Legal
Privacy Policy Beta
This policy explains what RobinRun collects, why, and what you can ask us to do about it. It covers both restaurants that use RobinRun and guests who order through a RobinRun page.
RobinRun is in beta. The platform is in active development and this policy will change as it does. We will post updates here and email restaurant accounts before any material change takes effect.
1. Who we are
RobinRun ("RobinRun", "we", "us") provides ordering and operations software to restaurants. We are based in Mississauga, Ontario, Canada. For privacy questions, contact privacy@robinrun.com.
When a guest places an order through a restaurant's RobinRun page, the restaurant is the party that decides how that guest's information is used for its own purposes. RobinRun processes it on the restaurant's behalf, and also acts on its own behalf for operating and securing the platform.
2. What we collect
From restaurants
- Account details: name, business name, email, phone, business address.
- Menu and operational content you upload.
- Payout and billing information, handled by our payment processor.
- Usage data: pages visited in the dashboard, features used, device and browser type, IP address, and timestamps.
From guests ordering through a RobinRun page
- Order contents, order time, and pickup or table details.
- Name, phone number, and email where the restaurant requires them for the order.
- Payment information, collected and stored by our payment processor. RobinRun does not store full card numbers.
- Technical data: IP address, device and browser type, and cookie identifiers needed to keep the cart and session working.
We do not knowingly collect information from children under 13.
3. Why we use it
- To provide the service: route orders, take payment, print tickets, send order status messages.
- To keep it working and secure: diagnose faults, prevent fraud and abuse, maintain backups.
- To bill restaurants for the platform fee.
- To support you when you contact us.
- To improve the product, using aggregated and de-identified usage data.
- To meet legal obligations, including tax and accounting records.
We rely on performance of a contract, our legitimate interests in operating a secure service, your consent where required for marketing messages, and compliance with legal obligations.
4. What we do not do
- We do not sell personal information.
- We do not rent or share a restaurant's guest list with other restaurants.
- We do not market our own products to a restaurant's guests using data collected through that restaurant's ordering page.
- We do not use guest order data to train models that would be shared across unrelated customers without de-identification.
5. Who we share it with
We share information only with service providers who need it to run the platform, under contract and only for that purpose: payment processing, cloud hosting, transactional email and SMS delivery, error monitoring, and customer support tooling. We may also disclose information where required by law, to protect our rights or someone's safety, or in connection with a merger or acquisition — in which case this policy continues to apply to the transferred information until it is replaced by one that is at least as protective.
6. Where it is stored
Data is stored on servers in Canada and the United States. Where information is transferred outside your jurisdiction, we use contractual protections intended to give it comparable safeguards.
7. How long we keep it
- Order records: seven years, to meet tax and accounting requirements.
- Restaurant account data: for the life of the account, then up to 90 days after closure, unless we must keep it longer by law.
- Guest contact details held for a restaurant: until the restaurant deletes them or closes its account.
- Server and security logs: up to 12 months.
8. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, withdraw consent, object to certain processing, receive a copy in a portable format, and not be discriminated against for exercising these rights. Email privacy@robinrun.com and we will respond within 30 days.
If you ordered from a restaurant using RobinRun and want your details removed, you can contact us and we will pass the request to that restaurant, or contact the restaurant directly. Under Canadian federal law you may also complain to the Office of the Privacy Commissioner of Canada if you are unsatisfied with our response.
9. Cookies
We use cookies and similar storage that are necessary for the service to function — keeping you signed in, remembering a cart, and protecting against fraud. We use a small amount of first-party analytics to understand which dashboard features are used. We do not run third-party advertising trackers on ordering pages.
10. Security
We use encryption in transit, access controls limited to staff who need them, audit logging, and regular backups. No system is perfectly secure. If a breach affects your information and creates a real risk of significant harm, we will notify you and the appropriate regulator as required by law.
11. Changes
We will post any changes here and update the date above. For material changes affecting restaurants, we will give notice by email at least 30 days before they take effect.
12. Contact
RobinRun, Mississauga, Ontario, Canada · privacy@robinrun.com