1. Overview
This Privacy Policy explains how IMIDUS Restaurant ("we", "us", or "our") collects, uses, and shares information about you when you use our mobile app to browse our menu, place an order, or interact with us. It applies specifically to our iOS and Android mobile application — our website and in-store interactions may be covered by separate notices.
2. Information we collect
2.1 Information you give us
- Account information — your name, email address, phone number, and password when you sign up for an account.
- Order information — items ordered, modifications, pickup time, and any notes you send the kitchen.
- Payment information — card details are tokenized by our payment processor; we never see or store the full card number.
- Communications — messages you send us through the in-app contact form, replies to our emails, or feedback after an order.
2.2 Information we collect automatically
- Device information — device type, operating system version, and a randomly generated device identifier we use to keep your session and push notifications attached to the right install.
- App usage — screens visited and actions taken inside the app (for example, items added to cart), used to diagnose problems and improve the ordering experience.
- Network information — IP address and approximate region derived from it, recorded with each request to our servers.
The app does not request access to your camera, microphone, contacts, photos, or precise location. If we ever add a feature that requires one of those permissions, we will ask you for it in a clear in-app prompt.
3. How we use your information
- To process and prepare your orders.
- To send order confirmations and pickup-ready notifications (see Section 5).
- To respond to questions, feedback, and support requests.
- To improve our menu and ordering experience.
- To send marketing emails or push notifications only if you've opted in. Every email has a one-click unsubscribe, and you can turn off push notifications in your device settings at any time.
- To detect and prevent fraud or abuse.
- To comply with legal obligations including tax records.
5. Push notifications
If you allow push notifications when prompted, the app registers a push token with Apple or Google and sends it to our servers, paired with your device identifier. We use this token to send you order updates (for example, "your order is ready") and, only if you have opted in, occasional promotional messages.
You can turn off push notifications at any time in your device's system settings. Doing so does not affect your ability to place orders — you'll still receive order updates by email.
6. Local storage on your device
The app stores a small amount of information directly on your device so it can work offline and keep you signed in:
- Your authentication tokens, stored in the operating system's secure keystore (Keychain on iOS, EncryptedSharedPreferences on Android).
- Your cart, preferences, and a cached copy of the menu, stored in the app's standard local storage.
You can clear all of this by signing out of the app or by clearing the app's data through your device settings. Doing so will sign you out and empty your cart.
7. Your choices & rights
You can do any of the following at any time:
- Access and download your account data.
- Correct any information that's wrong.
- Delete your account and the personal information tied to it.
- Unsubscribe from marketing emails.
- Turn off push notifications in your device settings.
Depending on where you live, you may have additional rights under laws like the GDPR (EU), UK GDPR, or CCPA (California). Contact us using the details below and we'll help you exercise them.
8. Data retention
We retain personal information only as long as we need it to provide the service, support refunds and accounting, and meet our legal obligations. Account data is removed within a reasonable period after an account is closed; some records (for example, order receipts) may be retained longer where tax or accounting law requires it.
9. Security
We use industry-standard safeguards: encrypted connections (TLS) for all traffic between the app and our servers, hashed and salted passwords, restricted internal access, and ongoing monitoring for suspicious activity. Authentication tokens on your device are stored in the operating system's secure keystore. If we ever suffer a data breach affecting your personal information, we'll notify you promptly as required by law.
10. Children's privacy
Our app is designed for adults 13 and older. We don't knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Material changes will be communicated in the app or by email.
12. Contact us
Questions, concerns, or requests about this policy?