Orderance Customer Privacy Policy

Last updated: October 1, 2026
Privacy and support contact: support@orderance.com

1. Introduction

Orderance is an online ordering and restaurant-services platform operated by TOG. In this Privacy Policy, “TOG,” “we,” “us,” and “our” refer to the organization operating Orderance. Orderance is a product and brand of TOG, not a separate legal entity.

This policy explains how personal information is collected, used, disclosed, retained, and protected when customers use websites, ordering widgets, applications, and related services powered by Orderance that display or link to this policy.

Depending on the features enabled by a participating restaurant, these services may include online ordering, reservations, catering requests, customer accounts, memberships, promotions, rewards, payment integrations, delivery integrations, and customer communications. We refer to these collectively as the “Services.”

A participating restaurant is referred to as the “Restaurant.” A person using the customer-facing Services is referred to as a “Customer” or “you.” An authorized reseller, agency, or other business helping a Restaurant use the Services is referred to as a “Partner.”

“Personal information” means information about an identified or identifiable individual, including information that can reasonably be linked to an individual through an account, device, order, or other identifier.

2. Scope

This policy applies to TOG’s handling of Customer personal information when you place an order, make a reservation, use an enabled customer account, membership or reward program, subscribe to an identified marketing program, or contact TOG for support. It includes information collected through the Services on a Restaurant’s behalf and information processed for TOG’s own disclosed platform purposes.

It also describes information disclosed to the relevant Restaurant and other organizations involved in providing the requested service.

The policy applies to TOG-operated Services displaying this policy, including services presented under a Restaurant’s branding or an authorized reseller’s branding.

Restaurants, resellers, payment providers, and delivery providers may have their own privacy notices for their respective activities. Those notices do not replace TOG’s responsibilities for its own handling of personal information.

Commercial arrangements between TOG, Restaurants, and resellers, including restaurant subscription billing, are governed separately. A referral or billing relationship does not, by itself, authorize access to Customer information.

3. TOG’s Role and the Restaurant’s Role

TOG provides the technology

TOG provides tools that allow Restaurants to display menu information, receive orders and reservations, manage enabled customer-facing features, communicate order updates, and connect with payment and delivery providers.

TOG and authorized partners may assist Restaurants with website setup, menu entry, configuration, and technical support. TOG does not operate the Restaurant, prepare or handle its food, supervise its kitchen, or physically deliver its orders.

Restaurants control their operations

The Restaurant determines its menu, prices, availability, operating hours, preparation settings, acceptance settings, and fulfillment arrangements within the available platform features.

Restaurants may accept orders manually or choose to enable automatic acceptance. Automatic acceptance follows the Restaurant’s selected settings and does not establish that an employee has individually reviewed every instruction.

The Restaurant prepares the food and arranges fulfillment through its own personnel or a third-party delivery provider it chooses to use.

The Restaurant collects information for its customer relationship

When you place an order, make a reservation, or use a Restaurant’s customer program, the Restaurant identified on the storefront collects the relevant personal information for its business through the Services. It uses that information to manage the transaction, serve you, maintain its records, and conduct other properly disclosed activities, including permitted marketing.

TOG receives, hosts, organizes, transmits, and otherwise processes this information to provide the platform. The information is not necessarily stored only at the Restaurant or on its devices. Restaurants can access their authorized records through administration tools, order-taking devices, receipts, and exports.

The Restaurant determines the purposes of its own customer records and campaigns and is responsible for its notices, lawful instructions, required permissions, and handling of exported or printed records. Its choices remain subject to applicable law.

TOG and Partner responsibilities

For Restaurant-directed order, reservation, customer-management, and marketing-support activities, TOG and authorized Partners process information to provide the agreed services on the Restaurant’s behalf. Partner activities are described in Sections 5 and 8.

TOG also handles information for its own disclosed platform purposes, including account administration, technical support, security, reliability monitoring, service analytics, incident investigation, and legal obligations.

Where applicable law uses these terms, TOG may act as a processor or service provider for Restaurant-directed activities and as a controller or business for activities it determines independently. A Partner that determines an independent use has its own corresponding responsibilities. The applicable role depends on the actual activity, not merely the label “technology provider” or “reseller.”

Each organization remains responsible for its own handling of personal information. The Restaurant’s control of its customer relationship does not eliminate TOG’s responsibilities, and no description of data ownership removes a Customer’s privacy rights.

4. Personal Information We Collect

The information collected depends on the service requested and the features enabled.

Contact and account information

This may include your name, email address, telephone number, account identifiers, authentication information, saved preferences, and records of communication or consent choices.

Order and reservation information

This may include ordered items, quantities, sizes, modifiers, instructions, order amounts, discounts, reservation dates and times, party sizes, and relevant status history.

We also process records associated with acceptance, preparation estimates, fulfillment, cancellations, refunds, and related support.

Membership and reward information

Where enabled, these features may involve membership status, subscription references, eligible purchases, benefits, reward balances, redemptions, and related adjustments.

Participation in a membership or reward program does not, by itself, authorize unrelated marketing or disclosure of your information to unrelated Restaurants.

Marketing, preference, and analytics information

Where the relevant functions are enabled and the information is lawfully collected, records may include marketing permissions, unsubscribe choices, campaign referrals, offer redemptions, purchase frequency, spending history, membership segments, and message delivery or engagement information. This information can support Restaurant reporting, relevant offers, and permitted campaign measurement by the Restaurant, TOG, or its authorized Partner.

Order instructions about health, allergies, or accessibility are not ordinary marketing-profile information. Their treatment is addressed in Section 13.

Payment-related information

We process information needed to associate payments with orders or memberships, including payment-provider references, transaction identifiers, amounts, currency, payment status, refund status, and limited payment-method information supplied by the provider.

Online payments are processed through integrated providers such as Stripe and Moneris. Their handling of payment information is also subject to their respective privacy notices.

Do not enter complete card numbers, security codes, banking passwords, or other payment credentials into order notes or support messages.

Delivery and location information

For delivery, we may process your street address, unit or suite number, city, province or region, postal code, country, delivery instructions, and confirmed map pin or coordinates.

If a feature requests access to your device’s location, the applicable device permission and notice will apply. Entering an address manually is separate from allowing access to device location.

Delivery records may include quote and delivery references, tracking information, original and updated pickup and arrival estimates, actual milestones where supplied, quoted and billed delivery charges, adjustments, cancellation or return information, and completion outcomes. Where enabled and supplied by the provider, this may also include proof of delivery and limited courier information needed to coordinate or investigate the delivery.

Support information

We process information you provide when contacting TOG, including messages and relevant supporting material such as screenshots. Please provide only information needed to explain the issue.

Technical, usage, and reliability information

This may include IP addresses, browser and operating-system information, device or installation identifiers, application versions, session activity, and interactions with the Services.

Technical records may include information about checkout attempts, order transmission, notifications, payment responses, acceptance timing, printing outcomes, connection status, and application errors. Order-taking diagnostics may also include memory measurements, resource usage, and crash or restart evidence.

Information linked to an account, device, or transaction may remain personal information even when names and contact details have been removed.

Sources

Information is collected directly from you, through forms and checkout interfaces operated for the relevant Restaurant, through your use of the Services, from the Restaurant or its authorized Partners, and from integrated providers involved in the requested service.

A Restaurant or Partner may provide existing records during onboarding or migration, or enter a request you made through another authorized channel. It must have authority to supply the information for the stated purpose. Importing an old customer list does not create new marketing consent.

If you supply another person’s information, such as a delivery recipient’s contact details, provide only what is needed and ensure that you have authority to provide it and that the person receives appropriate information about its use.

5. How We Use Personal Information

Providing the Services. We use information to transmit orders and reservations, support account functions, facilitate payments, coordinate delivery integrations, provide status updates, produce receipts, and administer enabled memberships, promotions, and rewards.

Communications and support. We use contact and transaction information to send relevant confirmations, verification messages, order updates, reservation information, delivery updates, and responses to support requests.

Restaurant reporting and analytics. We process relevant order, membership, payment-status, campaign, and delivery records to support order history, sales reports, repeat-customer reporting, offer performance, delivery-cost reconciliation, and fulfillment analysis. Authorized Partners may assist a Restaurant with these activities. Reporting can include average order value, preparation and delivery duration, cancellations, refunds, and discount usage, subject to applicable permissions and access restrictions.

Reliability and security. We use technical and transaction-related information to monitor performance, investigate failed order delivery, prevent duplicate actions, diagnose application or printing problems, protect accounts, and investigate suspected fraud or misuse.

Business administration and legal obligations. We process information where necessary for billing, reconciliation, audits, dispute handling, recordkeeping, legal obligations, and establishing or defending legal claims.

Restaurant and Partner marketing. A Restaurant may use permitted contact, order-history, membership, and preference information for its disclosed promotions, loyalty campaigns, and customer communications. TOG or an authorized Partner may help collect preferences, manage the permitted audience, prepare or send messages on the Restaurant’s behalf, and measure campaign performance. These activities must stay within the applicable notice, consent or other lawful authority, and unsubscribe choices.

Independent marketing. TOG or a Partner may offer an independently identified marketing program only with the notices and valid permissions required for that program. A Restaurant’s instruction alone is not permission for a Partner to use Customer information for its own unrelated campaigns. Details of independent uses must be presented to you before the use or disclosure where required.

Your choices. Promotional email and SMS are separate from communications needed for an order, payment, reservation, delivery, or account security. Where promotional messages require consent, the sender must hold valid consent, identify the required sending organizations, and provide an unsubscribe method. You can unsubscribe without deleting your ordering account. This policy is not a subscription to every Restaurant’s or Partner’s marketing list.

Aggregated information. We may produce aggregated reports about service use and performance. Information is treated as anonymous only where individuals cannot reasonably be identified from it. Replacing a name with an identifier does not necessarily make information anonymous.

6. Consent and Other Grounds for Processing

We collect, use, and disclose personal information with consent where required, or where another applicable legal basis or exception permits the activity.

Some information is necessary to provide a requested service. For example, delivery requires a delivery location and suitable contact information. If necessary information is not provided, the relevant service may not be available.

Optional uses are separate from the information needed to complete a transaction. Where consent is required for an optional use, the relevant information and choice must be provided.

You may withdraw consent where applicable, subject to legal or contractual restrictions and reasonable notice. We will explain relevant consequences, such as a feature no longer being available.

Where applicable law requires a specified processing basis, relevant grounds may include performing a contract with you, meeting legal obligations, consent, and legitimate interests such as maintaining secure and functional Services, subject to the required assessment of your rights.

For Restaurant-directed processing, the Restaurant is responsible for establishing the appropriate basis, and TOG processes information under the applicable service arrangement.

This policy explains our practices. It is not blanket consent to undisclosed activities or unrelated uses.

7. Retention and Deletion

Personal information is retained for as long as reasonably necessary for the purpose for which it was collected, taking account of applicable legal obligations and legitimate operational requirements.

Different records may have different retention periods. Relevant considerations include whether an account remains active, whether a transaction or dispute is outstanding, the Restaurant’s lawful instructions, security needs, accounting requirements, and whether information can be deleted or made anonymous.

Archiving an order is not the same as deleting personal information. An order removed from an active order-taking screen may remain in authorized order history, reporting, or records required for a permitted purpose.

Deleting an account does not necessarily remove transaction information that must be retained to complete an order, comply with law, resolve a dispute, or fulfill another permitted purpose.

Where a retention requirement limits a deletion request, we will explain the applicable limitation as required by law. Retention should not continue indefinitely merely because storage is available.

Backup copies may remain until the applicable backup-retention cycle expires and remain subject to access restrictions. You may contact support@orderance.com to ask about retention or deletion relevant to your information.

8. Disclosure of Personal Information

The relevant Restaurant

We provide the Restaurant and its authorized personnel with information needed to manage your order, reservation, membership, or other requested service and carry out its properly disclosed customer activities. The Restaurant is a recipient and collector of its customer information, not merely a name displayed on TOG’s checkout.

Its use of records on its own systems, printed receipts, and authorized exports remains subject to its privacy obligations and your applicable choices. It may engage its own providers for permitted customer service, reporting, or marketing.

Authorized Partners and resellers

An authorized Partner may collect, enter, access, organize, or use relevant information to operate a Restaurant’s branded storefront, migrate records, provide account support, manage customer relationships, analyze orders and campaigns, or conduct permitted marketing on the Restaurant’s behalf.

Access is limited to the accounts and purposes for which the Partner is authorized. Restaurant authorization and the Customer permissions required by law are separate requirements. A referral, billing, or reseller relationship does not authorize unrestricted access, sale of customer lists, or undisclosed independent marketing.

Where a Partner seeks to collect information for its own purposes, including its own promotions, it must identify itself and explain those purposes, recipients, and available choices, and obtain the permissions required for that activity. Contact the Restaurant or TOG to identify the Partner involved in your transaction or campaign.

Customer records are not made available to unrelated Restaurants solely because they use Orderance. Any sharing within a multi-location group or a joint campaign must be covered by the relevant disclosure and lawful authority; a shared login or common reseller is not blanket permission.

Payment providers

Providers such as Stripe and Moneris process payment-related information for authorization, settlement, fraud prevention, refunds, disputes, and their other applicable responsibilities.

TOG exchanges information needed to connect a payment with the relevant transaction and support its processing. A payment provider’s own privacy notice explains processing it undertakes independently. See the Stripe Privacy Policy and Moneris Privacy Statement, as applicable.

Delivery providers

Where the Restaurant uses third-party delivery, TOG passes information needed to obtain a quote, arrange collection, complete delivery, send delivery updates, and resolve delivery problems to the selected provider. This can include the Customer’s or recipient’s name, contact number, delivery address, postal code, confirmed location pin, relevant access instructions, pickup information, order or package references, and package contents or value where needed for the service.

These integrations include Uber Direct and other delivery providers enabled for the Restaurant. The relevant provider and its courier receive the information needed for their roles. The provider may contact the recipient with service-related calls, texts, or tracking updates.

TOG and the Restaurant may receive and retain delivery references, tracking links, assignment updates, estimates, pickup and delivery milestones, costs and adjustments, cancellations, returns, and proof of delivery where available. We use these records for order tracking, delivery-cost reconciliation, customer support, disputes, service reliability, and operational analytics, including delivery time and success rates.

The disclosure is connected to the delivery, not permission for unrelated marketing. Unrelated customer history, payment credentials, or sensitive notes must not be included merely because they appear elsewhere in an account.

A delivery provider may have its own responsibilities for information it processes independently. For Uber Direct deliveries, see Uber’s Privacy Notice for Riders and Order Recipients, which also addresses recipients of deliveries arranged by a business.

Infrastructure and support providers

We use providers for functions such as hosting, storage, network security, email delivery, notifications, technical support, mapping, and service performance.

Depending on the service, these may include Cloudflare for network and security services and Resend for email delivery. Email providers receive the recipient address and relevant message content and may return delivery, bounce, complaint, and lawfully enabled engagement information. Mapping providers may receive address or location information needed to locate and validate a delivery destination.

Not every provider receives information about every Customer or transaction. See the Cloudflare Privacy Policy and Resend Privacy Policy for their respective independent practices.

Where a provider processes information on our behalf, access is limited to the authorized service and applicable contractual and legal requirements. Providers may also have independent responsibilities for some processing.

Authorized TOG personnel

Personnel may access personal information where needed for their duties, including support, system maintenance, security, billing, and incident investigation.

Legal requirements and business changes

We may disclose information when required or permitted by law, including responding to valid legal demands, protecting people or systems, investigating suspected wrongdoing, or establishing or defending legal claims.

Information may also be disclosed in connection with a proposed or completed business transaction, such as a sale or restructuring, subject to appropriate restrictions and applicable legal requirements.

Any materially different use or disclosure requires the additional notice, consent, or other legal basis applicable to that activity. This policy does not authorize unrestricted disclosure of Customer information.

9. International Processing

TOG operates from Alberta, Canada. Personal information may be stored, accessed, or processed outside your province, territory, or country when the Services involve providers or authorized personnel operating elsewhere.

Relevant processing may include hosting, backup, payment processing, email delivery, network security, technical support, authorized marketing assistance, and delivery services. The locations involved depend on the provider and service used, including access by authorized personnel.

Processing can include Canada and the United States, as well as other jurisdictions involved in a provider’s operations. For example, Resend describes United States processing for its email service, and Stripe and Uber describe international processing that includes the United States. Their notices linked in Section 8 provide further information. These examples are not a representation that every order is processed in the same locations or an exhaustive list of processing countries.

Information processed in another country may be subject to that country’s laws and lawful access by its courts, law-enforcement agencies, or other authorities.

TOG remains responsible for its own handling of personal information and for the safeguards required when information is processed on its behalf. Where a particular international-transfer mechanism is required, it must be established for the relevant transfer; this policy does not itself create that mechanism.

To obtain access to TOG’s policies and practices concerning service providers outside Canada, or to ask which countries and purposes apply to your information, contact the TOG Privacy Contact at support@orderance.com using the contact details in Section 16. This contact can answer questions on TOG’s behalf and coordinate requests concerning the relevant Restaurant or Partner. This policy does not represent that all information is stored exclusively in Canada.

10. Security

TOG uses safeguards intended to protect personal information against unauthorized access, use, alteration, disclosure, or loss.

Safeguards should be appropriate to the sensitivity of the information, the purposes for which it is processed, and the relevant risks. They include measures relating to access control, account security, system maintenance, and incident handling.

No website, application, network, or storage system can guarantee absolute security.

Customers should protect account access and report suspected misuse. Restaurant administrators are responsible for managing authorized staff access and protecting devices and records within their control.

If a privacy or security incident occurs, TOG will assess the incident and provide notifications to affected organizations, individuals, or authorities where required by applicable law.

11. Cookies, Local Storage, and Similar Technologies

The Services use cookies, local storage, application storage, and similar technologies to support relevant functionality.

Necessary technologies may support authentication, security, cart contents, checkout continuity, and functions you request.

Preference technologies may remember selections such as language or interface preferences.

Analytics and advertising technologies, where enabled, may measure usage, campaign performance, or other specifically disclosed activities. An analytics or advertising technology is not necessary merely because it is useful to TOG or a Restaurant.

The technologies used depend on the interface, provider integrations, and features enabled. Campaign measurement may involve referral parameters, promotion codes, cookies, pixels, or tracked links where lawfully enabled. A Restaurant or Partner may select some of these tools independently.

Where consent is required for optional technologies, the provider, purpose, relevant duration, and available choice must be explained before use, and the required consent must be obtained. Refusing optional marketing or tracking does not prevent ordinary ordering where that processing is unnecessary to fulfill the request. This policy is not consent to undisclosed advertising, cross-business audience sharing, or tracking.

Browser and device settings may allow you to restrict or delete stored information. Blocking necessary storage may prevent login, checkout, or other requested functions from working. Browser controls do not replace a service’s obligation to obtain consent where required.

Deleting cookies or local storage does not necessarily delete records already held on a server.

Restaurants may independently add tools to their own websites. Their notices and choices apply to those additional tools. Contact the Restaurant about its independently selected website integrations or support@orderance.com about technologies used by TOG.

12. Your Privacy Rights and Choices

Depending on applicable law, you may have rights to request access to your personal information, correction of inaccuracies, deletion, restriction, portability, or information about its use and disclosure. You may also have rights to object to certain processing or withdraw consent.

Submit privacy enquiries and requests to support@orderance.com. Identify the relevant Restaurant or account and the nature of your request. Do not send passwords or complete payment credentials.

We may request proportionate information to verify your identity or authority before disclosing personal information or making certain changes. We will respond within applicable legal time limits and explain any permitted refusal, limitation, or extension.

Where TOG processes information for a Restaurant, we may coordinate your request with that Restaurant. You do not need to resolve a privacy concern about TOG’s own conduct through the Restaurant first.

You may use the unsubscribe mechanism in promotional communications or contact the relevant sender to change marketing preferences. Unsubscribe requests are handled without delay and within the legally required period. You do not need to close your account or make another purchase to unsubscribe.

A Partner sending messages for a Restaurant must apply the relevant unsubscribe choice to that Restaurant’s campaign. An independently operated marketing program must provide its own clearly identified choices. Necessary messages about an existing transaction, account security, or a legal obligation may still be sent where permitted. Adding promotional material to a service message does not automatically exempt it from marketing requirements.

Requests submitted through an authorized representative will be handled according to applicable verification requirements.

13. Sensitive Information and Children

Allergy, dietary, and accessibility information

Order and reservation instructions may contain sensitive personal information, including allergy or accessibility details.

Provide only information relevant to the requested service. Relevant instructions are transmitted to the Restaurant so it can assess and handle the request. TOG may access them where necessary for authorized support or incident investigation.

Allergy, health, and accessibility instructions supplied for fulfillment are not used to build marketing audiences merely because they are present in an order. Any additional use requires its own appropriate explanation and legal basis, including specific consent where required. Additional safeguards apply as appropriate to the sensitivity of the information.

Customers with food allergies should contact the Restaurant directly before placing an order to discuss ingredients, preparation methods, and whether the Restaurant can accommodate their needs.

An order note or automatic acceptance does not confirm that an allergy request has been individually reviewed or can be accommodated. TOG does not inspect ingredients or kitchen practices or certify food as allergen-free.

Children

The Services are not specifically directed at children.

Where parental or guardian consent is required by applicable law, that consent must be obtained. If you believe a child’s information has been collected improperly, contact support@orderance.com so we can investigate and take appropriate action.

14. Additional Regional Rights

The rights and obligations applicable to personal information depend on the circumstances and the relevant jurisdiction.

Where EU, UK, or comparable data-protection laws apply, additional rights may include objecting to processing based on legitimate interests, requesting restriction or portability, and complaining to the relevant supervisory authority.

Where California privacy law applies to the relevant activity, California residents may have rights to know, access, correct, or delete personal information; opt out of a sale or sharing covered by that law; limit certain uses or disclosures of sensitive information; and receive equal treatment when exercising their rights.

These rights are subject to the applicable law’s scope and exceptions. This section does not state that every right applies to every Customer or that TOG is subject to every jurisdiction’s requirements.

To ask about applicable rights or submit a request, contact support@orderance.com. Any additional notice or choice required for a particular activity must be provided for that activity; this general section does not replace it.

15. Third-Party Websites and Services

The Services may link to or integrate with independently operated restaurant websites, payment interfaces, delivery tracking, and other services.

Those organizations may handle information under their own privacy notices. Review the notice applicable to the service you use.

A link does not mean TOG operates that third-party service. It also does not remove TOG’s responsibilities for information it discloses or for processing performed on its behalf.

16. Privacy Contact

TOG Privacy Contact
Orderance
Address: 11033 127 St, Edmonton, AB, Canada
Email: support@orderance.com

Use this email for privacy questions, access and correction requests, deletion enquiries, concerns about international processing, and complaints about TOG’s handling of personal information.

For immediate questions about an order, food preparation, delivery instructions, or a reservation, contact the Restaurant using the contact details shown with your order. TOG can assist with platform-related technical matters.

17. Privacy Complaints

Please contact support@orderance.com with concerns about how TOG handles personal information. We will investigate and respond as required by applicable law.

You may also contact the privacy authority with jurisdiction over the matter. Depending on the circumstances, this may include the Office of the Information and Privacy Commissioner of Alberta, the Office of the Privacy Commissioner of Canada, or another applicable authority.

You do not lose the right to contact an authority by first raising the issue with TOG.

18. Changes to This Policy

We may update this policy when our Services, practices, or applicable requirements change.

The current version will show its update date. We will provide additional notice of material changes where required and obtain any further consent required before introducing a new use or disclosure.

Publication of an updated policy does not, by itself, authorize a materially different use of personal information already collected. Adding a new Partner, marketing purpose, or shared campaign requires the notice and further permission applicable to that change; historical customer records are not automatically enrolled.