Privacy Policy
Last updated: August 30, 2026
Tacoter Inc. (“Tacoter”, “we”, “us”) builds ordering websites, marketing tools and AI features for Mexican restaurants. This policy explains what we collect, why, and the choices you have.
Table of contents
1. Introduction
This Privacy Policy covers tacoter.com, every restaurant ordering site we host, our owner dashboard, our email and SMS messaging, and our mobile-web experiences.
It applies to two groups: restaurant owners and staff who use Tacoter as a business tool, and diners who order from a restaurant powered by Tacoter.
2. Information We Collect
- Account data: name, business name, email address, phone number, password hash, and role on a restaurant account.
- Order data: items ordered, order totals, pickup or delivery selection, delivery address, special instructions, and order status history.
- Customer data: diner name, phone, email, saved addresses, saved payment method tokens (held by our payment processor, never the full card number), loyalty and gift card balances.
- Usage data: pages viewed, device and browser type, approximate location derived from IP, referring page, and interactions such as add-to-cart or checkout events.
- Communications: messages you send to support, review responses, and chatbot conversations.
3. How We Use Information
- Provide the service: build and host ordering sites, process orders, deliver receipts and status updates.
- Improve the platform: measure feature usage, diagnose errors, and evaluate A/B tests in aggregate.
- Send communications: transactional order messages, account notices, and — where a recipient has opted in — restaurant marketing email and SMS.
- Protect the platform: detect fraud, abuse, spam and chargeback risk.
- Comply with law and enforce our Terms of Service.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. AI-Generated Content
Tacoter uses artificial intelligence to draft menu descriptions, generate menu and marketing images, write social posts and review replies, summarize operations in the AI Morning Brief, and answer diner questions through the restaurant chatbot.
- AI output is a draft. Restaurant owners are responsible for reviewing content before it is published.
- Prompts we send to AI providers may include menu content, aggregated order statistics and the text of a diner's chatbot question. We do not send payment credentials or passwords.
- Our AI providers process this data under contract and are not permitted to train foundation models on it.
5. Restaurant Customer Data
For diner data collected through a restaurant's Tacoter site, the restaurant is the data controller and Tacoter is the processor. The restaurant owns its customer list and may export or delete it at any time.
We process that data only to operate the service on the restaurant's behalf and under the terms of our Data Processing Agreement.
6. Data Sharing
We share data with vendors that help us run the platform, each bound by contract:
- Payment processors (Stripe, NMI) for card authorization, refunds and payouts.
- SMS provider (Telnyx) for order and marketing text messages.
- Email provider (Twilio SendGrid) for transactional and marketing email.
- AI providers (DeepSeek for text, FLUX for images) for generated content.
- Infrastructure (Supabase, Cloudflare) for database hosting, DNS and content delivery.
- Mapping (Mapbox) for address autocomplete and maps.
We may also disclose information when required by law, to enforce our agreements, or as part of a merger or acquisition, with notice to affected users.
The full list is maintained on our Subprocessors page.
8. Data Retention
- Order records: retained for 7 years for tax and accounting purposes.
- Diner accounts: retained while active, then deleted within 90 days of a deletion request.
- Analytics events: retained in identifiable form for 14 months, then aggregated.
- Restaurant account data: deleted within 30 days of account termination, except records we must keep by law.
9. Your Rights
Depending on where you live, you may have rights under the CCPA/CPRA, the GDPR or similar laws to access, correct, delete, port or restrict processing of your personal information, and to object to certain uses.
Diners should contact the restaurant they ordered from first; we assist restaurants in fulfilling those requests. You can also email privacy@tacoter.com and we will respond within 45 days (30 days in the EEA/UK). We will not discriminate against you for exercising a privacy right.
10. Children's Privacy
Tacoter is not directed to children under 13 and we do not knowingly collect their personal information. If we learn that we have, we delete it promptly. Contact privacy@tacoter.com to report such an account.
11. International Data Transfers
Tacoter is operated from the United States and data is primarily processed in U.S. data centers. Where we transfer personal data from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses and apply supplementary safeguards.
12. Changes to This Policy
We will update the “Last updated” date whenever this policy changes. For material changes we will email restaurant account owners and post a notice in the dashboard at least 14 days before the change takes effect.
13. Contact
Privacy questions: privacy@tacoter.com
Tacoter Inc · 5900 Balcones Dr, Suite 100 · Austin, TX 78731