Privacy Policy
1. Overview
This Privacy Policy explains how Zandoe Inc. ("Zandoe," "we," "us," or "our") collects, uses, discloses, and protects information when you use the Zandoe websites, mobile applications, and related services (collectively, the "Platform"), whether you're a Customer, Merchant, Driver, or API Partner. This Policy is incorporated into, and should be read together with, our Terms and Conditions.
Because the Platform serves several different kinds of users with different data needs — a Customer ordering dinner, a Merchant managing a live order queue, a Driver navigating a delivery, or an API Partner integrating machine-to-machine — this Policy is organized by data category and use, and notes where a section applies to a specific role.
2. Information We Collect
We collect the following categories of information, depending on how you use the Platform:
| Category | Examples | Who |
|---|---|---|
| Account information | Name, email, phone number, password, business name and address, saved delivery addresses | CustomerMerchantDriver |
| Order & catalog data | Items ordered, order history, menu/catalog content and pricing you upload, order notes | CustomerMerchant |
| Location data | Delivery address, real-time GPS location during an active delivery, restaurant/warehouse geo-coordinates — see Section 3 | CustomerMerchantDriver |
| Payment & financial data | Tokenized payment method, Stripe Connect account details, bank-linked transaction data via Plaid — see Section 5 | CustomerMerchantDriver |
| Identity & verification data | Driver's license, vehicle registration and insurance, background-check results, QR/OTP verification events | Driver |
| Payroll & bookkeeping data | Employee gross pay and jurisdiction entered into the tax calculator, ledger entries — see Section 6 | Merchant |
| Device & usage data | IP address, device identifiers, app version, crash logs, pages and features used, push-notification token | CustomerMerchantDriver |
| Communications | Support tickets, in-app messages between Customer and Driver, ratings and feedback | CustomerMerchantDriver |
| Advertising data | Sponsored-placement impressions and clicks — see Section 9 | Customer |
| API Partner data | API key, external order reference, pickup/dropoff address and package value submitted via the Partner API | API Partner |
We collect this information directly from you (account creation, order placement, catalog upload, onboarding forms), automatically through your use of the Platform (device and usage data, location while the app is active), and from third parties (identity-verification vendors, Stripe, Plaid, and, for API Partners, the partner's own system as the source of order details).
3. Location Data
Location is core to how the Platform works, so we collect and use it more extensively than a typical app:
- Customers: we use your delivery address to determine which Merchants and grocery warehouses can reach you within the standard 5-mile delivery radius, and to calculate delivery fees and estimated arrival times.
- Merchants: your restaurant, bodega, or store location is stored as a geographic coordinate to match you with nearby Customers and Drivers.
- Drivers: we collect real-time GPS location while you are online and available for offers, and continuously during an active Delivery, to route you, match you to nearby offers, calculate batched-stop pricing, and provide live tracking to the Customer. We do not collect Driver location when the Driver app is closed or you are offline.
- Geocoding & mapping: we use third-party mapping and geocoding providers, including HERE Technologies, to convert addresses to coordinates and calculate delivery distances and routes. Location queries sent to these providers are limited to what's needed to perform that function.
4. How We Use Information
We use the information described above to:
- create and maintain your account and authenticate you across the Customer, Merchant, Driver, and Partner API surfaces;
- process and fulfill Orders, including matching Orders to nearby Merchants, warehouses, and Drivers, calculating delivery fees, and routing Deliveries;
- process payments, subscriptions, and payouts through Stripe and Stripe Connect, and bank-sync bookkeeping data through Plaid;
- send transactional notifications — order confirmations, status updates, delivery-offer alerts — in real time and, where a client isn't connected, as a push-notification fallback;
- verify Driver identity and eligibility, and confirm pickup and dropoff via QR code or one-time passcode;
- provide the Merchant Portal's payroll tax calculator and bookkeeping tools, using the data a Merchant enters or connects for that purpose only;
- detect and prevent fraud, abuse, and violations of our Terms;
- provide customer support and respond to disputes, chargebacks, and verification-record requests;
- measure and deliver sponsored placements, and log impressions and clicks to support advertiser reporting;
- improve and maintain the Platform, including diagnosing technical issues from device and crash data; and
- comply with legal obligations, including tax, recordkeeping, and law-enforcement requests.
We do not use Customer order history, Driver location, or Merchant catalog data for any purpose beyond operating and improving the Platform and the uses listed above, and we do not sell this information to third parties for their own independent marketing purposes.
5. Payments and Financial Data
We do not store your full payment card number on our servers. Customer payment methods are tokenized and processed by Stripe; Zandoe receives only a token and limited metadata (such as card type and last four digits) needed to display your saved payment method and process a charge.
Merchant order settlement and Driver delivery payouts are processed through Stripe Connect. Merchant and retail-chain subscription billing is processed through Stripe Billing. Where a Merchant connects a bank account for the bookkeeping dashboard, that connection and the resulting transaction data are provided through Plaid's Transactions product, under Plaid's own data-handling terms, which are presented to the Merchant at the time of connection.
6. Payroll and Bookkeeping Data
If a Merchant uses the payroll tax calculator, the employee pay data and jurisdiction information entered or imported is used solely to calculate estimated withholding and present it back to that Merchant. Zandoe does not use this data for advertising, does not share it with other Merchants, and does not disburse payroll funds, file taxes, or remit withholding — the Merchant remains the employer of record and controls this data as between Zandoe and their own employees. Ledger entries in the bookkeeping dashboard combine platform-generated records (such as subscription charges) with Plaid-synced bank data, and are visible only to the Merchant account that created or connected them.
7. Cookies and Tracking Technologies
The Merchant Portal and Zandoe's websites use cookies and similar technologies to keep you signed in, remember preferences, and understand how the Platform is used. You can control cookies through your browser settings; disabling them may affect Portal functionality such as staying signed in. The native Customer and Driver apps do not use browser cookies but may use comparable device-level identifiers for the same purposes.
8. Push Notifications
We send push notifications for order and delivery-offer events using Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS). Push notifications are primarily used as a fallback when the Merchant Portal or Driver app isn't actively connected in real time, so an order or delivery offer is never silently missed. You can disable push notifications in your device settings at any time, though this may delay your awareness of new orders or offers.
9. Advertising Data
When a brand sponsors a placement in Customer search or category results, we log impressions and clicks against that placement to support advertiser reporting and renewal decisions. This logging is tied to the placement and aggregate performance, not used to build an individual advertising profile of you for sale to third parties. Sponsored results are always clearly labeled as such and are never blended into organic ranking.
10. How We Share Information
We share information as follows:
- Between users, as needed to fulfill an Order: a Merchant sees the Customer information needed to prepare and hand off an Order; a Driver sees pickup and dropoff details and limited contact information for a Delivery; a Customer sees the Driver's name, photo, vehicle, and live location during an active Delivery.
- Service providers: Stripe (payments, billing, and Connect payouts), Plaid (bank-linked bookkeeping data), HERE Technologies (geocoding and mapping), Firebase/APNs (push notifications), our identity-verification and background-check vendor(s) for Driver onboarding, and cloud-hosting infrastructure — each bound by contract to use the data only to provide services to Zandoe.
- API Partners: for a delivery routed through the Partner API, we share only the pickup/dropoff and Delivery-status data needed to fulfill that request; the API Partner's own system remains the record of what's being delivered.
- Legal and safety reasons: where required by law, subpoena, or court order, or where necessary to protect the rights, safety, or property of Zandoe, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
- With your consent: for any other purpose we've separately disclosed and you've agreed to.
We do not sell Customer, Merchant, or Driver personal information to third parties for their own independent marketing purposes.
11. Data Retention
We retain information for as long as needed to provide the Platform, comply with legal and tax obligations, resolve disputes, and enforce our agreements. Verification events (QR/OTP pickup and dropoff records) and financial transaction records are retained for the period required to support chargeback and dispute resolution and applicable recordkeeping law. You may request deletion of your account as described in Section 13, subject to information we're required to retain for legal or legitimate business purposes, such as completed transaction and tax records.
12. Data Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, consistent with the reasonable security requirements of the New York SHIELD Act. These include encryption of data in transit, access controls limiting internal access to what a role requires, and tokenized handling of payment data through Stripe rather than storing card numbers ourselves. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Your Privacy Rights
Depending on your role and location, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information, including through your account settings for most account and catalog fields;
- Delete your account and associated personal information, subject to records we're legally required to retain;
- Withdraw consent for optional data uses, such as push notifications or marketing communications; and
- Object to or restrict certain processing, where applicable law provides that right.
To exercise any of these rights, contact us using the details in Section 18. We may need to verify your identity before completing a request.
14. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), gives you additional rights: to know what personal information we collect, use, and disclose about you; to request deletion; to correct inaccurate information; and to opt out of the "sale" or "sharing" of personal information, if applicable. Zandoe does not sell personal information for money, and does not "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA. You may submit a CCPA request using the contact details in Section 18; we will not discriminate against you for exercising these rights.
15. Children's Privacy
The Platform is not directed to children, and you must be at least 18 years old to create a Customer, Merchant, or Driver account, consistent with the eligibility requirement in our Terms. We do not knowingly collect personal information from children under 13. If we learn we've collected such information, we will delete it. If you believe a child has provided us with personal information, contact us using the details in Section 18.
16. Third-Party Links
The Platform may contain links to third-party websites or services, including sponsored-placement destinations and Merchant-provided links. This Policy does not apply to those third parties, and we encourage you to review their privacy policies before providing any information to them.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or by email at least 15 days before taking effect, consistent with the notice period in our Terms. Continued use of the Platform after a change takes effect constitutes acceptance of the revised Policy.
18. Contact Us
Zandoe Inc.
[COMPANY STREET ADDRESS]
New York, NY [ZIP]
Privacy requests: [PRIVACY EMAIL] · General support: [SUPPORT EMAIL] · [SUPPORT PHONE]
