Website & Data Protection Policies
1. Website & Online Services Policy
This Website Policy explains how [Restaurant Name] (“we,” “our,” or “us”) collects, uses, and protects information obtained through our online platforms. This includes our website, mobile versions of our website, online ordering tools, social media pages, email communications, and any other digital services (“Web Platforms”).
This policy also applies to information collected when you:
• Place online orders, catering requests, or reservations
• Engage with us on social media
• Contact us for customer support
• Interact with us at restaurant events, tastings, catering events, or promotions
• Visit our restaurant or catering office locations
How We Use Your Information
We may use data collected through our Web Platforms to:
• Process online orders and catering requests
• Improve your browsing and ordering experience
• Enhance our menu, services, and catering offerings
• Communicate promotions, updates, or service notices
• Maintain compliance with applicable legal and food-safety regulations
We may update this Website Policy periodically. Any revisions will be reflected by updating the effective date. When legally required, we will notify you of significant changes.
Note: This policy does not cover data related to employees or job applicants. It also does not govern customer data processed by third-party delivery or payment platforms (e.g., Square, Toast, Uber Eats).
________________________________________
2. PCI DSS Online Payment Security Policy
To ensure the safety of online transactions, [Restaurant Name] complies with industry-standard Payment Card Industry Data Security Standards (PCI DSS).
This policy also applies to information collected when you:
Our Commitments
• Protection of Payment Data: All payment card information submitted through our website or online ordering system is processed securely in accordance with PCI DSS requirements.
• Secure Transactions: We use encryption, secure payment gateways, and authentication measures to protect your card information.
• Continuous Monitoring: Our systems and payment processors undergo regular monitoring, testing, and compliance assessments.
• Restricted Access: Cardholder data is accessible only to authorized individuals and never stored in plain text on our systems.
For more information about PCI DSS, please visit the official PCI Security Standards Council website.
________________________________________
3. Customer Data Privacy Policy
Stela’s Kitchen is committed to protecting the personal information of our guests and catering clients.
This policy also applies to information collected when you:
Our Privacy Practices
• We collect and process your data only for legitimate business purposes (e.g., fulfilling orders, catering contracts, customer support).
• We maintain confidentiality and apply appropriate security measures to protect your information.
• We obtain authorization before using third-party service providers (“sub-processors”) and inform customers if these providers change.
• We support your rights regarding your data, including access, correction, deletion, and restriction where applicable.
• We allow customers to request deletion or return of their data when legally permitted.
• We provide transparency and cooperate with audits or inquiries when required.
• We will notify you promptly of any data breach that affects your personal information.
• Our staff receives regular training on privacy and responsible data handling.
• When transferring data internationally (e.g., through global service providers), we apply appropriate safeguards.
• This policy may be updated as needed to reflect changes in laws or our practices.
________________________________________
4. Cybersecurity Policy
We take cybersecurity seriously in all restaurant and catering operations.
Key Security Measures
• Protecting confidential customer information, including order details, billing data, and catering contracts
• Maintaining secure devices and POS systems through passwords, system updates, and antivirus software
• Verifying all emails to avoid phishing, scams, or unauthorized data requests
• Using strong, unique passwords and updating them regularly
• Keeping data transfers secure using encrypted connections and trusted networks
• Restricting access to internal systems to authorized team members only
• Locking devices and POS terminals when unattended
• Requiring remote or mobile employees (including catering staff using mobile tablets) to follow the same security standards
• Enforcing disciplinary actions for violations of security practices
This policy aims to ensure the protection of both dine-in guests and catering clients.
________________________________________
5. Data Retention & Secure Destruction Policy
To maintain compliance and protect guest information, Stela’s Kitchen follows clear guidelines for retaining and securely disposing of data.
Our Data Retention Standards
• We keep records (such as receipts, contact forms, catering contracts, and invoices) only as long as legally or operationally necessary.
• We ensure data is accurate, complete, and relevant throughout its retention period.
• Sensitive data—including payment records, catering contracts, and customer contact information—is disposed of using secure methods such as shredding or digital wiping.
• Each department (restaurant management, catering team, finance, etc.) is responsible for managing the retention of its respective records.
• The destruction of documents must be authorized and performed according to security standards.
• All records remain the property of Stela’s Kitchen and must be treated as confidential at all times
________________________________________