Privacy Policy
What we collect, what we do with it, and how to get it back — in words a restaurant operator can read.
Last updated 31 August 2026
Effective 31 August 2026
Who we are
MiniRestaurants is operated by Bobb LLC – MiniRestaurants Series, a Wyoming protected series of Bobb LLC, 30 N Gould St Ste R, Sheridan, WY 82801-6317.
This policy covers two different relationships and it matters which one you are in:
- If you run a restaurant that uses us, we decide how your account data is handled. We are the controller of it.
- If you are a guest at a restaurant that uses us, the restaurant decides how your data is handled. We only act on that restaurant’s instructions. We are their processor. The terms of that are in our Data Processing Addendum.
What we collect from you
If you hold an account with us:
- Your name, email, phone number, business name and business address.
- Billing information. Card details go to our payment processor and are handled by our payment processor. We never hold a card number.
- How you use the product: which devices are paired, how your screens are configured, when you log in, and what you tell our support team.
- Your IP address. We record it when you sign in, when you ask to reset a password, and when a screen or printer connects to us. We use it to keep accounts secure and to work out where a problem is coming from.
- Operating numbers your restaurant generates: how long tickets take, throughput, speed of service. These are timestamps and counts about a kitchen, not information about a person.
What we collect about guests
A guest’s name and phone number, and whatever else your point of sale attaches to the order.
In practice that means: name, phone number, any note left on the order, and, where the order type calls for it, a delivery address, the delivery service’s details, and a vehicle description for curbside and drive-thru. We take what your system sends. We never ask a guest for anything directly.
Not their email. Not their payment details. We do not record a guest’s IP address, because guests never touch our software.
This is unusually little, and it is deliberate: the safest place for guest data is a system that never asked for it.
On card data: MiniRestaurants is not built to receive payment card data and does not ask any integration for it. We are working to add an automated check that rejects card-shaped data if a connected system ever sends it to us unexpectedly.
Why we hold it
| Why | What we use |
|---|---|
| Run your account and show orders on your screens | Account details, configuration |
| Tell you how your kitchen is performing | Timing data, not guest data |
| Bill you | Billing details, through our payment processor |
| Keep the service secure and stop abuse | Login and access logs |
| Answer your support questions | Whatever you send us |
Why we hold data, and what we use for each purpose.
Run your account and show orders on your screens
- What we use
- Account details, configuration
Tell you how your kitchen is performing
- What we use
- Timing data, not guest data
Bill you
- What we use
- Billing details, through our payment processor
Keep the service secure and stop abuse
- What we use
- Login and access logs
Answer your support questions
- What we use
- Whatever you send us
Who else sees it
We use a small number of service providers. Each one is bound by its written terms with us, which limit it to providing that service to us.
| What they do | Who |
|---|---|
| Subscription billing and card handling | A third-party payment processor |
| Hosting and compute | A third-party hosting provider |
| Domain name service, content delivery, and encryption of traffic between you and us | A third-party network infrastructure provider |
| Account and receipt email | None. We send no account or transactional email today. If and when subscription billing goes live, billing receipts are sent by our payment processor, listed above |
| Error monitoring | None separate. Our content delivery network automatically reports when a page fails to reach a browser |
| Company email you send to us | A third-party email provider |
Our service providers, and what each of them does.
Subscription billing and card handling
- Who
- A third-party payment processor
Hosting and compute
- Who
- A third-party hosting provider
Domain name service, content delivery, and encryption of traffic between you and us
- Who
- A third-party network infrastructure provider
Account and receipt email
- Who
- None. We send no account or transactional email today. If and when subscription billing goes live, billing receipts are sent by our payment processor, listed above
Error monitoring
- Who
- None separate. Our content delivery network automatically reports when a page fails to reach a browser
Company email you send to us
- Who
- A third-party email provider
We name the job rather than the company. That is how we treat vendor information everywhere on this site, and it is not evasion: if you are a customer, or you are deciding whether to become one, write to [email protected] and we will send you the named list for your own vendor review or your compliance file. We will tell you at least 30 days before we add a new provider that handles your data or your guests’ data.
On error monitoring: we use no separate crash-reporting service. Our content delivery network automatically collects basic network-error reports about page delivery, which is whether a page reached your browser, not what was in it.
On the mail you send us. Mail addressed to [email protected] or [email protected] is delivered to our own mail server, and a copy is forwarded to a mailbox at a third-party email provider that we read. Anything you write to us, including a privacy request and anything you choose to put in it, is stored by that provider. Replies we send go out from our own mail server and do not pass through it.
If your own compliance rules require a written commitment about where your data is stored, ask us at [email protected] before you open an account and we will answer you in writing.
We do not sell your data and we do not share it for advertising. There is no ad pixel, no audience matching and no advertising surface anywhere in this product. There is nothing here for anyone to buy.
How long we keep it
Read this section as a description of what the system does today, not of what we intend. The two are different right now, and the difference is ours to close, not yours to guess at.
- Guest names and phone numbers: we keep them until you ask us to remove them. Your account carries a retention setting, set to 90 days unless you change it. That setting is recorded and reported, but no automatic job reads it and erases anything yet. Until you ask, a guest’s name and phone number stay in the order record for as long as the order record exists.
- What is in an order record. Guest name, phone number, any note attached to the order, and, on delivery, curbside and drive-thru orders, the delivery address, the delivery service’s details, and the vehicle description your point of sale sends.
- Order records are kept for 25 months, then archived rather than destroyed. When a month’s orders age out, that month is moved aside and locked so the application can no longer read it. Moved aside is not erased.
- Raw copies of what your point of sale sent us are kept 7 days by policy, and that policy is also not yet automatic. We keep the original message so a failed order can be replayed.
- Operating statistics are kept indefinitely. These are timings and counts about a kitchen. Because guest details are not yet purged on a schedule, assume the statistics still sit alongside them rather than having been separated from them.
- Your account data: for as long as you have an account. After you leave we export it to you or remove it on request, and that is a request we action by hand.
- Text messaging consent, if and when messaging ships: 4 years. The table that holds that record exists. Like the rest of this section, the 4-year window is a stated rule and not yet an automatic one.
On request, at any time, we will remove a guest’s data or your own, and we do it by hand. Ask at the address below. We can already produce a complete export of everything held about a person, and the removal is carried out by a person rather than a scheduled job.
We say this in months and years on purpose, and we say “not automatic” where it is not automatic. “As long as necessary” is not an answer, and neither is a number that nothing enforces.
Backups. We take encrypted backups so we can restore the service after a failure. A backup is a snapshot of the whole system, so a record you asked us to delete can remain inside an older backup until that backup expires. Daily backups are kept for 30 days and monthly backups for 12 months. We do not use backups to look up or restore individual records, and expired backups are destroyed on that schedule.
Which privacy law applies to you
California (CCPA/CPRA): the rights listed below are offered to every account holder and every guest, everywhere in the United States, whether or not we fall within the statute's thresholds. We have not made a formal determination of whether we are a "business" under Cal. Civ. Code 1798.140(d), and we do not claim one here. We offer the rights either way.
Other US states: several states have their own privacy statutes, and their tests differ. Some turn on how many residents' data a company handles; others, including Texas, do not turn on a number at all. Our assessment against those statutes is not finished. Until it is, we apply the rights described on this page to residents of every US state.
Europe and the United Kingdom (GDPR / UK GDPR): not currently triggered. European and UK privacy law reaches a company established elsewhere in two situations: where it has an establishment there, meaning real activity carried on through stable arrangements, or where it offers goods or services to people there or monitors their behaviour online (GDPR Article 3). Neither applies to us. We have no office, staff or representative in the European Union or the United Kingdom, we do not market or offer the service there, we onboard no customer established there, and we do not profile or track anyone anywhere. This is expected to change, because we intend to sell wherever our payment processor permits us to operate. The day we take a customer established in Europe or the United Kingdom, that law applies to us whatever our state of incorporation, and we will rewrite this section and appoint a representative before that day rather than after it.
Canada: Canadian restaurants are not onboarded today. Canada’s messaging law is stricter than the US one, and we will not send a text to a Canadian number without explicit recorded opt-in.
Your rights and your guests’ rights
You can ask us to tell you what we hold about you, correct it, delete it, or hand it to you in a portable form. You can object to us using it. You will never be treated worse for asking. We do not sell or share personal information, so the opt-out right exists but has nothing to act on.
Email [email protected]. We answer within 45 days.
If you are a guest at a restaurant that uses us: the restaurant holds your data, so the fastest route is to ask the restaurant directly. They can ask us to export or remove your order data, and we action that by hand for them. If you cannot reach them, write to us and we will pass your request on and help them action it.
Data export
You can take your data out, in a standard format, whenever you want — including on the day you leave.
Today you get it by asking us and we produce it for you. There is not yet a button in the product that does it for you.
We offer the export before your account closes, not after, because an export link on a confirmation email a week later is worth nothing. This is also the honest answer to “what happens to my kitchen if you go out of business”: you leave with your data.
How we protect it
Data is encrypted in transit. Each restaurant’s data is separated at the database layer, not just in application code. Secrets never appear in the app or in logs. When our support team needs to look at your data, you have to let them, and the access is logged.
If you need more detail for a vendor-security review, write to [email protected] and we will send it to you.
Breach notification
If personal data is breached, we notify affected customers within 72 hours of confirming it, by email to the account address, and we publish a post-incident review.
This same 72-hour commitment is a contractual term in our Data Processing Addendum, not only a statement on this page. They are one and the same promise: the page and the Addendum state a single commitment, and neither can be changed without changing the other.
Who to contact
Bobb LLC – MiniRestaurants Series, 30 N Gould St Ste R, Sheridan, WY 82801-6317