Privacy Policy

This policy explains what information FoodOrders.ai collects and how we use it. It is written to be plain and specific; please contact us if anything is unclear.

Information we collect

For merchants: account details, business information, menu content and billing records. For diners ordering through a merchant storefront or phone agent: name, phone number, order contents, fulfillment details and, where provided, delivery address. Call and chat transcripts may be retained to complete and support orders.

How we use it

To take and fulfill orders, send order notifications, provide merchant reporting, process payments, prevent abuse and improve the service. We do not sell personal information.

Who we share it with

Service providers acting on our behalf, including our hosting and database platform, payment processing, telephony and messaging, voice and language model providers, and email delivery. Each receives only the data needed to perform its function.

Retention

Order and billing records are retained while an account is active and afterwards where required for accounting or legal purposes. Merchants may request deletion of their workspace data.

Your rights

Depending on where you live, you may request access to, correction of, or deletion of your personal information, and object to certain processing. We design the product with privacy, transparency, data minimization and user rights in mind, and will respond to requests sent to the address below.

Contact

Email privacy@foodorders.ai with any privacy question or request.

Security, Privacy & Responsible AI

Our application is built using Lovable, a platform that maintains SOC 2 Type II compliance and ISO 27001:2022 certification. We combine this security-focused infrastructure with privacy-conscious data practices, GDPR-supporting safeguards, and responsible AI governance informed by ISO/IEC 42001 principles.

Platform certifications apply to Lovable and its defined systems and controls. They do not constitute independent SOC 2 or ISO certification of our company or this application. Compliance responsibilities are shared across our platform providers, application controls, connected services and internal operating practices.

  • SOC 2 Type II

    Built using a platform subject to independent security-control assessment.

  • ISO 27001:2022

    Supported by an information-security management framework certified at the platform level.

  • GDPR

    Designed with privacy, transparency, data minimization and user rights in mind.

  • Responsible AI

    AI practices informed by ISO/IEC 42001 principles for accountable AI management.