Privacy policy
This page says what happens to your data when you use marumi.restaurant. It covers the forms, the cookies, the tracking scripts and the frames the site embeds from other companies.
Data controller
The company below runs the restaurant and this website, and decides what happens to the data described here. For anything about your own data, write to the e-mail address listed for data requests.
- Company
- YOKI WARSAW sp. z o.o.
- Registered address
- ul. Franciszkańska 3/35, 00-233 Warszawa
- NIP tax ID
- 5252966213
- E-mail for data requests
- kontakt@marumi.restaurant
- Phone
- +48 602 500 999
- Website
- marumi.restaurant
- Restaurant address
- Krucza 50, 00-025 Warszawa
Forms on the site
Three forms send data to us. Each one asks only for what we need to answer you, and the server checks those fields before it accepts a submission.
Table reservation /reservations
Handling your reservation and confirming the table with you.
Event enquiry /events
Preparing an offer for your event and agreeing the details.
Special offer /special
Sending you the offer and the terms that come with it.
Leave the optional fields empty and the form still goes through. Nothing you type into these forms is written to a database, because the site does not have one.
Where a submission goes
The server sends every submission to two places at once. One copy arrives as a message in the restaurant team chat on Telegram, through the Telegram Bot API. The other arrives as e-mail in the restaurant mailbox, sent over SMTP from our own domain. Your address goes into the Reply-To header of that e-mail, so staff can answer you straight from the mailbox. There is no database behind any of this. Your submission lives in that chat and that mailbox, and nowhere else.
Tracking scripts
Three scripts can run here. None of them is fetched before you answer the banner, and until then none of their cookies exists. Two switches govern them, and they work separately. Analytics turns on Google Tag Manager and Ringostat. Marketing turns on Meta Pixel. Accept all allows both, Essential only leaves all three scripts off, and Customize lets you allow one purpose and refuse the other before you press Save choices.
Google Tag Manager, container GTM-MX7B8M9Q Analytics
A tool for managing other tags. No tag is configured in the container, so it collects nothing. Your choices reach Google as consent signals, so a tag added later has to obey them.
Meta Pixel, id 1439761464862854 Marketing
Measuring how our advertising performs, and remarketing.
Ringostat, call tracking Analytics
The script from script.ringostat.com swaps the phone number shown on the site, so an incoming call can be matched to the traffic source it came from.
The container holds no tags today and Google Analytics 4 is not connected to it. The consent signals go out anyway, so that a tag added later obeys them. Before Google Tag Manager loads, the site sets a default that denies ad_storage, ad_user_data, ad_personalization and analytics_storage, and allows only functionality_storage and security_storage. Your answer to the banner then sends the matching update. This is basic consent mode, so the script itself stays behind the Analytics switch and no request goes to Google Tag Manager before you answer, not even a cookieless ping. Add a tag to the container and we update this page to say what it does.
Embedded frames
Two pages embed a frame served by another company, and both load before you answer the banner. They are how those pages work, so no consent gate sits in front of them. Each company sets its own cookies inside its own frame.
Google Maps on /contact
Showing where the restaurant is. The frame comes from www.google.com/maps and carries the referrerpolicy attribute set to no-referrer-when-downgrade.
TheFork booking widget on /reservations
Booking a table inside the widget. TheFork is a separate data controller. A booking made in that frame goes to TheFork, and the TheFork privacy policy governs it.
Hosting
Vercel Inc. hosts the site. The server function that receives the forms is pinned to the fra1 region, which is Frankfurt, inside the EEA. Vercel handles request logs as our processor. Beyond those logs there is nothing to store, because the site has no database.
Legal bases
| Purpose | Legal basis |
|---|---|
| Handling form submissions: table reservations, event enquiries and the special offer. | Art. 6(1)(b) GDPR. Steps taken before a contract, and performing it. |
| Analytics and marketing, consented to separately. Google Tag Manager and Ringostat sit behind Analytics, Meta Pixel behind Marketing, along with the cookies each one sets. | Art. 6(1)(a) GDPR. Your consent. |
| Server logs, security and keeping the site running. | Art. 6(1)(f) GDPR. Our legitimate interest. |
| Establishing claims and defending against them. | Art. 6(1)(f) GDPR. Our legitimate interest. |
Who else sees your data
These companies can see part of it, each in the role named below. What they then do with it is set out in their own policies.
| Company | Role | Policy |
|---|---|---|
| Google Ireland Ltd. / Google LLC | Google Tag Manager, and the embedded Google Maps frame. | Privacy policy |
| Meta Platforms Ireland Ltd. | Meta Pixel. Advertising measurement and remarketing. | Privacy policy |
| Ringostat | Call tracking, and the swapped phone number. | Privacy policy |
| Telegram Messenger Inc. | Delivery of form submissions to the team chat. | Privacy policy |
| Vercel Inc. | Site hosting, server functions and request logs. | Privacy policy |
| TheFork | The table booking widget. A separate data controller. | Privacy policy |
Transfers outside the EEA
Google, Meta and Telegram are United States companies. Each one states that it relies on the standard contractual clauses and on the EU-US Data Privacy Framework. That is the statement of the provider, not a guarantee from us. Our own server function stays in Frankfurt, so that part of the processing stays inside the EEA.
How long we keep it
- Form submissions. They live in the team chat on Telegram and in the restaurant mailbox. We keep them no longer than handling your request takes, and after that only within the limitation period for claims. The exact period is [[ SUBMISSION RETENTION PERIOD — TO BE FILLED IN ]].
- Cookies. Each one lasts as long as the table above says. You can change your consent decision whenever you want.
- Server logs. Vercel keeps them briefly and its log rotation cycles them out.
Your rights
The GDPR gives you these rights over the data described on this page.
- Access
- Ask what data about you we hold, and get a copy of it.
- Rectification
- If something about you is wrong or missing, have it corrected.
- Erasure
- Ask us to delete your data. We will, unless we still have grounds to hold it, either a duty under the law or a claim we have to establish or defend.
- Restriction of processing
- Ask us to keep your data on file and stop using it.
- Portability
- Ask for the data you gave us in a machine-readable file, or have us send it on to someone else.
- Objection
- Object to any processing we base on our legitimate interest.
- Withdrawal of consent
- Withdraw your consent to the tracking scripts at any time, one purpose or both. What ran before that stays lawful.
To use any of these rights, write to kontakt@marumi.restaurant. Say which right you mean and what it concerns, and we will take it from there.
You can also complain to the supervisory authority. In Poland that is the Prezes Urzędu Ochrony Danych Osobowych (UODO), the Polish data protection authority, at ul. Stawki 2, 00-193 Warszawa.
Withdrawing consent
Your answer to the banner sits in one cookie and nowhere else. You can change it whenever you want, and the two purposes move independently, so keeping Analytics while dropping Marketing is a valid answer.
- The footer carries a Cookie settings button. It reopens the banner straight on the two switches, so you can change either purpose on its own and save the choice.
- Delete this site's cookies in your browser. Your answer is held only in the marumi-consent cookie, so once it is gone the banner comes back and you can switch on just the purpose you want.
- Turn a purpose off and the page reloads. A third-party script that has already loaded cannot be taken back out of memory, and neither Meta Pixel nor Ringostat knows anything about consent mode, so the reload is what actually stops them. Cookie blocking and tracking protection in your browser work independently of the banner, and each vendor policy linked above describes that company's own opt-out.
Children
This site is not meant for anyone under 16. We do not knowingly collect data about them, and nothing here is aimed at children.
Automated decisions
We make no automated decision about you that carries legal consequences, and no profiling feeds one. The only profiling is the advertising measurement through Meta Pixel and the call tracking through Ringostat, both described above, and neither one runs until you allow the purpose it sits behind.
Changes to this page
When what the site does changes, the text here changes with it. A tag added to the Google Tag Manager container, another form, another embedded widget, and we rewrite this page to match. The date at the top tells you when that last happened.