Privacy Policy
Version 1
Privacy Policy
Status: baseline draft for legal review. This policy describes the data inventory currently represented in PrepOrder code.
Information we collect or generate
We may process account and authentication data (email, verification data, profile details and session security data); restaurant staff and organization data; restaurant, branch, menu and knowledge content; orders and fulfilment details; payment references and provider responses; current or saved locations; search and discovery activity; carts, follows, favorites, preferences and taste signals; notifications and device/browser identifiers; Food Copilot and Concierge conversations; campaign participation and delivery records; analytics and operational events; security, audit and application logs.
Some activity is possible before sign-in. In that case, PrepOrder may use a device identifier. When a person later signs in, selected anonymous activity can be associated with the account.
Why we use it
We use this information to create and secure accounts, show nearby or relevant food, retain carts, accept and fulfil orders, process refunds and settlements, send service messages, detect abuse, provide support, measure and improve the marketplace, personalize recommendations, operate campaigns, and provide Food Copilot and Concierge.
Food Copilot and Concierge
Messages and relevant context may be stored as conversation records and sent to the configured AI provider to generate a response. Do not enter unnecessary sensitive personal information. Structured intent such as a query, category, dietary constraint, price range, party size and coarse geography may be used to produce marketplace demand intelligence.
PrepIQ relationship
PrepOrder produces selected business and marketplace signals, including demand, views, carts, orders, availability, offers, campaigns and structured intent. Signals are designed to use restaurant/item references, counts, time windows, aggregate intent and coarse geography rather than customer names, phone numbers or email addresses. The exact outbound envelope and retention period must be confirmed before this draft is finalized.
Storage, sharing and retention
Data is stored in PrepOrder databases and configured media/logging systems. Payment, email, push, map/geocoding, AI and hosting providers may process data when their features are used. Transaction and financial history may be retained after account deletion. PrepOrder deletes or anonymizes defined account data after the deletion process, while retaining records needed for orders, payments, security, audit, fraud or legal requirements. Exact retention periods and provider locations are [TO CONFIRM].
Your choices and contact
You may manage profile, saved locations, preferences, follows and notification choices in the product, and request account deletion. Some transaction, security, audit and financial records cannot be immediately deleted. Contact [PRIVACY CONTACT / EMAIL] for access, correction, deletion or privacy questions.
The operator identity, legal basis, rights process, retention schedule, children/age rules, transfers and processor list require legal and deployment review before publication.