Privacy policy
This page describes what the platform actually collects and stores today. It is written from the software, not from a template, and it is pending review by our lawyers.
What we collect
There are three ways personal data reaches us.
- Onboarding enquiries. When a restaurant asks us to set it up, we collect the restaurant name, a contact name, an email address, and optionally a phone number, a city and a current website address.
- Messages to a restaurant. A restaurant’s site can carry a contact form. What that form collects — typically a name, an email address and the message text — is stored for that restaurant to read.
- Orders. Placing an order records the customer’s name, phone number, the delivery address where delivery is offered, the items ordered and the amounts, and any note left for the kitchen. Order history is kept so the restaurant and the customer can look an order up.
Restaurant staff also have login accounts, which carry the name and email address the account was created with.
Analytics
This marketing site may load a single cookie-less analytics script. When it does, the script’s source address is visible in the page source of every page — there is nothing hidden. It records page views and referring links so we can tell whether this site is doing its job. It does not record your name, your email address or anything you type. When a build of this site is not configured with an analytics provider, no third-party script is loaded at all and no third-party origin is permitted by the page’s content-security policy.
Where it is stored, and who else sees it
Data is held in a PostgreSQL database; uploaded images are held in object storage.
- Clerk handles operator and staff authentication, so it holds the login identity for those accounts.
- Twilio is used to send SMS order notifications and phone verification, so a customer’s phone number and the message text pass through it.
- Resend is used to deliver transactional email, such as forwarding a contact-form message to the restaurant.
A restaurant sees the data belonging to its own orders and its own contact messages, and nothing from any other restaurant. We access data to operate and support the platform. We do not sell it.
Export and deletion
To ask for a copy of the data we hold about you, or to ask us to delete it, email hello@restaurantweb-staging.com from the address the data is associated with, or tell us the order the request concerns. We handle these requests manually — there is no self-service export button yet — and we will tell you what we hold before we act on a deletion. Where a restaurant asked us to hold the data, we will pass the request on to that restaurant and act with them.
How long we keep it
Order records are retained while the restaurant’s account is open, because the restaurant needs its own trading history. We have not yet implemented an automatic deletion schedule, and we are not going to claim one on this page until we have. If that matters to you, ask us and we will tell you exactly what exists for your records.
Contact
Privacy questions: hello@restaurantweb-staging.com.