Kitchn LLC ("Kitchn," "we," "us," or "our") operates a multi-tenant restaurant commerce platform that restaurants use to run branded online ordering storefronts, manage menus and orders, accept payments, run marketing, and connect to their point-of-sale ("POS") and delivery systems.
This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. It applies to our websites and services wherever this Policy is posted or linked, including:
- restaurant storefronts powered by Kitchn — on
eatkitchn.comsubdomains and on restaurants' own custom domains; - the Kitchn operator dashboard used by restaurant staff;
- the Kitchn mobile applications, where offered; and
- email, push, and other communications sent through the platform.
Collectively, these are the "Services."
The Services are offered and directed solely to persons located in the United States. We do not offer the Services to, or monitor the behavior of, individuals in the European Economic Area, the United Kingdom, Switzerland, or Canada, and this Policy does not extend GDPR, UK GDPR, FADP, or PIPEDA rights except where those laws apply to us as a matter of law notwithstanding this scoping.
This Policy does not apply to: (a) a restaurant's own website, physical location, or offline dealings with you; (b) third-party services you reach through the Services, including Stripe, Clover, Square, Lightspeed, Toast, Uber, and Google; or (c) any restaurant's own privacy policy, which governs that restaurant's independent use of your information.
1. The Most Important Thing to Understand: Our Two Roles
Kitchn plays two different roles depending on whose information is involved and what we are doing with it. Which role applies determines who is accountable for the information and who you should contact about it.
Kitchn generally acts as a processor or service provider when we handle information on a restaurant's behalf — operating that restaurant's storefront, fulfilling orders, synchronizing POS data, or sending restaurant-directed communications. For that processing, the restaurant decides how the information is used, and under the Clover Developer Legal Guidelines we act solely for the exclusive benefit of the merchant.
Kitchn acts as an independent controller or business for certain limited purposes — managing Kitchn accounts, billing and collections, platform security, fraud and abuse prevention, legal compliance, Kitchn's own business communications with restaurants, and platform-level analytics using aggregated or de-identified data.
The table below shows how these roles map to what we actually do:
| Processing activity | Kitchn's role |
|---|---|
| Processing a restaurant's orders and storefront transactions | Processor / service provider |
| Hosting a restaurant's customer lists, loyalty members, and marketing subscribers | Processor / service provider |
| Sending a restaurant's marketing campaigns | Processor / service provider |
| POS synchronization (Section 7) | Processor / service provider |
| Restaurant-specific reporting and analytics | Processor / service provider |
| Managing restaurant subscriber accounts, billing, and collections | Controller / business |
| Platform security, fraud prevention, and abuse prevention | Controller, or an independent business purpose, depending on applicable law |
| Legal compliance and responding to legal process | Controller / business |
| Kitchn's own marketing to restaurants and prospective restaurants | Controller / business |
Operating eatkitchn.com and orderkitchn.com (our own marketing sites) | Controller / business |
| Platform-level de-identified analytics (Section 6.5) | Separate permitted use, subject to de-identification requirements |
Who to contact about your rights: if your information relates to a restaurant's storefront, its customer lists, or its POS, contact the restaurant first — we will assist it in responding (Section 10). Where Kitchn is the controller, contact Kitchn at info@orderkitchn.com.
What we will not do with diner or merchant data, in any role: we do not sell it, we do not rent it, we do not use it to build advertising profiles, we do not use it to market to a restaurant's guests on our own behalf, and we do not use it to train third-party artificial intelligence models. Beyond the restaurant-directed processing described above, our own uses are limited to the specific purposes described in Section 6.
2. Quick Reference
Our single point of contact for every matter in this Policy is info@orderkitchn.com. To help us route your message quickly, please use the subject line indicated below.
| If you are… | And you want to… | Do this |
|---|---|---|
| A diner who ordered from a restaurant's storefront | Access, correct, or delete your information; stop marketing | Contact the restaurant using the contact details on its storefront. You may also email info@orderkitchn.com with the subject line "Privacy Request" and we will route your request. |
| A restaurant subscriber or staff member | Exercise your rights over your own account data | Email info@orderkitchn.com, subject line "Privacy Request", or use the in-dashboard privacy request form |
| A restaurant subscriber | Get help responding to a guest's privacy request | Email info@orderkitchn.com, subject line "Merchant Privacy Assistance" — we will assist with access, export, and deletion |
| Anyone | Report a suspected security incident or vulnerability | Email info@orderkitchn.com, subject line "Security" |
3. Categories of Personal Information We Collect
3.1 Information restaurant subscribers and their staff provide
When a restaurant signs up for Kitchn or an authorized user administers an account, we collect:
- Account and identity information — name, business email address, phone number, password credentials (stored in protected, hashed form by our identity provider), profile photo, preferred language, and multi-factor authentication enrollment data, where you enable multi-factor authentication.
- Business information — legal entity name, doing-business-as name, business address, business phone, website, cuisine type, hours of operation, service periods, tax identification information, health-permit and licensing information you choose to supply, and the number and location of restaurants.
- Role and access information — assigned role (Tenant Owner, Location Owner, Location User, Kitchen User), the restaurants a user may access, and the permissions granted.
- Onboarding information — the answers, uploads, and selections you provide during our multi-step onboarding flow, including menus, logos, and brand assets.
- Payout and verification information — collected by Stripe, not by Kitchn, when you connect a Stripe Connect account. This may include beneficial-owner identity details, government identification numbers, date of birth, and bank account details. We receive only the resulting account status, capability flags, and non-sensitive identifiers from Stripe. See Section 5.
- Billing information — subscription tier (Basic, Essential, Premium), billing interval, subscription and invoice history, proration records, tier-change history, and the last four digits and brand of the payment method on file.
- Support and communications — the content of support tickets, emails, chat messages, in-product feedback, and any notes our team records about your account.
3.2 Information diners and guests provide
When you use a restaurant's Kitchn storefront, we collect on that restaurant's behalf:
- Contact and account information — name, email address, phone number, and password credentials or one-time-passcode verification records; if you sign in with Google, the identity token fields Google returns to us (name, email address, email-verified flag, and Google account identifier).
- Order information — items ordered, modifiers and special instructions, quantities, order totals, taxes, tips, fees, discounts and promotional codes applied, fulfillment method (pickup, delivery, dine-in, catering), scheduled pickup or delivery times, and order status history.
- Delivery and address information — delivery addresses, saved addresses, delivery instructions, and the approximate geolocation used to determine delivery eligibility and to display nearby restaurants.
- Payment information — see Section 5. We store only tokenized references and non-sensitive descriptors.
- Catering and event information — inquiry details, headcount, event date and location, quote and proposal history, and any dietary or logistical notes you supply.
- Loyalty, gift card, and promotion information — loyalty account balances and transaction history, gift card purchases, balances and redemptions, referral participation, and promo code usage, where the restaurant has enabled these features.
- Group ordering information — participant names, individual selections, and session details when you join a group order.
- Reviews and user-generated content — ratings, review text, photos, and any other content you submit, where the restaurant has enabled reviews.
- Marketing preferences — subscription and unsubscribe status, email engagement, communication preferences, and audience segment membership.
- Order notes you volunteer — free-text notes to the kitchen and similar per-order instructions, where the restaurant has enabled them, which may include allergy or dietary information you choose to share. These notes are transmitted to the restaurant to fulfill the specific order they accompany and are not kept as a separate preference profile; see Section 3.6.
3.3 Information collected automatically
Across the Services we and our analytics providers automatically collect:
- Device and browser information — device type, operating system and version, browser type and version, screen resolution, language settings, and time zone.
- Network and identifier information — IP address, general location inferred from IP address (typically city, state, and country — not precise GPS), and cookie, session, and device identifiers.
- Usage information — pages and screens viewed, referring and exit pages, links and buttons clicked, search terms entered in the storefront or dashboard, cart activity, time spent, session duration, and navigation paths.
- Email and notification engagement — whether an email was delivered, opened, bounced, or complained about, and which links were clicked, recorded through our email service provider; whether a push notification was delivered and opened.
- Log, diagnostic, and security information — request logs, error and crash reports, API request identifiers, idempotency keys, rate-limit events, login attempts (successful and failed), lockout events, session and token issuance records, and audit trails of privileged actions.
3.4 Information we receive from third parties and integrated systems
- Point-of-sale providers. Where a restaurant connects a POS system — including Clover, and where supported Square, Lightspeed, and Toast — we receive merchant profile information, menu and item catalog data, modifier and pricing data, inventory and availability status, order records pushed to or synchronized from the POS, and order and payment status. See Section 7, which governs this data specifically.
- Payment processor. Stripe provides us with payment status, authorization and capture results, refund and dispute records, payout and balance information, connected-account onboarding and capability status, and non-sensitive card descriptors (brand, last four digits, expiration month and year, and issuing country).
- Delivery providers. Uber Direct provides delivery quotes, courier assignment and status, tracking links, estimated and actual delivery times, and proof-of-delivery events.
- Identity and mapping providers. Google provides identity token claims when you sign in with Google, and address autocomplete, geocoding, address validation, and mapping data when you enter an address.
- Restaurant-supplied lists. A restaurant may import its own customer, loyalty, or marketing lists into Kitchn. The restaurant is responsible for having a lawful basis and, where required, consent for that import.
- Service providers and security sources. Fraud-prevention, bot-detection, and threat-intelligence signals from our infrastructure and security vendors.
3.5 Information from restaurant staff devices
Where a restaurant uses the Kitchn dashboard mobile application or connects receipt printers or kitchen display hardware, we collect device registration tokens for push notification delivery, device model and operating system version, printer identifiers and targets, and application version.
3.6 Sensitive information
We do not intentionally collect government identification numbers, precise geolocation, biometric data, health information, racial or ethnic origin, religious beliefs, sexual orientation, or trade union membership, and we ask that you not submit them.
Two exceptions warrant specific mention:
- Dietary, allergen, and religious-observance information in order notes. The Services do not maintain a persistent dietary or allergen profile for diners. If you choose to include an allergy, a dietary restriction, or a preference such as halal or kosher in a free-text order note or catering inquiry, that information may in some jurisdictions be treated as sensitive personal information or consumer health data because it can reveal health or religious information. We process it solely to transmit your instructions to the restaurant with that specific order, at your direction; we do not use it for marketing, profiling, or inference; and we do not sell it. It is retained only as part of the order record (Section 11).
- Identity verification for payouts. Government identification numbers and dates of birth collected during Stripe Connect onboarding are collected by Stripe directly, under Stripe's own privacy policy. Kitchn does not receive, store, or have access to those values.
4. Cookies, Analytics, and Similar Technologies
We use cookies, local storage, session storage, pixels, and similar technologies. The categories we use are:
| Category | Purpose | Can you turn it off? |
|---|---|---|
| Strictly necessary | Authentication and session management (our session cookies are HttpOnly and Secure, with same-site restrictions), tenant resolution, load balancing, cart persistence for guest sessions, CSRF and abuse prevention, and honoring your consent choices. | No — the Services will not function without these. |
| Functional | Remembering language, theme, selected restaurant, date-range filters, dashboard layout, and other preferences. | Yes |
| Analytics and performance | Understanding how the Services are used so we can improve them, measure feature adoption, and diagnose errors. On our marketing site we use Google Analytics with Google Consent Mode. | Yes |
| Advertising | Measuring the effectiveness of Kitchn's own marketing for the Kitchn platform. We do not run advertising cookies on restaurant storefronts on our own behalf. | Yes |
Your controls.
- On
eatkitchn.com, use the cookie banner or the Cookie Settings link in the footer to grant or withdraw consent by category at any time. We implement Google Consent Mode with analytics and advertising storage denied by default, so no analytics or advertising cookies are set unless you consent. (The Google tag itself may load before consent and send cookieless signals that are not stored on your device.) - Most browsers let you block or delete cookies. Blocking strictly necessary cookies will break sign-in and checkout.
- Global Privacy Control. We do not sell personal information or share it for cross-context behavioral advertising, so there is generally no sale or sharing for a universal opt-out signal to stop. Where applicable law nonetheless requires us to treat a Global Privacy Control (GPC) signal as a valid opt-out request, we will honor it.
- Do Not Track. There is no accepted industry standard for "Do Not Track" browser signals, and we do not currently respond to them.
- Industry opt-outs. For interest-based advertising generally, see the Network Advertising Initiative at
optout.networkadvertising.organd the Digital Advertising Alliance atoptout.aboutads.info.
5. Payment Card Information: What We Do Not Collect
This section matters for diners, for restaurant subscribers, and for our payment and POS partners.
Kitchn never receives, transmits, or stores full payment card numbers, magnetic stripe data, chip data, CVV/CVC security codes, or PINs.
- Card entry on Kitchn storefronts is rendered by Stripe Elements, which are hosted iframes served directly by Stripe. Card data travels from your browser to Stripe and never passes through Kitchn's servers or network.
- Stripe returns to us only a payment method token and non-sensitive descriptors: card brand, last four digits, expiration month and year, issuing country, and funding type. "Saving a card for later" saves Stripe's token, not your card number.
- Stripe is a PCI DSS Level 1 certified service provider. Kitchn's own cardholder-data environment is minimized accordingly, and we maintain PCI DSS compliance appropriate to that reduced scope.
- Card-present transactions processed on a restaurant's POS terminal — including Clover devices — are processed by that POS provider and its acquirer. Kitchn receives only the transaction outcome and non-sensitive summary fields necessary to reconcile the order. We do not receive cardholder data from POS terminals.
If you ever encounter a page that appears to be part of Kitchn and asks you to type a full card number outside of a Stripe-hosted field, do not enter it — report it to info@orderkitchn.com.
6. How We Use Personal Information
6.1 To provide the Services
- Create, authenticate, and secure accounts; issue and refresh session tokens; enforce roles, permissions, and multi-factor authentication.
- Display restaurant storefronts, menus, availability, pricing, and promotions.
- Build and persist carts, process checkout, calculate taxes, fees, tips, and discounts, and place orders with the restaurant.
- Route orders to the restaurant's dashboard, kitchen display, receipt printers, and connected POS.
- Obtain delivery quotes, dispatch couriers, and relay delivery tracking.
- Process payments, refunds, and disputes through Stripe; calculate and settle restaurant payouts and platform fees.
- Send transactional messages: order confirmations and receipts, order status updates, scheduled-order reminders, delivery notifications, catering quotes, password resets, one-time passcodes, security alerts, and billing notices. You cannot opt out of transactional messages while you have an active order or account, because they are necessary to deliver the service you requested.
- Operate loyalty programs, gift cards, promotions, referrals, group ordering, and reviews where the restaurant has enabled them.
- Generate the analytics, dashboards, and scheduled reports that restaurants use to run their business.
6.2 To operate and improve the platform
- Monitor availability and performance, debug errors, and conduct capacity planning.
- Test, develop, and improve features, including analyzing aggregate usage patterns.
- Provide customer support and respond to inquiries.
6.3 For safety, security, and integrity
- Detect, investigate, and prevent fraud, payment abuse, account takeover, credential stuffing, scraping, spam, and other malicious or unauthorized activity.
- Enforce rate limits, lockouts, and our Terms; maintain audit and login-audit trails.
- Protect the rights, property, and safety of Kitchn, our restaurant subscribers, diners, and the public.
6.4 For marketing — and the limits on it
- Kitchn's own marketing. We market the Kitchn platform to restaurants and prospective restaurants using business contact information. Restaurant subscribers may opt out of non-transactional Kitchn marketing at any time.
- Restaurant marketing to diners. Where a restaurant runs email campaigns through Kitchn, we send those messages as the restaurant's processor, at the restaurant's direction, to the restaurant's own audience. The restaurant is responsible for having the necessary consent and for complying with the CAN-SPAM Act, the Telephone Consumer Protection Act, and any applicable state or international marketing law. Every marketing email carries an unsubscribe link, and we maintain suppression lists.
- What we will not do. We do not market Kitchn or any third party to a restaurant's diners using that restaurant's guest data. We do not combine one restaurant's guest data with another's for marketing. We do not sell or share guest data for cross-context behavioral advertising.
6.5 To create aggregated and de-identified data
We create statistical, aggregated, and de-identified data — for example, aggregate order volumes, category trends, or performance benchmarks — that cannot reasonably be used to identify any individual. We may use and disclose such data for lawful business purposes, including benchmarking and product development. Where we de-identify data, we maintain it in de-identified form, do not attempt to re-identify it except to test our de-identification process, and contractually require recipients to do the same.
6.6 To comply with law
To comply with applicable laws, regulations, subpoenas, court orders, lawful requests from public authorities, tax and accounting obligations, and to establish, exercise, or defend legal claims.
7. Point-of-Sale Integration Data
This section applies whenever a restaurant connects a POS system to Kitchn — currently Clover and Square, and any additional providers we support in the future (such as Lightspeed or Toast). It is written to satisfy the disclosure expectations of those providers' developer programs, and it governs over any inconsistent general statement elsewhere in this Policy.
7.1 Authorization. We access a POS account only after the merchant grants authorization through that provider's OAuth flow. We request the minimum scopes required for the features the merchant has enabled — typically merchant profile, menu and item catalog (read and, where the merchant enables catalog sync, write), inventory and availability, and orders (read and write). We do not request payment-credential scopes.
7.2 Data we receive. Merchant and location profile; employee identifiers where required to attribute orders; item, category, modifier, and pricing catalog; inventory and availability state; order records including line items, modifiers, totals, taxes, discounts, and tender type; order and payment status; and refund and void status.
7.3 What we do with it — and only this. We use POS data solely and exclusively for the benefit of the merchant that authorized it, to: synchronize menus and availability between Kitchn and the POS; push Kitchn online orders into the POS; reflect POS order and payment status in the merchant's Kitchn dashboard; reconcile orders, tenders, and payouts; and produce reports for that merchant.
7.4 What we will not do.
- We do not use POS data for any purpose independent of the authorizing merchant.
- We do not sell, rent, license, or share POS data with any third party except the subprocessors listed in Appendix A acting on our behalf under written contract, or as required by law.
- We do not commingle one merchant's POS data with another merchant's data, or use one merchant's data to benefit a competitor.
- We do not use POS data to build advertising profiles or to train third-party AI models.
- We do not attempt to access cardholder data, and we do not circumvent or alter any surcharge, cash-discount, or fee configuration set by the POS provider.
7.5 Deletion on disconnection or uninstall. When a merchant disconnects an integration from the Kitchn dashboard, we immediately delete the stored OAuth tokens and stop accessing that POS account. If authorization is instead revoked, or the Kitchn application uninstalled, at the POS provider, the stored tokens cease to function, and we delete them promptly upon becoming aware of the revocation or on the merchant's request. In each case, we delete or de-identify the POS-derived data in our systems within 30 days of the disconnection, except records we are required to retain for tax, accounting, dispute-resolution, or legal-compliance purposes, which are retained under Section 11 and remain protected by this Policy.
7.6 Your relationship with the POS provider. Clover, Square, Lightspeed, and Toast each maintain their own privacy notices and their own agreements with the merchant. Nothing in this Policy modifies, limits, or overrides the merchant's agreement with its POS provider, and this Policy is not a substitute for any privacy policy a merchant is required to provide to its own customers. Where this Policy conflicts with a POS provider's applicable developer or merchant terms with respect to that provider's data, the POS provider's terms govern.
8. How We Share Personal Information
We share personal information only as described below. Kitchn does not sell personal information for monetary consideration, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. If a change to our analytics or advertising configuration would make either statement inaccurate, we will update this Policy and provide the opt-out rights applicable law requires before making that change.
| We share with | What | Why |
|---|---|---|
| The restaurant you ordered from | Your order, contact, fulfillment, and any preferences you supplied | So the restaurant can prepare and fulfill your order and manage its customer relationship. The restaurant's own privacy policy then applies to its independent use. |
| Service providers and subprocessors | Only what each needs for its function | Hosting, payments, delivery, email, mapping, analytics, and support. Each is bound by written contract limiting use to our instructions. See Appendix A. |
| Stripe | Tokenized payment data, order amounts, connected-account information | To process payments, refunds, disputes, subscriptions, and payouts. |
| POS providers (Clover, Square, Lightspeed, Toast) | Order and catalog data for the authorizing merchant only | To synchronize orders and menus, at the merchant's direction. See Section 7. |
| Delivery providers (Uber Direct) | Delivery name, phone, address, delivery instructions, order reference | To dispatch a courier and complete delivery. |
| Other diners in a group order | Your display name and your selections | Inherent to the group ordering feature you chose to join. |
| Professional advisors | As necessary | Lawyers, auditors, accountants, bankers, and insurers under duties of confidentiality. |
| Law enforcement and government | As required | To comply with law, subpoenas, court orders, and lawful requests; to protect rights, property, and safety; and to investigate fraud or security incidents. Where legally permitted, we will notify the affected restaurant before disclosing its data. |
| Acquirers in a corporate transaction | As part of due diligence or transfer | In connection with a merger, acquisition, financing, reorganization, or sale of assets. Any acquirer will remain bound by this Policy for information transferred, or we will notify you and give you the choices required by law. |
| With your direction or consent | As you specify | For example, when you choose to share a receipt or an order tracking link. |
We may also disclose aggregated or de-identified information that cannot reasonably identify you, as described in Section 6.5.
9. Communications and Your Choices
Email. Transactional emails (receipts, order status, password resets, security and billing notices) are necessary to the Services and are not subject to opt-out while your account or order is active. Marketing emails always include an unsubscribe link; unsubscribing is honored through a suppression list and takes effect promptly.
Push notifications. Where you install a Kitchn mobile application, you may enable or disable push notifications in your device settings at any time.
Text messages (SMS). The Services do not currently send text messages. If we introduce text messaging in the future, we will present program terms, consent, and opt-out instructions at enrollment.
Marketing preferences. Diners may manage marketing preferences from the account area of the storefront, from the footer of any marketing email, or by contacting the restaurant. Restaurant subscribers may manage Kitchn's marketing to them from the dashboard or by emailing info@orderkitchn.com.
10. Your Privacy Rights and Choices
10.1 Rights available to everyone
Kitchn offers the rights in this Section 10.1 voluntarily, to everyone, regardless of where you live — they are not conditioned on any particular privacy statute applying to you or to us. The state- and region-specific subsections that follow describe additional or legally mandated rights that apply where the relevant law in fact applies to Kitchn's processing. Where applicable law grants you rights beyond those described here, we will honor those rights as required by law.
Regardless of where you live, you may ask us to:
- Confirm whether we hold personal information about you and obtain a copy;
- Correct inaccurate information;
- Delete information;
- Receive a portable copy in a structured, commonly used, machine-readable format; and
- Opt out of marketing.
10.2 How to submit a request — and who to submit it to
If you are a diner or guest of a restaurant's storefront: contact the restaurant first, using the contact details on its storefront. The restaurant controls that information and decides how it is used; we act on the restaurant's instructions. If you contact us instead, we will forward your request to the relevant restaurant and assist it in responding, and we will tell you we have done so.
If you are a restaurant subscriber, a staff user, a visitor to eatkitchn.com, or someone who contacted us directly: submit your request to info@orderkitchn.com or through the privacy request form in the dashboard.
Verification. We will take reasonable steps to verify your identity before acting, typically by confirming control of the email address or phone number on the account, and for sensitive requests by requiring you to be signed in. We may ask for additional information if we cannot verify you; we will not use that information for any other purpose.
Authorized agents. You may use an authorized agent, including a parent or guardian acting for a child. We will require written authorization signed by you and may require you to verify your own identity directly.
Timing. We respond within the period required by applicable law — generally 45 days for U.S. state privacy requests, extendable once by an additional 45 days with notice. Requests are free unless they are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline, and will explain why.
Appeals. If we decline your request and you reside in a U.S. state that provides an appeal right — including Virginia, Colorado, Connecticut, Texas, Montana, Oregon, and others — you may appeal by replying to our decision or emailing info@orderkitchn.com with the subject line "Privacy Appeal." We will respond within 60 days. If your appeal is denied, we will provide a method to contact your state Attorney General.
Non-discrimination. We will not deny you service, charge you a different price, provide a different level of quality, or retaliate against you for exercising a privacy right.
10.3 Virginia residents
Where the Virginia Consumer Data Protection Act ("VCDPA") applies to Kitchn's processing of your personal data as a controller, Virginia residents have the right to confirm whether we process your personal data and to access it; to correct inaccuracies; to delete personal data you provided or we obtained; to obtain a portable copy; and to opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects. Whether the VCDPA applies depends on statutory thresholds and on the nature of the processing, not on where Kitchn is formed; where it does not apply, the voluntary rights in Section 10.1 still do. We do not sell personal data, do not engage in targeted advertising using diner or merchant data, and do not conduct profiling that produces legal or similarly significant effects. We do not process sensitive data without your consent. Submit requests as described in Section 10.2, and appeal as described above.
10.4 California residents
Where the California Consumer Privacy Act, as amended by the CPRA (the "CCPA"), applies to Kitchn's processing of your personal information as a business, California residents have the rights to know, access, delete, correct, and obtain a portable copy of personal information; to opt out of sale or sharing for cross-context behavioral advertising; and to limit the use of sensitive personal information. Whether the CCPA applies depends on its statutory thresholds; where it does not apply, the voluntary rights in Section 10.1 still do.
- We do not sell personal information and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months, including with respect to consumers we know to be under 16.
- We do not use or disclose sensitive personal information for purposes beyond those permitted under CCPA § 7027(m), so the right to limit does not currently apply. Dietary or allergen information you include in an order note is used only to fulfill that order.
- Categories collected, sources, purposes, and recipients are set out in Appendix B.
- Retention is described in Section 11.
- Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures. Requests may be sent to info@orderkitchn.com.
- Minors. California residents under 18 who have publicly posted content may request its removal by emailing info@orderkitchn.com; removal may not be complete or comprehensive where copies persist elsewhere.
10.5 Other U.S. state privacy laws
Where the comprehensive privacy law of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or another state applies to Kitchn's processing of your personal data, you have the rights that law grants, which are generally substantially similar to those described in Sections 10.1–10.3 and may include access, correction, deletion, portability, opt-out of targeted advertising and sale, and — in most of those states — an appeal right. Each of those laws has its own applicability thresholds; where a given law does not apply, the voluntary rights in Section 10.1 still do. We honor universal opt-out mechanisms such as Global Privacy Control where required. Nevada residents may submit a request not to sell covered information to info@orderkitchn.com, though we do not sell such information.
Washington and Nevada consumer health data. We do not seek to collect consumer health data as defined by the Washington My Health My Data Act or Nevada SB 370. Order notes and preferences you choose to provide are used solely to transmit your order requirements to the restaurant you ordered from, at your direction, and are never sold, shared for advertising, or used for profiling or inference.
11. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, and then delete or de-identify it. Specific periods depend on the data and the instructions of the restaurant that controls it. The periods below describe our production environment and are our standard retention targets; individual records may be retained longer where a legal hold, dispute, or regulatory obligation requires it.
| Category | Retention |
|---|---|
| Restaurant subscriber account and business records | For the term of the subscription, plus 7 years after termination for tax, accounting, and legal-defense purposes |
| Diner accounts | While the account is active; deleted or de-identified at the diner's or the restaurant's request, subject to the transaction-record row below |
| Order and transaction records | 7 years, to satisfy tax, accounting, chargeback, and dispute-resolution obligations |
| Payment tokens and payment method descriptors | Until you remove the payment method or your account is closed |
| Carts and guest sessions | Automatically expired on a rolling short-term basis |
| Marketing subscriber lists and campaign records | Per the restaurant's configuration and instruction; suppression and unsubscribe records are retained indefinitely so we can continue to honor your opt-out |
| Email engagement and delivery events | For the life of the restaurant's account; deleted or de-identified with the restaurant's data on termination |
| POS-derived data | For the life of the integration; deleted or de-identified within 30 days of disconnection (Section 7.5) |
| Login attempt and lockout records | Only for the duration of the failure or lockout window, then expired automatically; sessions expire with their tokens |
| Login audit trail | 60 days in primary storage, then archived automatically to cold storage (retained up to 7 years in production) |
| Application, access, and error logs | 30–90 days in primary storage; longer where archived for security or legal-hold purposes |
| Backups | Rolling backups are overwritten on a defined cycle; deleted records persist in backups until that cycle completes, and are not restored into production in the ordinary course |
| Support communications | 3 years |
Where a restaurant instructs us to delete data, or where a restaurant's subscription terminates, we delete or de-identify that restaurant's data in accordance with our Terms, subject to the retention obligations above and to any legal hold.
12. Security
We maintain an information security program with administrative, technical, and physical safeguards designed to protect personal information and appropriate to the nature of the Services. These include:
- Encryption — TLS for data in transit; encryption at rest for production data stores holding personal information.
- Payment isolation — cardholder data is not transmitted to or stored on Kitchn systems (Section 5).
- Access control — role-based and resource-based authorization enforced server-side; least-privilege identity and access management; multi-factor authentication available for supported account types; credentials and secrets held in managed secret stores rather than in source code.
- Tenant isolation — logical separation of each restaurant's data, enforced in the application layer and reinforced at the data layer; per-tenant identity pools and token audiences.
- Session security —
HttpOnly,Securecookies with same-site restrictions; short-lived access tokens; token revocation; login-attempt lockouts. - Network and edge protection — private subnets with no direct public database exposure; a web application firewall in front of the production API; rate limiting; and bot and abuse protections.
- Monitoring and logging — structured logging, audit trails for privileged actions, alerting, and log archival.
- Vendor management — written data protection terms with subprocessors, and review of their security posture.
- Personnel — confidentiality obligations and security training appropriate to role.
- Resilience — automated backups, high-availability multi-availability-zone deployment for production databases, and recovery procedures.
Additional detail about our security controls is available to restaurant subscribers on request (see Section 17) and, where a Data Processing Addendum applies, in its security schedule.
Incident response. We maintain an incident response plan. If a security incident affects your personal information, we will notify affected restaurants without undue delay and, where we are the controller, notify affected individuals and regulators as required by applicable law.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for safeguarding your own credentials, enabling multi-factor authentication where offered, and promptly reporting suspected compromise to info@orderkitchn.com.
13. International Data Transfers
Kitchn's infrastructure is hosted in the United States (AWS, US East region). Some of our service providers operate in other countries. If you access the Services from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your country.
The Services are offered only in the United States, and we do not transfer personal data subject to the GDPR, UK GDPR, or Swiss FADP in reliance on any specific transfer mechanism. If you nonetheless access the Services from outside the United States, you understand your information will be processed in the United States.
14. Children's Privacy
The Services are not directed to children. Restaurant subscriber accounts require users to be at least 18. Diner accounts require users to be at least 16, or the minimum age of digital consent in their jurisdiction if higher.
We do not knowingly collect personal information from children under 13, and we do not knowingly sell or share the personal information of consumers under 16. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly. A parent or guardian who believes a child has provided us information may contact info@orderkitchn.com or the relevant restaurant.
15. Third-Party Sites and Services
The Services link to and integrate with third-party websites and services, including Stripe, Clover, Square, Lightspeed, Toast, Uber, Google, and restaurants' own websites and social media. We do not control those services, and this Policy does not apply to them. Review their privacy policies before providing information to them.
16. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Last Updated" date above. If we make material changes, we will provide prominent notice — such as a banner in the Services or an email to the address on file — before the change takes effect, and where required by law we will obtain your consent. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy. Prior versions are available on request.
17. How to Contact Us
Kitchn LLC 42590 Harlow Meadows Ter Sterling, Virginia 20166 United States
Email: info@orderkitchn.com
This is our single point of contact for all privacy, data protection, and security matters. Messages are monitored and routed internally to the responsible team. To help us respond quickly, please use one of the following subject lines:
| Purpose | Subject line |
|---|---|
| Privacy questions and rights requests (access, correction, deletion, portability, opt-out) | Privacy Request |
| Appeal of a denied privacy request | Privacy Appeal |
| Security reports and vulnerability disclosure | Security |
| Merchant requests for subprocessor lists or a Data Processing Addendum | Merchant Privacy Assistance |
| General support | Support |
| Legal notices | Legal |
If you ordered from a restaurant's storefront, contact that restaurant first — it controls your information. Its contact details appear on its storefront and on your order confirmation.
Appendix A: Service Providers and Subprocessors
We engage the following categories of service providers. Each is bound by written terms restricting use of personal information to the services it performs for us.
| Provider | Function | Data involved | Location |
|---|---|---|---|
| Amazon Web Services | Cloud hosting, databases, object storage, CDN, identity pools, email delivery, queuing, serverless compute, logging | All categories | United States |
| Stripe, Inc. | Payment processing, subscription billing, Stripe Connect payouts, identity verification for payouts | Payment and payout data, order amounts, business identity data | United States |
| Clover Network, LLC (a Fiserv company) | POS integration, at the merchant's direction | Merchant, catalog, and order data (Section 7) | United States |
| Square, Inc. | POS integration, at the merchant's direction | Merchant, catalog, and order data (Section 7) | United States |
| Uber Technologies, Inc. (Uber Direct) | On-demand delivery dispatch | Recipient name, phone, delivery address, instructions, order reference | United States |
| Google LLC | Sign-in with Google; Maps, Places, geocoding, and Address Validation; Google Analytics on our marketing site | Identity claims, address and location data, marketing-site usage data | United States |
| Apple Inc. / Google LLC | Mobile push notification delivery, where mobile apps are offered | Device push tokens | United States |
A current list of subprocessors, and the ability to subscribe to notice of changes, is available to restaurant subscribers on request to info@orderkitchn.com.
Appendix B: California Notice at Collection
Categories collected in the preceding 12 months, using the categories enumerated in Cal. Civ. Code § 1798.140(v).
| CCPA category | Examples we collect | Source | Business purpose | Disclosed to | Sold or shared? |
|---|---|---|---|---|---|
| Identifiers | Name, email, phone, postal address, IP address, account and device identifiers | You; automatically; restaurants; POS providers | Service delivery, account management, security, support | Restaurants, service providers, POS and delivery providers | No |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, address, phone, payment method descriptors | You; Stripe | Order fulfillment, payment, billing | Restaurants, Stripe | No |
| Commercial information | Orders, items, transaction history, subscription and billing records, loyalty and gift card activity | You; automatically; POS providers | Order fulfillment, reporting, reconciliation, loyalty | Restaurants, service providers, POS providers | No |
| Internet or network activity | Pages viewed, clicks, session and cart activity, email opens and clicks, logs | Automatically | Service delivery, analytics, security, debugging | Service providers | No |
| Geolocation data (approximate) | City/region inferred from IP; delivery address geocoding | Automatically; you | Restaurant discovery, delivery eligibility, fraud prevention | Service providers, delivery providers | No |
| Audio, electronic, or visual information | Photos uploaded to reviews or profiles; support message content | You | Service delivery, support | Restaurants, service providers | No |
| Professional or employment information | Role, restaurant assignment, staff identifiers from POS | You; restaurants; POS providers | Access control, order attribution | Restaurants, service providers | No |
| Inferences | Audience segment membership, order preferences | Derived | Restaurant's own marketing, at its direction | Restaurants, email service provider | No |
| Sensitive personal information | Account credentials; dietary/allergen or religious-observance information you include in order notes | You | Authentication; communicating order requirements to the restaurant. Not used for inference or marketing. | Restaurants (order notes only) | No |
We retain each category for the periods stated in Section 11.