OrderEatRepeat Privacy Policy
OrderEatRepeat Privacy Policy
Effective 29 July 2026
1. Who we are
Order Eat Repeat Ltd., carrying on business as OrderEatRepeat, operates an online ordering platform that restaurants use to take orders from their own customers. Our registered office is 3 Hawthorne Ave., Ottawa, Ontario K1S 0A9.
This policy explains what personal information we collect for our own purposes, why we collect it, who we share it with, and the rights you have. Terms defined in the OrderEatRepeat Restaurant Services Agreement have the same meaning here.
2. Who this policy is for
This policy covers personal information about:
- Restaurant owners, managers and staff who hold or use an OrderEatRepeat account;
- Prospective customers who contact us, request a demo, or sign up for a trial;
- Visitors to our own website.
3. What this policy does not cover
If you ordered food from a restaurant, this is not the policy that applies to you.
When a diner places an order through a restaurant's storefront, we handle that information on behalf of the restaurant and on its instructions. The restaurant decides what to collect, how to use it, and how long to keep it. The restaurant is responsible for telling its customers how it handles their information, and is required to do so under its agreement with us.
If you have a question about an order you placed, or want your information corrected or deleted, contact the restaurant you ordered from. If you can't reach them, write to us at help@ordereatrepeat.com and we will pass your request on and help where we reasonably can.
We are not a food ordering marketplace. We do not operate a consumer app, we do not maintain a directory of diners, and we do not use one restaurant's customer information to market to those customers, or for our own purposes, or on behalf of any other restaurant.
4. What we collect
Account information. Your name, business email address, phone number, password (stored hashed, never in readable form), role, and the Google account identifier if you sign in with Google.
Business information. Your legal and trading name, business address, location addresses and coordinates, hours, delivery areas, menu content, and tax configuration. Most of this is business information rather than personal information, but it can identify a sole proprietor.
Billing information. Your subscription plan, billing currency, location count, invoice and payment history, and billing contact details. We do not receive or store your card number. Card details are entered directly with our payment processor, and we hold only a token and the last four digits.
Payment gateway credentials. Where you connect your own payment provider, we store the API credentials you supply, encrypted. These identify your merchant account, not an individual.
Support information. Emails, messages and any information you include when you contact us for help.
Usage and technical information. IP address, browser and device type, operating system, pages visited, actions taken in the admin dashboard, timestamps, and error and security logs.
Acceptance records. When you accept our agreement, we record the accepting person's name and email, the account identifier, the version accepted, the contents of your Order, and the date, time and IP address.
Prospect information. Contact details and correspondence where you enquire about the platform or we contact you about it.
5. Why we use it
We use personal information to:
- create and administer your account, and authenticate you;
- provide, operate, maintain and improve the Services;
- bill you, collect payment, and keep the financial records we are required to keep;
- send you service, billing, security and legal notices;
- respond to your support requests;
- keep the platform secure — detect and investigate fraud, abuse, unauthorized access and technical faults;
- understand how the platform is used in aggregate, so we can improve it;
- send you product news and marketing, where you have consented;
- comply with our legal obligations, and establish, exercise or defend legal claims.
We collect and use personal information with your knowledge and consent. In some cases consent is implied by your use of the Services — for example, we use your email address to send order-related and account notices because that is obviously necessary to run your account. Where the law permits us to act without consent — such as to investigate a breach of an agreement, to detect fraud, or to comply with a legal requirement — we may do so.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
6. Automated decision-making
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
7. Who we share it with
Service providers. We use the following providers to run the platform. Each is bound by contract to protect the information and to use it only to provide services to us.
| Provider | What it does | Where it processes |
|---|---|---|
| Supabase | Database, authentication, file storage | Canada / United States |
| Vercel | Application hosting and delivery | United States |
| Stripe | Our subscription billing, and payment infrastructure for restaurants using Stripe Connect | Canada / United States |
| Resend | Transactional and notification email delivery | United States |
| Google (Places) | Address lookup and autocomplete | United States |
| Anthropic | Menu parsing during import | United States |
| Star Micronics (CloudPRNT) | Cloud receipt printing | United States |
This list is current as at the effective date above. We will keep it updated and will give notice of material changes. If you want the current list at any time, ask us.
Other payment providers. Where you connect your own gateway, we transmit payment instructions to that provider on your behalf. Your relationship with them is governed by your agreement with them and their privacy policy.
Professional advisers. Lawyers, accountants and auditors, where necessary and under a duty of confidentiality.
Legal and safety. Where required by law, court order or a valid request from a public authority, or where necessary to protect our rights, your safety or the safety of others.
Business transfer. If our business is sold, merged, reorganized or wound up, information may transfer as part of that transaction. We will require the recipient to continue to protect it, and we will tell you if the transfer materially affects how your information is handled.
8. Where your information is processed
Your information is processed in Canada and the United States.
While it is in the United States, or held by a provider subject to United States law, it may be accessible to United States courts, law enforcement and national security authorities under the laws of that country. That is true of any Canadian business using United States cloud infrastructure, and we tell you because you are entitled to know before you decide to use the platform. We contract with our providers for protections comparable to those required under Canadian law.
9. How long we keep it
We keep personal information only as long as we need it for the purposes described above, or as long as the law requires.
In practice:
- Account information is kept while your account is active, and for a limited period afterwards so that you can reactivate or retrieve your data.
- Billing and financial records are kept for the period required by Canadian tax law, generally six years.
- Acceptance records are kept for as long as the agreement could be relevant to a dispute.
- Security and access logs are kept on a short rolling window.
- Support correspondence is kept while it remains useful for supporting you.
Where we no longer need to identify someone but still need the underlying record — most commonly to defend a payment dispute — we de-identify rather than delete. Deleted information may persist briefly in encrypted backups before those rotate out.
10. How we protect it
We use administrative and technical safeguards designed to protect personal information against loss, theft, and unauthorized access, use, disclosure or alteration. These include encryption in transit and at rest, encrypted storage of payment gateway credentials, logical separation of each customer's data, role-based access controls, and access limited to personnel who need it.
No system is perfectly secure. If a breach of our security safeguards occurs that creates a real risk of significant harm, we will notify affected individuals and the Privacy Commissioner of Canada as the law requires, and we keep records of security breaches whether or not they meet that threshold. If the breach affects information we hold on behalf of a restaurant, we will notify that restaurant of any confirmed breach so that it can meet its own obligations.
11. Cookies and similar technologies
We use cookies and similar technologies, including browser local storage, for the purposes described below. We do not use advertising cookies, and we do not track you across other companies' websites.
On the OrderEatRepeat admin dashboard, we use strictly necessary cookies to sign you in and keep your session active. The dashboard cannot work without them, so they are set without consent as the law permits.
On restaurant storefronts, cookies and local storage hold the contents of a cart while an order is being built, and can remember a returning diner's details so they are not re-typed. Where the restaurant has connected a payment provider, that provider may set its own cookies for fraud prevention — Stripe does this, and its use of them is governed by Stripe's privacy policy. Storefront cookies are set in the course of providing the service to the restaurant, and are covered by that restaurant's own privacy notice.
On our marketing website, we use cookies necessary to operate the site. Where we use analytics cookies to understand how the site is used, we set them only with your consent, and you can withdraw that consent at any time.
You can block or delete cookies through your browser settings, and most browsers let you review what has been set. If you block strictly necessary cookies you will not be able to sign in to the platform.
A current list of the cookies we set, including their purpose and how long they last, is available on request from help@ordereatrepeat.com.
12. Your rights
You may:
- access the personal information we hold about you, and ask what we have used it for and who we have shared it with;
- correct it where it is inaccurate or incomplete;
- withdraw consent to uses that are not necessary to provide the Services or required by law — note that withdrawing consent to essential processing may mean we can no longer provide your account;
- ask us to delete it, subject to the retention obligations in Section 9;
- receive a copy in a structured, commonly used technical format, or have it transmitted to another organization, where the law provides for this;
- complain to us, and to a regulator.
To exercise any of these, write to help@ordereatrepeat.com. We will respond within 30 days. We may ask you to verify your identity first, and we will tell you if we need more time or cannot fully comply, and why.
Quebec residents additionally have the right to request that information be de-indexed or that its dissemination cease where the conditions in Quebec law are met, and the right to be informed about the use of automated decision-making.
United States residents. Depending on your state, you may have rights to know, delete, correct, obtain a copy of, and opt out of the sale or sharing of personal information, and to be free from discrimination for exercising them. We do not sell personal information or share it for targeted advertising. Use the same contact address above.
13. Complaints
Write to our Privacy Officer first at help@ordereatrepeat.com — we would rather resolve it directly. If you are not satisfied, you can complain to:
- the Office of the Privacy Commissioner of Canada (priv.gc.ca);
- the Commission d'accès à l'information du Québec, if you are in Quebec;
- the Information and Privacy Commissioner for Alberta or British Columbia, if you are in those provinces;
- your state Attorney General, if you are in the United States.
14. Sensitive information and children
Do not send us sensitive personal information — such as health information, government identification numbers, financial account numbers, or information about racial or ethnic origin, religion, political views, or biometric characteristics. We do not need it and do not want it in the platform.
The platform is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under the age of majority. If you believe we have, contact us and we will delete it.
15. Accountability
We have designated a Privacy Officer who is accountable for our compliance with this policy and with applicable privacy law. You can reach them at help@ordereatrepeat.com, or by mail at the address in Section 1.
16. Changes to this policy
We may update this policy. The effective date at the top tells you when it last changed. If a change materially affects how we handle your personal information, we will tell you by email or in the product before it takes effect. Previous versions are available on request.
17. Third-party sites
This policy does not cover websites or services operated by others, including any we link to. Read their policies.