Privacy Policy

Effective date: July 23, 2026

Restos (restos.io) is an online ordering platform for restaurants and cafes, operated by Polid, Inc. (“Polid”, “we”, “us”), a company incorporated in California, USA. This Privacy Policy explains what personal data we collect, how we use it, and the choices you have.

Our two roles

Restos serves two groups of people, and our role differs for each:

  • Restaurant owners and staff (“Merchants”) who sign up for Restos, and visitors to restos.io. For this data, we decide how and why it is processed — we act as the data controller.
  • Customers of Merchants (“End Customers”) who browse a Merchant's ordering website and place orders. This data belongs to the Merchant; we process it on the Merchant's behalf as a service provider (data processor). The Merchant is responsible for providing its own privacy notice to its customers.

Information we collect

From Merchants

  • Account details: name, email address, and password (stored in hashed form) when you sign up
  • Business details you add to your site: restaurant name, address, opening hours, menu content, and images
  • Billing details for paid plans, where applicable (payments are handled by third-party payment processors; we do not store full card numbers)
  • Messages you send us, such as support requests

From End Customers (on behalf of Merchants)

  • Order details: items ordered, order total, time of order, and any notes provided
  • Contact and delivery details: name, phone number, email address, and delivery address where the Merchant offers delivery
  • Sign-in data where an End Customer creates an account on a Merchant's site (authentication is provided by Google Firebase)

Collected automatically

  • Log data: IP address, browser type, pages visited, and timestamps
  • Cookies and similar technologies — see “Cookies and analytics” below

How we use information

  • To provide the service: hosting ordering websites, transmitting orders to Merchants, and notifying End Customers about order status
  • To create and manage Merchant accounts, including verification and service emails
  • To respond to support requests
  • To measure and improve the platform, including aggregate usage analytics
  • To protect the service against fraud, abuse, and security incidents
  • To comply with legal obligations and enforce our Terms of Service

We do not sell personal data, and we do not use End Customer data for our own marketing.

Cookies and analytics

We use cookies and similar technologies to keep you signed in, remember preferences (such as language), and understand how the site is used. On restos.io we use Google Analytics and Google Ads conversion measurement to understand where visitors come from and how our pages perform. You can control cookies through your browser settings; blocking some cookies may affect signed-in functionality.

How we share information

We share personal data only with:

  • The relevant Merchant — orders and related End Customer details are shared with the Merchant the order was placed with
  • Service providers that help us run the platform, such as cloud hosting, email delivery, authentication (Google Firebase), and analytics providers, under agreements limiting their use of the data
  • Legal authorities when required by law, subpoena, or to protect our rights, users, or the public
  • A successor entity in the event of a merger, acquisition, or sale of assets, in which case this policy will continue to apply

Data retention

We keep Merchant account data for as long as the account is active, and for a reasonable period afterwards to handle legal and accounting obligations. End Customer data is retained on behalf of the Merchant for as long as the Merchant uses the service, and is deleted or anonymized when no longer needed. You can request deletion at any time — see “Your rights” below.

Security

We use reasonable technical and organizational safeguards to protect personal data, including encrypted connections (HTTPS), hashed passwords, and access controls. No online service can guarantee absolute security; please notify us immediately if you suspect unauthorized access to your account.

Your rights

You may request access to, correction of, or deletion of your personal data by contacting us at the address below. We will respond within the timeframe required by applicable law.

California residents have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right not to be discriminated against for exercising these rights. We do not sell personal information as defined by the CCPA.

Residents of the European Economic Area and the United Kingdom have rights under the GDPR, including access, rectification, erasure, restriction, portability, and objection. Where we act as a processor for a Merchant, we will refer your request to the Merchant and assist them in fulfilling it.

International transfers

We operate internationally: our servers and service providers are located in the European Union and the United States. Where personal data is transferred across borders, we take steps to ensure it receives an adequate level of protection.

Children

Restos is a business service and is not directed at children under 16. We do not knowingly collect personal data from children.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a new effective date, and for material changes we will notify Merchants by email or through the dashboard.

Contact

Polid, Inc. (California, USA)
Email: [email protected]