Privacy Policy
Welcome to Tatte. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website tatte-food.rest, place orders, interact with our services, or otherwise engage with us. Please read this policy carefully. If you disagree with its terms, please discontinue use of our site and services.
This Privacy Policy applies to all personal information processed by Tatte in connection with our food services, online ordering platform, and digital presence. We take your privacy seriously and handle your data with the utmost care and in compliance with applicable United States federal and state privacy laws, including but not limited to the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the Federal Trade Commission (FTC) Act.
1. Who We Are
Tatte is a food business operating in the United States. We provide food products and related services to our customers through our physical locations and our online platform. For the purposes of this Privacy Policy, Tatte acts as the data controller for personal information collected through our website and services.
| Business Name | Tatte |
|---|---|
| [email protected] | |
| Website | tatte-food.rest |
2. Information We Collect
We collect various types of information in connection with the services we provide. This includes information you provide directly to us, information we collect automatically when you use our website, and information we receive from third parties.
2.1 Personal Information You Provide Directly
When you interact with Tatte — whether placing an order, creating an account, contacting us, subscribing to newsletters, or participating in promotions — you may provide us with personal information, including but not limited to:
- Identity Information: Full name, username or display name.
- Contact Information: Email address, phone number, mailing address, billing address, and delivery address.
- Account Credentials: Username and password (stored in encrypted form).
- Payment Information: Credit card details, debit card details, billing information, and transaction history. Note: full payment card numbers are processed by our secure third-party payment processors and are not stored on our servers.
- Order Information: Details about food items ordered, dietary preferences, special instructions, order history, and delivery preferences.
- Communication Data: Any messages, feedback, reviews, or correspondence you send us via email, contact forms, or other channels.
- Promotional Data: Information you provide when entering contests, sweepstakes, surveys, or promotional campaigns.
- Dietary and Preference Information: Allergies, dietary restrictions, or food preferences you voluntarily share with us to personalize your experience.
2.2 Information Collected Automatically
When you visit our website or use our digital services, we automatically collect certain technical and usage data, including:
- Device Information: Device type, operating system, browser type and version, device identifiers, screen resolution, and hardware model.
- Log Data: IP address, access times, pages viewed, time spent on pages, links clicked, referring URLs, and exit pages.
- Location Data: General geographic location inferred from your IP address. If you grant permission, we may collect precise geolocation data to facilitate delivery services or help you find nearby Tatte locations.
- Usage Data: Information about how you navigate and interact with our website, including the features you use and the content you access.
- Cookies and Tracking Technologies: Data collected through cookies, web beacons, pixel tags, local storage, and similar tracking technologies. Please see Section 8 of this policy for more information on our use of cookies.
2.3 Information From Third Parties
We may receive information about you from third-party sources, including:
- Social Media Platforms: If you connect your social media account to our services or interact with our social media pages, we may receive information from those platforms in accordance with their privacy settings and policies.
- Payment Processors: Our payment processing partners may share transaction confirmation details with us.
- Delivery Partners: Third-party delivery service providers may share delivery status and related information with us.
- Analytics Providers: We use analytics tools that may provide us with aggregated or demographic insights about our website visitors.
- Marketing Partners: We may receive information to help us update, expand, and analyze our contact lists and identify new customers.
3. How We Use Your Information
We use the personal information we collect for a variety of business and operational purposes, always in accordance with applicable law. Our lawful bases for processing your information include contract performance, legitimate business interests, legal obligations, and your consent (where applicable).
3.1 Service Provision and Order Fulfillment
- To process and fulfill your food orders, including preparation and delivery coordination.
- To manage your account and provide you with access to our services.
- To process payments and prevent fraudulent transactions.
- To send you order confirmations, receipts, delivery updates, and other transactional communications.
- To manage loyalty programs, rewards, or promotional credits associated with your account.
- To respond to your inquiries, complaints, and requests for customer support.
3.2 Analytics and Service Improvement
- To analyze usage patterns and trends to improve our website, menu offerings, and overall customer experience.
- To conduct internal research and development to enhance our food products and services.
- To monitor the performance, security, and reliability of our website and digital infrastructure.
- To generate aggregated, de-identified statistical data for business analysis and reporting purposes.
- To understand customer preferences and behaviors in order to make more informed business decisions.
3.3 Marketing and Communications
- To send you promotional emails, newsletters, special offers, and information about new menu items or events, where you have consented or where we have a legitimate business interest to do so.
- To personalize your experience and deliver content, product recommendations, and advertisements that are relevant to your interests.
- To conduct marketing campaigns, contests, and promotional activities.
- To retarget you with relevant advertisements on third-party platforms and social media networks.
- You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us directly at [email protected].
3.4 Legal and Compliance Purposes
- To comply with applicable federal and state laws, regulations, and legal obligations.
- To enforce our Terms of Service and other applicable agreements.
- To protect the rights, property, and safety of Tatte, our customers, employees, and the public.
- To detect, investigate, and prevent fraudulent transactions, abuse, and other illegal or unauthorized activities.
- To respond to lawful requests from government authorities, courts, and law enforcement agencies.
4. Sharing Your Information With Third Parties
We do not sell your personal information to third parties. However, we may share your information with certain trusted third parties in the following circumstances:
4.1 Service Providers and Business Partners
We engage trusted third-party companies and individuals to perform services on our behalf, including:
- Payment Processors: To securely process payments made through our platform.
- Delivery Partners: To coordinate and fulfill food delivery to your address.
- Cloud Hosting Providers: To store and manage our data and website infrastructure.
- Email Service Providers: To send transactional and marketing emails on our behalf.
- Analytics Providers: Such as Google Analytics, to help us understand website usage and customer behavior.
- Customer Support Tools: Platforms that help us manage and respond to customer inquiries efficiently.
- Marketing and Advertising Partners: To help us serve targeted advertisements and manage marketing campaigns.
All service providers are required to handle your information in accordance with this Privacy Policy and applicable law. They are not permitted to use your data for their own independent purposes beyond the scope of services they provide to us.
4.2 Legal Requirements and Protection of Rights
We may disclose your personal information if we believe in good faith that such disclosure is necessary to:
- Comply with a legal obligation, court order, subpoena, or government request.
- Enforce our Terms of Service or other agreements.
- Protect and defend the rights, property, or safety of Tatte, our employees, customers, or others.
- Prevent or investigate possible wrongdoing, fraud, or illegal activity in connection with our services.
4.3 Business Transfers
In the event that Tatte undergoes a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of its assets, your personal information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website of any such change and any choices you may have regarding your information.
4.4 With Your Consent
We may share your information with other third parties when you have given us your explicit consent to do so, for purposes clearly disclosed at the time your consent is obtained.
5. Data Security
We take the security of your personal information seriously and implement a range of administrative, technical, and physical security measures designed to protect your data from unauthorized access, disclosure, alteration, and destruction.
5.1 Security Measures We Implement
- Encryption: We use Secure Sockets Layer (SSL) / Transport Layer Security (TLS) encryption to protect data transmitted between your browser and our servers. Sensitive data such as passwords is stored using strong, industry-standard hashing algorithms.
- Access Controls: Access to personal information is restricted to authorized personnel who need it to perform their job functions. We enforce role-based access controls and require strong authentication.
- Secure Payment Processing: Payment card data is processed by PCI-DSS compliant third-party payment processors. We do not store full card numbers on our systems.
- Regular Security Assessments: We conduct periodic security reviews and vulnerability assessments of our systems and infrastructure.
- Incident Response: We maintain data breach response procedures to promptly address and notify affected parties in the event of a security incident, as required by applicable law.
- Employee Training: Our team members receive training on data privacy best practices and security protocols.
While we implement these safeguards, please be aware that no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, and we encourage you to take steps to protect your own information, such as using strong passwords and keeping your login credentials confidential.
6. Your Privacy Rights
Depending on your location within the United States, you may have certain rights regarding your personal information. We respect and honor these rights to the fullest extent required by applicable law.
6.1 Rights for California Residents (CCPA/CPRA)
If you are a resident of California, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell about you, including the categories of personal information, the purposes for collection, the categories of third parties with whom we share it, and the specific pieces of personal information we hold about you.
- Right to Delete: You have the right to request the deletion of personal information we have collected from you, subject to certain legal exceptions.
- Right to Correct: You have the right to request that we correct inaccurate personal information we maintain about you.
- Right to Opt-Out of Sale or Sharing: You have the right to opt out of the sale or sharing of your personal information with third parties for cross-context behavioral advertising. We do not sell your personal information in the traditional sense, but if we engage in sharing for advertising purposes, you have the right to opt out.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of sensitive personal information, including precise geolocation data and dietary information, to purposes necessary for service provision.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you services, charge different prices, or provide a different level of service based solely on your exercise of these rights.
- Authorized Agent: You may designate an authorized agent to make a request on your behalf. The authorized agent must provide written authorization and we may verify the agent's identity.
6.2 General Privacy Rights for All US Residents
Regardless of your state of residence, we offer the following rights to all our customers to the extent practicable:
- Right of Access: You may request a copy of the personal information we hold about you.
- Right to Correction: You may request that we correct any inaccurate or incomplete personal information we hold about you.
- Right to Deletion: You may request that we delete your personal information, subject to our legal obligations and legitimate business interests in retaining certain data.
- Right to Data Portability: Where technically feasible, you may request that we provide your personal information in a structured, commonly used, and machine-readable format.
- Right to Opt-Out of Marketing: You may opt out of receiving marketing communications from us at any time.
6.3 How to Exercise Your Rights
To exercise any of the rights described above, please contact us using one of the following methods:
- Email: [email protected] — Please include "Privacy Request" in the subject line.
- Website: tatte-food.rest
We will respond to your request within 45 days of receipt. We may extend this period by an additional 45 days where reasonably necessary, with prior notice. We may need to verify your identity before processing your request to ensure we are providing information to the correct person and protecting your privacy.
7. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, resolve disputes, and enforce our agreements. Our specific retention periods are as follows:
| Category of Data | Retention Period |
|---|---|
| Account Information | Duration of account plus 3 years after account closure |
| Order and Transaction Records | 7 years (for tax and accounting purposes) |
| Payment Records | 7 years (as required by financial regulations) |
| Customer Service Communications | 3 years from the date of last interaction |
| Marketing Consent Records | Until you withdraw consent, plus 3 years |
| Website Analytics Data | 26 months (in anonymized or aggregated form) |
| Cookie and Tracking Data | As specified in our Cookie Policy (typically 12–24 months) |
| Legal and Compliance Records | As required by applicable law (up to 10 years) |
When personal information is no longer required for any active purpose and its retention period has expired, we will securely delete, anonymize, or de-identify it in accordance with our data disposal procedures.
8. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, remember your preferences, analyze site traffic, and support our marketing efforts. A cookie is a small text file stored on your device by your web browser.
8.1 Types of Cookies We Use
- Strictly Necessary Cookies: Essential for the functioning of our website. These enable core features such as user authentication, shopping cart functionality, and security. You cannot opt out of these cookies.
- Performance and Analytics Cookies: These collect anonymous information about how visitors use our website, such as which pages are visited most often and whether users encounter error messages. We use this data to improve our website's performance.
- Functionality Cookies: These remember choices you make (such as your preferred location or language settings) to provide a more personalized experience.
- Targeting and Advertising Cookies: These are used to deliver relevant advertisements to you on our website and on third-party platforms. They track your browsing habits and allow us to show you ads based on your interests.
You can control and manage cookies through your browser settings. However, please note that disabling certain cookies may affect the functionality of our website and your ability to use some of our services. For detailed information about the cookies we use, the data they collect, and how to manage your cookie preferences, please review our full Cookie Policy, available on our website at tatte-food.rest.
9. Children's Privacy
Our website and services are intended for use by individuals who are 18 years of age or older. We do not knowingly collect, solicit, or maintain personal information from children under the age of 13, or in some contexts under the age of 18, without verifiable parental or guardian consent.
We comply with the Children's Online Privacy Protection Act (COPPA), which restricts the collection of personal information from children under 13. If we learn that we have collected personal information from a child under the age of 13 without appropriate consent, we will take prompt steps to delete that information from our records.
If you are a parent or guardian and you believe that your child has provided us with personal information without your consent, please contact us immediately at [email protected]. We will investigate and take appropriate action as quickly as possible.
By using our website and services, you represent and warrant that you are at least 18 years of age. If you are between 13 and 17 years of age, you may only use our services under the supervision and with the consent of a parent or legal guardian.
10. International Data Transfers
Tatte is based in the United States, and the personal information we collect is primarily processed and stored on servers located within the United States. If you access our services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence.
We take appropriate steps to ensure that any international transfers of personal data are conducted in compliance with applicable law and that your data receives an adequate level of protection wherever it is processed. These steps may include:
- Entering into data processing agreements with our service providers that incorporate appropriate data transfer safeguards.
- Implementing technical and organizational measures to protect the confidentiality and security of data during transfer and storage.
- Ensuring that third-party service providers located outside the United States adhere to privacy standards that are at least as protective as those described in this Privacy Policy.
If you have questions about how we handle international data transfers, please contact us at [email protected].
11. Third-Party Links and Services
Our website may contain links to third-party websites, applications, and services that are not owned or controlled by Tatte. This Privacy Policy applies only to information collected by our website and services. We have no control over and assume no responsibility for the privacy practices, content, or security of any third-party sites or services.
We encourage you to review the privacy policies of any third-party websites you visit through links on our site before providing them with any personal information. The inclusion of a link on our website does not imply our endorsement of that third party's privacy practices.
12. Your Choices and Controls
We want to give you meaningful control over your personal information. In addition to the rights described in Section 6, you have the following choices:
12.1 Account Information
If you have created an account with us, you may review, update, or correct your account information at any time by logging into your account settings. If you wish to close your account entirely, please contact us at [email protected].
12.2 Marketing Communications
You may opt out of receiving promotional emails from us by clicking the "unsubscribe" or "opt-out" link contained in any marketing email we send you, or by contacting us directly at [email protected]. Please note that even if you opt out of marketing emails, we will continue to send you transactional and operational communications related to your orders and account.
12.3 Push Notifications
If you have opted in to receive push notifications from our website or mobile application, you may opt out by adjusting the notification settings on your device or through your account preferences.
12.4 Location Data
You may disable the collection of precise geolocation data by adjusting the location settings on your device or browser. Please note that disabling location services may affect your ability to use certain features of our services, such as delivery address detection.
12.5 Do Not Track
Some web browsers offer a "Do Not Track" (DNT) feature that sends a signal to websites indicating that you do not want to be tracked. Currently, there is no industry-wide standard for responding to DNT signals, and our website does not currently respond to DNT browser signals in a standardized way. We will continue to monitor developments in this area and update our practices accordingly.
13. FTC Act Compliance and Consumer Protection
Tatte is committed to fair and transparent data practices in accordance with the Federal Trade Commission (FTC) Act, which prohibits unfair or deceptive acts or practices in commerce. Our privacy practices are designed to be transparent, fair, and consistent with the representations we make to our customers. We will not engage in deceptive data collection or use practices, and we are committed to honoring the privacy choices and preferences of our users.
If you believe that our privacy practices are unfair, deceptive, or otherwise in violation of applicable consumer protection laws, you have the right to file a complaint with the Federal Trade Commission. Information about filing a complaint with the FTC is available at www.ftc.gov or by calling 1-877-FTC-HELP (1-877-382-4357).
14. Filing Complaints With Data Protection Authorities
If you have concerns about how we handle your personal information that we have not been able to resolve to your satisfaction, you have the right to escalate your complaint to the appropriate regulatory authority.
14.1 Federal Trade Commission (FTC)
The FTC is the primary federal agency responsible for enforcing consumer privacy and data security in the United States.
- Website: www.ftc.gov
- Consumer Helpline: 1-877-FTC-HELP (1-877-382-4357)
- Online Complaint Portal: reportfraud.ftc.gov
14.2 California Residents — California Privacy Protection Agency (CPPA)
California residents may also file privacy complaints with the California Privacy Protection Agency (CPPA), the state agency responsible for enforcing the CCPA/CPRA.
- Website: cppa.ca.gov
- Email: [email protected]
14.3 State Attorneys General
Residents of all states may contact their respective State Attorney General's office to report privacy concerns or consumer protection violations. Contact information for each state's Attorney General is publicly available through your state government's official website.
15. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our business practices, legal requirements, or industry standards. When we make material changes to this policy, we will:
- Update the "Last Updated" date at the top of this page.
- Post a prominent notice on our website notifying users of the changes.
- Where required by law or where we deem it appropriate, send a notification to the email address associated with your account.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website and services after the effective date of any changes to this policy constitutes your acceptance of the updated policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact our privacy team. We are committed to addressing your inquiry promptly and transparently.
| Business Name | Tatte |
|---|---|
| [email protected] | |
| Website | tatte-food.rest |
| Country | United States |
When contacting us with a privacy inquiry, please include the following information to help us process your request efficiently:
- Your full name and email address associated with your account (if applicable).
- A clear description of your request or concern.
- The specific right you wish to exercise (if applicable).
- Any relevant order numbers or account identifiers that may help us locate your records.
We are dedicated to working with you to resolve any privacy-related concerns and to ensuring that your personal information is handled with the care and respect it deserves. We will acknowledge receipt of your inquiry within 5 business days and will endeavor to provide a complete response within the timeframes required by applicable law.