Skip to content
Help

Privacy and data retention

What customer data Restro keeps, for how long, and how to answer a request to see or delete it.

Settings & billing3 min read

Settings → Privacy.

Diners in the EU and UK have the right to ask for a copy of the personal data you hold on them, and to ask you to delete it. The law gives you one month to answer. This page is where you set your retention policy and service those requests.

#What is held about a diner

DataWhere it comes fromKept because
Name, email, phoneAccount sign-up, checkout, or a member of staffIdentifying the diner and contacting them about an order
Saved addresses, including map coordinatesDelivery checkout and the account pageDelivering to them without retyping the address
Order history and totalsEvery order placedTax and accounting records
BookingsReservations and the waitlistRunning the booking, and no-show history
ReviewsReview invitations after an order or visitPublic reputation and service feedback
Store credit transactionsRefunds to credit and manual grantsExplaining a balance
Saved favouritesThe heart button on a menu itemReordering quickly
Sign-in codesSigning in by email or textVerifying the diner is who they say

#Letting diners handle it themselves

Let diners manage their own data adds a Your data section to the account page on your website and in your app. From there a diner can download everything you hold on them as a JSON file, or ask you to delete it — without going through your team.

Leave it off and diners have to contact you instead; your team then services the request from the customer's page in the dashboard.

#Downloading a diner's data

Open the customer, then Data and privacy → Download data. You get a JSON file with their profile, addresses, orders, bookings, reviews, store credit history and favourites. Send it to them however they asked.

Every download is recorded, so you can show when a request was answered.

#Deleting a diner's data

Deletion does not remove the orders. Order records have to be kept for tax, so Restro anonymises instead: the diner's personal details go, and the money stays.

What is removed:

  • Name, email and phone on the customer record
  • Every saved address, including coordinates
  • Saved favourites
  • Delivery addresses, coordinates and notes on past orders
  • Name, phone, email, occasion and notes on past bookings
  • Reviewer name and review text
  • Outstanding sign-in codes

What stays:

  • Order numbers, line items, totals, VAT, tips and refunds
  • Store credit transactions, so a balance can still be explained
  • Star ratings, counted anonymously towards your averages

The customer record itself stays behind, blank, so the orders still add up in your reports.

This cannot be undone.

#The grace period

A deletion request waits before it runs — seven days by default — so a diner who changes their mind can cancel from their account page, and so your team can spot a request made in error. Set Days before a deletion goes through to 0 to delete immediately.

While a request is waiting it shows on the customer's page and in the request list, and anyone with permission can cancel it or run it early.

#Automatic retention

Two windows run without anyone asking, as part of the nightly Privacy retention automation (Settings → Automations):

  • Erase quiet customers after — days without an order or booking before a diner's personal details are removed automatically. Leave it empty to keep customers indefinitely. Diners holding store credit are never swept, so nobody loses money they are owed.
  • Keep login codes for — hours before used and expired sign-in codes are deleted. Expired codes are always removed regardless.

The same run executes any deletion requests whose grace period has elapsed.

#Who can do this

Two permissions, held by owners and admins by default:

  • privacy:read — see the requests and the retention policy
  • privacy:manage — download a diner's data, delete it, and change the retention windows

If someone else handles data requests, add the permissions to their member as a grant — see Roles and permissions.

#Keeping a record

Every download, deletion request, cancellation and automatic sweep is written to the activity log with who did it and when. Filter the log by Data requests to produce an audit trail if a regulator asks.

Your privacy policy still needs to say what you collect and why — write it under Settings → Policies.

Did this page miss something? Tell us.

Back to top