Legal
Privacy Policy
Short version: we collect what we need to run your orders and loyalty program, we do not sell your data, and SMS opt-in data is never shared with third parties for marketing purposes.
1. What we collect
- Account info — name, email address, optional phone number.
- Order info — what you ordered, when, where, total, and tip amount.
- Loyalty activity — points earned, NFC taps, QR scans, and check-ins.
- Device & usage data — basic analytics such as page views and errors so we can keep the app working reliably.
- Location — only when you explicitly allow it, to show restaurants near you.
2. What we do not collect
- We do not store full credit card numbers. Payments are processed through Stripe, who holds card data under their own PCI-compliant systems.
- We do not sell your personal data to advertisers. Full stop.
- We do not share SMS opt-in consent or phone numbers with third parties for their own marketing purposes.
3. How we use your data
- To process your orders and route them to the correct restaurant.
- To award and track loyalty points and rewards.
- To send you order updates and — only if you explicitly opt in — marketing messages.
- To improve the product, fix bugs, and monitor performance.
- To detect and prevent fraud and abuse.
4. Who we share it with
- The restaurant you ordered from — your name, order items, and contact information if you chose pickup or delivery, plus your loyalty balance at that restaurant.
- Payment processors (Stripe) — to securely process payment. Stripe is PCI DSS compliant.
- Communication providers (Telnyx for SMS, email providers) — to deliver the messages you signed up for and no others.
- Legal or safety purposes — if required by law, court order, or to protect the safety of users or the public.
5. SMS data & third-party disclosure
See our SMS Terms for full details on what we send, how often, opt-in, opt-out, supported carriers, and message & data rates.
5b. Restaurant owner & ISV data isolation
LoopMenu operates as an Independent Software Vendor (ISV) and sends SMS on behalf of independent restaurant owners to their own opted-in customers. Each restaurant's customer data — including phone numbers, order history, and SMS opt-in status — is strictly isolated to that restaurant's account.
A customer's marketing SMS opt-in for one restaurant does not apply to any other restaurant on the LoopMenu platform. Each opt-in is restaurant-specific and customer-controlled.
6. Your choices
- Access your data — email privacy@loopmenu.app and we will send you a copy of your personal data within 30 days.
- Delete your data — email us and we will close your account and delete personal data, except what we are legally required to retain (such as transaction records for tax purposes).
- Opt out of marketing emails — every marketing email contains an unsubscribe link. You can also update your preferences in your account at any time.
- Opt out of marketing SMS — reply STOP to any LoopMenu SMS, or update your SMS preferences in your account at loopmenu.app.
7. Children
LoopMenu is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has created an account, please email us at support@loopmenu.app and we will delete the account promptly.
8. Security
We use industry-standard encryption in transit (HTTPS/TLS) and at rest (Supabase Postgres with row-level security). Access to personal data is restricted to employees and systems that need it to operate the platform. No system is 100% secure, but we take security seriously and will notify you promptly if a material breach occurs that affects your data.
9. Changes to this policy
We will update this page when our data practices change. The "Last updated" date at the bottom always reflects the current version. For material changes we will notify account holders by email.
10. Contact
Privacy requests: privacy@loopmenu.app
General support: support@loopmenu.app
Last updated June 27, 2026. Questions? Email support@loopmenu.app.