Skip to main content

CakeMarket Privacy Policy (Hungary)

Last updated: July 2026

Disclaimer

This document describes the planned data-processing model for the Hungarian market and requires review by a data-protection specialist before production publication. It does not constitute legal advice.

Country and language

Legal documentation is maintained separately per country; this document applies to the Hungarian market (hu.cakemarket.app). The Hungarian version is the source and governing text, and this English page is its 1:1 courtesy translation. The structure mirrors the Polish source documents 1:1, differing only in country-specific points. The corresponding document for the Polish market is in the Poland section.

Operator details

CakeMarket is not a registered company yet. The controller's final company name, registered address, tax number (adószám) / company registration number and contact details must be completed before production publication.

§ 1. Controller and scope

1.1. The data controller is the current operator of the CakeMarket project indicated in the application or the deployment documents. CakeMarket is not a registered company yet, so the controller's final company name, registered address, tax number (adószám) / company registration number and contact details must be completed before this document is published in production. Data are processed in accordance with the GDPR, Act CXII of 2011 on informational self-determination and freedom of information (Infotv.), Act CVIII of 2001 on electronic commerce services (Ektv.) and applicable sector-specific legislation.

1.2. CakeMarket operates as a marketplace for made-to-order cakes: it handles accounts, requests, offers, orders, messages, online payments via Stripe, notifications, reviews, seller organisations and an admin panel.

§ 2. Data categories

AreaData
Accountfirst and last name, e-mail, phone, role, language, profile photo, password stored as a hash or OAuth provider login data
Guestsserver-issued guest-session identifier and secret token, order tracking token, account attachment data
Organisationsname, address, coordinates, e-mail, phone, tax number (adószám), legal name, invoicing address, Stripe Connect data, pickup locations, delivery and deposit configuration
Optional certificate reviewprivately uploaded food-chain authority document, expiry date, badge level and review notes
Requests and ordersdate, servings, event type, flavour preferences, special requirements, food/allergen information supplied by the Seller, delivery address, reference photos, selected visualisations, statuses, amounts and cancellations
PaymentsStripe PaymentIntent/Transfer identifiers, payment type, amounts, commission, status, refunds; no full card data
CommunicationBuyer–Seller messages, e-mail and in-app notifications
Reviewsratings, comments, linked orders
Technicallogs, IP address, device/browser data, localStorage, service worker, security events, map/address data from Google Places
PurposeGDPR basis
operating accounts and guest sessions and providing the servicesArt. 6(1)(b)
handling requests, offers, orders, messages and transactional notificationsArt. 6(1)(b)
payments, technical escrow, refunds and payouts via StripeArt. 6(1)(b) and (f)
settlements, accounting and tax obligationsArt. 6(1)(c)
administration of Organisations and optional certificate badges, security and abuse preventionArt. 6(1)(f)
reviews, ranking and marketplace improvementArt. 6(1)(f)
AI visualisations and cake-design suggestionsArt. 6(1)(b) or (f), depending on the feature
direct marketing or a newsletter, if launchedArt. 6(1)(a) or (f), in line with electronic-communication rules

§ 4. Data sharing within the marketplace

4.1. Buyers see the Organisation data needed to choose a Seller: name, profile, portfolio photos, rating, any admin-issued badge, pickup locations, delivery range, Offer content, price, Deposit percentage, the proposed image and the Seller's messages. Buyers never receive the uploaded document, its URL or its expiry date. A badge means only that CakeMarket reviewed the submitted document for display; it is not an inspection or guarantee.

4.2. Sellers see the Buyer data needed to prepare an Offer and fulfil an Order: name or guest designation, contact details provided for the order, Request description, date, servings, flavour preferences, special requirements and allergens, reference photos, selected visualisations, the delivery address or the chosen pickup location, message history, payment status and Order status.

4.3. Authorised CakeMarket administrators see user, Organisation, request, offer, order, payment, message, review and optional certificate data to the extent needed to operate the platform, ensure security, moderate content, process refunds, review badge requests and provide support. A private certificate is also available to active administrators of the Organisation, but not to ordinary members or customers.

§ 5. Providers and processors

Provider / categoryData and purposeNotes
Cloudflare Workers / application hostingrequest handling, technical logs, security, CDNapplication hosting and infrastructure
Cloudflare D1 / databaseaccount, guest, Organisation, request, offer, order, payment, message, review and notification datamain production database; SQLite/better-sqlite3 may be used locally
Cloudflare Images / file storageportfolio photos, reference photos, generated or uploaded cake imageswhen configured; smaller files may be stored in the database
Stripe and Stripe Connectpayment data, PaymentIntents, refunds, transfers, Seller onboarding status, data required by Stripe/KYCCakeMarket does not store full card data
Resende-mail address, subject, content and metadata of transactional messagesin production; in development messages may be logged instead of sent
Google OAuthGoogle account identifier, e-mail and login dataonly if the user chooses Google sign-in
Google Places / Mapsaddress queries, geocoding data, coordinates and map previewsfor address autocomplete, delivery distance and maps
AI provider / Gemini and image-generation servicestheme description, preferences, reference photos, Seller notes, generated images and suggestionsfor cake visualisation; do not enter data unnecessary for the design
Számlázz.huOrganisation and invoicing data, CakeMarket platform-fee amount, invoice items and settlement statusused only for CakeMarket's platform-fee invoice issued to the Seller after Order completion; the Seller issues any invoice or receipt for the cake to the Buyer; real-time invoice-data reporting under NAV Online Számla is performed by Számlázz.hu where configured
Legal and tax providersinvoicing data, payments and documents required by lawafter business registration and once settlement handling is implemented

5.1. Data are not sold. Transfers outside the EEA take place only with appropriate safeguards, such as an adequacy decision, the Data Privacy Framework or standard contractual clauses.

§ 6. Retention

DataPeriod
accountfor as long as the account exists, then up to 30 days unless another legal basis applies
guest requestsup to 90 days from the last activity, or until attached to an account/deleted
orders, payments, invoicingfor the period required by tax and accounting law, as a rule 8 years under Act C of 2000 on Accounting
messages and support recordsfor as long as needed to handle the Order, defend claims and keep the marketplace safe
technical logsfor the period necessary for security and diagnostics

§ 7. Data subject rights

7.1. You have the right of access, rectification, erasure, restriction, portability, objection and withdrawal of consent.

7.2. Requests can be submitted through the Service or via the operator's contact details. We respond, as a rule, within one month.

7.3. A complaint may be lodged with the National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11; postal address: 1363 Budapest, Pf. 9.

§ 8. Profiling and automation

8.1. CakeMarket may sort offers by price, ratings and certification level. Sorting helps present offers, but the Buyer chooses the Seller themselves.

8.2. The Service does not make decisions producing legal effects based solely on automated processing within the meaning of Article 22 GDPR.

§ 9. Security

9.1. We apply technical and organisational measures, including HTTPS, data validation, role-based access control, password hashing, session tokens, restricted access to panels and logging of payment and order events.

9.2. Details of cookies and similar technologies are described in the Cookie Policy.