Template — not legal advice

This page is template text provided with the software. It has not been reviewed by a lawyer and contains placeholders in [brackets]. The platform operator must have it reviewed and completed by qualified counsel before relying on it.

Privacy Policy

Template — last edited [date]

This policy explains what personal data the [Platform name] software processes when you use a Restaurant's website, app or in-restaurant services, and your choices. For guest data, each Restaurant is the controller (it decides why the data is used); [Operator legal name] processes it on the Restaurant's behalf. A Restaurant may publish its own privacy policy, which applies in addition to this one.

1. Data we process

Contact details you give (name, email, phone), delivery addresses, order and reservation history, marketing consent choices, loyalty points, feedback you submit, and technical data such as IP address, device and browser type for security and fraud prevention.

Staff accounts: name, email, role, sign-in sessions (device and time), time-clock records.

2. Why

To take and fulfil your orders and reservations, process payments, send order updates, run loyalty programs you join, send marketing only if you opted in, keep accounts secure, and meet legal and tax record-keeping obligations.

3. Marketing

Marketing messages are sent only with your consent, which is recorded with the time and source. You can withdraw it at any time from your account or with the unsubscribe link.

4. Sharing and subprocessors

We share data with the Restaurant you order from and with the service providers listed below, only as needed to provide the service. We do not sell personal data.

5. Retention

Restaurants choose how long operational data is kept. Order and payment records may be kept (anonymized when you delete your account) for financial and tax obligations. [Specific retention periods to be completed.]

6. Your rights

You can download a copy of your data and delete your account from your account page. You can also ask the Restaurant to export or erase your data; staff can do this for you, including for orders placed without an account. Depending on where you live you may have additional rights (access, correction, objection, complaint to a regulator). [Jurisdiction-specific rights to be completed by counsel.]

7. Security

Passwords are hashed, staff accounts support multi-factor authentication, each restaurant's data is isolated at the database level, and card details are handled only by Stripe. No system is perfectly secure.

8. Contact

Questions about a Restaurant's use of your data: contact the Restaurant. About the Platform: [privacy contact email], [postal address].

Service providers (subprocessors)

Each provider is used only when the operator or restaurant has configured it. Rows marked in yellow are placeholders the operator must complete.

ProviderPurposeDataWhen used
StripeCard payments, payouts to restaurants, in-person terminalsPayment card details (entered directly with Stripe; never stored by us), name, email, amountsWhen a restaurant has connected Stripe
ResendTransactional and (opt-in) marketing emailEmail address, name, message contentWhen email delivery is configured
TwilioSMS order updates, reservation and waitlist messagesPhone number, message contentWhen SMS delivery is configured
Expo (650 Industries)Push notifications to the mobile appDevice push token, notification contentWhen push notifications are enabled
[Hosting provider]Application servers, database, file storage and backupsAll data held by the platformAlways — the operator must name the provider and region here
[Maps / geocoding provider]Turning delivery addresses into map coordinatesDelivery addressOnly if a geocoder (e.g. Mapbox or Google) is configured

Terms