31 de Janeiro

Privacy Policy

Last updated: 2026-09-25

This policy explains how Restaurante 31 de Janeiro, Unipessoal, Lda., which operates the 31 de Janeiro restaurant (Grupo M), processes the personal data of people who visit this website, view our digital menu, make a reservation, join the loyalty programme, subscribe to the newsletter or answer our satisfaction survey.

We process your data in accordance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and applicable Portuguese law.

1. Data controller

Restaurante 31 de Janeiro, Unipessoal, Lda., company no. 502447842, registered office at Rua 31 de Janeiro, 161, 4490-533 Póvoa de Varzim.

For any question about your personal data, or to exercise your rights, please contact us at marketing@grupo-m.pt.

2. What data we collect and why

  • Reservations — name, mobile number and/or email, date, time, party size, any notes you give us and your preferred language. Used to manage your reservation and send you confirmations and change notices by email or SMS. Legal basis: performance of your request (Art. 6(1)(b) GDPR).
  • Guest profile — visit history and, only if you tell us, allergies, preferences or special dates, so we can serve you better and safely. Allergies are health data: we only record them with your explicit consent and use them solely to prepare and serve your meal (Art. 9(2)(a)). If you use the same email or mobile number for reservations and loyalty, we link both records so we know they belong to the same person.
  • Loyalty programme — email, name and, if you provide them, mobile number and date of birth, plus the record of your stamps (date and restaurant). You can sign in with a code sent by email or with your Google or Facebook account; in that case we only receive the name, email and profile picture made available by that service. The programme is shared by the Grupo M restaurants (M'Brasa, 31 de Janeiro and Ostras & Coisas): stamps recorded at any of them are linked to the same account. Legal basis: performance of the programme you joined (Art. 6(1)(b)).
  • Satisfaction survey — your ratings and comments and, if you provide it, your email. Used to improve our service and, where the rating warrants it, to contact you. Legal basis: legitimate interest in improving our service (Art. 6(1)(f)); email is optional.
  • Marketing communications — email and/or mobile number, only when you expressly agree to receive news and promotions (in reservations, loyalty, newsletter or survey). Legal basis: consent (Art. 6(1)(a)), which you can withdraw at any time via the unsubscribe link in each message or by contacting us.
  • Job applications — the data you send through the application form, used only for recruitment.
  • Public Google reviews — we reply to reviews left publicly on each restaurant's Google profile; we only process the public name and review text for that purpose.

3. Cookies and audience measurement

This website keeps its own usage statistics anonymously — without cookies and without storing IP addresses or any personal identifier.

This website does not use third-party advertising or analytics cookies.

We only store in your browser what is needed for the site to work, such as your preferences and, if you sign in to the loyalty programme, that session.

4. Who we share data with

We do not sell personal data. We use service providers that process it only on our behalf and under our instructions (processors):

  • Supabase — database and authentication.
  • Railway — hosting of the websites and applications.
  • Resend — email delivery (reservation confirmations, access codes, surveys).
  • E-goi — SMS delivery and marketing communications.
  • Google — Sign in with Google, management of Google profile reviews and internal spreadsheets.
  • Meta (Facebook) — Facebook login.
  • Telegram — internal staff alerts about new reservations.

5. Transfers outside the European Economic Area

Some of these providers may process data outside the European Economic Area (for example, in the United States). In those cases, the transfer relies on the safeguards provided for in the GDPR, such as the European Commission's standard contractual clauses or the EU-US Data Privacy Framework.

6. How long we keep data

  • Reservations and guest profile — while you are a guest and for as long as needed to meet legal obligations.
  • Loyalty — while you remain a member of the programme; you can ask for deletion at any time.
  • Marketing — until you withdraw consent.
  • Satisfaction surveys — for as long as needed for statistical analysis of our service.

7. Your rights

You have the right to access, rectify and erase your data, to restrict or object to its processing, to data portability and to withdraw consent at any time, without affecting the lawfulness of prior processing. To exercise these rights, contact us at marketing@grupo-m.pt.

You also have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD — www.cnpd.pt).

8. Security

We apply appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS), role- and restaurant-based access restrictions in our management system, and strong authentication for staff.

9. Changes to this policy

We may update this policy to reflect changes in our services or in the law. The date of the last update is shown at the top of this page.