Privacy Policy
Last updated: 27.05.2026
This Privacy Policy describes how Food4connection OÜ (registry code: 16083652, hereinafter — the Company, we) collects, uses, stores and protects the personal data of users of the website fimede.ee. By using the Website, you confirm that you have read this Policy.
1. What Personal Data We Collect
We collect and process personal data only to the extent necessary to provide our services.
When registering and using an account: first name, last name, email, password (stored encrypted with bcrypt), profile photo (when signing in via Google OAuth), phone number, delivery address, delivery district.
When placing an order: full name, phone number, email, delivery address, district, order comment, order details (products, quantities, prices, status).
When placing an order without registration: name, phone number, email, delivery address, district, order details.
Automatically collected data: selected interface language (et/ru/en), data about actions on the website.
2. Purposes of Processing Personal Data
2.1. Performance of a contract — account registration, order processing, communication with the Buyer, delivery, returns. Legal basis: GDPR Art. 6(1)(b) — performance of a contract.
2.2. Notifications — sending email notifications about order status. Legal basis: performance of a contract and legitimate interest.
2.3. Service improvement — analysis of website usage to improve functionality. Legal basis: consent (analytics cookies).
2.4. Compliance with legislation — storage of order data in accordance with Estonian tax legislation. Legal basis: GDPR Art. 6(1)(c) — legal obligation.
3. Cookies
We use the following categories of cookies:
Essential (without consent, based on legitimate interest): userToken — JWT authentication token; NEXT_LOCALE — selected interface language; cookie-consent — your cookie preferences. The shopping cart is stored in your browser's localStorage. The Website cannot function properly without this data.
Analytics (with your consent): anonymous visit and usage statistics that help us improve our service.
You can manage cookies via the banner on your first visit, as well as through the 'Cookie settings' link in the footer. Essential cookies cannot be disabled as the website cannot function without them.
4. Sharing Data with Third Parties
We share personal data only in the following cases:
Google — authentication via Google OAuth (only an identifier is transmitted for sign-in purposes).
SMTP provider — sending email notifications about order status (the recipient's email address and message content are transmitted).
We do NOT sell personal data to third parties. We do NOT use data for advertising. We do NOT transfer data outside the European Economic Area (EEA).
In cases provided for by law, data may be transferred to government authorities of the Republic of Estonia.
5. Data Retention Periods
5.1. Account data — stored while the account is active. Upon account deletion, personal data is permanently removed.
5.2. Order data — stored for 7 years after order fulfilment in accordance with Estonian tax legislation (Raamatupidamise seadus). Upon account deletion, orders are anonymised, but financial data is retained.
5.3. Guest order data — stored for 7 years.
5.4. Cookies — in accordance with the periods specified in Section 3.
6. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR) you have the following rights:
6.1. Right of access — you may request information about what personal data we process.
6.2. Right to rectification — you may correct inaccurate data through your profile settings or by contacting us.
6.3. Right to erasure ('right to be forgotten') — you may request deletion of your account and personal data by contacting info@fimede.ee.
6.4. Right to restriction of processing — you may request restriction of the processing of your data.
6.5. Right to data portability — you may request your data in a machine-readable format.
6.6. Right to withdraw consent — you may withdraw your consent to data processing at any time (e.g. disable analytics cookies).
6.7. Right to lodge a complaint — if you believe your rights have been violated, you may contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).
To exercise your rights, contact: info@fimede.ee. A response will be provided within 30 days.
7. Data Security
We apply the following measures to protect your data:
Password encryption (bcrypt). HTTPS encryption across the entire website. Authentication via secure JWT tokens. Access to data restricted on a need-to-know basis. Regular database backups.
8. Children
The Website is not intended for use by persons under 18 years of age. We do not knowingly collect personal data from children. If you believe a minor has provided us with their data, please contact info@fimede.ee. We will promptly delete such data.
9. Changes to this Policy
We reserve the right to amend this Privacy Policy. We will notify you of significant changes via email or a notice on the Website. By continuing to use the Website after changes, you accept the updated Policy.
The current version of the Policy is always available at: fimede.ee/privacy
10. Contact Information
For any questions related to the processing of personal data: Food4connection OÜ, info@fimede.ee, +372 5829 2007.
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): www.aki.ee
Consumer Protection and Technical Regulatory Authority (TTJA): Endla 10A, 10122 Tallinn, info@ttja.ee
EU Online Dispute Resolution platform: https://ec.europa.eu/odr
