CakeMarket Privacy Policy (Hungary)
Last updated: July 2026
This document describes the planned data-processing model for the Hungarian market and requires review by a data-protection specialist before production publication. It does not constitute legal advice.
Legal documentation is maintained separately per country; this document applies to the Hungarian market (hu.cakemarket.app). The Hungarian version is the source and governing text, and this English page is its 1:1 courtesy translation. The structure mirrors the Polish source documents 1:1, differing only in country-specific points. The corresponding document for the Polish market is in the Poland section.
CakeMarket is not a registered company yet. The controller's final company name, registered address, tax number (adószám) / company registration number and contact details must be completed before production publication.
§ 1. Controller and scope
1.1. The data controller is the current operator of the CakeMarket project indicated in the application or the deployment documents. CakeMarket is not a registered company yet, so the controller's final company name, registered address, tax number (adószám) / company registration number and contact details must be completed before this document is published in production. Data are processed in accordance with the GDPR, Act CXII of 2011 on informational self-determination and freedom of information (Infotv.), Act CVIII of 2001 on electronic commerce services (Ektv.) and applicable sector-specific legislation.
1.2. CakeMarket operates as a marketplace for made-to-order cakes: it handles accounts, requests, offers, orders, messages, online payments via Stripe, notifications, reviews, seller organisations and an admin panel.
§ 2. Data categories
| Area | Data |
|---|---|
| Account | first and last name, e-mail, phone, role, language, profile photo, password stored as a hash or OAuth provider login data |
| Guests | server-issued guest-session identifier and secret token, order tracking token, account attachment data |
| Organisations | name, address, coordinates, e-mail, phone, tax number (adószám), legal name, invoicing address, Stripe Connect data, pickup locations, delivery and deposit configuration |
| Optional certificate review | privately uploaded food-chain authority document, expiry date, badge level and review notes |
| Requests and orders | date, servings, event type, flavour preferences, special requirements, food/allergen information supplied by the Seller, delivery address, reference photos, selected visualisations, statuses, amounts and cancellations |
| Payments | Stripe PaymentIntent/Transfer identifiers, payment type, amounts, commission, status, refunds; no full card data |
| Communication | Buyer–Seller messages, e-mail and in-app notifications |
| Reviews | ratings, comments, linked orders |
| Technical | logs, IP address, device/browser data, localStorage, service worker, security events, map/address data from Google Places |
§ 3. Purposes and legal bases
| Purpose | GDPR basis |
|---|---|
| operating accounts and guest sessions and providing the services | Art. 6(1)(b) |
| handling requests, offers, orders, messages and transactional notifications | Art. 6(1)(b) |
| payments, technical escrow, refunds and payouts via Stripe | Art. 6(1)(b) and (f) |
| settlements, accounting and tax obligations | Art. 6(1)(c) |
| administration of Organisations and optional certificate badges, security and abuse prevention | Art. 6(1)(f) |
| reviews, ranking and marketplace improvement | Art. 6(1)(f) |
| AI visualisations and cake-design suggestions | Art. 6(1)(b) or (f), depending on the feature |
| direct marketing or a newsletter, if launched | Art. 6(1)(a) or (f), in line with electronic-communication rules |
§ 4. Data sharing within the marketplace
4.1. Buyers see the Organisation data needed to choose a Seller: name, profile, portfolio photos, rating, any admin-issued badge, pickup locations, delivery range, Offer content, price, Deposit percentage, the proposed image and the Seller's messages. Buyers never receive the uploaded document, its URL or its expiry date. A badge means only that CakeMarket reviewed the submitted document for display; it is not an inspection or guarantee.
4.2. Sellers see the Buyer data needed to prepare an Offer and fulfil an Order: name or guest designation, contact details provided for the order, Request description, date, servings, flavour preferences, special requirements and allergens, reference photos, selected visualisations, the delivery address or the chosen pickup location, message history, payment status and Order status.
4.3. Authorised CakeMarket administrators see user, Organisation, request, offer, order, payment, message, review and optional certificate data to the extent needed to operate the platform, ensure security, moderate content, process refunds, review badge requests and provide support. A private certificate is also available to active administrators of the Organisation, but not to ordinary members or customers.
§ 5. Providers and processors
| Provider / category | Data and purpose | Notes |
|---|---|---|
| Cloudflare Workers / application hosting | request handling, technical logs, security, CDN | application hosting and infrastructure |
| Cloudflare D1 / database | account, guest, Organisation, request, offer, order, payment, message, review and notification data | main production database; SQLite/better-sqlite3 may be used locally |
| Cloudflare Images / file storage | portfolio photos, reference photos, generated or uploaded cake images | when configured; smaller files may be stored in the database |
| Stripe and Stripe Connect | payment data, PaymentIntents, refunds, transfers, Seller onboarding status, data required by Stripe/KYC | CakeMarket does not store full card data |
| Resend | e-mail address, subject, content and metadata of transactional messages | in production; in development messages may be logged instead of sent |
| Google OAuth | Google account identifier, e-mail and login data | only if the user chooses Google sign-in |
| Google Places / Maps | address queries, geocoding data, coordinates and map previews | for address autocomplete, delivery distance and maps |
| AI provider / Gemini and image-generation services | theme description, preferences, reference photos, Seller notes, generated images and suggestions | for cake visualisation; do not enter data unnecessary for the design |
| Számlázz.hu | Organisation and invoicing data, CakeMarket platform-fee amount, invoice items and settlement status | used only for CakeMarket's platform-fee invoice issued to the Seller after Order completion; the Seller issues any invoice or receipt for the cake to the Buyer; real-time invoice-data reporting under NAV Online Számla is performed by Számlázz.hu where configured |
| Legal and tax providers | invoicing data, payments and documents required by law | after business registration and once settlement handling is implemented |
5.1. Data are not sold. Transfers outside the EEA take place only with appropriate safeguards, such as an adequacy decision, the Data Privacy Framework or standard contractual clauses.
§ 6. Retention
| Data | Period |
|---|---|
| account | for as long as the account exists, then up to 30 days unless another legal basis applies |
| guest requests | up to 90 days from the last activity, or until attached to an account/deleted |
| orders, payments, invoicing | for the period required by tax and accounting law, as a rule 8 years under Act C of 2000 on Accounting |
| messages and support records | for as long as needed to handle the Order, defend claims and keep the marketplace safe |
| technical logs | for the period necessary for security and diagnostics |
§ 7. Data subject rights
7.1. You have the right of access, rectification, erasure, restriction, portability, objection and withdrawal of consent.
7.2. Requests can be submitted through the Service or via the operator's contact details. We respond, as a rule, within one month.
7.3. A complaint may be lodged with the National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11; postal address: 1363 Budapest, Pf. 9.
§ 8. Profiling and automation
8.1. CakeMarket may sort offers by price, ratings and certification level. Sorting helps present offers, but the Buyer chooses the Seller themselves.
8.2. The Service does not make decisions producing legal effects based solely on automated processing within the meaning of Article 22 GDPR.
§ 9. Security
9.1. We apply technical and organisational measures, including HTTPS, data validation, role-based access control, password hashing, session tokens, restricted access to panels and logging of payment and order events.
9.2. Details of cookies and similar technologies are described in the Cookie Policy.