1. Identity of the data controller
The Ma Table Halal website and application are published on a non-professional basis by a private individual, who is the data controller. Contact: hello@matablehalal.com.
2. Data collected
Ma Table Halal is designed to work without account creation, without login, without collecting any name, e-mail, address or phone number. The only data processed is that strictly necessary for the features described below.
2.1 Geographic location
The application asks for permission to access your location in two situations:
- Sorting by distance: your location is read by the application only on your device to sort the list of restaurants from nearest to farthest. This data does not leave the device.
- Search for nearby restaurants: if you use the "add a restaurant" feature and search by proximity, your approximate location is sent to Google Places API (Google LLC) through our server to retrieve the results. It is not stored on our servers beyond the duration of the request.
You can refuse or revoke the location permission at any time in your phone's settings. The application remains functional (browsing, filters, search by name) without geolocation.
2.2 Anonymous device identifier (UUID)
When you vote on the halal nature of a restaurant or add a restaurant to the directory, an anonymous UUID is generated and stored on your device. This identifier is sent to our servers to:
- prevent the same device from voting several times for the same restaurant;
- limit the number of additions per 24 h (anti-spam, up to 5 additions per 24 h window for a non-administrator user).
This UUID is not linked to any personal data (no e-mail, no name, no phone number). If you use neither voting nor restaurant addition, no UUID is generated or transmitted.
2.3 Search queries
When you type text in the search bar to add a restaurant, your query is relayed by our server to Google Places API to retrieve the matching results. The query is not kept on our servers beyond the duration of the response.
2.4 Server logs
- IP address, user-agent, requested URL: kept 30 days for security and technical diagnostic reasons, then automatically purged.
- No advertising cookie or third-party tracking (no Google Analytics, no Meta Pixel).
2.5 Crash and diagnostic reports (Sentry)
If the mobile application crashes, a technical report is sent to Sentry GmbH (hosted in Germany) to allow us to identify and fix bugs. This report contains:
- the error's stack trace;
- the technical context (OS version, device model, app version);
- the actions preceding the crash ("breadcrumbs") in the app, without sensitive text content;
- an anonymous installation identifier generated by Sentry (distinct from the UUID described in 2.2).
We have explicitly disabled the sending of your IP address to Sentry. No personal data (name, e-mail, location) is attached to the report.
2.6 Restaurant data
Restaurant listings come from public sources (Google Places API, halal certification registries such as ACHAHADA and AVS). No personal data of third parties (customers, restaurant employees) is processed.
2.7 Sworn declaration by a restaurant owner
When an owner signs a halal sworn declaration from the mobile application (see article 5 of the Terms of Use), the following information is collected and kept in order to identify the author of the declaration and make it publishable:
- First and last name of the owner (signatory of the declaration);
- E-mail address (for moderation notification and right of withdrawal);
- Company name and SIRET of the operating company (public data from the trade register);
- List of meat suppliers and their certification body (declared).
- Electronic signature (full name typed) and timestamp of the submission.
- Optional certificate file (PDF or image, max 5 MB) attached by the owner.
- Technical audit metadata: IP address, anonymous device identifier (UUID), browser/application user-agent at the time of submission. This metadata is necessary to respond to a judicial request to identify the declarant in case of a report (hosting provider status under the LCEN, art. 6).
The full text of the declaration, together with the owner's identity, the company name, the SIRET, the list of suppliers and any attached certificate, is made public on the corresponding certificate page (URL matablehalal.com/declarations/MTH-…) and shown on the restaurant's listing. The owner is explicitly informed of this and consents to it at the time of signing (checkbox in the application's form).
The technical audit information (IP, UUID, user-agent), on the other hand, is never published: it is accessible only to the publisher, and where applicable to a judicial authority that requests it in accordance with the law.
2.8 Anonymous audience measurement (Plausible)
We use Plausible Analytics, an anonymous audience measurement tool self-hosted on our European infrastructure (Hetzner, European Union). No cookie is set, no data is transferred to a third party, and collection is strictly limited to aggregated statistics. This configuration complies with the consent exemption provided by article 82 of the French Data Protection Act (loi Informatique et Libertés) and by CNIL deliberation no. 2020-091 on strictly anonymous audience measurement.
- Tool and hosting. Plausible Analytics, self-hosted on Hetzner (EU). The script and all the data remain on our infrastructure, without any request to a third-party analytics service.
- Purpose. Aggregated audience measurement of the site: number of page views, traffic sources, breakdown by country, device type, browser, restaurant listings viewed, and MoM / WoW trends.
- Legal basis. Legitimate interest (article 6.1.f of the GDPR), combined with the consent exemption provided by article 82 of the French Data Protection Act (loi Informatique et Libertés) (transposing article 5(3) of the ePrivacy directive 2002/58/EC) and by CNIL deliberation no. 2020-091.
- Data collected. URL of the visited page, referrer, user-agent, country derived from the IP address, and an anonymized daily identifier renewed every day, which does not allow two visits to be linked to the same person.
- No storage on your device. Plausible in its default configuration writes no cookie, uses neither localStorage, nor sessionStorage, nor IndexedDB, and leaves no persistent fingerprint.
- No third-party transfer and IP not retained. All data stays on our EU infrastructure. Your IP address is not kept beyond 24 hours: it is used only to derive the country and is then deleted.
- Right to object. You can refuse this measurement at any time by enabling the "Do Not Track" signal (
navigator.doNotTrack = 1) or "Global Privacy Control" (Sec-GPC: 1). Plausible honors these signals.
For the technical detail of how Plausible works, see their data policy.
3. Legal basis
The processing relies on:
- your consent for geolocation (OS permission), for community contributions (voting, addition) and for the owner's sworn declaration (explicit checkbox before signing);
- the legitimate interest of the publisher for security and technical diagnostics (server logs), as well as for keeping the audit metadata of the sworn declarations (art. 6 LCEN, ability to identify the declarant in case of a report).
4. Recipients (processors and third parties)
Your data is never sold or transferred for commercial purposes. The recipients are:
- The host of the website and API (Hetzner Online GmbH, Germany, deployment orchestrated via Ploi.io), for the technical operation of the service.
- Google LLC (Google Places API): your approximate location and your search queries are sent to it to retrieve the list of nearby restaurants or those matching your search. See Google privacy policy.
- OpenStreetMap Foundation: the map tiles displayed in a restaurant's preview are loaded from its servers (which implies transmitting your IP address to OSM for the duration of the tile loading).
- Sentry GmbH (Germany): receives the crash and technical diagnostic reports of the mobile application (see point 2.5). See Sentry privacy policy.
- Apple Inc. and Google LLC, for distributing the application through their respective stores and the aggregated crash diagnostics (App Store Connect and Play Console Vitals).
5. Retention period
- Server logs: 30 days then automatic purge.
- Device UUID and associated votes/additions: kept as long as you use the application. You can request their deletion at any time via the procedure described on the Delete my data page.
- Approximate location and search queries: not kept on our servers beyond the duration of the request (ephemeral processing).
- Halal sworn declarations and associated data (owner's identity, company name, SIRET, suppliers, attached certificate, signature): kept as long as the declaration is published on the Service, that is throughout the period of operation of the declaring restaurant. The signatory owner can request the withdrawal of their declaration at any time by writing to hello@matablehalal.com from the e-mail address used when signing.
- Audit metadata of a declaration (IP, UUID, signatory's user-agent): kept 5 years from the signature, in accordance with the standard limitation period in civil matters, then purged.
6. Your rights
In accordance with the GDPR and the French Data Protection Act, you have a right of access, rectification, erasure, restriction and objection.
- For the deletion of your data (UUID, votes, associated additions): follow the procedure on the Delete my data page.
- For the other rights (access, rectification, objection): contact hello@matablehalal.com.
You can also lodge a complaint with the CNIL (cnil.fr).
7. Security
Communications between your device and our servers are encrypted (HTTPS / TLS 1.2 minimum). Requests to Google Places API and OpenStreetMap tiles also use HTTPS.
8. Changes
This policy may be updated. The date of last update appears at the top of this page.