Privacy Policy
Last updated 4 July 2026
This Privacy Policy explains how OrderBee ("OrderBee," "we," "us") collects, uses, and shares personal information across everything we operate: the orderbee.app website; the OrderBee skill / API; our dine-in, walk-in/to-go, phone-order, and waitlist/host agents (reached by QR code, phone call, or a link texted by the OrderBee Companion app); the owner dashboard; and our internal admin tools.
By using any of these, you agree to this Policy. If you do not agree, do not use the service. Your use is also governed by our Terms of Use and our SMS & Telegram Messaging Policy.
1. Who this Policy covers
Where it matters, we call out which group a practice applies to:
- Site visitors — anyone browsing orderbee.app.
- Skill / API users — people (or their AI agents) who create an API key and order through the OrderBee skill.
- Diners — guests who scan a table or counter QR code, join a waitlist at the door, call a restaurant's phone-order line, or otherwise chat with an OrderBee agent to order, wait, or pay.
- Owners — restaurant and shop operators who run a business account on OrderBee.
Notice at Collection (California)
At or before the point we collect it, here is what we take and why:
| Category (CCPA) | What we collect | Purpose | Retention |
|---|---|---|---|
| Identifiers | Name or first name, phone number, email (owners) | Take and fulfill your order; manage the waitlist; contact you about your order; owner account access | Guest chat data: as long as needed for the order, support, and dispute windows; owner accounts: life of the account |
| Commercial information | Order history, items, amounts | Fulfill orders, receipts, support, tax records | Transaction records ~4 years (tax), then deleted or de-identified |
| Financial information | Payment card, processed by Stripe | Payment processing | We never store your card number — Stripe holds it; we keep only a payment token |
| Geolocation (coarse) | Delivery address you give us | Deliver your order | With the order record, per above |
We do not sell your personal information or share it for cross-context behavioral advertising, and we honor Global Privacy Control signals. You can ask us to access, correct, or delete your information — see "Your rights" below or email support@orderbee.app.
2. Information we collect
From site visitors
- The email address you submit to join the waitlist or request access.
- Basic technical and usage data (IP address, browser/device type, pages viewed) collected by our hosting provider.
From skill / API users
- The email address you provide to create an API key, and your API key.
- An optional default delivery address you choose to save.
- The orders you place — items, quantities, merchant, fulfilment type, totals, and the delivery address for that order.
From diners (dine-in, walk-in/to-go, phone, and waitlist agents)
- Your chat messages with the agent and the conversation transcript, retained so the conversation survives a page reload.
- Your order — items, quantities, table or pickup details, and the restaurant. For the waitlist/host agent, your name, party size, and queue position. For phone ordering, the number you called from, so we can text you a link to the chat.
- Payment for the order, handled through Stripe (see §5). Card details are entered on Stripe's hosted payment element; OrderBee never sees or stores your full card number. If a restaurant offers "pay at the end," we ask before saving a card to your tab, and Stripe securely stores the payment method until you settle. For cash ("pay onsite") orders we record only that the order was placed.
- You do not need an OrderBee account to use these agents.
From owners
- Account details — email and the sign-in session created with a magic link; optionally a phone number verified by one-time code.
- Business profile — name, address, phone, category, hours, photos, service area, and display language.
- Agent settings — the agent's name, persona, and supported languages you configure.
- Point-of-sale connection — when you connect Square (or another POS), the OAuth access tokens and the menu/catalog and order data needed to keep them in sync.
- Payout details — handled through Stripe Connect. Banking and identity-verification details are collected and held by Stripe, not by OrderBee.
- Messaging connection — if you enable Telegram order alerts, your Telegram chat identifier; if you use the OrderBee Companion app to handle inbound calls, the pairing between that device and your account.
Collected automatically (all surfaces)
- Log and device data — IP address, timestamps, user agent, request paths — for security, debugging, and abuse prevention.
- Coarse location — for aggregate reporting, we derive a rough, city/region-level area from IP address. We do not store precise device geolocation for this purpose.
- Cookies / local storage — see §7.
3. How we use information
We use personal information to: create and authenticate your account or API key; fulfil orders (send details to the merchant's POS and, for delivery, the courier; process payment); operate our ordering, phone, and waitlist agents (see §4); validate and geocode addresses; send transactional messages (magic-link sign-ins, verification codes, order alerts, account email); provide owner analytics about that owner's own business; calculate, collect, and remit sales tax, acting as the marketplace facilitator in states where we are registered to do so on a restaurant's behalf; screen chat messages for abusive content using automated moderation; maintain security, fraud prevention, and an internal audit log of administrative actions; and comply with legal obligations and enforce our terms.
Our legal bases are performing our contract with you, our legitimate interests (security, abuse prevention, improving the service), your consent where required (e.g. marketing email), and legal obligation where applicable.
4. AI processing of your messages
Our agents, and certain owner features such as menu import and note polishing, are powered by third-party large-language-model providers — primarily Anthropic, with DeepSeek available as an automatic fallback if the primary provider is unavailable. To provide these features we send the relevant content — for diners, your chat messages and the menu context; for owners, the menu/notes being processed — to whichever provider is handling the request. We also send chat messages to OpenAI's moderation service to automatically screen for abusive or harmful content.
We do not use this content to train our own models. Each provider processes it under its own terms as our service provider. Please avoid sending sensitive personal information in chat that is not needed to place your order.
5. Payments
Card payments are processed live by Stripe. Card details are entered directly into Stripe's hosted fields; OrderBee receives only confirmation of the payment and limited metadata (amount, status, order reference) — never your full card number. Depending on the order, your payment is either charged directly to the restaurant's own connected Stripe account (the restaurant is the seller of record) or routed through OrderBee via Stripe Connect before the restaurant's share is paid out. Where a restaurant offers "pay at the end," settling your tab may charge a payment method you previously saved, off-session. Your use of payment features is also subject to Stripe's Privacy Policy.
6. How we share information
We share personal information only as needed to run the service. We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. We share your mobile number only with subcontractors that help us operate the service — for example, our SMS provider (Telnyx) to send messages, or a courier to hand off a delivery — and only for those purposes.
| Recipient | Why |
|---|---|
| Merchant's point-of-sale (e.g. Square, Toast) | To send the order to the restaurant or shop |
| Couriers (delivery drivers) | To deliver the order — includes the delivery address and contact for handoff |
| Stripe | To process payments, calculate/collect/remit sales tax, and pay owners |
| Anthropic, DeepSeek | To power AI chat and menu/notes features (see §4) |
| OpenAI | To automatically screen chat messages for abusive content (see §4) |
| Telnyx | To send SMS links/codes and to receive calls for phone ordering |
| Telegram | To deliver order alerts to owners who enable it |
| Smarty | To validate and autocomplete addresses |
| Nominatim / OpenStreetMap | To geocode business addresses for the map |
| Email provider (Fastmail SMTP) | To send account and transactional email |
| Hosting & database (Vercel, Neon) | To host the application and store data |
A restaurant's own OrderBee Companion app, if they use one, sends texts from that restaurant's own phone number and is operated by the restaurant, not by us — see our SMS & Telegram Messaging Policy.
We may also disclose information to comply with law or valid legal process, to protect rights, safety, and security, and to a successor entity in a merger, acquisition, or sale of assets.
7. Cookies and similar technologies
We use cookies and browser local storage to keep owners signed in (session cookies), keep an admin user signed in to admin tools, and preserve a diner's agent conversation across page reloads (local storage). Our website also loads Google Fonts, which may expose your IP address to Google when the font is fetched. We do not use third-party advertising cookies. You can block or delete cookies in your browser, but parts of the service may stop working.
8. Data retention
- Account and order records are kept while your account or API key is active and as needed to provide the service, meet legal/tax/accounting obligations, and resolve disputes.
- Diner chat transcripts are retained to support the live conversation and order; we remove or de-identify them once no longer needed for that order, support, or fraud purposes.
- Logs are kept for a limited period for security and debugging.
When we no longer need information, we delete or de-identify it.
9. Security
We use measures such as encrypted transport (HTTPS), restricted access, scoped API keys, encryption at rest for connected point-of-sale and payment credentials, and reliance on PCI-compliant processors (Stripe) for card data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Keep your API key and sign-in links secret — you are responsible for activity under your credentials.
10. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or port your information, to opt out of sale or sharing for targeted advertising (note: we do not sell or share in this way), and to be free from discrimination for exercising these rights.
To exercise any right, contact support@orderbee.app. We will verify your request (typically via the email associated with your account) before acting. You may use an authorised agent where the law allows.
California (CCPA/CPRA). We do not sell or share personal information as defined under California law. California residents have the rights above and the right to limit use of sensitive personal information; we do not use sensitive information for purposes that trigger that right.
EEA / UK (GDPR). Where the GDPR applies, our legal bases are in §3. You may lodge a complaint with your local supervisory authority. Where we transfer data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses.
11. Children
OrderBee is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal information. Some goods are age-restricted (e.g. alcohol, dispensary items); you must meet the legal age and comply with local law to order them. If you believe a child has given us information, contact us and we will delete it.
12. International users
OrderBee is operated from the United States and data is processed there and in the regions used by our service providers. By using the service you understand your information may be transferred to and processed in the United States.
13. Changes to this Policy
We may update this Policy from time to time. We will revise the "Last updated" date above and, for material changes, provide additional notice where required. Continued use after a change means you accept the updated Policy.
14. Contact
Questions, requests, or complaints: FREE HIM INC. (operating as OrderBee), support@orderbee.app.
This Policy is governed by the laws of the State of California, United States, without regard to conflict-of-laws rules.
← Back to OrderBee · Terms of Use · Restaurant Partner Agreement · SMS Policy →