Skip to main content
Branded Bites

Legal

Privacy Policy

Effective April 6, 2026 · Last updated August 3, 2026

This Privacy Policy explains how Branded Bites LLC ("Branded Bites," "we," "our," or "us") collects, uses, discloses, and protects personal information in connection with our marketing website at brandedbites.com and our direct ordering and customer marketing platform for restaurants (the "Platform"). It also describes the privacy rights available to you under applicable United States law, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and similar state laws.

1

Who We Are and Our Roles

Branded Bites LLC is an Illinois limited liability company headquartered at 444 W Lake St, Chicago, IL 60606. We operate the marketing website at brandedbites.com and the Branded Bites Platform, which powers branded online ordering websites and mobile apps, loyalty and rewards programs, SMS and email marketing campaigns, delivery handoff, Toast POS integration, and customer analytics for restaurants.

Business / Controller

When we collect and process information about visitors to brandedbites.com (such as demo request form submissions and website analytics), and when we process information about our restaurant customers (your account data, billing contacts, and usage of the Branded Bites dashboard), we act as the business/controller that determines the purposes and means of processing. This Privacy Policy applies in full to those activities.

Service Provider / Processor

When a restaurant uses the Branded Bites Platform to manage its own customer relationships — processing orders, running loyalty programs, managing guest contact information, and sending marketing messages — that restaurant is the business/controller for its guests' data. Branded Bites acts as a service provider/processor for that data, operating under the restaurant's instructions and the Data Processing Addendum (DPA) available at /dpa. In that capacity, we do not use guest data for our own marketing or sell it to third parties.

2

Information We Collect

From Website Visitors (brandedbites.com)

  • Demo request form: restaurant name, contact name, email address, phone number, restaurant website, number of locations, current POS, current delivery platforms, approximate monthly online order volume, primary goal, and any message you choose to include.
  • Usage data via Google Analytics 4 (when you consent): pages visited, time on page, approximate location derived from IP address, referring URL, browser type and version, and device type. This data is collected through first- and third-party cookies as described in our Cookie Policy.
  • Technical data automatically provided by your browser: IP address, user agent string, and language preference. We use this data solely for security, fraud prevention, and server operation.

From Restaurant Customers (Platform Accounts)

  • Account registration: business name, contact name, email address, phone number, restaurant website, number of locations, and POS system.
  • Billing and payment: billing contact information. Payment card data is transmitted directly to and stored exclusively by our payment processor; we do not store full payment card numbers.
  • Platform usage: dashboard activity, feature usage, campaign configuration, menu data, and communications with our support team.
  • Communications: emails, support tickets, and chat messages you send to us.

From Diners (as Service Provider on behalf of Restaurants)

When diners use a restaurant's branded ordering website or mobile app powered by Branded Bites, we process the following categories of information on behalf of and under the instructions of the restaurant:

  • Account and contact: name, email address, phone number, and delivery address.
  • Order history: items ordered, order frequency, order values, and fulfillment method.
  • Payment data: tokenized payment information provided by our payment processor. We do not store full card numbers.
  • Loyalty data: points balances, reward redemptions, tier status, and engagement history.
  • Marketing preferences: SMS and email opt-in status and campaign engagement.
  • Device and usage data: app or browser type, session data, and feature interaction to support platform functionality.
If you are a restaurant guest and want to understand how your data is used, please review the privacy policy of the specific restaurant from which you are ordering. For data deletion or access requests related to your order history or loyalty account, contact that restaurant directly. Branded Bites will assist restaurants in responding to valid guest requests.

Information We Do Not Collect

  • We do not knowingly collect information from children under 13. See Section 14 (Children's Privacy).
  • We do not collect health or medical information.
  • We do not collect Social Security numbers or government ID numbers.
  • We do not collect or store biometric identifiers for authentication. If we ever add biometric features beyond your device's built-in authentication (Face ID, Touch ID), we will update this Policy and comply with the Illinois Biometric Information Privacy Act (BIPA). See Section 15 (Biometrics and BIPA).
3

How We Use Information

We use the information we collect for the following business purposes:

  • To respond to demo requests and schedule product demonstrations.
  • To provide, operate, maintain, and improve the Branded Bites Platform.
  • To process orders, manage loyalty programs, and enable marketing campaigns on behalf of restaurants.
  • To bill restaurant customers and manage their accounts.
  • To send transactional communications, including account notices, security alerts, and support responses.
  • To send restaurant customers promotional communications about Branded Bites products and services, subject to their marketing preferences.
  • To analyze how our website and Platform are used, improve our products, and measure the effectiveness of our marketing (subject to your consent for analytics cookies).
  • To train, evaluate, and improve AI-powered features within the Platform, using aggregated and de-identified data where possible. See Section 8 (Artificial Intelligence Features).
  • To detect, investigate, and prevent security incidents, fraud, and violations of our Terms of Service.
  • To comply with legal obligations and respond to lawful government requests.
  • To enforce our agreements and protect the rights, safety, and property of Branded Bites, our customers, and the public.
4

Data Sharing and Disclosure

We do not sell your personal information, and we do not share it for cross-context behavioral advertising without your consent. We disclose information in the following circumstances:

Service Providers

We engage service providers (subprocessors) that process personal information on our behalf to operate the Platform and this website. These providers are contractually required to use data only for the services they provide to us and to maintain appropriate security. See our Subprocessor List for the current list. Categories of providers include:

  • Email delivery: Resend (processes demo request notifications)
  • Payment processing: our third-party payment processor (processes card data; see your card receipt for the processor identity)
  • Analytics: Google Analytics 4 (processes website usage data when you consent)
  • Cloud infrastructure: hosting, storage, and database providers
  • POS integration: Toast (for restaurants using Toast integration, order data is shared with Toast)
  • Delivery partners: Uber Direct and DoorDash Drive (for applicable delivery orders, relevant order data is shared)
  • Messaging providers: SMS and email marketing infrastructure providers
  • AI providers: third-party AI model providers (see Section 8)
  • Customer support: support platform providers

Restaurants

Information about diner orders, loyalty balances, and marketing engagement is shared with the restaurant on whose behalf we are acting as a service provider. Restaurants use this data to operate their ordering channels and marketing programs.

Business Transfers

If Branded Bites is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, personal information may be transferred as part of that transaction. We will provide notice before personal information becomes subject to a different privacy policy.

Legal Requirements

We may disclose information if we believe in good faith that doing so is necessary to comply with applicable law or a valid legal process, to protect the safety of any person, or to protect our rights and property.

With Your Consent

We may share information with third parties when you have given us explicit consent to do so.

5

Analytics and Tracking

We use Google Analytics 4 (GA4) to understand how visitors use our website. GA4 collects data through cookies and assigns a persistent identifier to your browser. The data collected includes pages viewed, session duration, approximate geographic location, device type, and referring sources. This data is processed by Google in accordance with Google's privacy policy.

We implement Google Consent Mode v2. Analytics tracking is disabled by default until you accept cookies using our cookie consent banner. If you decline or dismiss the banner, or if your browser signals the Global Privacy Control (GPC), we will not activate analytics storage.

You can manage your analytics preferences at any time by clicking the "Your Privacy Choices" link in our website footer, by using Google's opt-out browser add-on, or by visiting our Cookie Policy for full details.

6

Cookies and Similar Technologies

Our website uses cookies and similar technologies. "Strictly necessary" cookies are required for the website to function and cannot be disabled. "Analytics" cookies, including Google Analytics cookies, are only set if you consent. We also store your consent preference in your browser's local storage.

For a complete list of cookies, their purpose, duration, and instructions for managing or deleting them, please see our Cookie Policy.

7

Artificial Intelligence Features

The Branded Bites Platform includes and will continue to add AI-powered features designed to help restaurants operate more effectively. Current and planned AI use cases include:

  • Analytics insights: AI analysis of order patterns, campaign performance, and customer behavior to surface actionable recommendations for restaurants.
  • Campaign and content generation: AI-assisted drafting of SMS and email campaign copy, menu descriptions, and promotional offers.
  • Customer segmentation: AI-driven identification of customer groups for targeted marketing.
  • A site assistant or chatbot on brandedbites.com to answer questions about our product.

Data Sent to AI Providers

To power these features, we may transmit aggregated or pseudonymized data, including order data, customer segments, and campaign content, to third-party AI model providers. We select providers that agree to process this data only for the purpose of delivering the requested service and that commit not to use it to train their general models without authorization.

AI Output Limitations

AI-generated content and recommendations may be inaccurate, incomplete, or inappropriate for a particular restaurant's context. Restaurant operators are responsible for reviewing AI-generated content before publishing it. Branded Bites makes no warranty regarding the accuracy or fitness of AI-generated outputs. See also our Disclaimer.

Human Review

We do not use fully automated decision-making that produces legal or similarly significant effects on individuals without human oversight. Restaurants retain control over whether and how AI-generated content and recommendations are applied.

8

Data Retention

We retain personal information for as long as necessary to provide our services, fulfill the purposes described in this Policy, comply with our legal obligations, resolve disputes, and enforce our agreements. Typical retention periods are:

Data CategoryApproximate Retention Period
Demo request submissions24 months from submission
Restaurant account dataDuration of account plus 5 years after termination
Diner order and loyalty data (as service provider)As directed by the restaurant; we delete or return data within [RETENTION PERIOD] of receiving a valid deletion instruction
Analytics data (with consent)As configured in Google Analytics (default 14 months)
Consent records7 years or as required by applicable law
Financial and billing records7 years or as required by applicable law
Security and access logs12 months
Placeholder: The retention periods marked [RETENTION PERIOD] must be confirmed with your data governance and legal counsel before publication.
9

Your Privacy Rights

Depending on where you reside, you may have certain rights regarding your personal information. We describe these rights below and explain how to exercise them.

California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the CCPA/CPRA:

  • Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, our business purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to delete: You may request that we delete personal information we have collected about you, subject to certain exceptions (such as data we need to complete a transaction, detect fraud, comply with legal obligations, or exercise our legal rights).
  • Right to correct: You may request correction of inaccurate personal information we maintain about you.
  • Right to opt out of sale or sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising without your consent. You can withdraw analytics consent at any time via the "Your Privacy Choices" link in our footer.
  • Right to limit use of sensitive personal information: We do not collect or use sensitive personal information beyond the purposes for which we have disclosed it.
  • Right to non-discrimination: We will not discriminate against you for exercising any of these rights.

To submit a California privacy rights request, email us at ${company.privacyEmail} with the subject line "California Privacy Rights Request" or write to us at ${company.address}. We will verify your identity before responding. We will respond within 45 days of receipt; if we need more time (up to 90 days total), we will notify you.

Other US State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with comprehensive privacy laws have rights that are similar to those described above for California residents. These typically include the right to access, correct, delete, and obtain a portable copy of your personal information, and the right to opt out of the processing of personal information for targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects.

To exercise your rights under applicable state law, contact us as described in the California section above. We honor all verified requests from residents of states with active privacy laws and will respond within the timeframe required by your state's law.

Global Privacy Control

We honor the Global Privacy Control (GPC) signal. If your browser or browser extension communicates a GPC signal when you visit brandedbites.com, we will treat it as a request to opt out of the use of your personal information for analytics and any sharing that constitutes a sale or sharing for cross-context behavioral advertising under applicable law. You will not need to separately interact with our cookie consent banner.

Agents

California and some other state residents may designate an authorized agent to submit privacy rights requests on their behalf. We require the authorized agent to provide written authorization signed by you, and we may separately verify your identity.

10

Loyalty Program and Financial Incentive Notice

The Branded Bites Platform enables restaurants to offer loyalty programs to their guests. If you participate in a restaurant's loyalty program powered by Branded Bites, you provide personal information (name, contact, order history, visit frequency) in exchange for points, rewards, or other benefits. This arrangement may constitute a "financial incentive" under the CCPA/CPRA.

The value of the financial incentive to participating guests — in the form of reward discounts, free items, and exclusive offers — is reasonably related to the value the restaurant derives from the loyalty relationship, namely increased order frequency and customer retention. Participation in any loyalty program is entirely optional, and you may withdraw at any time by contacting the restaurant or us at ${company.email}.

The restaurant, as the controller for its guest data, maintains its own financial incentive disclosure, which may be displayed in the restaurant's ordering app or website.

11

Security

We implement administrative, technical, and physical security measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit (TLS), access controls, and security monitoring.

No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee the absolute security of your information. If you believe your information has been compromised, please contact us immediately at ${company.email}.

Payment card data is processed by our third-party payment processor in accordance with PCI-DSS standards. We do not store full payment card numbers on our systems.

13

Children's Privacy

The Branded Bites website and Platform are not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete that information promptly.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at ${company.email}.

14

Biometrics and Illinois BIPA

Branded Bites LLC is an Illinois company and takes its obligations under the Illinois Biometric Information Privacy Act (BIPA) seriously. BIPA, 740 ILCS 14/, governs the collection, storage, use, and destruction of biometric identifiers (such as fingerprints and facial geometry scans) and biometric information.

As of the effective date of this Policy, Branded Bites does not collect, capture, purchase, receive through trade, or otherwise obtain any biometric identifiers or biometric information from restaurant employees, guests, or any other individuals. Device-level authentication features such as Apple Face ID and Touch ID are controlled by the device operating system, not by Branded Bites, and Branded Bites does not have access to the underlying biometric data.

If we ever introduce features that would involve the collection of biometric identifiers or biometric information, we will: (a) provide a written notice describing the specific purpose and length of term for collection, storage, use, and disclosure before any collection occurs; (b) receive a written release executed by the individual; (c) develop a publicly available retention schedule and destruction policy; and (d) store, transmit, and protect all biometric data using the standard of care required by BIPA. We will update this Policy to reflect any such change.

15

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this Policy and, where appropriate, provide additional notice (such as by email to restaurant account holders or a prominent notice on our website). Your continued use of our website or Platform after the effective date of the updated Policy constitutes your acceptance of the changes.

16

How to Contact Us

If you have questions, comments, or requests regarding this Privacy Policy or our data practices, please contact us:

We will respond to all requests within the timeframe required by applicable law, but we aim to respond to all inquiries within 10 business days.

Not legal advice. This document is for informational purposes. It does not constitute legal advice. For questions about your specific legal situation, consult a licensed attorney.