Opal Noir Society S.r.l. (“Opal Noir Society,” “we,” “us”), registered in Milan, Italy, is the data controller for the personal data collected and processed in connection with your membership and use of our application.
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003 as amended by Decree 101/2018.
For any privacy-related enquiry or to exercise a right, contact us at info@opalnoirsociety.com.
Identity and contact data. Your full name, email address, telephone number, and optional social media handle — collected during application and account management.
Application and preference data. Your dining preferences, preferred neighbourhoods and atmospheres, cuisine preferences, dining frequency, and occasion types — collected during the application process and updated when you edit your preferences.
Payment data. We receive a secure token from our payment processor, Stripe, that references your saved payment method. We do not receive, store, or process your full card number, CVV, or PIN. Stripe handles raw card data under its own privacy policy and PCI-DSS certification.
Booking and concierge data. Records of each concierge request you submit, including venue preferences, requested date and time, party size, occasion, special notes, and the status of each request. Communications exchanged in your concierge thread.
Account data. Login credentials (stored in hashed form only), membership tier, billing history, and account settings.
Technical data. Device type, operating system version, app version, IP address recorded at registration, and session activity logs — collected automatically when you use our application for security and service operation purposes.
We process your personal data only for specific, lawful purposes. The table below sets out each purpose and its legal basis under GDPR.
| Purpose | Legal basis |
|---|---|
| Processing your application and setting up your membership | Pre-contractual steps at your request — Art. 6(1)(b) GDPR |
| Delivering the concierge service — handling requests, communicating with venues, confirming bookings | Performance of contract — Art. 6(1)(b) GDPR |
| Charging membership fees and managing your subscription | Performance of contract — Art. 6(1)(b) GDPR |
| Sending service communications — booking updates, status changes, billing receipts | Performance of contract — Art. 6(1)(b) GDPR |
| Improving the quality of the service and our venue network, using aggregated usage patterns | Legitimate interests — Art. 6(1)(f) GDPR |
| Maintaining accounting records and complying with Italian tax obligations | Legal obligation — Art. 6(1)(c) GDPR |
| Sending optional editorial content (new venues, seasonal guides) if you have opted in | Consent — Art. 6(1)(a) GDPR |
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects. We do not use your data for advertising or marketing by third parties.
Payments are handled by Stripe Payments Europe, Ltd., a company regulated by the Central Bank of Ireland and authorised as a payment institution throughout the EEA. Stripe’s registered address is 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
When you enter card details during your application, those details pass directly to Stripe over an encrypted connection and are never transmitted to or stored on our servers. Stripe returns a token we use to charge your saved method for recurring membership fees.
Stripe processes your payment data as a data processor acting on our instruction, under a data processing agreement. Stripe may process payment data in the United States; where it does so, it relies on Standard Contractual Clauses approved by the European Commission. Stripe’s own privacy policy is available at stripe.com/privacy.
We retain your personal data only for as long as necessary for the purposes described above. Specific retention periods are:
When the applicable period expires, data is either deleted or irreversibly anonymised.
We do not sell or rent your personal data. We share it only in the following circumstances:
Service providers. We engage a small number of third-party processors to operate the service, including Stripe (payment processing), our transactional email provider, and our cloud infrastructure provider. Each processor is bound by a data processing agreement and is prohibited from using your data for any purpose other than providing the contracted service.
Venue partners. To secure a reservation, we share only the minimum details necessary — typically a first name and surname, party size, requested date and time, and any notes relevant to the booking. We do not disclose your membership tier, email address, telephone number, or any other account information to venues unless you explicitly instruct us to.
Legal and regulatory requirements. We will disclose personal data when required to do so by applicable law, court order, or at the documented request of a competent authority. Where lawful to do so, we will notify you before making such a disclosure.
Business transfers. In the event of a merger, acquisition, or sale of substantially all of our assets, your data may be transferred to a successor entity, subject to that entity honouring this Privacy Policy or providing you with reasonable advance notice of any material change.
As a data subject under GDPR, you hold the following rights. They are not absolute — exceptions apply in limited circumstances — but we will honour them as fully as the law requires.
To exercise any of these rights, write to us at info@opalnoirsociety.com. We will respond within one calendar month. Where a request is complex or numerous, we may extend this period by up to two further months; if so, we will notify you within the first month and explain the reason for the extension.
We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act.
Your personal data is stored on servers located within the European Economic Area. Where we engage processors that transfer data outside the EEA — including Stripe, which may process payment data in the United States — we ensure that such transfers are protected by Standard Contractual Clauses adopted by the European Commission, or another approved transfer mechanism under Article 46 GDPR.
You may request a copy of the relevant transfer safeguards by contacting us at info@opalnoirsociety.com.
The Opal Noir Society mobile application does not use browser cookies. The technical data described in Section 2 is collected solely for security monitoring and service operation — not for behavioural advertising, cross-application tracking, or sale to any third party.
We do not embed third-party advertising SDKs, social media pixels, or cross-app tracking identifiers in our application. We do not share technical or usage data with any advertising platform.
If in future we introduce any analytics tooling beyond basic session logs, we will update this section and notify members in advance.
We may update this Privacy Policy from time to time. We will notify you by email of any material change at least 30 days before it takes effect. The current version of this policy is always available within the application.
If a change affects how we process data in a way that requires your consent, we will seek that consent separately.
If you are not satisfied with our response to a privacy enquiry or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Italian data protection supervisory authority:
Garante per la protezione dei dati personali
Piazza Venezia, 11
00187 Roma, Italy
www.garanteprivacy.it
If you are resident in another EU member state, you may also complain to the supervisory authority of your country of residence.
We would prefer the opportunity to address your concern directly before you refer it to a supervisory authority. Please contact us first at info@opalnoirsociety.com.
Opal Noir Society S.r.l.
Milan, Italy
We do not currently have a designated Data Protection Officer, as we do not meet the thresholds requiring one under Article 37 GDPR. The member of our team responsible for data protection enquiries can be reached at the email address above.