Contents
1. Scope and Who We Are
This Privacy Policy explains how Fiesto, Inc. ("Fiesto," "we," "us," or "our") collects, uses, discloses, retains, and otherwise processes personal information when you use our restaurant marketplace, websites, mobile applications, merchant tools, driver tools, communications, and related services (collectively, the "Services"). Fiesto, Inc. is a Delaware corporation and is extra-provincially registered in Alberta as Fiesto Inc. References to Fiesto in this Policy refer to that same legal entity.
This Policy applies across our user groups and digital properties, including: (a) consumers who browse restaurants, create accounts, place orders, receive deliveries, submit ratings or reviews, or contact support; (b) restaurant merchants, owners, operators, employees, and store managers who use the Fiesto merchant website/dashboard or Store Manager app; (c) delivery drivers who apply to, onboard with, or use the Fiesto Driver app; and (d) visitors to our websites and other persons who interact with Fiesto.
Fiesto initially operates in Alberta, Canada, beginning with Edmonton and Calgary and later other Alberta cities. Fiesto expects to expand to selected U.S. states, which may include New York, New Jersey, and Pennsylvania. Supplemental rights described below apply only when the relevant law applies to Fiesto and to the individual making the request.
2. Personal Information We Collect
We collect information that you provide directly, information generated through your use of the Services, information collected automatically from devices and browsers, and information from third parties such as payment processors, screening providers, merchants, drivers, analytics providers, and advertising partners.
Consumers
- Account and identity information, such as name, email address, phone number, authentication credentials or account-verification information.
- Delivery and transaction information, such as delivery addresses, order history, restaurant searches and views, menu interactions, promo-code usage, refunds, tips, ratings, reviews, and support communications.
- Payment-related information. Consumer card details are collected through Stripe Elements and processed by Stripe. Fiesto does not store full payment-card numbers or card security codes on its own systems. We may receive and retain limited payment metadata such as payment or customer identifiers, payment status, card brand, last four digits, fraud or risk signals, and transaction records.
- Device, usage, and location information, such as IP address, device and browser type, operating system, app version, device identifiers, pages or screens viewed, interactions with the Services, approximate location derived from IP address, and precise location when you grant device permission and the feature requires it.
Merchants and Merchant Personnel
- Business and account information, including restaurant or business name, owner/operator names, business address, email, phone number, menus, pricing, hours, order history, store settings, employee and store-manager accounts, and support communications.
- Financial, tax, and payout information required for onboarding and payouts. Merchants use Stripe Connect Express. Stripe may collect identity, bank, tax, and verification information directly. Fiesto may receive connected-account identifiers, verification status, payout status, and other information made available to Fiesto through Stripe.
- Operational and device information, including order-management activity, account permissions, login and security events, device identifiers, IP address, and diagnostic data.
Drivers
- Identity and eligibility information, including name, email, phone number, home address, date of birth, driver's license information, government identification, profile photo, vehicle information, and insurance information.
- Financial and tax information used for onboarding, payments, and tax reporting. Drivers use Stripe Connect Express. Stripe may collect bank, identity, tax, and verification information directly; Fiesto may receive status and payout-related information needed to operate the platform.
- Delivery and performance information, including delivery history, earnings, offer and acceptance events, pickup and drop-off timestamps, completion/cancellation information, service quality and performance metrics, fraud and safety signals, and support communications.
- Location information. When a Driver is online, available for delivery opportunities, or completing a delivery, the Driver app may collect precise foreground and background location, depending on device permissions and operating-system settings. We use this information for nearby delivery opportunities, dispatch, pickup and drop-off execution, arrival and progress estimates, safety, fraud prevention, support, and marketplace operations. As a standard historical Driver record, Fiesto does not intend to retain a continuous GPS route history or a history of Driver speed or movement. We do retain delivery-event records such as pickup and drop-off timestamps. Short-lived technical logs may temporarily contain location-related information for security, reliability, troubleshooting, or legal purposes.
- Screening information. Fiesto may require identity verification, criminal-record screening, driving-record screening, or other eligibility checks where lawful and appropriate. Such checks may be performed by third-party screening providers. Fiesto may receive screening status, eligibility results, or reports as permitted by law. Separate disclosures, authorizations, and adverse-action notices may apply and are not replaced by this Privacy Policy.
4. How We Use Personal Information
We use personal information to:
- Provide, personalize, maintain, and improve the Services, including account creation, restaurant discovery, ordering, fulfillment, delivery, merchant operations, Driver dispatch, payments, payouts, refunds, and customer support.
- Authenticate users, verify identities, administer accounts and permissions, detect suspicious activity, prevent fraud and abuse, investigate incidents, enforce our terms, and protect users, merchants, Drivers, Fiesto, and the public.
- Process payments and payouts, reconcile transactions, handle chargebacks and disputes, maintain financial records, and satisfy tax, accounting, and reporting obligations.
- Operate marketplace logistics, including matching Drivers with delivery opportunities, supporting pickup and drop-off, estimating progress and arrival, and resolving order or delivery issues.
- Evaluate Driver eligibility and marketplace performance, including lawful identity, driving, background, safety, and quality checks.
- Communicate about accounts, orders, deliveries, security, support, service changes, payouts, and other operational matters by email, SMS, push notification, in-app message, or phone where appropriate.
- Send offers, discounts, promotions, recommendations, and other marketing by email or promotional push notification where permitted. We do not plan to send promotional SMS; SMS is intended for transactional and service-related communications.
- Send occasional business-development or promotional communications to Merchant contacts where permitted. Drivers are not intended to receive promotional or non-operational communications from Fiesto.
- Analyze usage, measure product performance, conduct research, troubleshoot errors, develop new features, perform analytics and attribution, and improve marketplace quality.
- Comply with law, respond to lawful requests, establish or defend legal claims, conduct audits, and meet regulatory, insurance, and contractual requirements.
5. Marketing and Communications Choices
Consumer marketing email is optional. Where Fiesto relies on express consent, the marketing choice should require an affirmative opt-in. Canadian users should not be presented with a pre-checked marketing-consent box. You can unsubscribe from marketing emails using the unsubscribe link in the message or by contacting us. We may retain a suppression record so that we can honor your opt-out.
Transactional communications are different from marketing. Even if you opt out of marketing, we may continue to send communications reasonably necessary to provide the Services, such as verification codes, order and delivery updates, account and security notices, payout information, receipts, and support messages.
You can manage push notifications through your device settings and, where available, in-app preferences. Where practical, Fiesto may provide separate controls for promotional push notifications and operational push notifications.
6. How We Disclose Personal Information
We may disclose personal information as described below:
- Between marketplace participants as needed to fulfill orders. For example, Merchants may receive Consumer order details and relevant delivery or contact information; Drivers may receive pickup and delivery information; Consumers may receive Driver or Merchant information needed to coordinate an order. We seek to limit these disclosures to what is reasonably needed for the transaction.
- To service providers that process information on our behalf or provide infrastructure, communications, analytics, security, support, or operational services. Current or anticipated providers include Stripe, Twilio, SendGrid, Mailchimp, Firebase, Mixpanel, Sentry, Amazon Web Services (AWS), Google Cloud, Google Analytics, and related providers.
- To payment and payout providers, including Stripe, for card processing, fraud prevention, connected-account onboarding, identity verification, tax information collection, payouts, and related financial services.
- To screening, identity, insurance, safety, fraud-prevention, and verification providers where appropriate for Driver or Merchant onboarding and risk management.
- To analytics and advertising partners, including Google Ads, Meta, and TikTok, where permitted and subject to applicable consent and opt-out choices. Certain disclosures through advertising technologies may be considered a "sale," "sharing," or processing for "targeted advertising" under some U.S. state privacy laws even when Fiesto does not sell lists of personal information for money.
- To professional advisers, auditors, insurers, financing sources, or transaction counterparties where reasonably necessary and subject to appropriate confidentiality protections.
- To law enforcement, regulators, courts, government authorities, or other parties when we believe disclosure is required or permitted by law, necessary to protect rights or safety, needed to prevent fraud or abuse, or appropriate in connection with legal claims.
- In connection with a merger, acquisition, financing, reorganization, sale of assets, insolvency process, or similar corporate transaction, subject to applicable law and appropriate safeguards.
7. International and Cross-Border Processing
Fiesto is a U.S. company operating in Canada and uses technology providers that may process information outside the province or country in which you live. Personal information may therefore be processed or stored in Canada and the United States and, depending on a service provider's infrastructure or support operations, potentially in other countries.
When personal information is processed in another jurisdiction, it may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement agencies, or government authorities there. Fiesto remains responsible for personal information under its control and uses contractual, organizational, and technical measures intended to protect information handled by service providers.
For questions about service providers outside Canada, including the countries in which they may process information and the purposes of that processing, contact our Privacy Officer at [email protected].
8. Retention and Deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining transaction and tax records, preventing fraud, resolving disputes, enforcing agreements, complying with legal obligations, and establishing or defending legal claims.
Retention periods vary by category. As an operational guideline, Fiesto may retain order, settlement, payout, refund, accounting, and related financial records for up to seven years where reasonably needed. Canadian tax rules commonly require relevant records for six years from the end of the last tax year to which they relate. This does not mean every category of personal information is kept for seven years.
Support communications may generally be retained for up to three years after account closure, or longer when connected to disputes, fraud, safety matters, legal claims, or regulatory obligations. Marketing-consent and suppression records may be retained as needed to demonstrate consent and honor opt-outs. Analytics and diagnostic data should be subject to finite vendor retention settings rather than indefinite storage.
Consumers, Merchants, and Drivers may submit deletion requests. Drivers may also deactivate their accounts. When an account is deleted, Fiesto will delete, de-identify, or anonymize information where reasonably possible, but may retain information that is necessary for legal, financial, fraud-prevention, safety, dispute-resolution, or other permitted purposes. Residual copies may remain temporarily in backups and disaster-recovery systems until overwritten in the ordinary course.
9. Security
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, or destruction. Measures may include access controls, authentication, encryption in transit and where appropriate at rest, logging, monitoring, vendor management, secure software-development practices, and incident-response procedures.
No security system is perfect, and we cannot guarantee that information will never be accessed, used, or disclosed in an unauthorized manner. If a privacy or security incident occurs, we will investigate and notify affected individuals, regulators, or other parties when required by applicable law.
10. Your Privacy Rights and Choices
Depending on where you live and which laws apply, you may have rights to request access to personal information, correction of inaccurate information, deletion, portability, withdrawal of consent, or information about our collection, use, disclosure, service providers, or cross-border processing. Some rights are subject to exceptions, identity verification, and legal limitations.
To exercise a privacy right, email [email protected] or use the contact form available in the applicable Fiesto app. Please describe your request and the account or relationship involved. We may ask for information reasonably necessary to verify your identity and authority. Authorized agents may be permitted where required by law and after appropriate verification.
We will not unlawfully discriminate against you for exercising a privacy right. If we deny or limit a request, we will provide an explanation when required and describe available appeal or complaint options.
11. Alberta and Canadian Privacy Rights
For personal information governed by Alberta's Personal Information Protection Act (PIPA), you may request access to personal information about you that is in Fiesto's custody or control and request correction of inaccurate or incomplete information, subject to statutory exceptions. You may also ask questions about Fiesto's privacy practices or make a complaint to our Privacy Officer.
PIPEDA may apply to interprovincial or international commercial processing, including certain transfers of personal information across provincial or national borders. Where consent is the legal basis for processing, you may withdraw consent subject to legal or contractual restrictions and reasonable notice; withdrawal may affect our ability to provide Services that require the information.
Canadian promotional electronic communications are also subject to Canada's Anti-Spam Legislation (CASL). Where express consent is required, Fiesto will seek affirmative consent and maintain appropriate consent records. Promotional messages will include legally required identification and unsubscribe mechanisms. Transactional or service messages may continue where permitted.
12. U.S. State Privacy Rights
If Fiesto becomes subject to a U.S. state comprehensive privacy law, residents covered by that law may have additional rights such as confirmation of processing, access, correction, deletion, portability, opt-out of targeted advertising or sale, and appeal of certain privacy-request decisions. These rights generally apply only when statutory thresholds and other requirements are met.
Before launching in a new U.S. jurisdiction, Fiesto may provide additional state-specific notices or update this Policy to reflect then-current law. Privacy laws can change, and the rights described in this section should be read together with any supplemental notice posted for your state.
13. New Jersey Supplemental Notice
If the New Jersey Data Privacy Law applies to Fiesto and to you, eligible New Jersey consumers may have rights to confirm whether we process personal data; access personal data; correct inaccuracies; delete personal data; obtain portable data; and opt out of targeted advertising, sale of personal data, and certain profiling in furtherance of decisions that produce legal or similarly significant effects.
New Jersey law treats precise geolocation as sensitive data. Where required, Fiesto will obtain consent before processing sensitive data and will provide mechanisms to withdraw consent. Fiesto may also be required to conduct data-protection assessments for specified higher-risk processing.
Fiesto does not sell personal information for money as a business model. However, disclosures to advertising technologies may be treated as a sale or targeted advertising under applicable state law. Before applicable U.S. state launch, Fiesto expects to implement a Privacy Choices mechanism and honor qualifying universal opt-out signals where required.
If applicable law provides a right to appeal a privacy-request decision, instructions for appeal will be included in our response or privacy-request workflow.
14. Children and Age Restrictions
The Services are intended only for individuals age 18 or older. Fiesto does not knowingly offer accounts or Services to children under 18. Our marketplace is limited to restaurant food and does not currently offer restricted categories such as alcohol, tobacco, recreational drugs, or similar regulated products.
If you believe a person under 18 has provided personal information to Fiesto, contact[email protected] so that we can review and take appropriate action.
15. Third-Party Services and Links
The Services may link to third-party websites, apps, payment services, merchant pages, or other services that Fiesto does not control. Those parties' privacy practices are governed by their own policies. This Policy does not apply to information a third party collects for its own purposes where Fiesto does not control that processing.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technologies, vendors, legal requirements, or business practices. We will post the updated version and revise the Last Updated date. If changes are material, we may provide additional notice through the Services, by email, or by another appropriate method.
17. Contact Us
Fiesto's Privacy Officer is responsible for questions and requests regarding this Privacy Policy and Fiesto's handling of personal information.
Privacy Officer
Fiesto, Inc.
Email: [email protected]
You may also contact us through the contact form available in the applicable Fiesto app.