Privacy Policy
What we collect, why, who it is shared with, and how to get a copy of it or have it deleted.
EZ Orders · Last updated
1. What this covers
This policy covers EZ Orders - our marketing site, the ordering pages we host for restaurants, the order status pages, and the dashboards restaurants use. It does not cover a restaurant's own website, its social accounts, or anything it does with your details outside our service.
2. Who is responsible for your data
Two different answers, depending on which data you mean.
| Data | Who decides what happens to it | Our role |
|---|---|---|
| Your order, phone number, name, and messaging consent at a restaurant | That restaurant | We process it on their instructions |
| Your account with us, our billing records, security logs, and aggregate platform statistics | Us | We decide |
If you want a restaurant to forget you, ask the restaurant - it is their list, and we will help them do it. If you want us to delete your platform account, ask us.
The customer list belongs to the restaurant. We do not sell it, rent it, share it with other restaurants on the platform, or use it to market anything of our own to you.
3. What we collect
- Order details - items, notes, totals, pickup or delivery time, and the restaurant you ordered from.
- Contact details - your phone number always, because that is how an order update reaches you; your name and email if you give them.
- Messaging consent - whether you agreed to marketing texts, the exact wording you were shown, and the time you agreed. We keep this because consent has to be provable, and it is the record that protects you as much as us.
- Payment status - whether a charge succeeded, the amount, and the last four digits and brand of the card. We never receive or store your full card number; Stripe handles the card itself.
- Account details - if you sign in with Google or Apple, the name, email address and stable identifier those providers return. We never receive your password with them.
- Usage analytics - pages viewed on a restaurant's ordering page, how long a visit lasted, and whether it ended in an order. See section 5.
- Support messages - anything you send us through the contact form or a support ticket.
- Technical data - IP address, browser and device type, and timestamps, kept for security and fraud prevention.
We do not collect precise device location, and we never sell personal information. If you ordered from a restaurant, nothing about you is shared for advertising: there are no third-party trackers on any restaurant's ordering page, and there is no setting anywhere that turns them on. The one exception applies only to visitors of our own marketing site, where we advertise to restaurant owners - see section 6.
4. Why we use it
| Purpose | Data used | Basis |
|---|---|---|
| Taking and fulfilling your order | Order, contact, payment status | Performance of a contract |
| Order updates by text | Phone number, order | Performance of a contract |
| Marketing texts from a restaurant | Phone number, consent record | Your consent, which you can withdraw |
| Fraud prevention and platform security | Technical data, order patterns | Our legitimate interests |
| Improving the product and reporting to restaurants | Usage analytics, aggregated | Our legitimate interests |
| Tax, accounting and dispute records | Order and payment records | Legal obligation |
5. Analytics, and what we deliberately do not do
We measure how restaurant ordering pages are used so owners can see which items get looked at and where people give up. Three limits are built into how this works, not just promised here:
- 1.The identifier used to group a visit is random, generated in your browser, different for every restaurant, and never joined to your customer record. It tells a restaurant that one person visited four times rather than four people visited once, and nothing else. It is not a fingerprint and we do not attempt device fingerprinting.
- 2.Analytics events carry a fixed set of typed fields. There is no free-form field, deliberately, so a phone number or an order note cannot end up in an analytics table and from there into every backup.
- 3.Restaurants see their own numbers. We see platform totals and per-restaurant summaries. No restaurant can see another restaurant's data.
7. How long we keep it
| Data | Kept for |
|---|---|
| Order and payment records | 7 years, for tax and dispute purposes |
| Messaging consent and opt-out records | As long as the number is on the list, then 4 years after opt-out - an opt-out record has to outlive the consent it revokes, or the number gets re-added |
| Analytics visits and events | 13 months, then deleted |
| Support tickets and contact messages | 3 years |
| Security and access logs | 12 months |
| Your account | Until you delete it, then 30 days |
8. Your rights
Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to some uses, or ask us not to sell or share it. We never sell it. The only sharing we do for advertising is on our own marketing site, and you can switch that off yourself from the Cookie choices link in the footer without emailing anyone.
Email hello@ezorders.shop and say which restaurant you ordered from. We answer within 45 days, usually much sooner, and we will not treat you differently for asking. If you ask us to delete data a restaurant controls, we pass the request to them and confirm when it is done.
If you are in the EU or UK: our legal bases are in section 4, you may lodge a complaint with your supervisory authority, and where data is transferred outside your region we rely on Standard Contractual Clauses.
9. Children
The service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has given us information, email hello@ezorders.shop and we will delete it.
10. Security
Data is encrypted in transit and at rest. Passwords are stored hashed, never in a recoverable form. Access to production data is limited to staff who need it and is logged. Each restaurant's data is separated at the query layer so one cannot read another's.
No system is perfect. If you find a vulnerability, email hello@ezorders.shop rather than disclosing it publicly, and we will not pursue you for a good-faith report.
11. Changes
We update this page when what we do changes. The date at the top changes with it. Material changes get notice through the service before they take effect.
Questions about this policy? Email hello@ezorders.shop or use the contact form. See all policies at /legal.