Effective Date: August 11, 2026

Privacy Policy

How ROCS collects, protects, and handles personal data for restaurant merchants and storefront diners.

1. Scope & Overview

This Privacy Policy describes how Restaurant Ordering Cloud Service ("ROCS", "we", "us", or "our") collects, uses, and discloses information when you access our restaurant administrative tools, kitchen displays, or storefront web applications.

2. Information We Collect

We collect information directly from restaurant operators ("Merchants") and from diners ordering through merchant storefronts ("Customers"):

  • Merchant Data: Account registration info, business name, staff accounts, tax identification, contact phone numbers, and billing history.
  • Customer Order Data: Diner name, phone number, pickup/delivery details, order item specifications, and special instructions.
  • Payment Data: Payment details are tokenized and processed securely through PCI-compliant partners (e.g., Stripe). ROCS does not directly store raw credit card credentials.
  • Technical Data: Device IP address, web browser type, operating system version, and system logs needed for service operation.

3. How We Use Information

We process personal data to:

  • Fulfill orders and sync order tickets directly to Kitchen Display Systems (KDS).
  • Send order updates and SMS notifications to customers regarding order readiness.
  • Provide sales reporting and analytics within the Business Dashboard.
  • Ensure system stability, cybersecurity, and fraud prevention.

4. Third-Party Sharing & Processing

We share data only as necessary to fulfill orders and operate the SaaS infrastructure:

  • Payment Gateways: To authorize and settle payment transactions securely.
  • Cloud Service Providers: Managed AWS server hosting and backend database infrastructure.
  • Merchants: Customer order details are shared directly with the restaurant where the order was placed.

5. Regional Privacy Disclosures (WA State & US Phasing)

As ROCS rolls out across Phase 1 (Washington State) and expands into Phase 2 (Nationwide US), we maintain compliance with state privacy statutes including the Washington My Health My Data Act, CCPA/CPRA, and other applicable state data regulations.

We do not sell or share customer personal information to third-party data brokers or targeted advertising networks.

6. Security & Data Retention

We employ industry-standard encryption protocols (TLS in transit and AES-256 at rest) to safeguard merchant and customer data. We retain order records only for as long as needed to support business operations, fulfill reporting requirements, or comply with financial and tax regulations.

7. Your Rights & Choices

Depending on your jurisdiction, you have the right to request access to, correction of, or deletion of your personal data collected through ROCS. Merchants can update store details or request full account deletion via the Business Dashboard.

8. Updates to This Policy

We may update this Privacy Policy from time to time as we expand features or roll out to additional states. Any updates will be published here with a updated effective date.

9. Privacy Inquiries

Have questions regarding data handling or privacy compliance for your restaurant?

Contact Privacy Officer