Privacy operating summary

Privacy behavior must match the configured service.

Legal activation gate: This page is a product and engineering summary, not an approved privacy notice or legal advice. Production collection remains blocked until accountable Canadian and U.S. legal/privacy review supplies the controller identity, contact path, lawful terms, jurisdiction text, effective date, and change process.

What the product handles

Restaurant account and configuration records; guest order, fulfillment, contact, consent, loyalty and service records; workforce scheduling and time records; provider references; device, security, audit and support diagnostics. A restaurant enables only the purposes and markets it has reviewed.

How records are used

To authenticate and authorize, publish menus and sites, quote and fulfil orders, process configured tenders, operate kitchens and devices, communicate approved transactional updates, reconcile finance and inventory, support staff workflows, protect the service, and satisfy documented legal obligations.

Sharing and providers

External processing stays disabled until the provider register records purpose, data categories, region where known, contract and review state, scopes, activation date, and disconnect/deletion procedure. OrderDock does not treat optional browser analytics as financial truth.

Retention and deletion

Retention is purpose- and market-specific. Account closure shows export, outstanding payments/disputes, legal holds, integration disconnect, domain steps, pseudonymization, backup expiry, deletion timing, and confirmation. Financial, stored-value, dispute, security, and workforce records may require a lawful retention period.

Choices and requests

The data model supports access, correction, export, purpose-specific consent withdrawal, channel suppression, account closure, and deletion or anonymization when permitted. Identity records are not merged solely from a weak name, phone, or email match.

Security and support

Tenant scope, server authorization, row policies, encryption boundaries, verified webhooks, append-only audit and ledgers, and time-bound visible support grants protect records. No method can promise absolute security; suspected vulnerabilities follow responsible disclosure.