Last updated: 3 July 2026
This Privacy Policy explains how Mise (“we”, “us”) collects, uses, and protects your personal data. It applies to everyone who uses the Mise app.
1. Who we are
Mise is operated by the Mise team, based in Copenhagen, Denmark. For any data-protection matter, contact us at hello@mise.app.
2. Data we collect
When you use Mise, we collect:
- Account: email, display name, role (chef, server, etc.), city, venue type, optional bio and avatar.
- Content: photos of dishes, description text, pickup times, chat messages, ratings and private notes.
- Location: the approximate coordinates you allow the browser to share when posting a meal.
- Technical: IP address, browser, device type, timestamps (kept in server logs for up to 30 days).
- Cookies: a session cookie used for authentication. We do not use tracking or advertising cookies.
3. Why we use your data
We use your data to:
- Run the app: authenticate you, show your meals to nearby users, deliver messages, compute ratings.
- Keep the service safe: detect abuse, enforce our Terms, investigate complaints.
- Communicate with you: sign-in links, product notifications you opt into.
4. Legal basis (GDPR Article 6)
We rely on the contract with you to provide the service you requested (creating an account, posting meals, chatting) and on our legitimate interests to keep the platform secure and free of abuse. Where we ask for something optional (like your location), we rely on your consent, which you can revoke any time in your browser or device settings.
5. Who we share data with
We use these processors to run Mise:
- Supabase (EU, Ireland) — database, authentication, file storage.
- Vercel (EU / Global CDN) — application hosting.
- Resend (US) — sending magic-link and notification emails. Standard Contractual Clauses apply.
- OpenStreetMap — public map tiles. We do not send your identifiable data to them.
We never sell your data to third parties. We never use it to train external AI models.
6. How long we keep it
- Account and profile: while your account is active. Deleted within 30 days of account closure.
- Messages and ratings: kept while both participants have active accounts. Otherwise deleted with the account.
- Server logs: 30 days maximum.
7. Your rights under GDPR
You have the right to:
- Access your data and get a copy.
- Correct anything wrong.
- Delete your account and all associated data (“right to be forgotten”).
- Export your data in a standard format.
- Restrict or object to processing.
- Complain to the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk.
To exercise any of these rights, email us at hello@mise.app. We respond within 30 days.
8. Children
Mise is intended for adults working in hospitality. It is not offered to anyone under 18. If we learn that a minor has created an account, we will delete it.
9. Data breaches
If a personal-data breach occurs and is likely to result in risk to your rights, we will notify Datatilsynet within 72 hours and, when required, notify you directly.
10. Changes to this policy
We will notify you of material changes via email or an in-app banner at least 14 days before they take effect. Continued use after the effective date counts as acceptance.
Governing law: Denmark. Jurisdiction: the courts of Copenhagen.