measurement the log entry is kept for up to 365 days, because the original link targets are stored there and nowhere else: without them the links in already delivered emails (e.g. vouchers valid for one year, quotes, invitations) would lead nowhere. The email content is removed from the log after 7 days in every case.

WhatsApp

If you contact us via WhatsApp or receive WhatsApp notifications, we use the WhatsApp Business Platform of Meta Platforms Ireland Ltd. (Ireland/USA). We process your phone number, your WhatsApp profile name and the message contents. We store the conversations in our system to handle your requests and delete them automatically 2 years after the last message.

Chat Assistant

Our website chat assistant is powered by AI services from OpenAI (OpenAI LLC, USA) and OpenRouter (OpenRouter Inc., USA, acting as an intermediary to further AI providers). Your chat messages are transferred to these services to generate responses. We store chat histories together with IP address and browser information and delete them after 90 days. Voice messages are also transferred to OpenAI for transcription. Please do not share sensitive data in the chat.

14. Images, Documents and Uploads

We store images and files (e.g. profile pictures, file attachments to quote requests, application documents) with the media service Cloudinary (Cloudinary Ltd., USA/Israel). Confidential documents are stored with access protection and can only be retrieved via signed, time-limited links.

15. Hosting and Infrastructure

Our website is operated on Vercel Inc. (USA). When you visit the website, connection data (IP address, date and time, page accessed, browser information) is processed in server logs for technical reasons.

  • Database: Prisma Postgres with Prisma Accelerate (Prisma Data Inc., USA/EU) for storing the data described in this policy
  • Upstash Redis (Upstash Inc., USA): short-lived technical keys based on the IP address to limit requests (rate limiting)
  • Cloudflare Inc. (USA): DNS and domain protection

16. Security and Logging

We protect your data with technical and organisational measures, including transport encryption (TLS), role-based access restrictions and two-factor authentication for administrative access.

  • Google reCAPTCHA (Google): protects forms from automated abuse; IP address and device information are transferred to Google
  • Security logs of login events (including IP address and browser information), automatically deleted after 90 days
  • Logs of failed login attempts, automatically deleted after 7 days
  • Rate limiting to prevent abuse (short-lived, IP-based counters)

17. Job Applications

If you apply via our application form, we process your details (personal data, contact details, availability, experience, motivation) and uploaded documents (e.g. CV, identity documents, work permit, bank details) solely to assess your application and to prepare a possible employment. Documents are stored with access protection (see section 14).

On our About page we also embed open positions via a widget from JOIN (JOIN Solutions AG). If you apply via JOIN, their privacy policy additionally applies.

After hiring, a separate internal privacy notice applies to employees, describing all personnel-related processing within the employment relationship.

18. Appointment Booking

For consultation appointments we sometimes link to Calendly (Calendly LLC, USA). Data processing during appointment booking is carried out directly by Calendly in accordance with their privacy policy.

19. Videos

On some pages we embed videos from YouTube (Google) in extended privacy mode (youtube-nocookie.com). When you play a video, data is transferred to Google.

20. Disclosure of Personal Data Abroad

Some of the service providers mentioned process personal data outside Switzerland, in particular in the EU and the USA. The EU and the EEA provide an adequate level of data protection within the meaning of the FADP.

For transfers to the USA, we rely on the Swiss-U.S. Data Privacy Framework where the provider is certified, and otherwise on the standard contractual clauses of the EU Commission (with the adaptations required for Switzerland) as appropriate safeguards within the meaning of Art. 16 para. 2 FADP.

21. Retention and Deletion

We retain personal data only as long as necessary for the stated purposes or as required by statutory retention obligations. In particular:

  • Accounting-relevant records (orders, invoices): 10 years (Swiss Code of Obligations)
  • Security and login logs: 90 days
  • Chat assistant conversation histories: 90 days
  • WhatsApp conversations: 2 years after the last message
  • Email sending logs and logs of failed logins: 7 days
  • Email sending logs with open and click measurement: 365 days, without the email content (which is removed after 7 days)
  • Customer account: until deletion or deactivation of the account
  • Application documents: for the duration of the application process; upon hiring they become part of the personnel file

You can deactivate your customer account yourself in your profile settings or ask us to delete it at info@mrbrunch.ch. Statutory retention obligations remain reserved.

22. Your Rights

Under the FADP you have in particular the following rights:

  • Information on whether and which personal data we process about you (Art. 25 FADP)
  • Correction of inaccurate personal data
  • Deletion of your personal data, unless retention obligations prevent this
  • Delivery of the personal data you provided to us in a common electronic format (Art. 28 FADP)
  • Objection to processing, in particular to marketing communication

To exercise these rights, contact info@mrbrunch.ch. We may request proof of identity to process your request. You may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch).

23. Changes to this Privacy Policy

We may amend this privacy policy at any time, for example when our services or the service providers we use change. The version published on the website applies.