Template. Replace every [bracketed] item and have a lawyer review before you rely on it. This is a starting point, not legal advice.

Privacy Policy

Last updated: [date]

What we collect

How we use it

To show menus, deliver orders to the kitchen, produce billing exports for the course, send order-status texts a member asked for, bill our customers, provide support, and keep the Service secure. We do not sell personal information and we do not use member information for advertising.

Who we share it with

Service providers who host and operate the Service on our behalf: [hosting provider, e.g. Railway] (hosting), Stripe (subscription billing), Twilio (text messages), and [email provider] (email). Each course sees only its own data. We share data with authorities only when legally required.

Text messages

Mobile numbers are used only to send messages about the specific order the member placed. See our text messaging policy.

Retention

Order data is kept for the course for as long as it has an account, and deleted [90] days after the account closes. Courses can ask us to delete specific member data at any time.

Your choices

Members can order without giving a phone number. Anyone can ask to see or delete the personal data we hold about them by emailing [support email]. California residents have additional rights under the CCPA, which we honor.

Security

Data is encrypted in transit (HTTPS). Passwords and PINs are stored hashed. Each course's data is stored separately. Backups are taken nightly and kept for 30 days.

Children

The Service is not directed at children under 13 and we do not knowingly collect their information.

Contact

[Company Name, LLC], [address], [support email]