DraftNot legal advice. Not reviewed by a lawyer.
This document was drafted by an AI. It has not been reviewed by a lawyer, it is not legal advice, and it is published here as a working draft so that a lawyer can edit rather than write. Do not rely on it, and do not take a customer’s money against it, until a qualified lawyer in your jurisdiction has reviewed it.
A value in [COMPANY LEGAL NAME]L1 has not been supplied. A value under a dashed rule such as support@pizzaflow.ioL6 is a working stand-in nobody has confirmed. A quiet [C1] after a number means that number is settled and traces back to the register.
PizzaFlow Privacy Policy
Last updated Version 1.0
Contents16
- 1Who this policy is for
- 2Who we are
- 3What we collect from shop owners and staff
- 4What passes through the system about callers
- 5How the data flows
- 6Who else handles data
- 7Our legal basis for processing
- 8How long we keep things
- 9Rights of shop owners
- 10Rights of callers, and how to use them when you never signed up with us
- 11Cookies and browser storage
- 12International transfers
- 13Security
- 14If there is a breach
- 15Changes to this policy
- 16Contact
Who this policy is for#
This policy covers two different groups of people, and the difference matters.
| Shop owners and staff | Callers | |
|---|---|---|
| Who they are | Shop owners and staffPeople who sign up, pay and use the panel | CallersMembers of the public who ring a shop or use its voice ordering link |
| Did they agree to anything with us? | Shop owners and staffYes, at signup | CallersNo. Never. |
| Our role | Shop owners and staffWe are the controller of their account data | CallersWe are a processor acting for the shop, which is the controller |
| Who they should complain to | Shop owners and staffUs | CallersThe shop first, but we must help |
| What we hold | Shop owners and staffName, email, business details, billing | CallersVoice, transcript, name, phone number, delivery address, order history |
Section 3 covers shop owners. Section 4 covers callers, and it is the important one.
Who we are#
[COMPANY LEGAL NAME]L1, of [REGISTERED ADDRESS]L3, operates PizzaFlow.
For questions about privacy, email privacy@pizzaflow.ioL7.
PizzaFlow is offered in the United States only. If that ever changes, this policy needs rewriting before the first customer outside the US is signed, and a UK or EU customer would also mean a named data protection representative and possibly a DPO.
What we collect from shop owners and staff#
Account data. Name, email address, and the password you set, which we never see in readable form because authentication is handled by our database provider.#
Business data. Business name, address, real phone number, opening hours, delivery settings, menu, prices, assistant configuration and any notes you write.#
Billing data. Your plan, your billing history and enough of your card details to identify it, such as the last four digits and the expiry. We never see or store your full card number. Stripe does.#
Usage data. When you sign in, what you change in the panel, and how many calls your shop handled. The system keeps an activity log for this.#
Technical data. IP address, browser type, and error logs, collected so the service works and so we can debug it.#
Why we hold it. To give you the service you are paying for, to bill you, to support you, to keep the service secure, and to meet our own legal duties such as keeping tax records.#
What passes through the system about callers#
This is the section a regulator will read first.
When somebody calls a shop that uses PizzaFlow, or uses that shop’s voice ordering page, the following is processed:#
| What | Where it goes | Why |
|---|---|---|
| Their voice, live, both directions | Where it goesStreamed to our telephony provider and to our AI provider in real time | WhyThe assistant cannot answer the phone without hearing them |
| Their caller ID number | Where it goesStored on the call record | WhySo the shop knows who rang and can call back |
| A written transcript of the whole conversation | Where it goesStored on the call record, visible to the shop | WhySo the shop can check what was agreed |
| Their name | Where it goesStored on the order and on a customer record | WhyTo label the order |
| Their phone number | Where it goesStored on the order and on a customer record | WhyTo confirm the order and to contact them |
| Their delivery address, if they order delivery | Where it goesStored on the order, and sent to a mapping provider to check it is real and within range | WhyTo deliver the food and to reject an address the shop cannot reach |
| What they ordered and any notes they gave | Where it goesStored on the order | WhyTo make the food |
| An in-progress copy of the order, held briefly | Where it goesHeld in a cache for up to three hours so a dropped call can resume | WhySo a caller does not have to start again if the line drops |
| A text message confirming the order, if enabled | Where it goesSent through our telephony provider | WhyTo give the caller a link to their order |
| A text message with the shop’s menu, only if the caller says yes when asked | Where it goesSent through our telephony provider | WhyBecause the caller asked for it. We never send it unrequested |
| A payment link, on shops whose plan includes paying by card for delivery | Where it goesCreated by Stripe on the shop’s own Stripe account and sent by text | WhySo a caller can pay for a delivery order before it arrives. The card details are entered on Stripe’s page and never reach us or the shop |
What we do not do with it.#
- We do not sell caller data. Ever.
- We do not use caller data for our own marketing.
- We do not use caller conversations to train our own AI models, and our AI provider is configured on a basis that does not use the content to train its public models.
- We do not share a caller’s data with any other shop on the platform. Each shop sees only its own callers.
Being recognised when you call back. Each shop keeps a customer record for the numbers that call it, so a regular does not have to repeat everything every time. That record holds the caller’s name, their phone number, their last delivery address, what they last ordered, any allergy or preparation note they gave, whether they asked us not to text them, how many times they have ordered and when they last called.#
The record belongs to that shop alone. It is never shared with another shop on the platform, and a caller who orders from two PizzaFlow shops has two unconnected records.
Two rules the assistant follows, and they are built into the product rather than left to each shop:
- It may greet you by name. It will never read out a saved address. If you are ordering delivery it asks whether you want the same address as last time and waits for you to say yes. Caller ID is unreliable on forwarded calls, phone numbers are shared inside households and workplaces, and carriers recycle numbers, so reading a saved home address to whoever is holding a number would be a data leak.
- A shop can block a number. If a caller is abusive or is making prank calls, the shop can mark that number blocked. The assistant then does not take a call from that number: the caller hears a short line and the call ends. The shop records why it blocked the number, and it can unblock it.
A caller can ask a shop to delete their record, or ask us. See section 10.
Call audio. We do not keep any. The assistant has to hear a caller in order to answer the phone, so audio passes through in real time to our AI provider. It is never recorded and never stored, on any plan. What is kept is the written transcript. There is no recording of your call anywhere in our systems, so there is none to give you, to lose, or to hand to anybody else.#
Children. The service is not aimed at children. We do not knowingly collect data from a child. If a child rings a shop and places an order, whatever they said will be in that call’s transcript. If you believe a child’s data is held and should not be, contact us and we will delete it.#
How the data flows#
One call, in order. Two of these steps carry most of the risk and are marked the risk: the caller is a person who agreed to nothing, and the AI provider is a company outside your building that hears their voice.
- The caller speaks into their phone. the risk They agreed to nothing and they had never heard of us before the call connected.
- Their voice reaches our telephony provider, which owns the phone number and the line.
- That provider streams the audio to the PizzaFlow bridge, our own server.
- The bridge passes the audio to our AI provider, which hears it and speaks back. the risk
- The bridge writes the transcript, the order, and the caller’s name, phone number and address to our database.
- The address alone goes to a mapping provider to check it is real and inside the delivery radius.
- An order that is still in progress is held in a three hour cache, so a dropped call can resume.
- A confirmation text message goes back out through the same telephony provider.
- The shop owner sees the order on their board and can read the transcript.
- Separately, the shop owner pays us through Stripe. No caller data goes anywhere near that.
Who else handles data#
We share what is described above with these kinds of company, and with nobody else. We stay responsible for what they do with it, whichever one we are using.
| Kind of provider | What it handles |
|---|---|
| Telephony | What it handlesPhone numbers, call audio, caller ID, confirmation texts |
| AI voice | What it handlesCall audio, in both directions, and the transcript of it |
| Hosting and database | What it handlesAccounts, shops, menus, orders, callers, calls and transcripts, all inside the United States. An order still being taken is also held in a cache for up to three hours so a dropped call can resume |
| Mapping | What it handlesDelivery addresses, and shop addresses |
| Payments, through Stripe | What it handlesShop billing details. Card details are entered on Stripe’s own page and never reach us or the shop. |
| Security and DNS | What it handlesSite traffic, and the bot check on the signup form |
We name categories rather than companies, because a policy that names a supplier is wrong the day we change one. Any customer may ask for the current list and we will send it. We will tell you before we add a kind of provider that handles call audio or caller details.
Our legal basis for processing#
Shop owners. We process your data to perform our contract with you, to meet legal obligations such as tax, and for our legitimate interests in running and securing the service.#
Callers. The shop is the controller and we are its processor. The shop’s legal basis is normally performance of a contract, because the caller is placing an order, together with the shop’s legitimate interest in taking orders efficiently.#
Transcription needs telling people, and we do it ourselves. In states where an automated call or a transcript requires notice or consent, the caller has to be told. Rather than leave that to each shop, the assistant discloses in its first sentence, on every call, that it is an AI and that it takes notes. There is no per-shop switch, so there is no shop that forgot to turn it on. A caller who objects is transferred to a person straight away. We keep no audio, which is a lighter position than a recording in every state that treats the two differently.#
The honest risk. The chain “the shop has a contract with the caller, so the shop can process their data, so we can process it for the shop” is standard and it is the same reasoning any online ordering system uses. What is not standard is that the caller’s voice goes to a third-party AI provider in real time. That is where this product is most exposed, and it is why the one sentence at the start of the call matters more than any sentence in this policy. It is also why that sentence is always on and cannot be switched off.#
How long we keep things#
| Data | Kept for | Then |
|---|---|---|
| Shop account and business data | Kept forWhile the account is open, and after cancellation for as long as the records below are kept, so you keep a read-only login to your own history | ThenDeleted or anonymised once the last of those records expires |
| Orders and order history | Kept for24 months [C11] | ThenDeleted, or stripped of caller identity and kept only as counts |
| Call transcripts | Kept for12 months [C10] | ThenDeleted |
| Call audio | Kept forNever kept at all | ThenThere is nothing to delete |
| Caller records, meaning name, phone, last address, last order and notes | Kept for24 months from the last time that caller ordered [C11] | ThenDeleted. The caller becomes a first-time caller again |
| In-progress order cache | Kept forThree hours | ThenDeleted automatically |
| Billing records | Kept for7 years [C12], because tax law requires it | ThenKept for tax only |
| Server and technical logs | Kept for30 days [C13] | ThenDeleted |
When a shop is deleted, its orders, its caller records and its call records are deleted with it. This is not reversible.#
These periods are only true if a job enforces them. Today nothing expires by itself except the three-hour order cache, so the deletion job is part of the work that ships with these pages rather than something added afterwards. Publishing “we delete transcripts after 12 months” and then not deleting them is worse than publishing nothing at all.#
Rights of shop owners#
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to how we use it. Email privacy@pizzaflow.ioL7. We respond within 30 days. [C15]
Rights of callers, and how to use them when you never signed up with us#
If you spoke to an AI assistant when you rang a restaurant, and you want to know what was kept, or you want it deleted, you have that right even though you have no account with us and never agreed to anything.#
The fastest route is to ask the restaurant you rang. They control their own order records and can delete your record from their panel.#
If you would rather come to us, or the restaurant does not help, email privacy@pizzaflow.ioL7 with:#
- the phone number you called from, which is how records are indexed;
- the restaurant you rang;
- roughly when you rang;
- what you want, meaning a copy of the data, a correction, or deletion.
We will find the records, tell the restaurant, and act within 30 days. [C15] We do not charge for this.#
What we will not do without more care. We will not hand a full transcript to somebody just because they email us with a phone number, because that would be a way to read a stranger’s order history. We check that the number is yours by texting a one-time code to it. That is proportionate, it is not itself invasive, and it is the only check we make.#
If you do not want to talk to an AI, say so and it will pass you to a person. The assistant tells you it is an AI in its first sentence, and if you say you would rather speak to somebody at the shop it transfers you there straight away. You do not have to argue with it and you do not have to hang up and try again.#
If you are unhappy with our answer you can complain to your data protection authority.#
Cookies and browser storage#
We use a small number of strictly necessary cookies to keep you signed in to the panel. Without them, sign-in does not work.#
The public voice ordering page uses browser storage to keep track of the conversation in progress. That data stays in the browser.#
International transfers#
Our providers operate in several countries, including the United States. If you or your callers are outside those countries, data will be transferred across borders.#
Where the law requires it, those transfers rely on standard contractual clauses or an equivalent approved mechanism in our contracts with each provider.#
Security#
All traffic to and from the service is encrypted in transit. Data at rest is encrypted by our database and hosting providers.#
Passwords are stored only as salted hashes by our authentication provider. We never see them.#
Access is separated per shop at the database level, so one shop cannot read another shop’s orders, callers or transcripts.#
Only staff who need access to run and support the service have it.#
No system is perfectly secure. We cannot promise a breach will never happen.#
If there is a breach#
If personal data is lost or exposed and it is likely to be a risk to people, we will notify the relevant authority within 72 hours of becoming aware, where the law requires it.#
We will tell affected shop owners without undue delay, and we will help them tell their callers where that is required.#
Changes to this policy#
We may update this policy. The date at the top changes. If a change materially affects how caller data is handled, we will tell shop owners by email.
Contact#
The Terms of Service and the Refund Policy sit alongside this policy.