Skip to main content
Data Protection

Privacy Policy

Effective Date: March 23, 2026.
Protecting your personal data in the digital age.

1. Introduction & Data Processor Status

CafeOS operates as a technology and infrastructure provider for independent restaurants. When you place an order with a partner restaurant using the CafeOS framework, CafeOS acts as a Data Processor, while the restaurant you order from acts as the Data Controller.

We do not sell, rent, or lease your personal data (including phone numbers, emails, or ordering histories) to third-party data brokers, marketers, or advertisers.

2. Information We Collect

To process your digital orders and maintain your loyalty profile, we collect the necessary transactional information:

  • Contact Information: Name, email address, and phone number (for SMS order completion statuses).
  • Order Data: Dietary preferences, cart history, and favorite menu items.
  • Device & Session Data: IP Address, browser type, and active tokens (such as our core cafeos_session cookie) necessary for keeping you logged in.

3. Payment Processing Integrity (PCI Compliance)

CafeOS is committed to strict financial security. We do not store your raw credit card numbers, CVV codes, or bank information on our servers. All payments are securely tokenized and processed directly by our PCI-DSS Level 1 compliant partner, Stripe. CafeOS only stores encrypted reference tokens to verify that your transaction with the restaurant was completed successfully.

4. Children’s Online Privacy Protection Act (COPPA)

CafeOS and its partner restaurant platforms are not intended for use by anyone under the age of 18. We do not knowingly collect, maintain, or process personal data from children under 13 under any circumstances, nor do we knowingly collect data from minors under 18 without explicit parental verification. If you believe we have inadvertently collected data on a minor, please contact us immediately to purge the records.

5. California Consumer Privacy Act (CCPA) Rights

If you are a resident of California or a state with equivalent data privacy mandates, you possess the legal right to request the deletion of your personal data ("Right to be Forgotten") or request a manifest of the data we hold ("Right to Access").

Because CafeOS acts as a Data Processor, any requests to entirely delete your profile must be routed through the specific restaurant you purchased from, or you can invoke a platform-wide deletion request by contacting us directly.

6. Secure Communications & Retention

Data transmitted between your browser and CafeOS APIs is encrypted using modern TLS (Transport Layer Security) protocols. We retain your profile data only for as long as necessary to provide the services or comply with our legal obligations.

7. Contact Information

To execute a data deletion request or address privacy concerns, please contact the Data Protection Officer at: privacy@cafeos.co.

CafeOS© 2026 CafeOS Inclusive Technologies