Last updated: 13 August 2026
1. Introduction
This Privacy Policy describes how Smash Burger collects, uses, stores, discloses and protects personal data processed through:
- this website and its public pages;
- reservation, enquiry and contact forms;
- online ordering or booking flows linked from this site, where available;
- messages you send us by email, phone or other channels indicated on the site;
- technical operation, security and maintenance of the website.
This notice should be read together with the Cookie Policy and the Terms of use published on this website.
2. Data controller
The data controller for the processing described in this notice is the venue that publishes this website:
CRIMA SRL
Via Secondo Bini, 7, 48100, Ravenna, RA
VAT / tax ID: IT02438880391
Tax code: 02438880391
Email: info@pandeajo.it
Phone: +390544461097
For questions about privacy, use the contact details above or the Contact page of this website.
3. Technology providers
This website may be built, hosted or operated with the help of technology providers (for example digital tools that publish pages, manage reservations or process orders). Where those providers process guest data on our behalf, they normally act as data processors under our documented instructions. Smash Burger remains the data controller for guest and customer data collected for venue services.
4. Categories of personal data
4.1 Browsing and technical data
When you visit the website we may process:
- IP address and approximate location derived from it;
- date and time of access;
- pages viewed and referring URL;
- browser, device and operating system information;
- language and technical settings;
- security, error and access logs;
- cookie consent preferences and similar technical identifiers.
4.2 Identity and contact data
Depending on the form or service you use, we may process:
- first and last name;
- email address;
- telephone number;
- postal address or delivery details, when needed for an order;
- company or event details you choose to provide;
- message content and preferences you submit.
4.3 Reservation, order and service data
We may process information needed to manage your request, such as date and time, number of guests, table or service preferences, order items, notes, payment status where applicable, and related communications (confirmations, reminders or updates).
5. Purposes and legal bases
We process personal data for the following purposes:
- Provide the website and keep it secure — legitimate interest in operating a reliable public site and preventing abuse;
- Manage reservations, orders and enquiries — performance of a contract or pre-contractual steps you request;
- Send service communications related to your booking or order — contract performance and legitimate interest in informing you of changes;
- Comply with legal and accounting obligations — legal obligation;
- Improve content and guest experience, including aggregated statistics — legitimate interest, or consent where required (for example non-essential cookies);
- Marketing communications only where permitted by law and, where required, with your consent — you may withdraw consent at any time.
6. How we collect data
Data may be collected:
- directly from you when you fill in forms or contact us;
- automatically through technical logs and cookies, as described in the Cookie Policy;
- from technology providers that process the request on our behalf (for example a booking or ordering tool).
7. Recipients and sharing
Personal data may be shared only with:
- authorised staff of Smash Burger;
- service providers acting as processors (hosting, website publishing, reservation or order platforms, messaging, payment providers where used);
- professional advisers and authorities when required by law or to protect our rights.
We do not sell personal data. We do not use guest data to build unrelated advertising profiles on our own behalf without a valid legal basis.
8. Retention
We retain personal data only as long as needed for the purposes above, including:
- browsing logs and security data for a limited technical period;
- reservation and order data for the time needed to manage the service and meet legal or accounting retention duties;
- enquiry messages for the time needed to reply and follow up;
- consent records for cookies or marketing for as long as needed to demonstrate compliance.
When retention ends, data are deleted, anonymised or archived as required by law.
9. International transfers
If a provider stores or accesses data outside your country, we take steps required by applicable law (for example appropriate contractual safeguards) so that your data remain protected.
10. Your rights
Subject to applicable law, you may request:
- access to your personal data;
- rectification of inaccurate data;
- erasure;
- restriction of processing;
- data portability;
- objection to processing based on legitimate interest;
- withdrawal of consent where processing is based on consent.
To exercise your rights, contact us at info@pandeajo.it. You may also lodge a complaint with your local supervisory authority.
11. Updates
We may update this Privacy Policy to reflect legal, technical or organisational changes. The “Last updated” date at the top of this page will be revised when material changes are published. Please review this page periodically.
Review this template with your counsel and adapt it to your venue before publishing.