Takeoutly Privacy Policy
Effective 18 August 2026. This is the current, published Takeoutly Privacy Policy.
1. Who we are
Takeoutly is ordering software for independent restaurants. A diner places a pickup order on a Takeoutly page, either at takeoutly.com or in a Takeoutly ordering window embedded on the restaurant's own website, and the restaurant prepares it.
This policy lives at takeoutly.com/privacy. A short notice sits directly above the name, phone, and email fields at checkout, before you type anything, saying what we collect and why and linking here. That notice appears both on takeoutly.com and inside the ordering window embedded on a restaurant's own site, and both places also carry a link to this policy in the footer.
This policy is issued by Takeoutly LLC, a California limited liability company, 5050 Laguna Blvd #112-619, Elk Grove, CA 95758 (“Takeoutly”, “we”). Takeoutly LLC is the controller of the personal information described here. Questions, requests, and complaints: team@takeoutly.com.
2. Our two roles, because they carry different duties
For order information, the restaurant decides and we execute. The restaurant you ordered from is the merchant of record for that order. It receives your money directly from Stripe, it decides its own refund and pickup policies, and the order information belongs to it. We handle that information on the restaurant's instructions and for no independent purpose of our own. In US privacy law terms we act as a service provider to the restaurant; under GDPR-style terms, a processor.
For running the platform, we decide. Restaurant staff accounts, billing, security logging, and our own site analytics are ours. For those we are the business / controller, and this policy is the notice for them.
We do not sell personal information. We do not rent, trade, or transfer it. We do not share it for cross-context behavioral advertising. We have never done any of those things. Section 10 says the same thing specifically about phone numbers.
3. What we collect when you place an order
Everything in this section comes from you, typed into the checkout page. The only personal information we get from anywhere else is the outcome of a payment (from Stripe) and the sign-in records our authentication provider keeps for restaurant staff.
To send an order to a kitchen we need:
| What | Why | Where it goes |
|---|---|---|
| Your name | So the kitchen can call it out at pickup | Stored with the order |
| Your phone number | So the kitchen can reach you about the order | Stored with the order |
| Your email address | Receipt, order-status emails, Stripe receipt, and so the restaurant can reach you if it misses your order | Stored with the order; passed to Stripe as the receipt address |
| What you ordered, options, and any note | To make the food | Stored with the order |
| Amounts: subtotal, tax, tip, fees, total | To charge you and to pay the restaurant | Stored with the order |
| Order timestamps and status | Pickup timing, and to expire unclaimed orders | Stored with the order |
We never see your card. Card details are entered into a payment form hosted by Stripe and go straight to Stripe. They do not pass through Takeoutly's servers and we do not store them. We receive only the outcome: approved, declined, or refunded. We do not receive or store any descriptor of your card, not even the last four digits.
You do not need an account to order. Diners have no logins on Takeoutly. There is nothing to sign into and no profile behind an order.
4. What we store on your own device
Three things are saved in your browser:
| Key | What it holds | Why |
|---|---|---|
takeoutly-customer-v1 | Your name, phone, and email | So you do not retype them next time |
fork-and-fast-cart-v1 | The contents of your cart, per restaurant | So a reload does not empty your cart |
takeoutly-last-slug | The last restaurant you viewed | So an installed shortcut reopens there |
None of it includes card details, and none of it is sent to us as a unit. It stays on your device. “Not you? Clear” on the checkout page erases your contact details. Clearing site data in your browser erases all three.
5. Cookies
Takeoutly sets no cookies of its own.
Ordering does rely on your browser's local storage to hold your cart. A browser configured to block site storage generally, beyond cookies alone, can stop the ordering page from working.
One cookie may be set by our security provider: Cloudflare's __cf_bm, which distinguishes humans from bots for roughly 30 minutes. It serves security purposes only, with no advertising or analytics use.
6. How we measure traffic
We count page views, menu views, items added to a cart, cart views, checkout views, checkout starts, whether a digital wallet was offered and whether it was used, and completed paid orders, so a restaurant can see whether its ordering page is working. The paid-order count is recorded on our servers when Stripe confirms the payment; everything else is recorded from your browser. We count the same way on our own marketing pages, where we also record that a lead form or contact form was submitted. With each one we record the page path, the host name of the site that linked you to us, any campaign tags in that link (utm_source, utm_medium, utm_campaign), the restaurant, and the time. This is built in-house and works this way:
- No cookies, and nothing written to your device.
- We do not store your IP address with these events. Your IP address and browser user-agent are combined with a secret we hold in our deployed environment, plus the current date, then run through a one-way hash (SHA-256). What we keep is the hash. Because the date is part of the input, the same visitor is not linkable from one day to the next. How opaque those hashes are depends on that secret staying secret: anyone who knew it could test a guess at an IP address and user-agent against a stored hash.
- No dish is recorded. A cart-add is counted against the restaurant, with no item identifier attached.
- Events from one visit on one day do share a session key. We can tell that a single visit viewed a menu, added to a cart, and then started checkout. That linkage is what makes the funnel numbers mean anything. We cannot tell which dish, and we cannot tell who you are.
We use no third-party analytics, no advertising pixels, and no session-replay tools.
7. Where your information lives, and who else touches it
Takeoutly's database and application are hosted in Amazon Web Services' Canada (Central) region. Operational access to that database from our hosting provider's control plane originates in AWS Europe (Ireland). If you order from the United States, your order information is therefore stored in Canada and may be accessed from Ireland.
These are the only companies that receive personal information from us, each for one job:
| Provider | What it does | What it receives |
|---|---|---|
| Stripe | Takes payment, pays the restaurant, sends card receipts | Your card details (directly from you), name, email, amounts |
| Lovable Cloud / Supabase | Hosts the application and the database | Everything stored, as our hosting provider |
| Amazon Web Services | Underlying data centers for the above | Same, as infrastructure |
| Lovable | Renders and sends our transactional email through its managed email service | Your email address and the content of order emails |
| Cloudflare | Serves and protects the site | Your IP address and request headers, in transit |
| Google Fonts | Serves the site's typefaces | Your IP address, browser, and the referring page |
Two notes worth stating plainly:
- Google Fonts means Google receives your IP address on every page load, including inside the ordering window embedded on a restaurant's site.
- Email routing. Our order emails are sent through Lovable's managed email service, which relays them through its own downstream email provider. Your email address and the contents of those emails pass through that infrastructure.
8. Order status links
When you place an order we take you straight to your order's status page. Its address is the link, and you should save it, because Takeoutly does not send a separate order-confirmation email. The same link appears in the emails we send you when the restaurant accepts your order, rejects it, or it expires, and when the food is ready; by the time an acceptance email reaches you the cancel window described below has usually closed, so cancelling normally means using the page you were sent to at checkout. That link is the key. Anyone who has it can see the order without signing in, and can cancel it for as long as the restaurant has not yet accepted it, which is what makes it work without an account. Once the kitchen accepts, the link still shows the order but can no longer cancel it. The link does not expire. It keeps working after pickup, indefinitely. Treat it like a receipt and do not post it publicly.
9. Restaurant staff accounts
Restaurant owners and staff have real accounts. For them we hold: email address, name, role, the restaurant they belong to, and standard authentication records including IP addresses and browser user-agents for sign-ins, which our authentication provider keeps as a security measure. Those staff sign-in IP addresses are stored as-is. The hashing described in section 6 covers visitor analytics only.
10. Restaurant surveys
We run occasional surveys for restaurant owners, such as the one at takeoutly.com/survey. Every question is optional, including the email field. We store the answers you give, and if you leave an email address we store that too, so we can send you the results and so you can ask us to delete your response later. Ticking the early access box additionally adds you to the same access request list the homepage form feeds.
A survey response holds no account and no order data. We record which campaign or link brought you to the page, in the same cookie-free way described in section 6, so we can tell which post reached which group of owners. To stop repeat and automated submissions we keep a salted hash of your IP address, never the address itself, for rate limiting. We publish survey findings only in aggregate, and never with your name, your restaurant, or your email attached.
11. Text messages
Takeoutly does not send text messages. We ask for your phone number so the restaurant can reach you about your order, such as a question about a substitution or a problem with pickup. We do not text you, and we do not have a texting program running. If that changes, we will update this policy and ask for your consent at checkout before sending you anything.
Your phone number is not shared for marketing. We do not sell, rent, or trade phone numbers, and we do not share them for anyone's marketing or promotional purposes. The restaurant you ordered from can see your number on its own order, because it may need to call you about that order; our agreement with every restaurant forbids it from texting that number at all, including adding it to any loyalty-club, review-request, or marketing platform, and forbids selling or renting it or handing it to a third party for that third party's marketing.
12. How long we keep things
We run exactly one automated deletion job, and it covers analytics only. Raw analytics events are deleted 90 days after they are recorded. Nothing else is deleted on a timer: there is no job that erases old orders, old contact details, or old form submissions. Those records are still there.
What we hold and why we keep it:
- Orders and their contents, including the name, phone number, and email on the order, are kept for as long as the restaurant's account is active, and after that for as long as we need them for tax and payment-dispute purposes. Chargebacks and tax questions can arrive years after an order, and the records are the evidence.
- Raw analytics events are deleted 90 days after they are recorded. The daily totals built from them are kept indefinitely. Neither holds an IP address or a name (section 6).
- Restaurant staff account records are kept for the life of the restaurant's account.
- Lead and contact-form submissions, meaning the email address, name, restaurant name, website and message you send us through a form on takeoutly.com, plus the campaign tags on the link that brought you, are kept for as long as we are talking to you and are not deleted on a schedule.
- Survey responses: kept until we have published what that survey found and acted on it, then deleted or stripped of the email address. Ask us sooner and we will delete yours.
- Rate-limit records: when a form is submitted we store a one-way hash of the submitting IP address, and nothing else, so one connection cannot flood the form. Unlike the analytics hash in section 6 this one does not rotate daily. These rows are kept indefinitely.
You can ask us to erase your information. Email team@takeoutly.com from the address you used to order, or give us the phone number you used. A person reads that mailbox and does the deletion by hand. There is no self-serve button. We will tell you what we deleted and what we kept. Where the order belongs to a restaurant, we forward the request to it and act on its instruction (section 13). We may keep completed transaction records we are required to hold for tax and payment-dispute purposes; if we do, we will say so.
13. Your rights
Depending on where you live, under California's CCPA/CPRA, other US state laws, or the GDPR, you may have the right to know what we hold about you, get a copy, correct it, delete it, and opt out of any sale or sharing of it (we do neither); and whichever you use, we will not refuse you service, charge you a different price, or give you slower or worse service because you used it.
Every one of these requests is handled by hand, over email. There is no self-serve export or delete. To exercise any of them, email team@takeoutly.com from the address you used, or include the phone number you used. We will respond within 45 days (CCPA) or one month (GDPR). You can also use an authorized agent: have the agent email us from their own address with your signed, written permission attached, and we may contact you directly to confirm you gave it and to verify who you are.
If your request concerns an order, the restaurant is the decision-maker: we will forward your request to it within 10 business days, tell you which restaurant it went to and how to reach it directly, carry out whatever it instructs, and tell you the outcome within the same 45 days. Some information we must keep despite a deletion request, in particular completed transaction records held for tax and dispute purposes.
14. Children
Takeoutly is not directed at children under 13 and we do not knowingly collect their information. If you believe a child gave us information, email team@takeoutly.com and we will delete it.
15. Security
Access to order information is enforced in the database itself: a restaurant's staff can reach that restaurant's orders and no other restaurant's. Takeoutly's own systems, and a small number of Takeoutly administrators, can reach order records where it is necessary to run and support the service. We say that plainly, because the database does not stop us.
Traffic is encrypted in transit. Payment card data never reaches us.
No system is perfectly secure. If a breach affects your information we will notify you as the law requires.
16. Changes
We will post changes here and update the date at the top. If a change materially affects how we use your information, we will say so prominently at the top of this page.
17. Contact
team@takeoutly.com
Takeoutly LLC
5050 Laguna Blvd #112-619, Elk Grove, CA 95758