The legacy offline version could not be removed safely. Dynamic content was not loaded. Refresh or reopen the page when a network connection is available.
Kokkino OyPrivacy Notice
Public website, B2B software services, and Kokkino Branch account deletion.
Controller
Kokkino Oy, Business ID 3616952-9, is responsible for this website and its public contact channel. You can contact us at admin@kokkino.app.
What we process
For Kokkino Branch we process the Firebase user identifier; linked email, Google or phone authentication details; Branch contact and access state; invitation and company-verification data; Business ID, legal name and selected PRH/YTJ registry facts; restaurant profile, fixed business address and coordinates, schedule, menu, image references and operational settings; Firebase Cloud Messaging and installation identifiers; order and decision activity; and Stripe Connect identifiers and readiness. Orders visible to a Branch can include customer delivery address and precise delivery coordinates, items, addons, amounts, payment state and fulfilment decisions. The Branch app also stores a protected deletion receipt, short-lived session data, wake markers and idempotent order commands on the device. The public website processes only the information needed for the requested page or authenticated deletion flow.
Legal basis
Depending on the context, processing may be necessary to respond to enquiries, take steps before an agreement, perform a contract, meet legal obligations, or protect legitimate business, service, and security interests.
Why we process data
We use information to authenticate the correct business user, verify the invited company, operate the restaurant profile and catalogue, receive and fulfil paid orders, maintain payment and connected-account readiness, deliver security and order notifications, prevent abuse, support users, reconcile transactions, investigate incidents, honour deletion requests and meet contractual, accounting and legal obligations. Device location is not requested by Kokkino Branch; restaurant and customer coordinates are supplied by the backend for business-location and order-fulfilment purposes.
Sharing and service providers
Google and Firebase provide normal and magic-link authentication, Google Sign-In, phone authentication and reCAPTCHA where applicable, Firestore, Realtime Database, Cloud Messaging, Firebase Installations and Cloud Run infrastructure. Apple Push Notification service delivers iOS notification traffic. PRH/YTJ sources support Finnish company verification. Google Address Validation or routing services may process business or delivery coordinates where the platform invokes those functions. Stripe provides Connect Standard onboarding and payment-related services and keeps provider-owned KYC, bank and tax information under its own terms. These processors receive only the data needed for their service. Kokkino Branch source does not include advertising, analytics, camera, device-location or Google Maps functionality.
International transfers
Some Google, Firebase, Apple, Stripe and support infrastructure may process data outside Finland or the EU/EEA. Where international processing occurs, Kokkino relies on the provider agreement and the legally required transfer mechanism and safeguards, such as an adequacy decision or standard contractual clauses. Provider privacy notices contain further details.
Retention and rights
We keep information only for as long as needed for the relevant business purpose, agreement, security need, or legal obligation. You may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to complain to a data protection authority. For privacy questions or requests, contact admin@kokkino.app.
Kokkino Branch deletion request and verification
A Kokkino Branch user can create an authenticated deletion request in the app or at https://kokkino.app/branch/account-deletion. The app supports a linked Google or phone credential and a recently opened email magic-link session. The website offers a Firebase Google popup, an email magic link that returns to the same Branch deletion page, or Firebase Phone Authentication with reCAPTCHA. Phone verification requires explicit consent before an SMS is sent; Google receives and stores the phone number for authentication and spam or abuse prevention across Google services, and carrier charges may apply. Browser authentication persistence is disabled, and the email flow asks the user to re-enter the receiving address instead of storing it across the redirect. The server, not the app or website, enforces the five-minute Firebase auth_time rule and Branch eligibility. The API receives a recent Firebase ID token and a client-generated private receipt, not a UID, email address or phone number typed into the deletion request body. If any web provider flow creates a new Firebase identity instead of matching an existing identity, the page rejects it and attempts best-effort deletion and sign-out; if full cleanup cannot be confirmed, the page reports that limitation rather than guaranteeing removal. The receipt is sent only in a JSON body, never a URL, and the web page keeps it in memory rather than browser storage. The app stores it in platform-protected storage so status and retry remain available after logout.
Kokkino Branch immediate cutoff
Acceptance of a deletion request fixes the request time. Branch access, public catalogue visibility, realtime access and Branch notification targeting are withdrawn immediately, with a maximum access-cutoff objective of 120 seconds. New checkouts are blocked. A legal hold never postpones this cutoff. Active captured or picked-up orders are not cancelled or rewritten to accelerate deletion; the request remains draining or action required until the backend-owned order and payment state is safe.
Kokkino Branch product and identity data
Personal profile and contact data, public location, schedules, operational settings, menu data, active invitation links and Branch-owned company-verification copies are removed or disconnected from the active product within 30 days of request acceptance, except for a specifically documented category under a valid legal hold or a minimum legal record identified below. Branch authorization and deletion tombstones retain pseudonymous identifiers, policy/version and disposition evidence for the stated three-year request-record period. Firebase Auth is deleted only after a final check proves the identity is Branch-exclusive. If the same Firebase identity also belongs to a Customer, Courier or Admin actor, Branch access and Branch-owned links are removed while the global identity remains for the surviving actor. An unverified identity fails closed and is not globally deleted.
Kokkino Branch workflow, logs, support and backups
Detailed allowlisted deletion-request events are scheduled for purge 30 days after completion. A minimal pseudonymised receipt and tombstone proving the request, result, retained categories and policy version are scheduled for purge three years after completion unless a legal hold applies. The approved minimisation schedule sets 30 days for operational logs, 180 days for narrowly defined security logs, 12 months after closure for a minimal deletion-support case and a maximum 35-day backup roll-off target. The application source records request deadlines and bounded purge operations; cloud log buckets, support systems, backup lifecycle and the production scheduler are separate operational controls that must be verified before those targets are represented as technically completed. Restores must re-apply deletion tombstones so access cannot revive. These periods are policy limits, not claims that law requires each exact duration.
Orders, payments, accounting and Stripe
Orders, payments, vouchers and accounting material are removed from active Branch product views when no longer operationally needed, but the deletion workflow does not rewrite historical orders merely to erase customer address, coordinates, item, payment or decision facts while a documented fulfilment, dispute, fraud, accounting or legal need continues. Access is restricted and each retained category remains governed by its retention rule. Under the approved Finnish accounting classification, vouchers, correspondence and other accounting material are retained for at least six years, while financial statements, ledgers and lists are retained for at least ten years, calculated from the applicable annual closing points. This does not justify retaining the full Branch profile. Stripe Connect Standard and Stripe-owned records remain subject to the provider relationship; Kokkino blocks further Branch updates, unlinks local selectors after reconciliation and retains only references required by the applicable order or accounting record. Kokkino does not promise deletion of a merchant Stripe account through this workflow.
Device storage, notifications and diagnostics
The Branch app stores a bounded session snapshot, wake marker, pending email-link address, idempotent order commands and the protected deletion receipt. After an accepted deletion request it stops realtime and keepalive activity, cancels Branch notifications, clears the session snapshot, wake marker, pending email address and user-bound order commands, deletes the Firebase Messaging device token and logs out; the protected receipt is deliberately preserved for status and retry. Firebase, Google Sign-In, Messaging and Installations SDKs may process user or device identifiers, usage information and diagnostics for authentication, delivery, reliability, abuse prevention and security as described in their privacy disclosures. Kokkino does not use those SDK declarations to enable advertising or cross-app tracking in Branch.
Ephemeral tracking and legal holds
Terminal-order realtime tracking is eligible for the existing cleanup process three hours after terminal closure. A legal hold may pause only the data category it covers and must be documented; it cannot preserve Branch access, public visibility, notification targeting, unnecessary contact data, or the ability to create new orders. Completion means each category has been deleted, anonymised, unlinked, or retained under the rule stated here; it does not mean that every byte held by every provider is erased.
Kokkino Asiakas account deletion
Kokkino Asiakas users can request deletion of their account by contacting Kokkino Oy at admin@kokkino.app. To process the request, include the app name Kokkino Asiakas, the email address used in the app, the phone number used in the app if available, and the request: Account deletion. After the request is verified, Kokkino Oy will delete or anonymize account data that is no longer needed to provide the service. Some records may be retained where required for legal, accounting, payment, fraud prevention, security, or dispute-resolution purposes. This may include order, payment, tax, audit, or operational records for the period required by applicable law. Changing email address or phone number is handled inside the app and is not part of the account deletion request.
Request Kokkino Branch account deletionLast updated 11 August 2026. Project-specific data processing terms may apply to customer projects without reducing the rights described here.