Privacy Policy
Last Updated: August 11, 2026
1. Scope and roles
This Privacy Policy explains how Curate Technologies, Inc. (“Curate,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes Personal Information through our websites, merchant-facing products, diner-facing ordering pages and applications, loyalty programs, marketing tools, support channels, and related services (collectively, the “Services”). When a restaurant, restaurant group, or franchise system uses the Services (a “Merchant”), that Merchant generally controls Personal Information it collects about its diners. In that role, Curate acts as a service provider or processor on behalf of the Merchant. Curate separately controls Personal Information used for account administration, billing, security, legal compliance, and corporate-site operations. This Policy does not replace a Merchant’s own privacy notice or ordering, refund, or fulfillment policies.
2. Personal Information we collect
Depending on how you use the Services, we may collect: (a) Identifiers and Contact Information, such as name, email address, phone number, device identifiers, IP address, and account identifiers; (b) Commercial Information, such as orders, payments, delivery, loyalty, offers, and transaction history; (c) Profile Information, such as preferences, birthday, and demographic information you choose to provide; (d) Location Information, including precise device location only when you permit it, and general location derived from your address or IP address; (e) Dietary Preferences or Allergy Information you choose to provide; (f) Communications and Support Information; (g) Device, Browser, and Online Activity Information, including advertising identifiers; (h) Merchant and Merchant-Employee Contact and Account Information; and (i) Payment Information, including payment tokens or other processor-generated payment data. Curate does not store raw payment-card numbers; payment processors handle card information under their own terms and notices.
3. Sources of Personal Information
We collect Personal Information: directly from you; from Merchants and their employees; from your use of the Services; from point-of-sale, payment, delivery, and other integrations that you or a Merchant enable; from cookies, pixels, SDKs, and similar technologies; and from service providers and business partners where permitted by law.
4. How we use Personal Information
We use Personal Information to: provide, operate, secure, troubleshoot, personalize, and improve the Services; process and support orders, payments, loyalty, delivery, and customer-service interactions; send receipts, order-status, delivery-status, account-security, and service messages; enable Merchant-directed marketing campaigns; measure performance and analyze use of the Services; conduct advertising and retargeting where permitted by law and consistent with your choices; prevent fraud and protect security; comply with law and enforce our agreements; and create and use Deidentified Data for analytics, benchmarking, product improvement, and artificial-intelligence or machine-learning model development. We do not use identifiable diner information to train a general-purpose AI model unless the relevant Merchant has expressly opted in and the use is permitted by applicable law.
5. How we disclose Personal Information
We may disclose Personal Information to: the Merchant with which you interact, and to locations, franchisees, or corporate administrators within that Merchant’s Brand Network when the Merchant has enabled that access; service providers and subprocessors that perform services for us, such as hosting, support, messaging, payment, delivery, analytics, and security providers; point-of-sale, payment, and delivery providers selected by a Merchant or you; advertising and analytics partners where permitted by law and subject to your choices; professional advisers, regulators, law enforcement, or others where required or permitted by law; and parties involved in a corporate transaction (such as a merger, acquisition, or asset sale). We do not sell Personal Information for monetary consideration. Our use of advertising or retargeting technologies may constitute “sharing” or a similar regulated disclosure under certain U.S. state privacy laws, including the California Consumer Privacy Act.
6. Marketing and operational messages
Merchants direct the marketing campaigns (email, SMS, push notifications, and similar messages) they send through the Services. You may: opt out of marketing emails by using the unsubscribe link in the email; opt out of marketing text messages by replying STOP or following the instructions in the message; and manage push notifications through your device settings. Opting out of marketing does not stop transactional messages, including receipts, order and delivery updates, security alerts, or service notices. We maintain information necessary to honor your opt-out and suppression requests.
7. Cookies, pixels, and similar technologies
We and our service providers use cookies, pixels, SDKs, tags, and similar technologies on our corporate sites and diner-facing properties to operate the Services, remember preferences, analyze use, measure campaigns, and support advertising or retargeting.
8. Retention
We retain Personal Information for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining loyalty and order records, addressing disputes, preventing fraud, complying with legal obligations, and enforcing agreements. Retention periods consider the nature and sensitivity of the information, the relationship with the Merchant or diner, applicable legal requirements, and whether the information is needed for an active request, dispute, or security matter. After a Merchant’s relationship with Curate ends, Curate generally provides the Merchant a ninety (90) day period to export applicable data, then deletes or deidentifies data from active systems, subject to legal, fraud, security, payment-dispute, and backup exceptions. Backup copies are retained only until deleted in the normal backup cycle and are not used for unrelated purposes. We may retain Deidentified Data indefinitely.
9. Security
We use reasonable administrative, technical, and physical safeguards designed to protect Personal Information. Our current measures include encryption in transit and at rest, role-based access controls, multifactor authentication for internal systems, and backup and disaster-recovery procedures. No system is completely secure, and we cannot guarantee absolute security.
10. Your privacy choices and requests
Depending on your location and relationship with Curate, you may have rights to: request access to, correction of, deletion of, or portability of your Personal Information; request restrictions on processing of your Personal Information; or object to or opt out of certain processing. To submit a request email privacy@getcurate.com. We may verify your identity before fulfilling a request. You may designate an authorized agent to submit a request on your behalf; we may require verification of the agent’s authority. If Curate processes the relevant information solely on behalf of a Merchant, we may route the request to that Merchant or assist it in responding. We aim to respond to verified requests within the time required by applicable law. We do not discriminate against individuals who exercise their privacy rights.
11. U.S. state privacy disclosures
Residents of certain U.S. states, including California, have additional privacy rights under applicable state law. California Residents: Under the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), California residents may: request information about the categories and specific pieces of Personal Information we have collected, the sources of collection, the purposes for collection, and the categories of third parties with whom we share Personal Information; request correction or deletion of Personal Information; request information about disclosures, sales, or sharing; opt out of the sale or sharing of Personal Information; opt out of targeted advertising; and limit certain uses of Sensitive Personal Information. We collect the following categories of Personal Information as defined under the CCPA: identifiers; customer-record information; commercial information; internet or other electronic-network activity information; geolocation information; and Sensitive Personal Information (such as precise geolocation and health-related dietary or allergy information, if provided). We use these categories for the purposes described in Section 4 and retain them using the criteria in Section 8. We may disclose these categories to Merchants, service providers, contractors, delivery and payment providers, and advertising and analytics partners as described in Section 5. To opt out of the sale or sharing of your Personal Information, submit a request as described above. If we deny a request where appeal rights apply, we will explain how to appeal and provide contact information for the California Attorney General.
12. Canada
For individuals in Canada, we collect, use, disclose, retain, and safeguard Personal Information for the purposes described in this Policy and in accordance with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation. We obtain consent where required and use Personal Information only for identified, appropriate purposes or as otherwise permitted by law. You may contact privacy@getcurate.com to request access to or correction of your Personal Information, to withdraw consent (subject to legal or contractual restrictions), or to ask questions about our practices. We respond to access requests within the time required by law.
13. Children
The Services are not directed to children under thirteen (13) years of age, and we do not knowingly collect Personal Information from children under 13 without verifiable parental consent. If you believe a child under 13 has provided us Personal Information without parental consent, please contact privacy@getcurate.com, and we will take steps to delete such information.
14. Third-Party Links and Services
The Services may contain links to third-party websites, applications, or services that are not operated by Curate. This Privacy Policy does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or the Services. We will post the updated Policy and revise the “Last Updated” date. Where required by law, we will provide additional notice or obtain consent before a material change takes effect.
16. International Data Transfers
Curate is based in the United States. If you access the Services from outside the United States, your Personal Information may be transferred to, stored, and processed in the United States or other countries where our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction. By using the Services, you acknowledge this transfer. We take steps to ensure that Personal Information receives an adequate level of protection in the jurisdictions in which we process it.
17. Contact Us
If you have questions about this Privacy Policy or wish to submit a privacy request, please contact us at:
Curate Technologies, Inc.
Attn: Privacy Office
1301 Dove Street, Suite 960
Newport Beach, CA 92660
Email: privacy@getcurate.com

