Privacy Policy
Short version: we collect what we need to run your orders and loyalty, we don't sell your data, and SMS opt-in data is never shared with third parties for marketing.
1. What we collect
- Account info — name, email, optional phone number.
- Order info — what you ordered, when, where, total, tip.
- Loyalty activity — points earned, NFC taps, QR scans, check-ins.
- Device + usage — basic analytics (page views, errors) so we can keep the app working.
- Location — only when you allow it, to show restaurants near you.
2. What we don't collect
- We don't store full credit card numbers. Payments go through Stripe, who keeps the card on file.
- We don't sell your personal data to advertisers. Full stop.
3. How we use it
- To process your orders and route them to the restaurant.
- To award and track loyalty points.
- To send you order updates and (only if you opt in) marketing messages.
- To improve the product and fix bugs.
- To prevent fraud and abuse.
4. Who we share it with
- The restaurant you ordered from — your name, items, contact info if you choose pickup/delivery, and loyalty balance at that restaurant.
- Payment processors (Stripe) — to take payment.
- Communication providers (e.g., SMS via Twilio, push, email) — to deliver the messages you signed up for.
- Legal/safety — if required by law or to protect users.
5. SMS data & third parties (mobile carrier required disclosure)
See our SMS Terms for full details on what we send, how often, opt-in, opt-out, supported carriers, and message & data rates.
6. Your choices
- See it — email privacy@loopmenu.app and we'll send you a copy of your data.
- Delete it — email us and we'll close your account and delete personal data, except what we're required to keep (e.g., transaction records for taxes).
- Opt out of marketing — every marketing message has an unsubscribe link, or update preferences in your account.
- Opt out of SMS — reply STOP to any LoopMenu SMS, or update SMS preferences in your account.
7. Children
LoopMenu isn't directed at children under 13. If you think a child has signed up, email us and we'll delete the account.
8. Security
We use industry standard encryption in transit (HTTPS) and at rest (Supabase Postgres with row-level security). No system is 100% bulletproof, but we work hard at it and we'll tell you if anything material happens.
9. Changes
We'll update this page when our practices change. The "Last updated" date at the bottom always reflects the current version.
10. Contact
Privacy requests: privacy@loopmenu.app
General support: support@loopmenu.app
Last updated June 1, 2026. Questions? Email support@loopmenu.app.