Privacy operating summary
Privacy behavior must match the configured service.
What the product handles
Restaurant account and configuration records; guest order, fulfillment, contact, consent, loyalty and service records; workforce scheduling and time records; provider references; device, security, audit and support diagnostics. A restaurant enables only the purposes and markets it has reviewed.
How records are used
To authenticate and authorize, publish menus and sites, quote and fulfil orders, process configured tenders, operate kitchens and devices, communicate approved transactional updates, reconcile finance and inventory, support staff workflows, protect the service, and satisfy documented legal obligations.
Sharing and providers
External processing stays disabled until the provider register records purpose, data categories, region where known, contract and review state, scopes, activation date, and disconnect/deletion procedure. OrderDock does not treat optional browser analytics as financial truth.
Website analytics
On this website, two analytics services load only after you choose Accept All in the cookie banner; with Essential Only they do not run and set no cookies. Google Analytics 4 (Google LLC) records the pages you view, the referring site, device and browser type, and approximate location; it sets _ga and _ga_* cookies that last up to two years, keeps data for two months, and runs with Google signals and advertising features off. PostHog (PostHog, Inc.) records pages viewed, the links and buttons clicked and forms submitted (not what is typed), device and browser type, and IP address, used to estimate approximate location; it sets a ph_ cookie and storage entry and keeps data for one year. Both are based in the United States. Change or withdraw your choice under Cookie choices.
Retention and deletion
Retention is purpose- and market-specific. Account closure shows export, outstanding payments/disputes, legal holds, integration disconnect, domain steps, pseudonymization, backup expiry, deletion timing, and confirmation. Financial, stored-value, dispute, security, and workforce records may require a lawful retention period.
Choices and requests
The data model supports access, correction, export, purpose-specific consent withdrawal, channel suppression, account closure, and deletion or anonymization when permitted. Identity records are not merged solely from a weak name, phone, or email match.
Security and support
Tenant scope, server authorization, row policies, encryption boundaries, verified webhooks, append-only audit and ledgers, and time-bound visible support grants protect records. No method can promise absolute security; suspected vulnerabilities follow responsible disclosure.