Last updated: 2026-07-11
This Privacy Policy explains how Restomer collects, uses, discloses, retains, and protects personal information when you visit restomer.com, use a restaurant website powered by Restomer, contact us, become a restaurant client, use a restaurant administrator or staff account, or otherwise interact with our platform.
1. About Restomer and our role
Restomer provides hosted restaurant websites, online ordering technology, customer accounts, loyalty and promotion tools, staff and administrator tools, analytics, delivery integrations, domain-management tools, and related support services.
When a customer orders from a restaurant powered by Restomer, the restaurant is generally responsible for the customer relationship and for deciding why and how its customer information is used for restaurant operations. Restomer processes information to provide the platform and services requested by the restaurant. Restomer may also independently process certain information to secure, operate, support, improve, and comply with obligations relating to our own platform.
Each restaurant is responsible for its own customer-facing privacy notice, terms, refund policy, delivery policy, food-safety practices, menu content, prices, taxes, marketing choices, and legal compliance. Restomer's editable templates are starting points only and do not replace the restaurant's own legal review.
2. Information we collect
We may collect the following categories of information:
- Restaurant business information, including legal and trading names, address, contact details, menus, prices, tax settings, operating hours, delivery settings, images, logo files, domain information, analytics identifiers, and policy content
- Restaurant owner, administrator, and staff information, including name, email address, phone number, account credentials, role, login events, device and security information, support communications, and actions performed in the platform
- Customer account and order information, including name, email address, phone number, delivery address, order content, modifiers, special instructions, loyalty activity, promotion redemption, marketing preferences, order history, support communications, and receipt details
- Payment and transaction metadata, such as payment status, payment method type, connected-account identifiers, transaction identifiers, refund identifiers, payout-related references, and the last four digits or card brand where returned by a payment provider
- Delivery and logistics information, including pickup and dropoff details, delivery instructions, delivery quote data, dispatch references, tracking references, and communications necessary to fulfill a delivery
- Technical, usage, and security information, including IP address, browser and device details, operating system, pages viewed, referral information, cookies, local storage, analytics events, error logs, security events, and approximate location derived from an address or device setting
- Information from third parties, including payment providers, delivery providers, domain and DNS providers, authentication providers, analytics providers, and service providers where needed to operate our platform
3. Payment information
Restomer may integrate with Stripe Connect and other payment services. We do not intentionally collect or store full payment-card numbers, CVV or CVC codes, or raw card credentials on our servers. Payment details are collected and processed by the applicable payment provider using its systems.
The payment provider may share status and transaction data with Restomer and the restaurant to facilitate order processing, refunds, fraud prevention, reconciliation, support, and compliance. Payment providers, banks, card networks, and wallets control approval, settlement, payout timing, reserve decisions, disputes, chargebacks, and payment-method availability under their own agreements.
4. How we use information
We use information to:
- Provide, host, configure, and maintain restaurant websites and online ordering services
- Authenticate users, administer accounts, enforce roles and access controls, and protect accounts and infrastructure
- Process restaurant instructions related to menus, orders, customers, loyalty, promotions, delivery, domains, website content, payments, and staff operations
- Send transactional messages, including order confirmations, receipts, order-status updates, password-reset messages, account notices, security notices, and support communications
- Provide delivery quotes, dispatch and track deliveries, and support delivery and pickup operations when the restaurant enables those services
- Provide analytics, reports, dashboards, and operational insights to restaurants
- Detect, investigate, prevent, and respond to fraud, abuse, security incidents, service outages, policy violations, and unlawful activity
- Improve reliability, accessibility, performance, product features, user experience, and documentation
- Meet legal, regulatory, tax, accounting, audit, contractual, insurance, and recordkeeping obligations
- Send Restomer business communications to restaurant clients where consent or another lawful basis permits
5. Marketing preferences
Restaurants using Restomer are responsible for ensuring they have a lawful basis, required notice, and appropriate consent before sending promotional or marketing communications to their customers. Restomer provides communication preferences and unsubscribe-related tooling where configured, but the restaurant remains responsible for its campaign content, audience selection, consent records, and compliance with applicable anti-spam, consumer-protection, and privacy laws.
Restomer may send service-related notices to restaurant clients and users. Marketing messages from Restomer itself will include an unsubscribe mechanism where required by law. Transactional and security messages may still be sent when necessary to provide or protect the service.
6. How we disclose information
We may disclose information to the following recipients when necessary for the purposes described in this policy:
- The applicable restaurant, its authorized owners, administrators, staff, and service providers
- Payment providers, including Stripe and connected-account services, to process payments, refunds, fraud checks, and transaction support
- Delivery, courier, dispatch, logistics, and mapping providers to quote, dispatch, track, and fulfill deliveries
- Hosting, cloud infrastructure, database, email, SMS, analytics, monitoring, logging, security, image-processing, geocoding, authentication, support, domain, and DNS providers
- Professional advisers, insurers, auditors, financing parties, law-enforcement bodies, regulators, courts, and government authorities where required or reasonably necessary
- A purchaser, successor, lender, or adviser in connection with a contemplated or completed merger, acquisition, financing, sale, reorganization, or transfer of all or part of our business, subject to appropriate safeguards where required
We do not sell personal information for money. We may disclose information where we reasonably believe disclosure is necessary to comply with law, enforce agreements, protect rights and safety, prevent fraud, investigate security incidents, or respond to lawful requests.
7. Cookies, analytics, and similar technologies
Restomer and our providers use cookies, local storage, tags, pixels, logs, and similar technologies to operate sessions, remember cart and account state, secure the platform, understand use, measure performance, troubleshoot errors, and improve services. Restaurants may separately enable analytics or advertising tools. Those tools may collect information under the restaurant's instructions and their own provider terms.
You may be able to control certain cookies through your browser or device settings. Disabling required cookies or storage may prevent sign-in, cart, checkout, security, or other core functionality from working correctly.
8. Data retention
We retain information for as long as reasonably necessary to provide the platform, follow restaurant instructions, maintain records, support orders and customer accounts, administer loyalty and promotions, prevent fraud, resolve disputes, comply with legal obligations, and enforce agreements. Retention periods vary by data type, legal requirement, contractual need, and the nature of the service.
When a restaurant relationship ends, we may delete or anonymize restaurant data in accordance with the applicable agreement and our retention practices, except where retention is needed for legal, tax, accounting, security, fraud-prevention, dispute, backup, or operational reasons.
9. Security
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. These measures include access controls, role-based permissions, secure credential practices, logging, monitoring, and use of service providers with appropriate safeguards.
No method of transmission or storage is completely secure. Restaurant owners and staff must protect their own account credentials, restrict staff access, use strong passwords, and promptly notify us of suspected unauthorized access or security concerns.
10. International transfers and processing
Restomer and our service providers may process or store information in Canada, the United States, and other jurisdictions where our providers operate. Information processed outside your jurisdiction may be subject to the laws of that jurisdiction and may be accessible to courts, regulators, law-enforcement agencies, or other authorities under applicable law.
11. Access, correction, deletion, and other rights
Depending on applicable law, individuals may have rights to request access to, correction of, deletion of, or information about personal information. We may need to verify identity and authority before responding. Requests relating to a restaurant customer's order or account should normally be directed to the relevant restaurant first, because the restaurant controls that customer relationship.
Restomer will assist restaurant clients with reasonable requests relating to information processed through the platform, subject to legal restrictions, technical feasibility, contractual terms, and our need to protect other users, security, confidential information, and legal rights.
12. Children
Restomer is not directed to children who are not legally able to enter into a commercial transaction in their jurisdiction. We do not knowingly seek to collect personal information from children without appropriate authorization. If you believe a child has provided personal information to us without authorization, please contact us.
13. Changes to this policy
We may update this policy to reflect changes in our platform, business, technology, legal requirements, or practices. We will post the current version with an updated "Last updated" date. Where required, we will provide additional notice or obtain consent for material changes.
14. Contact us
For questions, concerns, or privacy requests relating to Restomer, contact:
Restomer Support
Email: [email protected]
