Privacy and data retention
What customer data Restro keeps, for how long, and how to answer a request to see or delete it.
Settings → Privacy.
Diners in the EU and UK have the right to ask for a copy of the personal data you hold on them, and to ask you to delete it. The law gives you one month to answer. This page is where you set your retention policy and service those requests.
#What is held about a diner
| Data | Where it comes from | Kept because |
|---|---|---|
| Name, email, phone | Account sign-up, checkout, or a member of staff | Identifying the diner and contacting them about an order |
| Saved addresses, including map coordinates | Delivery checkout and the account page | Delivering to them without retyping the address |
| Order history and totals | Every order placed | Tax and accounting records |
| Bookings | Reservations and the waitlist | Running the booking, and no-show history |
| Reviews | Review invitations after an order or visit | Public reputation and service feedback |
| Store credit transactions | Refunds to credit and manual grants | Explaining a balance |
| Saved favourites | The heart button on a menu item | Reordering quickly |
| Sign-in codes | Signing in by email or text | Verifying the diner is who they say |
#Letting diners handle it themselves
Let diners manage their own data adds a Your data section to the account page on your website and in your app. From there a diner can download everything you hold on them as a JSON file, or ask you to delete it — without going through your team.
Leave it off and diners have to contact you instead; your team then services the request from the customer's page in the dashboard.
#Downloading a diner's data
Open the customer, then Data and privacy → Download data. You get a JSON file with their profile, addresses, orders, bookings, reviews, store credit history and favourites. Send it to them however they asked.
Every download is recorded, so you can show when a request was answered.
#Deleting a diner's data
Deletion does not remove the orders. Order records have to be kept for tax, so Restro anonymises instead: the diner's personal details go, and the money stays.
What is removed:
- Name, email and phone on the customer record
- Every saved address, including coordinates
- Saved favourites
- Delivery addresses, coordinates and notes on past orders
- Name, phone, email, occasion and notes on past bookings
- Reviewer name and review text
- Outstanding sign-in codes
What stays:
- Order numbers, line items, totals, VAT, tips and refunds
- Store credit transactions, so a balance can still be explained
- Star ratings, counted anonymously towards your averages
The customer record itself stays behind, blank, so the orders still add up in your reports.
This cannot be undone.
#The grace period
A deletion request waits before it runs — seven days by default — so a diner who changes their mind can cancel from their account page, and so your team can spot a request made in error. Set Days before a deletion goes through to 0 to delete immediately.
While a request is waiting it shows on the customer's page and in the request list, and anyone with permission can cancel it or run it early.
#Automatic retention
Two windows run without anyone asking, as part of the nightly Privacy retention automation (Settings → Automations):
- Erase quiet customers after — days without an order or booking before a diner's personal details are removed automatically. Leave it empty to keep customers indefinitely. Diners holding store credit are never swept, so nobody loses money they are owed.
- Keep login codes for — hours before used and expired sign-in codes are deleted. Expired codes are always removed regardless.
The same run executes any deletion requests whose grace period has elapsed.
#Who can do this
Two permissions, held by owners and admins by default:
privacy:read— see the requests and the retention policyprivacy:manage— download a diner's data, delete it, and change the retention windows
If someone else handles data requests, add the permissions to their member as a grant — see Roles and permissions.
#Keeping a record
Every download, deletion request, cancellation and automatic sweep is written to the activity log with who did it and when. Filter the log by Data requests to produce an audit trail if a regulator asks.
Your privacy policy still needs to say what you collect and why — write it under Settings → Policies.
Did this page miss something? Tell us.
Back to top