Privacy Policy
Last updated: March 1, 2026
1. Who We Are
OrderHeroAI is a software-as-a-service (SaaS) platform that provides AI-powered phone ordering, text-to-order, and payment processing for restaurants. This Privacy Policy describes how we collect, use, store, and protect your personal information when you interact with our platform — whether as a restaurant customer (End User), Restaurant Partner, or website visitor.
2. Information We Collect
Information You Provide
- Name — to identify you for orders and account management
- Phone number — for SMS ordering, call identification, and order notifications
- Email address — for account management, receipts, and communications
- Order history — items ordered, order preferences, and reorder data
- Payment information — processed and stored securely by Stripe; we do not store full credit card numbers
- Delivery address — when placing delivery orders
- Business information — for Restaurant Partners: business name, address, menu data, POS details
Information Collected Automatically
- Voice call recordings — calls handled by our AI voice agent (powered by Vapi) are recorded for quality assurance and order accuracy
- Call metadata — phone number, call duration, timestamp, and call outcome
- SMS metadata — message timestamps and delivery status
- Device and browser data — IP address, browser type, and device information when visiting our website
3. How We Use Your Information
- Process and fulfill food orders
- Send order confirmations, payment links, and receipts via SMS
- Enable “Your usual?” reorder functionality for returning customers
- Process payments securely through Stripe
- Provide customer support
- Improve our AI voice agent and text ordering accuracy
- Detect and prevent fraud
- Comply with legal obligations
- Send setup and onboarding communications to Restaurant Partners
4. Payment Processing
All payment processing is handled by Stripe. We use Stripe Connect to facilitate payments between End Users and Restaurant Partners. A convenience fee of $1.25 + 4% is applied to each order.
With your consent, Stripe may store your payment method for faster future orders (“saved cards”). You can request removal of saved payment methods at any time by contacting us.
5. Voice Call Recording
Phone calls processed through our platform are handled by our AI voice agent powered by Vapi. These calls may be recorded for:
- Order accuracy verification
- Quality assurance and AI improvement
- Dispute resolution
- Compliance monitoring
Call recordings are stored securely and retained for up to 90 days unless a longer retention period is required by law or for dispute resolution.
6. SMS Communications
We send SMS messages only to users who have opted in. You can opt out at any time by replying STOP. See our Terms of Service for full TCPA compliance details.
We do not sell your phone number or share it with third parties for marketing purposes.
7. Data Sharing
We share your information only with:
- Restaurant Partners — your name, phone number, order details, and delivery address (as needed to fulfill orders)
- Stripe — payment information for transaction processing
- Vapi — voice call data for AI processing
- Twilio — phone number and SMS content for message delivery
- Delivery partners (DoorDash Drive, Uber Direct) — delivery address and order details when applicable
- Law enforcement — when required by law, subpoena, or court order
We do not sell your personal information to third parties.
8. Data Retention
- Account data (name, phone, email) — retained while your account is active and for 12 months after last activity
- Order history — retained for 24 months for reorder functionality and reporting
- Voice recordings — retained for up to 90 days
- Payment data — managed by Stripe per their retention policies
- SMS logs — retained for 12 months
9. Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate information
- Deletion — request deletion of your personal data (subject to legal retention requirements)
- Opt-out of SMS — reply STOP to any message
- Remove saved payment methods — contact us to remove stored cards
- Data portability — request your data in a machine-readable format
To exercise any of these rights, email us at townherosubs@gmail.com. We will respond within 30 days.
10. Data Security
We implement industry-standard security measures including encrypted data transmission (TLS/SSL), secure API authentication, and access controls. Payment data is handled entirely by Stripe, which is PCI DSS Level 1 certified. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Children's Privacy
OrderHeroAI is not intended for use by individuals under 18. We do not knowingly collect personal information from minors. If we learn we have collected data from a minor, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or SMS. Continued use of the platform after changes constitutes acceptance.
13. Contact Us
For privacy-related questions or to exercise your data rights:
townherosubs@gmail.com