Privacy Policy
Last updated: August 29, 2026
This Privacy Policy explains how Ordr Ring ("we", "us") collects, uses, and protects information when restaurants and their staff use our point-of-sale software and when visitors use our website. By using Ordr Ring you agree to the practices described here.
Information we collect
- Account information - names, email addresses, phone numbers, and roles for restaurant owners and staff.
- Restaurant data - menus, orders, table activity, and sales history you create in the product.
- Customer data - where a restaurant uses features like receipts or order notifications, we may process a customer's phone number, email, or order history on the restaurant's behalf.
- Usage and device data - log data, device type, and basic analytics used to operate and improve the service. On our websites we use Vercel Web Analytics, run by the provider that already hosts them. It is cookieless: it stores nothing on your device and cannot follow you to another site. Visits are counted using a temporary identifier derived from your request, not from anything saved on your device. We do not collect analytics on our owner portal or our internal admin tools, and we never record the address of a page whose link is itself a private key - an invite, a sign-in confirmation, a store claim, a table check, or a receipt. In our app we use PostHog for product analytics, configured to receive internal account identifiers only (never your name, email, or phone), with order amounts sent as ranges, not exact totals. We use Sentry to monitor errors across our services, including our iOS app and all of our websites (this one, the owner portal, and the discovery site). Error reports contain technical diagnostic information about the failure; they do not include personal information, and session replay is disabled. None of this data is used for cross-app tracking or advertising.
- Other services your browser contacts - when you view the map on our discovery site, Mapbox serves the map tiles and receives an anonymous identifier it generates for that purpose. When you pay, Stripe loads its own payment script, which sets a cookie (
__stripe_mid) it uses for fraud prevention; that cookie is Stripe's, not ours, and lasts about a year. Where a place has not uploaded its own photos, we show placeholder images from a third-party image service. Signing in with Google or Apple loads their sign-in scripts.
What we store on your device
Our sites do not set advertising or tracking cookies, and there is no consent banner because there is nothing to consent to: everything below is either something you asked for or something you chose. It is all stored by your own browser, and clearing your browser data removes all of it.
- Your appearance choice - whether you picked light or dark mode, so the site does not change under you on the next visit.
- Your place in a check - when you scan a table QR code to order or pay, we store a random label for your device. It is what lets the check know which items are yours when a table is splitting the bill. It is not a name, it is not linked to your identity, and it is only ever sent to us.
- Your saved places and party details - favorites you save on the discovery site, and the name you enter when ordering with a group, so the rest of the table can see whose items are whose.
- Staying signed in - if you have an account, the token that keeps you signed in. Our owner portal and admin tools also keep a working copy of your workspace on your device so the software is usable; signing out clears it.
- Your analytics choice - only if you turn analytics off, we remember that. Turning it back on removes the record entirely.
Our admin tools use a session cookie set by our API to keep staff signed in. That is the only cookie we set ourselves.
Turning analytics off
There is an Analytics control in the footer of both of our websites. Turning it off stops us recording anything about your visit, on that device, from the next page onward - and you can turn it back on from the same place at any time. If your browser sends a Do-Not-Track or Global Privacy Control signal, we treat that as off already and do not let the site override it.
How we use information
- To provide, maintain, and improve the Ordr Ring service.
- To process orders and payments (payments are handled by Stripe; we do not store full card numbers).
- To send service-related communications and support responses.
- To detect, prevent, and address fraud, abuse, and security issues.
Payments
Card payments are processed by Stripe. Stripe handles cardholder data in accordance with PCI-DSS standards. Ordr Ring does not store full card numbers on its servers.
Sharing
We do not sell your data. We share information only with service providers that help us operate the product (such as hosting, payment, email, and SMS providers), and only as needed to deliver the service or comply with law.
Data retention & your rights
Customers can delete their account directly in the Ordr Ring app (the You tab → Delete account): your personal information (name, email, phone) is permanently removed, and your past orders and bookings remain in the records of the businesses you visited without your identity attached. You can also request a copy of your data or ask us to delete it by email. We retain business records (orders, receipts) as required for tax, accounting, and legal obligations. Depending on where you live, you may have rights under the GDPR or CCPA to access, correct, or delete your personal information.
Security
We use industry-standard measures including encrypted authentication, role-based access controls, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data.
Contact
Questions about this policy? Email us at hello@ordrring.com.