Privacy operating summary
Privacy behavior must match the configured service.
What the product handles
Restaurant account and configuration records; guest order, fulfillment, contact, consent, loyalty and service records; workforce scheduling and time records; provider references; device, security, audit and support diagnostics. A restaurant enables only the purposes and markets it has reviewed.
How records are used
To authenticate and authorize, publish menus and sites, quote and fulfil orders, process configured tenders, operate kitchens and devices, communicate approved transactional updates, reconcile finance and inventory, support staff workflows, protect the service, and satisfy documented legal obligations.
Sharing and providers
External processing stays disabled until the provider register records purpose, data categories, region where known, contract and review state, scopes, activation date, and disconnect/deletion procedure. OrderDock does not treat optional browser analytics as financial truth.
Retention and deletion
Retention is purpose- and market-specific. Account closure shows export, outstanding payments/disputes, legal holds, integration disconnect, domain steps, pseudonymization, backup expiry, deletion timing, and confirmation. Financial, stored-value, dispute, security, and workforce records may require a lawful retention period.
Choices and requests
The data model supports access, correction, export, purpose-specific consent withdrawal, channel suppression, account closure, and deletion or anonymization when permitted. Identity records are not merged solely from a weak name, phone, or email match.
Security and support
Tenant scope, server authorization, row policies, encryption boundaries, verified webhooks, append-only audit and ledgers, and time-bound visible support grants protect records. No method can promise absolute security; suspected vulnerabilities follow responsible disclosure.