Legal
Privacy Policy
Last updated August 30, 2026
This policy explains what personal data PlateLogic collects, why we collect it, who we share it with, how long we keep it and how you can control it.
It applies to plate-logic.com, the restaurant and staff consoles, the embeddable menu, and ordering storefronts we host for restaurant subscribers.
1. Who we are and our role
PlateLogic c/o MagnetIQ Marketing Solutions ("PlateLogic", "we", "us") operates the PlateLogic online ordering platform at plate-logic.com and on restaurant domains we host. Our registered address is 5900 Balcones Drive #31323, Austin, TX 78731, USA.
PlateLogic serves two groups. For restaurant subscribers and their staff, we act as the controller of the account, billing and support data we need to run the platform. For diner data submitted through a restaurant's storefront (names, contact details, order contents, delivery addresses), the restaurant is the controller and PlateLogic acts as a processor or service provider that handles that data on the restaurant's instructions.
If you ordered food from a restaurant that uses PlateLogic and want your data changed or deleted, you may contact the restaurant directly or contact us and we will route your request to the correct restaurant.
2. Personal data we collect
Depending on how you use PlateLogic, we may collect:
- Account data: name, business name, email address, phone number, hashed password, role and permissions, staff PIN hashes, and multi-factor authentication settings.
- Order data: items ordered, modifiers, order notes, order totals, pickup/delivery/dine-in method, delivery address, table number, order status timestamps, and cancellation or refund requests.
- Payment data: the last four digits, card brand, and payment/transaction identifiers returned by our payment processor. We never receive or store full card numbers, CVV codes or bank credentials.
- Communication data: emails and SMS messages we send on a restaurant's behalf, delivery/bounce/complaint events, opt-out (STOP) status, and support correspondence.
- Reviews and loyalty data: ratings, review text, loyalty point balances, promotion redemptions and store credit.
- Device and usage data: IP address, browser and device type, pages and menus viewed, embed loads, checkout starts, order completions, push notification tokens, and error diagnostics.
- Location data: a restaurant's business address and geocoded coordinates, and a delivery address that a guest chooses to enter. We do not track a device's background location.
3. How and why we use personal data
We use personal data only for the purposes below, and each purpose has a lawful basis. We describe the GDPR-style basis even though PlateLogic is currently offered to United States businesses.
- Providing the Services: taking and routing orders, kitchen notifications, dispatching delivery, table and reservation management, and account access. Basis: performance of a contract.
- Payments, billing and fraud prevention, including subscription invoicing and refunds. Basis: contract and legitimate interests.
- Transactional messaging: order confirmations, status updates, receipts, password resets and verification. Basis: contract.
- Marketing messaging: promotions, loyalty offers and review requests. Basis: consent, and you can opt out at any time.
- Security, abuse prevention, audit logging and rate limiting. Basis: legitimate interests and legal obligation.
- Product analytics and improvement using aggregated or de-identified data wherever possible. Basis: legitimate interests.
- Legal compliance, tax records, and defending or bringing legal claims. Basis: legal obligation and legitimate interests.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising. We do not knowingly collect data from children under 13.
4. Service providers and subprocessors
We share personal data only with vendors that process it on our behalf under contract, or where you direct us to send it. Current categories include:
- Cloud hosting, database, authentication and file storage infrastructure.
- Stripe for card processing, Apple Pay and Google Pay, and subscription billing.
- Email delivery for transactional and opt-in messaging from notify.plate-logic.com.
- Twilio for SMS alerts and delivery/reply status events, where a restaurant enables texting.
- DoorDash Drive for courier dispatch, and Uber Eats, Favor and Postmates where a restaurant connects a marketplace.
- Toast, Clover, Square or a generic webhook where a restaurant connects a point-of-sale system.
- Google, Apple Maps, Yelp, Tripadvisor or Facebook, where a restaurant chooses to publish its menu feed. Menu feeds contain business and menu data, not guest data.
- Geocoding and mapping providers used to place a location pin and validate delivery ranges.
We may also disclose data to comply with law, enforce our Terms, protect rights and safety, or in connection with a merger, financing or sale of assets, in which case this policy continues to apply to the transferred data.
6. Your privacy rights
Wherever you live, we honor the following rights on request, subject to verification and legal exceptions:
- Access: a copy of the personal data we hold about you.
- Rectification: correction of inaccurate or incomplete data.
- Erasure: deletion of your data, as described in our Data Deletion Policy.
- Portability: a machine-readable export of data you provided to us.
- Restriction and objection: including objecting to processing based on legitimate interests.
- Withdrawal of consent: for example unsubscribing from marketing email or replying STOP to SMS.
- Non-discrimination: we will not degrade your service for exercising a privacy right.
To exercise a right, email info@plate-logic.com with the email address or phone number used, and the restaurant involved if you are a diner. We respond within 30 days (45 days for California requests where an extension is permitted). If you are an EEA or UK resident you may also complain to your local supervisory authority; if we cannot resolve a California request you may contact the California Privacy Protection Agency.
7. SMS consent and mobile data protection
PlateLogic runs a registered A2P 10DLC text messaging program. Texts are sent by PlateLogic on behalf of the restaurant you interacted with. We only text a number when the person it belongs to gave express written consent by ticking an unchecked consent box on a PlateLogic form, or gave verbal consent to restaurant staff who then attested to it in the app. Consent is never a condition of purchase, of being seated, or of applying.
For every number we collect we store the number, whether consent was given, the exact disclosure wording that was shown or read out, the form it came from, the related restaurant and the timestamp, so a consent record can be produced on request.
Guests receive order confirmations, pickup, delivery, table-ready and waitlist updates, review requests, and, only with a separate marketing opt-in, occasional offers. Restaurant contacts and staff receive onboarding, account, billing, shift and order messages. Message frequency varies: typically 1–6 messages per order plus up to 4 marketing messages per month for guests, and up to 8 messages per month for restaurant contacts. Message and data rates may apply, and carriers are not liable for delayed or undelivered messages.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We disclose your number to our messaging carrier (Twilio) solely to deliver the messages you asked for.
You can opt out at any time by replying STOP to any message, by turning off text updates in your account settings, or by emailing us. Opting out is honored immediately and we keep an opt-out record so you are not messaged again. Reply HELP to any message for help.
8. Delivery driver data
Where you apply to or accept runs as an independent contractor driver, we are the controller of your driver data. We collect:
- Application and identity data: name, email, phone number, city, driving license number, issuing state and expiry date, insurer, policy number and policy expiry date, vehicle make, model and year, and eligibility answers.
- Verification documents: an image or PDF of your driving license, an image or PDF of your insurance card, and a selfie taken with your device camera at the time you apply, which we use to confirm the license belongs to you. These files are stored privately, are never published or shared with restaurants, and are only opened by PlateLogic staff reviewing your application. We keep them for the duration of your access plus 12 months, or 30 days after a denied application, whichever is shorter.
- Background check consent: the name you typed to sign the authorization and the date and time you signed it.
- Screening data: the result of a background and driving-record check performed by our screening provider. We receive a pass or fail result and the details needed to explain an adverse decision, and we do not receive the full underlying report unless the law requires us to share it with you.
- Location data while you are on shift: your device location is used to offer nearby runs, show a live position to the Guest and the Restaurant during an active run, and confirm pickup and drop-off. Collection stops when you go offline or pause offers, and you can revoke the permission in your device settings at any time, which ends run offers.
- Run and earnings data: runs offered, accepted and completed, distance, timestamps, base pay, tips and payout records, plus the tax information required for IRS Form 1099 reporting.
We do not record, display or score acceptance rates, and declining a run is not stored as a performance measure. Driver location history is kept for 90 days for support and dispute purposes, then deleted or aggregated. Payout and tax records are kept for 7 years because tax law requires it. Screening results are kept for the duration of network access plus 12 months.
9. Restaurant staff data
Where a restaurant adds you as a staff member, that restaurant is the controller and we process your data on its instructions. This includes your name, staff ID, assigned locations and console roles, a hashed sign-in PIN, saved-device records, schedules, shift requests, timesheets and break entries, and clock-in and clock-out events with the coordinates used to confirm you were on site.
Where you enable fingerprint or face unlock on your own device, the biometric never leaves your device and is never sent to us. We store only a public key credential that verifies the unlock succeeded.
Staff records are kept for the life of the restaurant's subscription plus 90 days, except timesheet and payroll-relevant records, which the restaurant may be required to keep for longer under wage and hour law.
10. United States state privacy rights
We do not sell personal data, we do not share it for cross-context behavioral advertising, and we do not use it for profiling that produces legal or similarly significant effects. In the last 12 months we disclosed personal data only to the service providers listed above for the purposes described.
If you are a resident of California, Texas, Colorado, Virginia, Connecticut, Utah, Oregon or another state with a comprehensive privacy law, you have the rights listed in the section above, and in addition:
- California (CCPA and CPRA): the right to know the categories and specific pieces of personal data collected, the sources, the business purpose and the categories of recipients; the right to delete; the right to correct; the right to limit the use of sensitive personal information; and the right not to be retaliated against. We do not offer financial incentives for personal data.
- Sensitive personal information: precise geolocation from drivers on shift is the only category of sensitive information we handle. It is used solely to run and verify a delivery, never to infer characteristics, and never for advertising.
- Texas, Colorado, Virginia, Connecticut, Oregon and Utah: the rights to confirm, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and qualifying profiling. Because we do none of those three activities, an opt-out request is recorded and no further action is needed.
- Authorized agents may submit a request on your behalf with written permission that we can verify.
- Appeals: if we decline a request you may appeal by replying to our decision within 60 days. We respond to an appeal within 45 days with a written explanation, and if the appeal is denied we will tell you how to contact your state attorney general.
Send any request or appeal to info@plate-logic.com from the email address on the account, or with the phone number used to order, so we can verify it.
11. Children's data and breach notification
The Services are not directed to children. We do not knowingly collect personal data from anyone under 13, and we do not knowingly sell or share the personal data of anyone under 16. If we learn that a child's data reached us, we delete it. A parent or guardian may contact us to have it removed.
If a breach affects your personal data we notify the affected restaurant without undue delay and, where the law requires, notify you and the relevant regulators within the applicable deadline, describing what happened, what data was involved and what to do next.
12. Retention
We keep personal data only as long as needed for the purpose it was collected, then delete or de-identify it. Typical periods: order and receipt records for up to 7 years for tax and dispute purposes; account and staff records for the life of the subscription plus 90 days; messaging delivery logs and suppression records for up to 24 months (suppression/opt-out entries are kept indefinitely so we do not message you again); audit and security logs for up to 24 months; analytics events in aggregated form indefinitely.
13. Security
We use encryption in transit, encrypted storage of integration credentials, row-level database access rules, role-scoped consoles, staff PIN hashing, optional multi-factor authentication for administrators, audit logging and idempotency protection on sensitive endpoints. No system is perfectly secure and we cannot guarantee absolute security. If a breach affecting your personal data occurs, we will notify affected restaurants without undue delay and, where required, the relevant authorities.
14. International data transfers
PlateLogic is operated from the United States and personal data is stored and processed there. If you access the Services from outside the United States, you understand your data will be transferred to the United States. Where a transfer of EEA or UK personal data occurs, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our subprocessors.
15. Changes to this policy
We may update this policy. Material changes will be posted here with a new "last updated" date and, for restaurant subscribers, emailed to the account owner. Continued use after the effective date means you accept the updated policy. This policy is effective August 30, 2026.
16. Contact
MagnetIQ Marketing Solutions, 5900 Balcones Drive #31323, Austin, TX 78731, USA. Privacy contact: info@plate-logic.com. This policy is governed by the laws of the State of Texas, and any dispute about it is subject to the state and federal courts located in Bexar County, Texas, as set out in our Terms and Conditions.