Garden-Runner

Privacy Policy

Last updated July 28, 2026. This policy explains how Garden-Runner processes personal data under Regulation (EU) 2016/679 (GDPR) and the Belgian Data Protection Act of 30 July 2018.

1. Data controller

The controller of your personal data is Garden-Runner, , enterprise number —, VAT —.

For all data protection matters you can contact us at privacy@garden-runner.com. We have not appointed a dedicated Data Protection Officer; this address is the contact point for data protection questions and requests.

2. Data we collect and the legal basis

We collect only what we need to run the platform:

  • Account data (name, email, phone, language, role) — necessary for the performance of our contract with you (Art. 6(1)(b) GDPR).
  • Booking data (job address, requested services, notes, scheduling) — performance of the contract (Art. 6(1)(b) GDPR).
  • Gardener business data (company name, VAT number, IBAN, invoicing details) — performance of the contract and compliance with a legal obligation (Art. 6(1)(b) and (c) GDPR).
  • Invoices, payments and accounting records — compliance with a legal obligation (Art. 6(1)(c) GDPR).
  • Technical and security logs — our legitimate interest in keeping the platform available, secure and free from abuse (Art. 6(1)(f) GDPR).
  • Optional analytics or marketing cookies — only with your consent (Art. 6(1)(a) GDPR and the applicable ePrivacy rules).

3. Sharing your data

When you book a job, the details needed to carry it out (name, job address, contact details, service description) are shared with the gardener assigned to that job. Gardeners act as independent controllers for the work they perform and for the invoices they issue.

We also use service providers acting as processors on our instructions: cloud hosting and database services, transactional email delivery, and electronic invoicing and Peppol dispatch. They may only process your data to deliver their service to us, under a written data processing agreement.

We do not sell your personal data, and we do not share it with third parties for their own marketing.

4. International transfers

Your data is primarily processed within the European Economic Area. Where a provider processes data outside the EEA, the transfer is covered by an adequacy decision of the European Commission or by the European Commission's Standard Contractual Clauses together with any additional safeguards required.

5. How long we keep your data

Retention depends on why we hold the data:

  • Invoices, payment records and other financial and accounting records: 10 years, as required by Belgian tax law (FPS Finance).
  • Account and profile data: for as long as your account is active, and deleted or anonymised after closure except where a longer legal retention period applies.
  • Booking history: kept for the period needed to handle disputes, warranty claims and accounting obligations.
  • Technical and security logs: a limited period proportionate to their purpose.
  • Cookie consent records: for the lifetime of the consent record you set in your browser.

6. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on our legitimate interests. Where processing is based on your consent, you can withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Erasure, restriction and objection are subject to the exceptions set out in the GDPR: for example, we must keep invoicing and accounting data for the statutory retention period, and we may need to retain data to establish, exercise or defend legal claims.

You can exercise these rights by writing to privacy@garden-runner.com. Signed-in users can also export or delete their personal data directly from their account page.

7. How quickly we respond

We answer requests without undue delay and in any event within one month of receipt. Where a request is complex, or where we have received a number of requests, that period may be extended by two further months; we will tell you within the first month if that happens and why (Art. 12(3) GDPR).

8. Security

We apply appropriate technical and organisational measures, including encryption in transit, role-based access control, row-level database access rules and logging of administrative actions.

9. Cookies

We use strictly necessary cookies and similar storage by default. Non-essential cookies are only placed with your consent. See our cookie policy for details, and use the "Cookie Settings" link in the footer to change your choice at any time.

10. Complaints

If you believe we handle your data unlawfully, please contact us first at privacy@garden-runner.com so we can try to resolve the matter. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be, www.gegevensbeschermingsautoriteit.be.

Cookie Policy · Legal Notice