Privacy Policy — OrderSomm
Effective date: January 1, 2025 · Last updated: May 2026
1. Who We Are
OrderSomm is an AI-powered dining intelligence platform ("OrderSomm," "we," "us," or "our"). OrderSomm acts as a data processor on behalf of restaurant operators (the data controllers) and collects limited personal data from dining guests in order to deliver personalized menu recommendations. This Policy applies to all data we process through the OrderSomm platform.
For questions about this Policy or to exercise your rights, contact us at: privacy@ordersomm.com.
2. What We Collect
When you use OrderSomm as a dining guest, we collect the information you provide during your session:
- Your first name (as entered on the welcome screen)
- Your table number
- Your dining preferences — flavor profile, mood, spice tolerance, alcohol preferences, dietary restrictions, and beverage preferences
- Items you select or bookmark during your session
If you create a customer account, we additionally collect your email address and a hashed password. We do not collect payment card information.
If you are a restaurant operator, we collect your name, email address, establishment name, and subscription payment information (processed by Stripe; card data never touches our servers).
3. Special-Category Data (Dietary & Health Information)
Dietary restrictions and food allergy information you provide (e.g., gluten-free, nut allergy, vegan) may constitute health-related data under applicable law, including Article 9 of the EU General Data Protection Regulation (GDPR). By entering this information, you explicitly consent to its processing for the sole purpose of filtering and ranking menu recommendations during your session. You may withdraw this consent at any time by clearing your session or deleting your account.
This information is not shared with third parties and is not used for advertising.
4. How We Use Your Data
Your data is used exclusively to:
- Generate personalized menu recommendations during your session
- Improve recommendation accuracy over time through aggregated, anonymized behavioral signals (e.g., which pairings guests accept or reject overall — not linked to you individually)
- Allow you to review and manage saved preferences on future visits if you have a customer account
- Process operator subscription payments via Stripe
- Send transactional emails (e.g., password reset) via Resend
We do not sell your personal data. We do not use your data for advertising or cross-site tracking.
5. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area, we rely on the following legal bases:
- Contractual necessity — to provide the recommendation service you have requested (basic preference data, session management)
- Explicit consent (Article 9) — to process dietary restriction and food allergy data, which may constitute health data
- Legitimate interests — to improve our recommendation engine using aggregated, anonymized signals, where these interests are not overridden by your rights
- Contractual necessity — to manage operator subscriptions and deliver the operator-facing platform
6. Data Processors & Sub-Processors
We share data with the following third-party processors only as necessary to deliver the service:
- Stripe, Inc. — payment processing for operator subscriptions. Stripe is PCI DSS Level 1 certified. No card data touches OrderSomm's servers.
- Resend, Inc. — transactional email delivery (password reset, account notifications). Email address and name only.
- OpenAI, L.P. — used by operators to parse and build their menu from uploaded content. Only operator-provided menu text is sent; no guest personal data is transmitted to OpenAI. Under OpenAI's API Terms (updated March 2023), API inputs are not used to train OpenAI models.
- Neon / PostgreSQL cloud — encrypted database hosting for all application data.
7. Data Retention
Guest session data (preferences and item selections) is automatically deleted after 90 days for guests without a registered account. A deletion job runs daily to enforce this policy.
Anonymized, aggregated signals derived from session behavior (e.g., aggregate accept/reject counts per pairing rule) may be retained indefinitely; these cannot be linked back to any individual guest.
Registered customer account data is retained for the lifetime of the account. Operator account data and associated menu content are retained for the lifetime of the subscription, plus a 30-day grace period after cancellation to allow data recovery.
8. Cookies & Local Storage
OrderSomm uses browser local storage to remember your session within a dining visit (e.g., your name and session ID). This data remains on your device and is not transmitted to third-party analytics services. We do not use third-party tracking cookies or behavioral advertising cookies.
9. Data Security
All data is transmitted over HTTPS. Passwords are hashed using scrypt with a unique salt per account — plain-text passwords are never stored. Admin and operator credentials are protected with secure token-based authentication. We apply industry-standard security headers including Content Security Policy and rate limiting to protect against abuse.
10. Your Rights (GDPR & EEA)
If you are located in the EEA, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure ("right to be forgotten") — request deletion of your data
- Restriction — request that we limit our use of your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — for health/dietary data processed under explicit consent
- Lodge a complaint — with your local supervisory authority
To exercise any of these rights, contact us at privacy@ordersomm.com. We will respond within 30 days.
11. Your Rights (CCPA — California Residents)
Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- Know what personal information we collect, use, disclose, and sell
- Delete personal information we have collected from you (subject to certain exceptions)
- Opt-out of sale — we do not sell personal information
- Non-discrimination — we will not discriminate against you for exercising CCPA rights
To submit a CCPA request, email privacy@ordersomm.com with "CCPA Request" in the subject line. We will verify your identity before processing the request.
12. Children's Privacy
OrderSomm is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us at privacy@ordersomm.com and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via a notice on the platform or by email to registered account holders. The "Last updated" date at the top of this page reflects the most recent revision.
See also: Terms of Service · Contact: privacy@ordersomm.com