Last updated: September 16, 2026
GDPR Compliant · LOPDGDD (Spain)WEEBEE DESIGN, S.L.
Calle Gremi de Fusters 33, Local 6
07009 Palma de Mallorca, Spain
Email: fabian@hiddin.app
Tax ID: ESB01597624
We collect the following personal data when you use Hiddin:
When you connect your TikTok account to Hiddin, we access the following data via the TikTok Login Kit API:
We do not post content on your behalf. We do not store your TikTok credentials. You can disconnect your TikTok account at any time in Hiddin (Settings → Social Media → TikTok → "Disconnect"); we then revoke the token and delete the stored TikTok data.
When you connect your Instagram Business or Creator account to Hiddin, we access the following data via the Instagram API (Business Login for Instagram):
Hiddin calculates a Hiddin Score (0–100) for each influencer profile, which determines visibility in the restaurant search marketplace. The score is calculated using the following parameters and weightings:
This is an automated individual decision under Article 22 of the GDPR. Influencers with a score below 40 are not shown in the restaurant search. You have the right to request manual review of your score by a Hiddin staff member. Requests are processed within 14 days, and you will receive a detailed explanation of the reasoning. Contact fabian@hiddin.app to request a review.
When you connect a Facebook Page you manage to Hiddin, we access the following data via the Meta Graph API:
What we do NOT do (Instagram and Facebook): We do not post on your behalf, we do not read your DMs, we do not access your contacts, we do not manage ads on your account. We do not sell your data to third parties.
Storage & Refresh: Access tokens are encrypted (AES-256-CBC) and stored only on our EU-hosted backend. Insights are refreshed on demand ("Refresh") and cached on our servers. Tokens can be revoked at any time.
Disconnect: You can disconnect your Instagram account or Facebook Page at any time inside Hiddin (Settings → Social Media → "Disconnect") or via your Facebook Settings → Apps and Websites → Hiddin → Remove. We then permanently delete all Instagram and Facebook data within 30 days, as confirmed by our Data Deletion Callback.
Hiddin uses YouTube API Services. When you connect your YouTube channel to Hiddin (Settings → Social Media → "Connect with YouTube"), you sign in with Google and grant the read-only scope youtube.readonly. We then access the following data via the YouTube Data API:
We do not upload, edit or delete videos, we do not read comments' contents or private data, and we do not post on your behalf. Restaurants only see the aggregated Hiddin Score, never your raw YouTube data.
Google API Services User Data Policy: Hiddin's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. By connecting your YouTube channel you also agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy.
Storage & Refresh: Google access and refresh tokens are encrypted (AES-256-CBC) and stored only on our EU-hosted backend. Channel statistics are refreshed on demand ("Refresh") and cached on our servers for up to 30 days.
Disconnect: You can disconnect your YouTube channel at any time inside Hiddin (Settings → Social Media → YouTube → "Disconnect"); we then revoke the token and delete the stored YouTube data. You can also revoke Hiddin's access in your Google Account security settings.
We share your data only with:
We never sell your personal data to third parties.
Under GDPR and LOPDGDD, you have the right to:
To exercise your rights, contact us at fabian@hiddin.app or use our Data Deletion Request page.
You also have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD): www.aepd.es
We use the following cookies:
You can sign in to Hiddin with an email address and password, with your Apple ID ("Sign in with Apple"), or with your Google account. When you sign in with Apple or Google, we receive your name and email address and an identifier that lets us recognise your account. We never receive a password.
If you choose Apple's "Hide My Email" option, we only receive the relay address Apple generates. The legal basis is Art. 6(1)(b) GDPR (performance of a contract: providing your account). Apple's and Google's own processing is governed by their privacy policies: Apple and Google. You can revoke the connection at any time in your Apple or Google account settings.
Our servers are operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in their Nuremberg data centre. Hetzner processes the data solely on our behalf.
We also use the following service providers. Each receives only the data required for its task:
Where a provider is located outside the EU, transfers are covered by the European Commission's Standard Contractual Clauses. We conclude data processing agreements under Art. 28 GDPR with all providers.
On the explicit instruction of a restaurant, we report individual Google reviews to Google for assessment. For this we process the publicly visible details of the review – its text, star rating, the reviewer's displayed name and the date – together with the reason the restaurant gives us.
This data comes from the publicly accessible business profile, not from accounts we maintain. We keep it only while the report is being processed and delete it afterwards. The legal basis is Art. 6(1)(f) GDPR (the restaurant's legitimate interest in having potentially inadmissible reviews examined). Google alone decides whether a review is removed.
On request we set up and manage advertising campaigns on Meta (Facebook and Instagram) for a restaurant. We process the restaurant's details about the offer, budget and target area, together with its ad account identifier.
Audiences are defined by location, age and interests. We do not transfer guest contacts, email addresses or customer lists to Meta, and we do not build Custom Audiences from your data. Campaign figures (reach, clicks, cost) are retrieved from Meta in aggregate and shown to the restaurant. The legal basis is Art. 6(1)(b) GDPR in relation to the restaurant. Meta is independently responsible for processing within its own systems; see the Meta Privacy Policy.
If you use our app and allow notifications, your device generates a random identifier (push token) which we store in order to alert you to new guest contacts, payouts or messages. Delivery runs through Expo and the systems operated by Apple and Google.
The token is not linked to a person and carries no content. The legal basis is your consent, Art. 6(1)(a) GDPR. You may withdraw it at any time by turning notifications off in your device settings or in the app; we then delete the token.
For any privacy-related questions:
Email: fabian@hiddin.app
Address: WEEBEE DESIGN, S.L., Calle Gremi de Fusters 33, Local 6, 07009 Palma de Mallorca, Spain