Privacy — Marmitons
Last updated 28 September 2026
The principle
Marmitons is the one Nidello app that keeps data about you on a server of ours. It is the members’ app of a gastronomic club, and the club needs to know who is coming to dinner, what they cannot eat and who has paid. So this page is different from the others: it says exactly what that server keeps, who can see it, and how it goes away. It keeps only what the club uses, nothing is sold or shared for advertising, and there are no analytics.
What the club’s server keeps
- your first and last name, your email address, and your phone number if you give one
- your dietary notes — allergies and restrictions. These are health information, and they are declared as such to Apple
- the language you want the club’s emails in, and your role in the club (member, committee, treasurer, administrator)
- your registrations to evenings, the guests you register or invite (their name, and their email if you give it), and where you stand on a waiting list
- whether each registration and your yearly dues are unpaid, paid, waived or refunded, with the method, a note and the date the treasurer entered
- a log of changes to payments, roles and evenings, with who made them and when
What it never keeps
No password: you sign in with a six-digit code sent by email, valid ten minutes. The code, your session token and the links in invitation emails are stored only as a hash — someone reading the database could not use them. No card number or bank detail: the app takes no payment of any kind. No log of requests, no analytics, no crash reporting, no advertising.
Who sees what
- Every member
- The published evenings, how many places are left, and their own registrations, guests, invitations and balance.
- The committee
- The list of members with their contact details and dietary notes, who is registered to each evening with their notes (so the chef can cook for them), and every invitation.
- The treasurer
- What each person owes and has paid, and the history of each payment.
- Nidello
- We run the server for the club. We do not read your data, sell it or use it for anything else; we would only open the database to fix a problem the club asked us to fix.
Where it lives, and who handles it
- Cloudflare
- The server and its database run on Cloudflare’s Workers and D1. Request logging is turned off.
- Resend
- Sends the club’s emails: your sign-in codes, confirmations, reminders and invitations. It receives the recipient’s address and the text of the email, nothing else.
- Your iPhone
- Your session token, in the device’s keychain, never backed up to another device. The latest list of evenings, your profile and your registrations, so the app works without a signal. Signing out erases them.
What it asks permission for
Nothing. The app requests no iOS permission — no location, camera, contacts or health data from the phone.
How it goes away
If the club deactivates your membership, every session you had is closed on the spot. To have your data deleted, ask the club’s administrator, or write to us: we delete it on the club’s request. You can export what the app holds about you, as JSON, from your Profile.
Children
The app is for adult members of a club. It is not directed at children.
Your rights
Quebec’s Law 25 and similar laws give you the right to access, correct and delete the personal information held about you. Most of it you can already read and correct yourself in the Profile tab; for the rest, write to us and we answer.
Changes to this page
If the app ever starts keeping something this page does not describe, this page changes first. The date at the top says when it last did.
Contact
Nidello — Canada — [email protected]