Privacy Policy
Last updated 29 September 2026
This policy explains how OrderGURU ("we", "us") handles personal data. We are a platform that lets food businesses ("vendors") take orders from their customers. Because we serve two groups of people, this policy covers both.
1. Who is responsible for your data
- Vendors and their staff. For the account and business details you give us when you sign up, we are the data controller.
- Customers ordering from a vendor. When you order from a business using OrderGURU, that business decides why and how your order details are used, so they are the controller. We process the data on their behalf to run the ordering service, and we are the controller only for the limited purposes of keeping the platform secure, preventing fraud and meeting our legal duties.
2. What we collect
- Vendor accounts: name, email address, password (stored only as a secure hash), business name, menu and settings, and staff details you add.
- Customer orders: name, email address, phone number, delivery address where relevant, order contents, notes, and loyalty points earned or spent.
- Payments: card payments are handled by Stripe. We never see or store full card numbers. We receive a payment reference and the amount.
- Technical data: IP address, browser type and basic logs, used for security and to keep the service working.
- Marketing choices: whether a customer agreed to hear from a particular vendor.
3. How we use it
- To provide the service: taking orders, taking payment, sending order updates by email and text, and showing vendors their orders and reports.
- To keep the service secure, prevent abuse and spam, and investigate problems.
- To contact vendors about their account and the service.
- To meet legal, tax and accounting duties.
Our legal bases are performing our contract with you, our legitimate interests in running a secure service, your consent where we ask for it (for example marketing emails from a vendor), and legal obligation.
4. Who we share it with
- The vendor you order from, who receives the details needed to fulfil your order.
- Stripe, for payments.
- Email and text message providers, so we can send order updates.
- Hosting and infrastructure providers who store data for us.
- Authorities, where the law requires it.
We do not sell personal data.
5. Cookies
We use only the cookies needed to make the service work, such as keeping you signed in and remembering your basket and orders during a visit. We do not use advertising cookies.
6. How long we keep it
We keep vendor account data while the account is open and for a reasonable period afterwards. Order records are kept as long as needed for the vendor's accounting and legal obligations, then deleted or anonymised. Unconfirmed sign ups are deleted automatically after a few days.
7. Your rights
Under UK data protection law you can ask to see, correct or delete your personal data, object to or restrict how it is used, ask for a copy in a portable format, and withdraw consent at any time. If you are a customer, the quickest route is usually the vendor you ordered from, but you can also contact us and we will help. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.
8. Security
We protect data with encryption in transit, hashed passwords, strict separation between businesses and access controls for our team. No system is perfectly secure, so please use a strong, unique password.
9. Changes
We may update this policy and will change the date above when we do.
10. Contact
Questions or requests about your data? Contact us and we will reply within one working day.