Cookie Policy

MEALZO COOKIE AND SIMILAR TECHNOLOGIES POLICY

Version: 1.0

Publication date: 2026-08-11

Effective date: 2026-08-16

The entity responsible for the use of cookies and similar technologies in Mealzo's services is:

Trading name: Mealzo Store

E-mail: hello@mealzo.store

Website: mealzo.store

This entity is hereinafter referred to as "Mealzo" or "we".

1. Why This Policy Exists

1. This Policy explains how Mealzo uses cookies, browser storage, session identifiers, measurement tools and other similar technologies when you use the website and related digital services.

2. We want users to know:

• which technologies may run on their device;

• what they are needed for;

• which of them are necessary for the service to work;

• which ones we activate only after obtaining consent;

• how to change or withdraw their choice;

• where to check the current list of active technologies.

3. The Policy applies primarily to:

• the mealzo.store website and its language versions;

• the Customer Account panel;

• the Package configurator;

• the registration, login and checkout process;

• the Menu selection, Skip, Pause and address change functions;

• contact forms, complaint forms and Delivery Zone interest lists;

• the web versions of the panels supporting the service, to the extent they use a browser.

4. Mobile applications may use equivalents of cookies, such as application identifiers, local storage, SDKs, session tokens or notification identifiers. The rules described in this Policy apply to them accordingly, and a detailed list of the tools used in the application should be available in its privacy settings.

5. This Policy should be read together with the Mealzo Privacy Policy. The Privacy Policy describes in more detail what personal data we process, for what purposes, to whom we disclose it and what rights users have.

6. The consent management model adopted by Mealzo is intended to take into account Thailand's Personal Data Protection Act B.E. 2562, hereinafter referred to as the "PDPA", as well as the principles of transparency, voluntariness and the ability to withdraw consent. The final Thai version and the manner of implementation should be reviewed before publication by a lawyer practising in Thailand.

2. What Cookies Are

1. A cookie is a small text record placed by a website in the user's browser or on their device.

2. A cookie may allow a website to, among other things:

• maintain a secure login session;

• remember the contents of a purchase process that has been started;

• recognise that the user has accepted or rejected certain categories of technologies;

• remember a language or another setting;

• protect forms and the Account against abuse;

• understand how the site works and where problems occur;

• measure the effectiveness of advertising, if the user has consented to this.

3. Not every cookie identifies a specific person by name. However, a cookie may contain or create an identifier which, when combined with other data, makes it possible to distinguish a device, session or user. For this reason, we treat tracking technologies with due caution and describe them transparently.

3. What We Mean by Similar Technologies

1. In this Policy, the word "technologies" covers not only classic cookies but also:

• localStorage;

• sessionStorage;

• IndexedDB;

• web pixels and tags;

• session and device identifiers;

• authentication tokens;

• mobile application identifiers;

• third-party SDKs;

• device advertising identifiers, where used;

• mechanisms securing forms and APIs;

• similar solutions used to store information on a device or read information from it.

2. LocalStorage and similar mechanisms are not technically cookies, but they can serve a similar function. That is why we include them in the same transparency and consent management system.

3. A given technology is classified according to its actual purpose, not solely by its technical name or provider.

4. First-Party and Third-Party Cookies

1. Mealzo may use its own technologies, set directly by the Mealzo domain. These are called first-party technologies.

2. Some functions may use technologies from external providers, for example a map, login, analytics, payment, chat, video or advertising provider. These are called third-party technologies.

3. A third party may process information in accordance with its own terms and privacy policy. Mealzo should select providers carefully, limit the scope of data shared and conclude the required agreements.

4. The mere fact of placing a link to an external website does not mean that its technologies have been activated on the Mealzo website. However, third-party technologies may run when an embedded map, video, widget, payment or login button is opened.

5. Session and Persistent Cookies

1. Session technologies operate for the duration of the current visit or until the browser is closed. They may be used to maintain a session, protect a form, or guide the user through checkout.

2. Persistent technologies remain on the device for a defined period or until they are deleted. They may be used to remember settings, consent, a preferred language, or to recognise a returning device.

3. The lifetime of each active technology should be shown in the Cookie Settings Centre. We do not use the term "indefinite". Each entry must have a specific validity period or clear information that it operates only during the session.

6. Categories of Technologies Used by Mealzo

Mealzo divides technologies into four main categories. A given technology can be assigned to only one category corresponding to its primary purpose.

6.1. Strictly Necessary Technologies

1. These are needed to enable the basic functions of the site and the secure provision of the service.

2. They may be used in particular to:

• maintain the user's session;

• secure the login process;

• protect against request forgery, automated attacks and abuse;

• retain the data required to complete checkout;

• link an Order to the correct session;

• remember the user's decision regarding cookies;

• ensure load balancing and infrastructure stability;

• enable basic communication with the server;

• perform a function explicitly requested by the user.

3. Necessary technologies are not used to build an advertising profile or to measure advertising.

4. They cannot be disabled in the Settings Centre if their operation is genuinely required. The user can block them in the browser, but parts of the site, the login, the checkout or the Account may then stop working.

5. Before a technology is deemed necessary, Mealzo should verify that without it the given function truly cannot be delivered securely.

6.2. Functionality and Preference Technologies

1. These make it possible to remember additional choices and make using the site more convenient.

2. They may be used to:

• remember the selected language;

• remember accessibility or display settings;

• retain the preferred way of presenting content;

• restore non-essential Account settings;

• activate an additional widget, chat or embedded content;

• remember voluntary preferences that are not necessary for the performance of the contract.

3. Depending on its actual function, a given technology may be necessary to fulfil the user's explicit request or may be optional. If it is not necessary, we activate it only after consent.

4. Disabling this category should not block the purchase of the basic service, but it may mean that some settings will need to be selected again.

6.3. Analytics and Performance Technologies

1. These help us understand how users use the site, which pages are visited, where errors occur and which functions need improvement.

2. They may collect, among other things:

• the number of visits;

• the traffic source;

• the subpages visited;

• the approximate time of use;

• events related to the use of functions;

• information about errors and performance;

• approximate technical data about the device.

3. Mealzo should limit the data collected, shorten retention periods, mask sensitive data and not send form contents, passwords, full addresses, allergy information or payment data to analytics tools.

4. Analytics technologies that are not necessary for security and basic diagnostics are activated only after the user's consent.

5. Refusing consent does not affect the ability to purchase a Package or use the Account.

6.4. Marketing and Advertising Technologies

1. These may be used to measure campaigns, limit ad frequency, build audiences, run remarketing and tailor advertising to previous activity.

2. They may be set by Mealzo or by third parties, such as advertising or social media platforms.

3. Marketing technologies may allow an external provider to recognise a browser or device on other websites and applications as well.

4. We do not activate marketing technologies without prior, freely given consent.

5. Refusing consent does not limit access to Mealzo's basic services. The user may still see Mealzo advertisements elsewhere, but they should not be tailored on the basis of technologies activated by Mealzo without the user's consent.

7. Basis for Using Technologies

1. Strictly necessary technologies may be used to the extent needed to:

• provide the service requested by the user;

• enter into or perform a contract;

• ensure the security of the site, the Account, Orders and payments;

• detect abuse;

• comply with a legal obligation;

• protect the legitimate interests of Mealzo or users, provided these are not overridden by the individual's rights.

2. Optional technologies are activated on the basis of consent, where consent is required for the given method of processing.

3. Consent to cookies is not consent to all other data operations. Each processing purpose must have an appropriate basis described in the Privacy Policy.

4. The user may refuse optional technologies without losing access to Mealzo's basic offering.

5. Withdrawal of consent takes effect going forward. It does not mean the automatic deletion of data that was previously processed lawfully or that must still be retained on another basis.

8. How the Cookie Banner Works

1. During the first visit, as well as after the choice's validity period expires or after a significant change in technologies, Mealzo displays a privacy settings banner.

2. The banner should contain easily accessible options:

• Accept all;

• Reject optional;

• Customise settings.

3. Refusing optional technologies should be as easy as accepting them.

4. No optional categories may be pre-selected.

5. Closing the banner without making a choice does not constitute consent to optional technologies.

6. Not reacting, scrolling the page or continuing to browse is not treated as consent.

7. Before consent is obtained, the site may run only necessary technologies.

8. The user can choose each category separately. Necessary technologies are marked as "always active".

9. The banner and the Settings Centre should be available in the language selected by the user. Mealzo supports th, en, pl, de, fr, ru and zh-CN.

10. The user's manual language choice takes precedence over automatic browser language detection.

9. How Long We Remember Your Choice

1. As a rule, we remember the cookie choice for 12 months, unless the user changes or withdraws it earlier.

2. We will ask for a new choice earlier when:

• we add a new category or a new provider that significantly changes the way of processing;

• we change the purposes of data use;

• the previous consent record has been lost;

• regulations or a risk assessment require it;

• we have a reasonable doubt as to whether the existing choice matches the current configuration.

3. Renewing consent should not consist of automatically ticking the previous options. The user must be able to consciously confirm or change the settings.

4. Evidence of consent given or withdrawn may be retained for the period described in the Privacy Policy, in particular for the duration of the consent and up to 5 years after it ends, if needed to demonstrate compliance or defend against claims.

10. How to Change or Withdraw Consent

1. The user can open the Cookie Settings at any time via the permanent link in the site footer or in the Account settings.

2. Once the Settings Centre is open, it is possible to:

• check the active categories;

• disable or enable optional technologies;

• see the list of specific technologies;

• check the provider, purpose and lifetime;

• save the new choice.

3. Withdrawal of consent should be effective from the moment the settings are saved. Optional scripts should not be run on subsequent page views.

4. Where technically possible, Mealzo deletes its own optional cookies after consent is withdrawn. For third-party technologies, it may also be necessary to delete cookies in the browser settings or use the given provider's tool.

5. Changing consent must not result in the deletion of an active Account, Package or Order.

11. Browser and Device Settings

1. Most browsers allow you to:

• view stored cookies;

• delete selected or all cookies;

• block cookies from specific domains;

• block third-party cookies;

• restrict local storage;

• set automatic data deletion after the browser is closed.

2. Blocking all cookies may cause problems with:

• logging in;

• form protection;

• checkout;

• remembering the language;

• managing the Package;

• saving the cookie decision.

3. Browser settings operate independently of the Mealzo Settings Centre. If the user deletes the cookie that records consent, the banner may appear again.

4. On mobile devices it is also possible to restrict advertising identifiers, cross-app tracking, location and the permissions of individual applications.

12. Language, Session and User Settings

1. Mealzo may save the selected language in order to display the correct version of the content when the site is reopened.

2. If remembering the language is necessary to carry out the user's explicit choice, it may be treated as a necessary function. If it serves only additional personalisation, it should be classified as functional.

3. Login tokens, session identifiers and form security measures are used only for the time needed for the secure use of the Account and the system.

4. Sensitive data, such as a password, full card details, allergy information or a full address, should not be stored in ordinary cookies or in browser storage accessible to scripts without strong justification and appropriate safeguards.

13. Sign-In via Google and Other Providers

1. Mealzo may offer sign-in via Google OAuth or another identity provider.

2. When such an option is selected, the user is taken to the external provider's service, which may use its own cookies or similar technologies.

3. The use of these technologies depends on the provider's settings and policies. Mealzo receives only the scope of data presented to the user during sign-in.

4. The sign-in button should not activate unnecessary marketing technologies before the user decides to use this method.

14. Maps, Location and Delivery Zone Checks

1. Mealzo plans to use a map to indicate the kitchen, the Delivery Zone and the Customer's location.

2. The map provider may use its own technologies to display the map, protect the service, bill requests or measure usage.

3. The map should be configured in a way that keeps data transfers to a minimum. Information about the Meal Plan, allergies, payments or the full Order history should not be sent to the map provider.

4. If displaying the map is not needed for browsing the site, a solution can be used in which the external map loads only after the user clicks or enters the address function.

5. Information about the active map provider, purposes and retention periods must be included in the current Technology Register before the function is launched.

15. Payments

1. When payments are launched, Mealzo may use a redirect, an embedded form or an external payment operator's component.

2. The payment operator may use technologies necessary to:

• authenticate the transaction;

• prevent fraud;

• carry out 3-D Secure or a similar check;

• maintain the continuity of the payment process;

• comply with legal obligations.

3. Technologies necessary to complete the payment chosen by the user may be treated as necessary for that specific action. However, they must not be automatically used for advertising without a separate basis.

4. At present, no planned operator, including PromptPay, Thai QR, a Thai bank, 2C2P, Apple Pay or Google Pay, should be listed in the public Register as active until the integration has actually been implemented and tested.

16. Analytics and Error Monitoring

1. Mealzo may use tools to analyse traffic, measure performance and detect errors.

2. A diagnostic tool used solely for security and immediate failure detection may, to a limited extent, operate as a necessary solution, provided it does not serve advertising or profiling and collects only the data that is required.

3. Extensive user behaviour analytics, session recording, heat maps and identification of returning devices should be treated as optional technologies.

4. Mealzo should not configure tools in a way that allows recording of:

• passwords;

• OTP codes;

• full addresses;

• payment data;

• messages to customer service;

• allergy and health information;

• the contents of fields marked as private.

5. Every analytics tool must be added to the Technology Register before activation.

17. Marketing, Social Media and Embedded Content

1. Advertising pixels, conversion tags, remarketing mechanisms and similar technologies are disabled by default until consent is obtained.

2. Buttons leading to external social media profiles should work like ordinary links, as long as there is no need to embed an active widget.

3. An embedded video, social media post, chat or widget may establish a connection with an external provider. The user should be informed of this, and optional content may be blocked until the appropriate choice is made.

4. Mealzo should not create advertising audiences based on allergy, health or other sensitive data.

5. Marketing consent for e-mail, SMS, LINE or PUSH is a separate matter from consent to marketing cookies. Giving one consent does not automatically mean giving the other.

18. Data Transfers Outside Thailand

1. Some technology providers may process identifiers or technical data outside Thailand.

2. Before activating a provider, Mealzo should check:

• where the data is stored;

• which entities have access to it;

• the purpose and duration of processing;

• whether the provider uses the data for its own purposes;

• what transfer safeguards are available;

• whether the transfer complies with the PDPA.

3. If the transfer requires additional information or consent, the user should receive it before the given technology is activated.

4. Up-to-date information about providers and processing locations should be included in the Technology Register and the Privacy Policy.

19. Security and Data Minimisation

1. Mealzo should use cookies and similar technologies only to the extent needed for clearly defined purposes.

2. In particular, we should:

• use secure cookie attributes such as Secure, HttpOnly and appropriate SameSite, where applicable;

• limit lifetimes;

• avoid unnecessary identifiers;

• not store passwords or full payment data in cookies;

• control third-party provider access;

• scan the site regularly;

• remove unused tags and scripts;

• document every configuration change;

• test whether optional scripts are actually blocked before consent.

3. The cookie Register should be updated with every deployment that changes scripts, integrations, maps, analytics, payments or login functions.

20. Children and Minors

1. Mealzo does not design marketing technologies specifically to profile children.

2. If a minor uses the service with a guardian's consent, cookie settings should be applied with caution, and marketing technologies should not be activated without an appropriate basis.

3. The rules on age and Account use are described in the Mealzo Terms and Conditions. The detailed requirements regarding guardian consent and minors' data should be verified before launching services aimed at children.

21. Current Register of Cookies and Similar Technologies

1. The current Register available in the Cookie Settings Centre is an integral part of this Policy.

2. For each technology, the Register should state at least:

• the technical name;

• the type of technology;

• the domain or application;

• the provider;

• the category;

• the exact purpose;

• the data or identifiers that may be processed;

• the lifetime;

• whether the technology is first-party or third-party;

• whether it is active before consent;

• a link to the provider's policy, where applicable.

3. The Register must be generated on the basis of the actual system configuration, not a generic list of possible tools.

4. If a given technology is not in the Register, it should not be activated in the production environment, except for an unforeseen security function, which will be promptly investigated, documented and appropriately disclosed.

5. Before this Policy is published, a scan must be carried out in at least the following states:

• a logged-out user;

• a user after rejecting the options;

• a user after accepting each category;

• a logged-in user;

• the Package configurator;

• guest checkout;

• checkout of a logged-in Customer;

• Google OAuth;

• the map and address check;

• the contact form;

• the Account panel;

• the mobile application, once released.

6. Until the scan is completed, only necessary and manually verified technologies may run on the site.

22. Changes to the Policy

1. The Policy may be updated when the law, the service's operating model, the list of providers, the way consent is obtained or the technologies used change.

2. Each version should have a number, a publication date and an effective date.

3. A significant change concerning optional technologies may require displaying the banner again and obtaining a new choice.

4. Archived versions should be stored in the system in a way that makes it possible to establish what information applied at the time consent was given.

5. A minor wording correction that does not change the purpose or scope of processing does not have to trigger a new consent request, but it should be recorded in the version history.

23. Contact

Questions about cookies, similar technologies and privacy settings can be sent to:

E-mail: hello@mealzo.store

For matters concerning personal data, the user may also use the channel indicated in the Privacy Policy.