Privacy Policy
Last updated: August 2026
1. Controller
Via Gusto Ristorante & Pizzeria
Owner: Eva Frejno
Dechant-Fein-Straße 5
51375 Leverkusen
Telefon: 0214 73458217
E-Mail: info@via-gusto.de
2. Overview of processing activities
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects.
Types of data processed
- Master data (e.g. names, addresses)
- Contact data (e.g. email, telephone numbers)
- Content data (e.g. inputs in forms)
- Usage data (e.g. pages visited, access times)
- Meta/communication data (e.g. IP addresses, device information)
3. Legal bases
The following provides an overview of the legal bases under the GDPR on which we process personal data:
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data (e.g. cookie consent).
- Performance of a contract (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract (e.g. table reservation).
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by us (e.g. operation and security of the website).
4. Hosting
Our website is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When you visit our website, the server automatically records technical access data (server log files), in particular:
- IP address of the requesting computer
- Date and time of the request
- Name and URL of the page accessed
- Volume of data transferred
- Browser type and version, operating system
- Referrer URL
Processing is carried out on the basis of our legitimate interest in the secure and efficient operation of our website (Art. 6(1)(f) GDPR). Vercel is certified under the EU-US Data Privacy Framework.
5. Contact
When you contact us by email or telephone, we process the information you provide where necessary to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in processing the enquiry).
6. Table reservations
For online reservations, we process your details (name, email address, phone number, party size, date/time and optional notes) in our own reservation system in order to confirm and manage your booking. Confirmation and notification emails are sent via Postmark. We retain this data only as long as required for the reservation and any statutory retention obligations. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures).
7. Cookies, statistics and advertising
Technically necessary cookies are required for the operation of the website and are set on the basis of Art. 6(1)(f) GDPR. These include session cookies for the administration area and the cookie in which we store your cookie decision.
All other services are loaded only after you have given your consent. Before your consent, no Google script is loaded and no data is transmitted to Google. The legal basis is your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time with future effect via “Cookie settings” in the footer.
Google Analytics 4
With your consent to the “Statistics” category we use Google Analytics 4 to analyse which pages are visited and how visitors reach our website. This processes usage data such as pages viewed, time on page, device type and approximate region of origin. Google Analytics does not store your IP address permanently. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads conversion tracking
With your consent to the “Advertising” category we measure whether your visit came through a Google ad and whether it led to a reservation or a phone call. Transmitted data includes the identifier of your ad click, the time and which action was triggered — in the case of a reservation also a random transaction number to prevent double counting. The name, email address and phone number from your reservation are not transmitted to Google.
Consent Mode v2
We use Google Consent Mode v2. All consent signals are initially set to “denied”. Only when you agree is the signal updated and the respective service loaded.
Transfer to the USA
With the Google services mentioned, a transfer of personal data to Google LLC in the USA cannot be ruled out. Google LLC is certified under the EU-US Data Privacy Framework, which means an adequacy decision by the European Commission is in place. Further information can be found in Google's privacy policy.
Cookies used
Depending on your selection, the following cookies may be set:
- vg_consent (necessary) — stores your cookie decision, lifetime 6 months.
- _ga and _ga_* (statistics) — distinguishing visitors in Google Analytics, lifetime up to 2 years.
- _gcl_au (advertising) — attributing ad clicks to conversions in Google Ads, lifetime up to 90 days.
8. Fonts
We use the fonts Lora, Playfair Display and Inter. These fonts are hosted locally on our server and are not loaded from external CDNs (such as Google Fonts). There is therefore no data transfer to third parties through the font integration.
9. Google Maps and social media links
The map on our contact page is loaded only after you give your consent. When it loads, your browser transmits technically required data, including your IP address, to Google. Alternatively, you can open the location through an external Google Maps link. Our website also contains links to profiles on Instagram, Facebook, Google and Tripadvisor. The privacy policies of the respective provider apply only when you click a link.
10. Your rights
You have the following rights with regard to your personal data:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
11. Database
For storing our menu and reservation data, we use a PostgreSQL database at Neon (Neon Inc., USA). Personal reservation data is stored only for processing and managing the reservation. Neon is certified under the EU-US Data Privacy Framework.
12. Changes to this privacy policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services. Your next visit will then be subject to the new privacy policy.