Privacy Policy
What we collect, why we collect it, who gets to see it, and how to make us delete it. Three audiences — website visitors, restaurant operators, and the diners ordering through Vendo-powered restaurants — each get their own section.
1. Who we are
Vendo is operated by MoonFactory LLC, a Georgia limited liability company based in the United States. Contact for any privacy question: legal@vendo.pizza.
2. Who this policy covers
This policy applies to three distinct groups. The rest of the document is organized around them.
- Website Visitors. People browsing
vendo.pizzaordemo.vendo.pizzabefore signing up. - Restaurant Operators. Restaurant owners and staff who subscribe to Vendo and run their business on the platform.
- Diners. Consumers who place orders through a Vendo-powered restaurant's website.
One distinction matters a lot: for diner data, the restaurant is the controller and Vendo is the processor. We process diner data only to deliver the platform to the restaurant. We do not market to diners, sell diner data, or use diner data for anything outside running the platform.
3. What we collect
From website visitors
| Data | How collected | Purpose |
|---|---|---|
| IP address | Automatically via Cloudflare | Security, DDoS protection |
| Browser and device info | Automatically via Cloudflare | Security |
| Pages visited, referring URL | Server logs | Site performance |
| Name, email, phone, restaurant name | Lead forms (demo lock screens, contact forms) | Sales outreach when you ask for it |
From restaurant operators
| Data | How collected | Purpose |
|---|---|---|
| Owner name, email, phone | Onboarding intake form | Account administration |
| Restaurant name, address, cuisine | Onboarding intake form | Platform configuration |
| Subscription and billing history | Stripe | Billing. Vendo never stores your card number. |
| Staff names, roles, PINs | Admin dashboard | Access control |
| Menu items, prices, categories, images | Menu editor | Platform functionality |
| Orders processed on the platform | Order flow | Platform functionality |
| Your customer records | Order flow + manual entry | CRM for you |
| Login activity, feature usage | Audit log | Security and support |
| Uploaded images (menu photos, logos) | Admin dashboard | Branding, menu display |
From diners
| Data | How collected | Purpose |
|---|---|---|
| Name | Order form | Order fulfillment |
| Phone number | Order form | Order communication |
| Email (if provided) | Order form | Order confirmation |
| Delivery address | Order form (delivery orders) | Delivery fulfillment |
| Order history | Order flow | Order tracking |
| Payment card details | Stripe checkout | Payment. Vendo never sees or stores card numbers. |
What we do not collect
- Credit or debit card numbers (Stripe handles those end-to-end).
- Social Security numbers.
- Government identification numbers.
- Biometric data.
- Data from anyone we know to be under 13.
- Location data beyond the delivery addresses people voluntarily enter.
4. How we use information
Visitors: we respond to inquiries you submit, we follow up on sales conversations you opened, and we protect the site from abuse. We do not email people who never asked us to.
Operators: we provide the platform, process your subscription billing through Stripe, send service announcements (downtime, billing, security), and answer support requests.
Diners: we process your order, route it to the kitchen, share it with the restaurant's staff, send confirmations and status updates, and pass payment data to Stripe.
What we do not do, in any audience, ever:
- We do not sell personal data. Not to anyone, for any reason.
- We do not run targeted advertising. There are no ad networks integrated into the platform.
- We do not market to diners. Diner data belongs to the restaurant; we don't use it for our own outreach.
- We do not build cross-restaurant behavioral profiles. Each restaurant's tenant data stays in its own database boundary.
- We do not share data between restaurant tenants. Restaurants cannot see each other's customers, menus, or orders.
5. How we share information
The full list of third parties that touch your data lives at /legal/subprocessors. Today it is exactly three companies:
- Stripe, Inc. (USA). Stripe processes subscription payments from operators and order payments from diners. They handle card details directly — we never see them.
- Hetzner Online GmbH (Germany, EU). All platform data is hosted on a dedicated Hetzner server in Germany.
- Cloudflare, Inc. (USA / global edge). Cloudflare provides our CDN, DDoS protection, DNS resolution, and SSL/TLS. They see request metadata (IP, headers).
Other ways data may move:
- Restaurant operators can access their own customers' data through the admin dashboard — that is the point of the product. Restaurants do not get access to other restaurants' data.
- Legal demands. We may disclose data if required by law, court order, or to protect someone's safety. We push back on overbroad requests.
- Corporate transactions. If MoonFactory is acquired or merged, data may transfer to the successor entity, with notice to you in advance.
6. Data retention
- Active accounts. Data is retained while the account is active.
- After cancellation. A 30-day export window, then deletion within 90 days. Billing records are kept longer where tax or legal rules require it.
- Diner data. Retained as long as the restaurant's subscription is active. Follows the same deletion timeline when the restaurant cancels.
- Lead capture data. Retained for 12 months and then deleted if the visitor did not become a Subscriber.
- Server logs. Retained for 90 days.
7. Data security
The honest list of what we actually do today:
- All connections use TLS 1.2 or newer. HTTPS is enforced at the Cloudflare edge.
- The platform runs on dedicated infrastructure — not shared cloud instances.
- Database access is restricted to application-level connections from the platform itself.
- Role-based access control gates every administrative feature.
- Every data-modifying administrative action is captured in an append-only audit log.
- Access to production data is limited to authorized MoonFactory personnel.
- Automated backups run on a regular schedule.
We have not certified anything about encryption-at-rest in this document because we will not claim controls we have not verified. If you need a written security questionnaire response, email legal@vendo.pizza and we will answer specifically.
8. Your rights
Everyone — in any jurisdiction — can:
- Request a copy of the data we hold about them.
- Request correction of inaccurate data.
- Request deletion of their data.
- Receive their data in a machine-readable format (data portability).
Email legal@vendo.pizza to exercise any of these. We respond within 30 days.
California residents (CCPA / CPRA)
In addition to the rights above, you have:
- The right to know what categories of personal information we collect and the purposes we use it for.
- The right to delete personal information we hold about you.
- The right to opt out of the sale of personal information. Vendo does not sell personal information.
- The right not to be discriminated against for exercising these rights.
We verify identity before responding to a request (typically by confirming control of an email address on file). An authorized agent can submit a request on your behalf with your written authorization.
EU / EEA residents (GDPR)
All of the above plus:
- The right to restrict processing.
- The right to object to processing.
- The right to lodge a complaint with your local supervisory authority.
Our legal bases for processing your data:
- Contract performance for operator data — we need it to run the service you bought.
- Legitimate interest for security logging and service improvement.
- Consent for any direct marketing communications.
On international transfers: your data's primary storage is in Germany, on Hetzner. When data is processed by U.S. subprocessors (Stripe, Cloudflare), the transfer is covered by appropriate safeguards including Standard Contractual Clauses where applicable. Data protection contact: legal@vendo.pizza.
9. Children
Vendo is designed for restaurant operators (businesses) and diners (typically adults placing orders). We do not knowingly collect personal information from children under 13. If we learn we have, we delete it promptly. Report concerns to legal@vendo.pizza.
10. Cookies
We use a small number of cookies — login session, CSRF token, Cloudflare security cookies, and (if you have set them) UI preferences. We do not use advertising, analytics, social-media, or tracking cookies. Full detail in the Cookie Policy.
11. Changes to this policy
Material changes are emailed to active Subscribers and posted on this page. We give at least 30 days' notice before a material change takes effect.
12. Contact
MoonFactory LLC
Georgia, United States
legal@vendo.pizza
