Privacy Policy

Last updated 2026-10-01. This explains what personal data we collect when you use this website or the Chère mobile apps, and why — in line with the EU General Data Protection Regulation (GDPR) and Malta's Data Protection Act (Cap. 586).

Who controls your data

Chère (VAT registration number MT18080822), Malta, is the data controller for the personal data described in this policy. Questions about your data, or to exercise any of the rights below, can be sent to info@cheremalta.com.

What we collect

When you place an order (as a guest or with an account), we collect your name, email address, phone number, and delivery/pickup details. If you create an account, we also store your login email and a securely hashed password — we never store your password in plain text. If you use the Chère mobile app and allow notifications, we store a device push token (see "Push notifications" below). If you contact us directly, we keep a record of that correspondence to help resolve your query.

Legal basis for processing

We only process your personal data where we have a lawful basis to do so under GDPR Article 6:

Contract — processing your name, contact details, and order information to take, confirm, and fulfil an order request is necessary to perform our contract with you (or to take steps at your request before entering one).

Consent — marketing emails and push notifications are only ever sent if you've actively opted in, and you can withdraw that consent at any time (see below).

Legal obligation — we keep certain order and transaction records because Maltese tax and accounting law requires it.

Legitimate interests — for example, keeping basic records of correspondence to handle your enquiries, and taking reasonable steps to prevent fraudulent orders. Where we rely on legitimate interests, we've considered that this doesn't override your own rights and freedoms.

Marketing emails

If you tick the "email me about sales and new stock" box at checkout, when creating an account, sign up in our website footer, or scan one of our in-store "Coming soon" QR codes and leave your details, we'll add your email address (and phone number, if you gave one) to our marketing list and occasionally email you — including, before launch, a one-off email letting you know the online shop has opened. This is entirely optional and off by default — we never add you without your consent. Every marketing email includes a one-click unsubscribe link that doesn't require logging in, and if you have an account you can also turn this on or off any time from your account page. If you signed up without an account and haven't received an email yet, you can also unsubscribe directly, any time, from this page — just enter the email address you signed up with.

Push notifications

If you install a Chère mobile app and allow notifications when prompted, we store a device push token — a unique identifier for your device, not linked to your name unless you're also logged into that device — so we can send you order updates and occasional announcements (like the marketing emails above). Sending these notifications is handled by Google Firebase Cloud Messaging (Android) or Apple's push notification service (iOS) — see "International data transfers" below. You can stop receiving notifications at any time by disabling them in your device's notification settings, or by uninstalling the app, which removes the token from use.

Cookies and local storage

This site uses one strictly necessary cookie to keep you signed in (for staff/owner accounts and customer accounts) — no advertising or analytics cookies or trackers are used. Items you add to your cart before checking out are stored only in your own browser (using local storage), not on our servers, until you actually submit an order. Because these are strictly necessary for the site to function, we don't need to ask for cookie consent for them.

Who we share your data with

We don't sell your personal data. We share it only where necessary to run this business:

Stripe — our payment processor, used to securely take payment when you check out. Stripe receives your name, email, and payment details directly (we never see or store your full card details ourselves); see Stripe's own privacy policy for how they handle it.

Resend — our email provider, used to send transactional emails (like order confirmations) and, if you've opted in, marketing emails.

Google Firebase Cloud Messaging and Apple's push notification service — used to deliver push notifications to the Android and iOS apps respectively, for customers who've enabled them.

Railway — our hosting provider, which stores our database and runs this website and its backend.

We may also share your data with a courier to deliver your order, or where we're required to by law (for example, a lawful request from a Maltese or EU authority). As our service grows — for example if we add new couriers, payment tools, or analytics — we'll update this list and this policy accordingly.

International data transfers

Some of the providers listed above are based outside the European Economic Area (EEA), principally in the United States. Where that's the case, we rely on the safeguards those providers make available for this purpose — such as the EU Standard Contractual Clauses or, where applicable, certification under the EU-U.S. Data Privacy Framework — to ensure your data continues to receive a level of protection consistent with the GDPR.

How long we keep it

We keep order and account records for as long as needed to provide our service, resolve any disputes, and meet our accounting, tax, and other legal obligations under Maltese and EU law, after which we delete or anonymise it. You can ask us to delete your account and associated personal data at any time, subject to what we're legally required to retain.

Children

This site isn't directed at children, and in line with Malta's digital age of consent, we don't knowingly collect personal data from anyone under 13 without appropriate consent. If you believe a child has provided us with personal data without the right consent, please contact us and we'll delete it.

Data Protection Officer

Given the size and nature of our business, we're not legally required to appoint a Data Protection Officer, and haven't appointed one. Any question about how we handle your data can be sent to the contact details in this policy.

Your rights, and self-service tools

Under GDPR, you have the right to ask us to: give you access to your personal data; correct it if it's inaccurate; delete it; restrict how we use it; object to our use of it; and receive a copy of it in a portable format. Where we rely on your consent (marketing emails, push notifications), you can withdraw it at any time, free of charge.

If you have an account, you can do most of this yourself from your account page: download a copy of everything we hold about you, change your marketing preference, or permanently delete your account (this removes your name, email, and phone number and signs you out everywhere; your past orders are kept for accounting records but are no longer linked to any personal details of yours). You can also contact us directly to exercise any of these rights, and we'll respond within one month as required by GDPR.

If you're not satisfied with our response, you have the right to complain to Malta's supervisory authority:

Office of the Information and Data Protection Commissioner (IDPC)
Floor 2, Airways House, Triq Il-Kbira, Tas-Sliema SLM 1549, Malta
Phone: +356 2328 7100 · Email: idpc.info@idpc.org.mt · Website: idpc.org.mt

Changes to this policy

We may update this policy from time to time, for example as our service grows or the law changes; the current version is always the one published on this page, with the date it was last updated shown at the top.

Contact

Questions about this policy? Get in touch.