BiteBuddy legal
Privacy Policy
How BiteBuddy collects, uses, shares, and protects personal information across our ordering platform and related services.
1. Privacy at a glance
- BiteBuddy is an online ordering technology platform for participating restaurants.
- The restaurant that receives your order is responsible for preparing and fulfilling it.
- BiteBuddy processes information needed for ordering, accounts, security, loyalty features (where offered), support, and communications you have agreed to receive.
- Order information is shared with the restaurant fulfilling your order and with service providers who help operate the platform.
- Unrelated restaurants do not receive your information for marketing purposes.
- BiteBuddy does not sell personal information.
- You may request access to or correction of your personal information, and you may withdraw marketing consent.
2. Who we are and scope
This Privacy Policy explains how BiteBuddy collects, uses, discloses, and protects personal information when you use our Services.
The Services are operated by Whitespace Studio LLP, operating as BiteBuddy (“BiteBuddy,” “we,” “us,” or “our”), based in Richmond, British Columbia, Canada.
This Policy is intended to comply with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial legislation, including British Columbia’s Personal Information Protection Act (BC PIPA).
This Policy applies to personal information collected in connection with:
bitebuddy.caand related BiteBuddy marketing pages;- restaurant ordering pages on
order.bitebuddy.ca; - customer accounts, guest checkout, loyalty, coupons, and related optional features where offered;
- the BiteBuddy Restaurant Manager tablet application and operator tools; and
- support and service-related communications.
Features may vary by restaurant. Depending on the restaurant’s settings, you may see guest checkout, accounts, loyalty or rewards, coupons or offers, scheduled ordering, email or SMS marketing opt-in, or brand-group features shared across related locations.
This Policy does not apply to third-party websites, apps, or services that BiteBuddy does not control, even if linked from our Services.
3. BiteBuddy and restaurant responsibilities
BiteBuddy provides ordering technology. Participating restaurants are independent businesses. Related locations may operate as a disclosed brand group. Service providers help us host, process payments, send messages, and secure the platform.
| Party | Primary role | Typical information responsibilities |
|---|---|---|
| BiteBuddy | Ordering technology platform operator | Operates the platform; processes personal information for ordering, accounts, security, support, loyalty tooling (where enabled), and communications; sets platform privacy practices described in this Policy. |
| Participating restaurant | Food seller and fulfillment business | Receives order and contact details needed to prepare and fulfill your order; responsible for food quality, safety, pricing, inventory, and restaurant operations; may run restaurant-specific marketing where you consent. |
| Related brand group | Disclosed group of related locations | Where clearly disclosed, may share limited customer-program information across related locations (for example loyalty balances, offers, or brand-group marketing preferences). |
| Service providers | Hosting, payments, messaging, security, and similar vendors | Process information only as needed to provide their services to BiteBuddy or the restaurant under contractual safeguards. |
Depending on the context, BiteBuddy may act as the organization responsible for personal information collected through the platform, and in some operational contexts as a service provider handling information to support a restaurant’s order fulfillment.
4. Information we collect
We collect personal information that is reasonably necessary to operate, secure, and improve the Services.
4.1 Account and membership information
Name, email address, phone number, authentication credentials (stored in protected form), account preferences, membership or loyalty status where offered, marketing preferences, and information you provide when creating or activating an account.
4.2 Order and transaction information
Items ordered, modifiers and notes, prices, taxes, tips, discounts and totals, timestamps, order status and fulfillment details, order history, coupon or loyalty redemptions, and refund, cancellation, or chargeback-related records.
4.3 Contact and fulfillment information
Name, email, phone number, pickup details, delivery address if delivery is offered for that restaurant, and other information you provide to help fulfill an order.
4.4 Payment information
Payments are processed by the third-party payment processor displayed or otherwise identified during checkout (for example, Stripe or Helcim, depending on the restaurant’s configuration). We may receive limited payment-related information such as transaction identifiers, payment status, refund identifiers, and limited card details such as brand or last four digits where provided by the processor. We do not store full credit card numbers.
4.5 Technical and usage information
IP address or masked IP subnet information, browser and device information, app version (for Restaurant Manager), log events, page interactions needed to operate the Services, crash or performance diagnostics where available, and cookies or similar technologies described in section 10.
4.6 Fraud prevention and security information
Masked IP subnet data, hashed device or browser identifiers, user-agent hashes, challenge or verification status (including one-time codes), suspicious activity signals, risk checks, rate-limiting events, and dispute or fraud investigation records.
4.7 Restaurant staff information
If you use Restaurant Manager or operator tools as restaurant staff, we may collect login information, restaurant access scope, device and app usage logs, operational actions, and diagnostic, connectivity, or printer-related logs.
5. How we collect information
- directly from you (for example when you place an order, create an account, or update preferences);
- automatically when you use the Services;
- from participating restaurants in connection with your order or a support request;
- from service providers such as payment processors, hosting providers, messaging providers, and security tools; and
- from fraud prevention, verification, and security systems used to protect the platform.
If non-identifiable information is combined with personal information, we treat the combined information as personal information.
6. How we use information
We use personal information to:
- operate the ordering platform and transmit orders to restaurants;
- create and manage customer accounts and guest checkout records;
- process payments, refunds, and related records through payment processors;
- provide customer support;
- operate optional loyalty, rewards, coupon, and offer features where enabled;
- send transactional communications and, where permitted, marketing communications;
- maintain security, prevent fraud and abuse, and investigate disputes; and
- comply with legal obligations and enforce our agreements.
Where a restaurant participates in a disclosed brand group, we may use limited information to operate shared customer-program features across those related locations.
We do not use personal information for materially different purposes without notice and consent where required by applicable law.
7. Fraud prevention and automated security checks
To protect customers, restaurants, and the platform, certain actions may be subject to automated risk analysis and security checks. This may include reviewing order, device, network, and verification signals.
If elevated risk is detected, we may require additional verification (such as a one-time code), delay processing, or decline a transaction. In a chargeback or dispute, we may use order records, timestamps, verification logs, and related security signals as evidence.
9. Email, SMS, and marketing consent
Commercial electronic messages are sent only with valid consent or another lawful basis under applicable law, including Canada’s Anti-Spam Legislation (CASL). Marketing consent is not a condition of purchase.
9.1 Transactional vs. marketing communications
Transactional communications are related to an order, account, or security event. Examples include:
- order confirmations;
- receipts;
- pickup or fulfillment updates;
- refund or cancellation notices;
- one-time verification codes; and
- account security and account-claim messages.
Marketing communications promote products or programs. Examples include:
- promotions;
- coupons;
- new menu announcements;
- loyalty campaigns;
- win-back messages; and
- other promotional email or SMS.
9.2 Separate email and SMS consent
Email consent and SMS consent are managed separately. Consenting to email marketing does not automatically consent to marketing SMS, and vice versa.
Marketing consent may be collected and managed at the restaurant level or, where clearly disclosed, at the brand-group level. Opting out from one restaurant or brand group may not automatically opt you out of every other restaurant on BiteBuddy unless the message or preference controls say otherwise.
9.3 SMS messaging
If you provide a phone number and request verification, enable notifications, or otherwise use phone-based features, we may send transactional SMS such as one-time codes or service notices. Where a restaurant offers marketing SMS and you opt in, we may send promotional texts for that restaurant or disclosed brand group.
- Message frequency varies.
- Message and data rates may apply.
- Reply STOP to opt out of SMS from that messaging program.
- Reply HELP for help.
- Opting out of SMS may limit phone verification or notification features that rely on text messages.
- Marketing SMS requires separate consent and is not a condition of purchase.
- Transactional toll-free senders are not used for marketing purposes.
You may also manage certain communication preferences in your account profile where available, or contact us at support@bitebuddy.ca.
10. Cookies and analytics
We use cookies and similar technologies as needed to operate the Services. Essential technologies support core functions such as session management, authentication, security, and checkout.
On the BiteBuddy marketing website (bitebuddy.ca), we may use analytics and tag-management tools (including Google Analytics via MonsterInsights and Google Tag Manager) to understand site traffic and improve content. On the ordering application (order.bitebuddy.ca), we use security tools such as Cloudflare Turnstile for bot protection and first-party operational logging needed to run checkout and accounts. The Restaurant Manager tablet application may include diagnostic tooling such as crash reporting.
BiteBuddy does not currently provide a separate cookie preference center. You can control cookies through your browser settings, understanding that blocking essential cookies may affect site functionality. Where a third-party analytics provider offers an opt-out mechanism, you may use that provider’s tools as well.
11. International processing
BiteBuddy is based in British Columbia, Canada. Personal information may be stored or processed outside your province or outside Canada, including in the United States, by our service providers (for example hosting, authentication, payment, email, and messaging providers). In those cases, information may be subject to the laws of those jurisdictions. We take reasonable steps to ensure appropriate protection consistent with Canadian privacy laws.
12. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, or as otherwise required or permitted by law.
Retention depends on the type of record and its purpose. For example:
- account and order records are kept while your account is active and as needed for order history, support, accounting, tax, fraud prevention, and dispute handling;
- if you request account deletion, we generally place the request on a hold period (currently 30 days) before anonymizing identity fields, while retaining minimal transaction records needed for legal, tax, or fraud purposes;
- certain security and operational logs are cleaned up on scheduled retention cycles (for example, many security challenge, trust, and block records are retained for up to about 12 months, some deduplication records longer, device-command logs about 90 days, and certain operational event logs for shorter periods); and
- fraud, chargeback, or legal dispute records may be kept until the matter is closed and longer where needed for legal or risk purposes.
When information is no longer required, it is deleted, anonymized, or de-identified where appropriate.
13. Security
We implement reasonable safeguards designed to protect personal information, including encryption in transit, role-based access controls, secure credential storage, logging and monitoring, and environment controls. No system can be guaranteed to be completely secure.
14. Your rights and choices
Subject to applicable law, you may have the right to:
- request access to your personal information;
- request correction of inaccurate information;
- request deletion where legally permitted;
- withdraw consent for certain uses, including marketing;
- request information about how your information is used or shared; and
- ask questions about shared brand-group programs where applicable.
We may need to verify your identity before responding. We may retain certain information where required for legal, accounting, fraud prevention, dispute resolution, or compliance reasons.
Privacy requests may be sent to the Privacy Officer at support@bitebuddy.ca.
15. Children’s privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information, contact us and we will take appropriate steps.
16. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” and “Effective date” at the top of this page will change when an update takes effect.
- Non-material changes may take effect when posted.
- Material changes that affect your rights or our data practices may be accompanied by email or in-service notice where appropriate.
- Changes that require a new legal consent will be presented for consent before they apply to you.
17. Contacting the Privacy Officer
Privacy Officer
Whitespace Studio LLP (BiteBuddy)
Richmond, British Columbia, Canada
Email: support@bitebuddy.ca
If your concerns are not resolved, you may contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy authority.
