Legal
Data Processing Addendum
Effective April 6, 2026 · Last updated August 3, 2026
This Data Processing Addendum ("DPA") is entered into between Branded Bites LLC ("Branded Bites") and the restaurant customer ("Restaurant") and is incorporated into and made part of the Terms of Service. It governs Branded Bites' processing of personal information of Restaurant guests ("Guest Data") on behalf of the Restaurant in connection with the Branded Bites Platform. This DPA is designed to satisfy the contractual requirements imposed on service providers under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and similar US state privacy laws.
Definitions
Capitalized terms not defined in this DPA have the meaning given in the Terms of Service.
- "Guest Data" means personal information of Restaurant's end-customers (diners) that Branded Bites processes on behalf of Restaurant in connection with the Platform, including order data, contact information, loyalty data, payment tokens, and marketing preferences.
- "Personal Information" has the meaning given in applicable privacy law, including the CCPA/CPRA.
- "Sale" and "Sharing" have the meaning given in the CCPA/CPRA.
- "Business Purpose" has the meaning given in the CCPA/CPRA.
- "Subprocessor" means a third party engaged by Branded Bites to process Guest Data.
- "Controller" and "Processor" (or equivalent terms) have the meanings given in applicable state privacy law.
Scope and Parties' Roles
Restaurant is the business/controller of Guest Data for purposes of applicable US privacy law. Branded Bites is a service provider/processor of Guest Data, processing it on behalf of and under the instructions of Restaurant solely for the Business Purposes described in Section 3.
This DPA applies only to Guest Data (diner personal information). For Branded Bites' own website visitor data and restaurant account holder data, Branded Bites acts as the controller and its Privacy Policy governs.
Processing Instructions and Business Purposes
Branded Bites will process Guest Data only on Restaurant's documented instructions and only for the following Business Purposes:
- 1Operating and providing the direct ordering website and mobile app on behalf of Restaurant.
- 2Processing guest orders and coordinating delivery or pickup fulfillment.
- 3Managing the Restaurant's loyalty and rewards program.
- 4Sending SMS and email marketing campaigns as configured and authorized by Restaurant.
- 5Processing payments through our third-party payment processor.
- 6Synchronizing order data with Toast POS as configured by Restaurant.
- 7Coordinating delivery handoff with Uber Direct or DoorDash Drive as configured by Restaurant.
- 8Providing order analytics, campaign reporting, and customer behavior reporting to Restaurant.
- 9Powering AI-assisted analytics insights and campaign recommendations for Restaurant.
- 10Providing customer support to Restaurant's guests when directed by Restaurant.
- 11Detecting fraud, security incidents, and preventing violations of our Terms.
- 12Complying with applicable legal obligations.
Branded Bites will not process Guest Data for any other purpose, including for Branded Bites' own commercial benefit, advertising to guests on behalf of other restaurants, or sale or sharing of Guest Data with third parties except as a Subprocessor relationship disclosed under Section 6.
If Branded Bites receives an instruction that it believes violates applicable law, it will notify Restaurant promptly.
Guest Privacy Rights Assistance
Restaurant is primarily responsible for responding to privacy rights requests from its guests (diners). Branded Bites will:
- Promptly notify Restaurant if Branded Bites receives a privacy rights request directly from a Restaurant guest, and direct the guest to contact the Restaurant.
- Assist Restaurant in responding to verified guest requests to access, correct, delete, or obtain a portable copy of their personal information, to the extent Branded Bites has the technical capability to do so.
- Process deletion instructions received from Restaurant within [DELETION TIMEFRAME — e.g., 30 days] of receiving a complete, verified instruction.
- Implement opt-out signals (including STOP for SMS) from guests within the Platform's technical capabilities.
Confidentiality
Branded Bites ensures that personnel authorized to process Guest Data are subject to appropriate confidentiality obligations. Branded Bites will not disclose Guest Data to any person except as necessary for the Business Purposes, as authorized by Restaurant, or as required by law.
Subprocessors
Restaurant authorizes Branded Bites to engage Subprocessors to assist in providing the Platform services. Current Subprocessors that may process Guest Data are listed at /subprocessors. Branded Bites will:
- Provide at least 30 days' advance notice before adding or replacing a Subprocessor that processes Guest Data.
- Impose data protection obligations on each Subprocessor that are no less protective than those set out in this DPA.
- Remain responsible to Restaurant for the performance of each Subprocessor's obligations under this DPA.
Restaurant may object to a new Subprocessor within 14 days of notice by contacting us at ${company.email}. If Restaurant objects and Branded Bites cannot provide the services without the new Subprocessor, either party may terminate the affected services with 30 days' written notice.
Security
Branded Bites implements and maintains technical and organizational security measures appropriate to the risk to Guest Data, including:
- Encryption of Guest Data in transit using TLS.
- Encryption of sensitive data at rest.
- Access controls limiting access to Guest Data to authorized personnel with a business need.
- Security monitoring and incident response procedures.
- PCI-DSS compliant payment data handling through our payment processor (we do not store full card numbers).
Security Incidents
If Branded Bites becomes aware of a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Guest Data, Branded Bites will notify Restaurant without undue delay and in any event within [TIMEFRAME — e.g., 72 hours] of becoming aware of the incident. The notification will include the information required by applicable law.
Data Return and Deletion
Upon termination or expiration of the Terms of Service, or upon Restaurant's written request, Branded Bites will:
- 1Provide Restaurant with a reasonable opportunity (not less than 30 days after termination) to export Guest Data in a machine-readable format.
- 2After the export window, delete or destroy Guest Data from Branded Bites' systems within [TIMEFRAME — e.g., 90 days], except to the extent retention is required by applicable law.
- 3Confirm completion of deletion to Restaurant in writing upon request.
Audit Rights
Branded Bites will make available to Restaurant information reasonably necessary to demonstrate compliance with this DPA, including providing written responses to security questionnaires. Upon 30 days' advance written notice, Branded Bites will accommodate an audit by Restaurant or a qualified third-party auditor, subject to reasonable confidentiality protections and scheduling requirements. Audits are limited to one per calendar year absent a demonstrated security incident.
General Provisions
This DPA supplements and is incorporated into the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding data processing, this DPA controls. This DPA is governed by the same law and dispute resolution provisions as the Terms of Service. If applicable law changes in a way that requires modifications to this DPA, the parties will cooperate in good faith to amend this DPA accordingly.
For questions about this DPA, contact us at support@brandedbites.app or at 444 W Lake St, Chicago, IL 60606.