RestaurantStockholm.com
Last updated: 12 September 2026
Review draft — not ready for publication. This text reflects the website settings reviewed on 12 September 2026. Items marked [TO CONFIRM] require the operator’s input or a completed technical check. In particular, the controller’s identity, retention periods, service-provider arrangements and consent controls are not yet verified. This draft does not certify compliance or promise that tracking is currently blocked before consent.
RestaurantStockholm.com publishes restaurant guides and food-related editorial content about Stockholm.
The controller responsible for the personal information described here is [TO CONFIRM: full legal name of the individual or organisation operating the website, and contact address]. The website uses the name Restaurant Stockholm. You can contact us at info@restaurantstockholm.com.
We receive the information you send us, such as your name, email address, enquiry subject, message and any optional website or page link.
Where comments are available, we receive the comment, name and email address, together with IP address and browser user-agent information used for moderation and spam checks. Published comments can display your chosen name and comment text. Where subscriptions are offered, Jetpack is configured to send new-post and comment notifications to subscribers. This involves your email address and subscription preferences. No subscriber numbers or sending history have been assumed.
Website delivery, security and measurement can also involve IP addresses, browser and device information, timestamps, referring pages, pages visited and interaction data. [TO CONFIRM: exact log fields and analytics events.]
We use information to respond to enquiries and correction requests, manage relevant business correspondence, moderate comments, provide subscriptions you request, deliver website content, investigate technical problems and protect the website from abuse. Analytics helps us understand readership and improve our guides and website.
The proposed legal bases are explained in section 9.
Our contact form uses WPForms Lite. It asks for your name, email address, subject and message, with an optional URL. The form includes a required checkbox permitting us to use the submitted information to respond. This does not subscribe you to marketing.
Notifications are addressed to info@restaurantstockholm.com. WPForms Lite entry backups are switched off; this does not mean that email copies, server records or other backups do not exist.
Name, email, subject, message and permission to respond are required to submit the form; the website URL is optional. The permission checkbox is not preselected. Please include only information relevant to your enquiry.
WPForms modern anti-spam protection is enabled. This form does not use its Akismet integration or a third-party CAPTCHA. WPForms Lite does not save ordinary enquiry entries to the WordPress entries database, and its optional cloud entry backups are off. Email copies and hosting records may remain. [TO CONFIRM: email provider, mail logs and other backup arrangements.]
Google Analytics is connected through Site Kit, with enhanced measurement and conversion tracking enabled. Google Tag Manager is also deployed, and Jetpack Stats is configured. These services can process information about page visits, devices and interactions. Tag Manager manages tags; the information processed depends on the tags it loads.
[TO CONFIRM: Tag Manager’s full tag inventory; actual guest tracking, events and identifiers; Google advertising features; retention; and consent-dependent behaviour.] We have not verified that all optional measurement waits for consent.
Cookies and similar technologies can support website functions, remember preferences and measure usage. Where comment-cookie opt-in is offered, choosing it can allow the browser to remember details for future comments.
CookieYes is installed, but its current cookie inventory, categories, durations, banner settings, prior blocking and withdrawal controls require verification. Site Kit’s consent-mode setting is currently off; this alone does not establish how other consent controls operate.
[TO CONFIRM: cookie table and a working link to change choices.] Nonessential cookies require prior consent under applicable rules. Browser settings can also remove cookies, although some functions may be affected.
Existing WordPress disclosures retained for verification: the previous draft describes comment-detail cookies lasting one year; a browser-session login test cookie; login cookies lasting two days or two weeks with “Remember Me”; display-preference cookies lasting one year; and an article-edit cookie lasting one day. These concern the relevant comment or authorised-user functions, not a requirement to register to read guides. [TO CONFIRM: these default durations against the current configuration before publication.]
We use Google translation through GTranslate. Automatic switching to the browser language is enabled, so contacting Google is not necessarily limited to a manual language choice.
Some images and website resources load from Automattic’s Jetpack content-delivery network, and some images load directly from Unsplash. These requests disclose technical connection information to the relevant provider.
Where comment avatars are displayed through Gravatar, a hash derived from the commenter’s email address may be sent to that service to check for a profile image. An approved comment can show that image publicly. A hash should not be treated as proof that the data is anonymous. [TO CONFIRM: public avatar behaviour.]
Restaurant, booking and directions links lead to external websites with their own privacy practices. These links are distinct from embedded maps or videos; none were observed on the sampled pages. If embedded third-party content is present on another page, its provider may receive technical data, use cookies and associate interactions with an account you hold there. [TO CONFIRM: complete embed inventory and consent handling.]
Our hosting and security systems support website operation, fault investigation and protection against abuse. Jetpack brute-force protection, availability monitoring and Akismet anti-spam are configured. Login attempts and comments may therefore involve security or spam checks. The contact form uses WPForms’ own modern anti-spam protection; its Akismet integration is off.
[TO CONFIRM: hosting provider, security-log fields, recipients, access restrictions and retention.]
[TO CONFIRM: the operator must approve the purpose-specific bases and document any legitimate-interest assessments before publication.]
The proposed approach is:
The contact-form checkbox should not be presented as consent for unrelated uses. [TO CONFIRM: align its wording with the chosen basis for responding to enquiries.]
We should retain identifiable information only for as long as its purpose requires, subject to applicable legal obligations. The following schedule needs completion before publication:
No fixed deletion period has yet been verified. The earlier draft says comments and their metadata are retained indefinitely to recognise follow-up comments. This statement has been preserved here for review rather than assumed obsolete: [TO CONFIRM: whether indefinite retention is current, necessary and appropriate, or replace with the verified practice.]
For authorised WordPress accounts, profile information can be accessed and edited by the user and website administrators; usernames have editing restrictions. The previous draft also says a password-reset email includes the requester’s IP address. [TO CONFIRM: current account and password-reset behaviour.] Public account registration is currently disabled. If images are supplied for publication, avoid unnecessary embedded location metadata: visitors may be able to extract metadata retained in published images. [TO CONFIRM: media-metadata handling.]
Relevant providers include Google for analytics, tag delivery and translation; Automattic for Jetpack features and potentially Gravatar; Akismet for configured spam protection; and Unsplash for externally hosted images. Hosting and email delivery also require providers whose identities need confirmation.
[TO CONFIRM: contracting entities, each provider’s role, processing agreements and any additional Tag Manager recipients.] Provider information is available from Google, Automattic and Unsplash.
AdSense setup is incomplete despite a script being present. [TO CONFIRM: any actual advertising processing before adding advertising disclosures.]
Some providers operate internationally, and personal information may be transferred or made accessible outside the EU/EEA. European hosting alone does not rule out overseas access.
[TO CONFIRM: recipients, relevant destinations and the transfer mechanism for each arrangement.] Where applicable, explain the relevant adequacy decision or safeguards, such as standard contractual clauses, and how a copy can be obtained. Do not assume a provider’s participation in an adequacy framework without checking it.
Depending on the circumstances, you can request access to your information, correction, erasure, restriction, or a portable copy. You can object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting the lawfulness of earlier processing.
These rights have conditions and exceptions. In particular, not every erasure or portability request applies to every record.
Email info@restaurantstockholm.com, explain your request and identify the information concerned. We may request proportionate information to confirm your identity where necessary.
For account or comment data, you may request an export or erasure, subject to records that must lawfully be retained. Requests are normally answered within one month. Where a permitted extension is necessary because of complexity or the number of requests, we will explain it within that first month. Requests are normally free of charge.
You can complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), or another competent supervisory authority. See IMY’s complaint information.
You are welcome to contact us, but doing so first is not a condition of making a complaint to IMY.
We will update this policy when our practices or relevant requirements change and revise the date above. Where required, we will provide additional information about a material change before using information for a new purpose.
Restaurant Stockholm — RestaurantStockholm.com
Email: info@restaurantstockholm.com
Controller and postal/contact address: [TO CONFIRM: verified legal identity and address].