Privacy Policy

Last updated: 12 April 2026

Zeri's Restaurant (“we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy. This policy explains what information we collect, why we collect it, and your rights under the General Data Protection Regulation (GDPR) and applicable Maltese law.

1. Data Controller

The data controller is Zeri's Restaurant, Portomaso Marina, St Julian's, Malta. You can contact us at info@zerisrestaurant.com.

2. Data We Collect

We collect the following personal data when you make a reservation:

  • Full name
  • Email address
  • Phone number
  • Reservation date, time, and party size
  • Any special requests or dietary requirements you provide

We do not collect any data automatically (no cookies, no analytics trackers, no fingerprinting). We use Vercel Speed Insights for anonymous, aggregated performance monitoring — this does not identify individual users.

3. Legal Basis for Processing

We process your reservation data on the basis of contract performance (Article 6(1)(b) GDPR) — processing is necessary to fulfil your reservation request. Where we send a confirmation email, this is part of the same contractual basis.

4. How We Use Your Data

  • To confirm and manage your table reservation
  • To send you a booking confirmation email
  • To contact you if there is a change to your reservation

We do not use your data for marketing without your explicit consent.

5. Data Sharing

We share your data only with the service providers necessary to operate our booking system:

  • Supabase (database hosting, EU data region) — stores reservation records
  • Resend (transactional email) — sends confirmation emails on our behalf

Both processors are bound by data processing agreements and do not use your data for their own purposes. We do not sell or transfer your data to any third party for marketing.

6. Data Retention

Reservation records are retained for up to 12 months from the reservation date, after which they are permanently deleted. You may request earlier deletion at any time (see Section 8).

7. Cookies

This website does not use tracking cookies or third-party advertising cookies. A session cookie may be set for the admin panel; it is essential for security and is deleted when you close your browser. No cookie consent banner is required.

8. Your Rights

Under the GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — ask us to correct inaccurate or incomplete data
  • Erasure — request deletion of your data (“right to be forgotten”)
  • Restriction — ask us to limit how we use your data
  • Portability — receive your data in a machine-readable format
  • Objection — object to processing based on legitimate interests

To exercise any of these rights, email us at info@zerisrestaurant.com. We will respond within 30 days. You also have the right to lodge a complaint with the Office of the Information and Data Protection Commissioner (IDPC) Malta.

9. Changes to This Policy

We may update this policy from time to time. The “Last updated” date at the top of this page will always reflect the most recent version. Continued use of the site after changes constitutes acceptance of the updated policy.

10. Contact

For any privacy-related questions, please contact us at info@zerisrestaurant.com or write to us at Zeri's Restaurant, Portomaso Marina, St Julian's, Malta.