A restaurant CRM is the customer database behind your tills and your ordering website. It holds who ordered, what they ordered, when, how often, how much they spent and whether they agreed to hear from you. For an independent restaurant or takeaway, that record is the difference between knowing your regulars and hoping they come back.
Most owners already collect the raw material. Every online order carries a name, a mobile number and an email address. Every phone order carries a caller ID. The trouble is that the data sits in three places, the permissions are unclear, and the customers who order through Just Eat, Deliveroo or Uber Eats are not yours to message at all.
Below: what customer data to collect, where it comes from, how to split it into segments you can act on, and the email and SMS consent rules in Ireland (the Data Protection Commission and S.I. No. 336 of 2011) and the UK (the ICO and PECR). How points and rewards work is on the restaurant loyalty programme page. Building campaigns is on the restaurant marketing software page.
Restaurant CRM basics
CRM stands for customer relationship management. In a sales office it tracks deals. In a restaurant it tracks people and their orders. A restaurant CRM does five jobs:
- Identify each customer once, even when the same person orders by phone on Monday and online on Friday.
- Record every order against that person: items, modifiers, spend, channel, date and time.
- Store permissions: which marketing channels the customer agreed to, when, where and with what wording.
- Group customers into segments, such as lapsed regulars or weekday lunch customers.
- Feed your loyalty programme, campaigns and reports from the same record.
The data has to arrive by itself. Nobody on the pass at 8pm on a Saturday is typing notes into a separate system. That is why, for most independents, the CRM lives inside the online ordering system and the POS rather than in a standalone sales tool.
Restaurant CRM software versus a spreadsheet
A spreadsheet and a free email tool can cover a café with 80 regulars who signed up on a card at the counter. It breaks down when:
- orders come from three channels and the same customer appears three times with three spellings;
- you cannot say who opted in, on what date, or from which form;
- an unsubscribe in the email tool has to be copied by hand into the SMS tool;
- you want everyone who ordered at least four times but not in the last 60 days, and finding them takes an evening.
The third point is where owners get into legal trouble. Two Irish prosecutions listed later on this page involved customers who tried to opt out and kept getting messages. A system that records an opt-out once and applies it to every channel removes that failure.
Restaurant CRM system versus a generic CRM
| Question | Generic sales CRM | Restaurant CRM system |
|---|---|---|
| Main record | A deal or a contact | A customer and their orders |
| How data arrives | Typed in by staff | Automatically from POS and online orders |
| Typical grouping | Deal stage | Order frequency, recency, spend, favourite items |
| Typical action | A sales call | A text, email or push offer to order again |
| Who uses it | A sales team, daily | The owner or manager, a few minutes a week |
| Fit for a takeaway | Poor | Good |
Restaurant customer data worth collecting
Collect what you will use. Each extra field is something to protect, explain in your privacy notice and delete later. Citizens Information’s summary of the GDPR says personal data should generally only be stored where there is a lawful basis, such as consent or a legal obligation.
| Data | What you use it for | Where it comes from | Notes |
|---|---|---|---|
| First name | Order labels, phone greeting, personal messages | Checkout, phone order, booking | A surname is rarely needed for takeaway |
| Mobile number | Order updates, driver contact, SMS marketing where permitted | Checkout, caller ID, booking | An order-update text is not permission to market |
| Email address | Receipts, confirmations, email marketing where permitted | Online checkout | Check the format at checkout |
| Delivery address | Delivery and decisions about your delivery area | Checkout | Address lookup cuts failed deliveries |
| Order history | Favourite items, frequency, spend, last order date | POS and ordering system | Should be captured automatically |
| Order channel | Pickup, delivery, dine-in, phone | POS | Shows who to move to online ordering |
| Marketing permissions | Who you may contact, and by which channel | Checkout, till, phone | Store date, wording, source and channel |
| Allergy notes | Safer repeat orders | Entered by the customer at checkout | Use for the order only, never for targeting |
| Date of birth | A birthday reward | Loyalty sign-up | Only if you will actually use it |
| Feedback | Fixing service problems | A message after the order | Ask every customer, happy or unhappy |
Data to leave out
- Card numbers. Online payments should go through a payment provider, never into a customer note or onto an order ticket.
- Friends’ contact details. The ICO advises against asking people for the contact details of friends and family for marketing, because you cannot be sure those friends agreed.
- Fields kept “just in case”. If no report, segment or message uses a field, take it off the form.
Restaurant customer database sources
Each channel gives you different data and a different right to use it.
| Source | What you get | Who sets the rules | Marketing use |
|---|---|---|---|
| Your ordering website | Name, mobile, email, address, full order history | You, within the law | Yes, with consent or a valid existing-customer exception |
| Your POS, in person | Order history once the customer is identified | You | Only if permission is captured at the till |
| Phone orders | Caller number, name, address | You | Harder to prove permission, so record it during the call |
| Table bookings | Name, mobile, email, party size | You | A separate opt-in at booking |
| Guest Wi-Fi sign-in | Email address | You | Consent only; a Wi-Fi login is not a purchase |
| Competitions and paper forms | Whatever the form asks | You | Specific, unticked consent; keep the form |
| Deliveroo | Order information for fulfilment | Deliveroo partner terms | Not for your marketing under the UK terms |
| Uber Eats | Personal data for providing items | Uber Eats merchant terms | Not for targeted marketing under the UK terms |
| Just Eat | Order details in the Partner Centre | Your Just Eat restaurant agreement | Read the agreement before any contact |
The Wi-Fi row matters in Ireland. The Data Protection Commission (DPC) says the existing-customer exception only covers contact details obtained in the context of a sale, and that it does not cover a prospective customer who never completes a purchase (DPC FAQ on consent for electronic direct marketing, version updated April 2020). An email typed into a Wi-Fi splash page is not a sale.
Marketplace customer data limits
Marketplaces send you orders. Under the terms checked for this page, they do not send you customers you can market to.
- Deliveroo. The UK Delivery Service, Marketplace+ and Pickup terms (last updated 14 January 2021, checked September 2026) say partners must not use order information for any purpose other than fulfilling the order it relates to. Source: Deliveroo partner terms.
- Uber Eats. The UK merchant terms (last modified 16 June 2025, checked September 2026) say merchants may use personal data provided by Uber solely to provide items to customers. Clause 12 also bars merging data from the agreement with other data for targeted marketing. Source: Uber Eats merchant terms.
- Just Eat. Just Eat sets its rules in its restaurant agreement and Partner Centre guidance. Read the version you signed before you text, call, email or post anything to someone who ordered through Just Eat.
Terms for Ireland can differ from the UK versions linked here. Ask your account manager for the current terms for your country, in writing.
Copying a marketplace customer’s number from the order screen into your own SMS tool breaks two sets of rules at once: the platform’s terms and, without consent, the marketing law below. The lawful route is slower. Cook well, deliver on time, and give marketplace customers a reason to find you directly next time, then capture their details and permission on your own channels. The practical steps are in the guide to getting more direct orders. What each app charges per order is in the guide to Deliveroo, Just Eat and Uber Eats commission rates.
Email and SMS consent rules in Ireland
Electronic marketing in Ireland is governed by the ePrivacy Regulations, S.I. No. 336 of 2011, read together with the GDPR and the Data Protection Act 2018. The regulator is the DPC. The Regulations define “electronic mail” to include SMS messages, so the same rules cover emails and texts.
The general rule
Regulation 13(1) says you must not send unsolicited direct marketing by electronic mail to an individual unless they have told you they consent. The DPC’s FAQ on consent for electronic direct marketing sets out what valid consent looks like:
- it must meet the GDPR standard: freely given, specific, informed and unambiguous;
- the request must be clearly distinguishable from other matters, such as your terms and conditions;
- the customer must be able to withdraw it as easily as they gave it;
- silence, pre-ticked boxes and inactivity do not count.
The existing customer exception
Regulation 13(11) allows marketing without specific consent only when all of these are true:
- You obtained the customer’s email address or mobile number lawfully, in the context of a sale.
- You are marketing your own product or service.
- That product or service is similar to what the customer bought.
- The customer was clearly given an easy, free chance to object when you collected the details, and in every message since.
- The sale happened no more than 12 months before the message, or you used the details for marketing within that 12-month period.
For a takeaway, a customer who ordered a curry online last month, saw a clear option at checkout to refuse marketing and did not use it, can receive a text about your weekend offer. The same customer cannot receive a text promoting the gym next door. One of the DPC’s worked cases covers exactly this: a hotel wants to email a customer about another business’s deal, and the answer is no, because the product is not the hotel’s own.
If a customer has not ordered in the last 12 months and you have not sent them marketing in that time, the exception no longer covers them. For a long-term list, use consent.
Sender identity and opt-outs
Regulation 13(12) says every marketing message must not hide who it is from and must include a valid address the customer can use to ask you to stop. The DPC notes that many businesses use an unsubscribe link in emails and a STOP short code for texts. The DPC also states that sending electronic marketing to someone who has objected is a criminal offence.
Penalties in Ireland
- Each message counts. Regulation 13(13) makes every unsolicited message a separate offence.
- You carry the proof. Under Regulation 13(14), if consent is disputed in proceedings, the sender has to establish that the customer consented.
- Fines. Regulation 13(15) sets a class A fine on summary conviction, which means a fine of up to €5,000 under the Fines Act 2010. On indictment the maximum is €250,000 for a company and €50,000 for an individual.
The DPC publishes its electronic direct marketing case studies. Food businesses appear on the list, and the details are under common mistakes below.
Email and SMS consent rules in the UK
Across the UK, including Northern Ireland, electronic marketing is governed by regulation 22 of the Privacy and Electronic Communications Regulations (PECR), alongside the UK GDPR and the Data Protection Act 2018. The regulator is the Information Commissioner’s Office (ICO).
The general rule and the soft opt-in
The ICO’s guidance on electronic mail marketing says you must not send marketing emails or texts to individuals unless:
- they have specifically consented to messages from you, for example by ticking an opt-in box; or
- they are an existing customer who bought, or negotiated to buy, a similar product or service from you, and you gave them a simple way to opt out when you collected their details and in every message since.
The ICO calls the second route the soft opt-in. It does not cover prospective customers, new contacts or bought-in lists. The ICO’s summary of the rule contains no equivalent of Ireland’s 12-month condition. A customer who last ordered years ago is still a weak basis for marketing, so review old records before a campaign.
Other points from the ICO
- Channels. The rule covers emails, texts, picture and video messages, voicemails and direct messages on social media.
- Identity. You must not disguise or conceal who you are, and you must give a valid contact address for opting out.
- No central register. There is no email or text equivalent of the Telephone Preference Service.
- Business customers. Sole traders and some partnerships count as individuals. Companies and LLPs do not, but the ICO recommends keeping a do-not-email list of any business that objects. This matters for office lunch and catering customers.
- Forwarding. If you encourage customers to forward your marketing to friends, you are treated as instigating that message, and the rules apply to you.
- Guidance status. The ICO says this guidance is under review because of changes made by the Data (Use and Access) Act. Check the page before a large campaign.
Penalties and fees in the UK
The ICO said in June 2025 that the Data (Use and Access) Act gives it power to issue fines of up to £17.5 million or 4% of global turnover under PECR. Separately, most businesses processing personal data must pay the ICO data protection fee. GOV.UK lists it as £52 or £78 a year for most organisations, including small businesses, and up to £3,763 for large employers with high turnover (checked September 2026). Not paying can lead to a fine.
Ireland and UK rules side by side
| Rule | Ireland | UK, including Northern Ireland |
|---|---|---|
| Main law for marketing messages | S.I. No. 336 of 2011, Regulation 13 | PECR, regulation 22 |
| Regulator | Data Protection Commission | Information Commissioner’s Office |
| Default for texts and emails to individuals | Consent | Specific consent |
| Existing customer route | Sale context, own similar products, opt-out at collection and in every message, 12-month condition | Bought or negotiated to buy a similar product, opt-out at collection and in every message |
| People who never bought | Not covered by the exception | Negotiation can count; new contacts and bought-in lists do not |
| Pre-ticked boxes | Not valid consent | Consent must be specific, such as ticking an opt-in box |
| Evidence | Sender must establish consent if disputed | Keep a do-not-contact list and screen every send against it |
| Maximum penalty | €5,000 per summary conviction; €250,000 for a company on indictment; each message a separate offence | Up to £17.5 million or 4% of global turnover |
GDPR for restaurants
The marketing rules sit on top of general data protection law. Six points cover most of what an independent needs.
Lawful basis for each use
Using a phone number to tell a customer their order is on its way and using the same number to send a Friday offer are two different purposes. Treat them separately. Order updates follow from the order. Marketing needs consent or the existing-customer route above.
Privacy notice
Link a short privacy notice from your checkout, booking form and loyalty sign-up. Citizens Information lists what people should be told, including the reason for processing and its legal basis, who will have access, whether data may be transferred outside the EU, and how long it will be stored or how that period will be decided. Write it for customers: what you collect, why, which software providers hold it, how long you keep it and how to contact you.
Customer rights
Customers can ask to see the data you hold, have it corrected, or have it erased in some circumstances. They can also object to direct marketing at any time. The DPC’s FAQ notes that under Article 21 of the GDPR, once someone objects, their data must no longer be processed for direct marketing. GOV.UK tells UK businesses they must respond to a data protection request when someone asks to see what you hold. Name the person in your business who handles these requests, and check your CRM can find and export one customer’s record in minutes.
Security and staff access
- Give each staff member their own login.
- Limit customer lists and exports to managers.
- Remove access the day someone leaves. Staff roles and records are covered on the restaurant staff management page.
- Never keep customer lists on a personal phone or behind a shared spreadsheet link.
Breaches
If customer data is lost, stolen or sent to the wrong people, Irish businesses must report it to the DPC within 72 hours of becoming aware of the breach where it presents a risk to the people affected, and must tell those people without undue delay if the risk is high. UK businesses report to the ICO under its own breach guidance. Write down who decides and who reports before anything goes wrong.
Retention
No single legal number fits restaurant marketing data. Pick a period you can justify, write it in your privacy notice and apply it. Example: remove marketing permissions for customers with no order for two years, and anonymise their order history so it still counts in your reports. Keep transaction records for as long as your accountant says tax law requires.
Opt-in set-up at checkout, till and phone
In Ireland the sender carries the burden of proving consent. A permission you cannot evidence is close to worthless. Set this up once, properly.
- Choose your channels. Decide whether you will use email, SMS, push notifications or all three. Only ask for what you will use.
- Use consent as the default. Unticked boxes, one per channel, work in both countries and are easier to evidence than the existing-customer route.
- Write plain wording. Example for a fictional pizzeria: “Text me offers and news from Nonna Rosa’s” and a separate “Email me offers and news from Nonna Rosa’s”. Both start unticked.
- Keep consent apart from your terms. Do not fold marketing consent into “I accept the terms and conditions”. The DPC requires the consent request to be clearly distinguishable from other matters.
- Link your privacy notice directly beside the boxes.
- Record the evidence. For each customer and channel, store the date and time, the exact wording shown, the source (website checkout, till, phone, booking) and the order number if there was one.
- Use a script for phone orders. Example: “Would you like our offers by text? You can reply STOP at any time.” Tick the box on the POS only when the customer says yes, while they are still on the line.
- Put the opt-out in every message. An unsubscribe link in every email. A STOP instruction in every text. Your restaurant name at the start of every text.
- Apply opt-outs everywhere. One unsubscribe should stop email, SMS and push marketing in every tool you use. The ICO’s checklist says to act on opt-outs promptly and to keep a do-not-contact list.
- Test every month. Sign up with a staff phone, receive a message, reply STOP, and confirm the next campaign does not reach that number.
Customer segments for restaurants
A segment is a group of customers who share a pattern and should get the same message. Three measures cover most of what matters:
- Recency: days since the last order.
- Frequency: orders in a set period.
- Spend: total spend or average order value.
The thresholds below are examples for a takeaway. A café with daily customers would use shorter windows. A sit-down restaurant would use longer ones.
| Segment | Example rule | What to send | Discount |
|---|---|---|---|
| New customers | First order in the last 7 days | Thanks, and a reason to order again | Small or none |
| One order only | One order, 30 to 60 days ago | A favourite dish or a new one | A modest first-return offer |
| Regulars | 4 or more orders in the last 90 days | New menu items first, recognition | None needed |
| Lapsed regulars | 4 or more orders in total, none in 60 days | A win-back message | Yes, time-limited |
| High spenders | Top 10% by spend over 12 months | A personal thank-you, early access | None needed |
| Weekend-only | Nearly all orders Friday to Sunday | A midweek reason to order | Midweek only |
| Phone orderers | 3 or more phone orders, no online orders | Why ordering online is quicker | A small first online order code |
| Office and group orders | Weekday orders over €80 (£70) | A team lunch menu | A volume offer |
| Close to a reward | One order away from a loyalty reward | A reminder of the reward | None |
Two rules keep segments useful. Cap marketing at one message a week per customer across all segments combined. Do not discount for regulars who already pay full price; recognise them instead.
Order value and repeat rate trends are covered on the restaurant analytics software page. Rewards that suit each segment are listed in the restaurant loyalty programme ideas guide.
Worked example: a win-back text to lapsed customers
This is an illustration with assumed numbers, not a forecast. Replace the inputs with your own.
Example in euro
A takeaway in Ireland has 2,400 customer profiles from 12 months of direct orders. 1,300 of them gave SMS consent at checkout. 350 of those are lapsed regulars: four or more orders in total, none in the last 60 days.
Assumptions:
- SMS cost: €0.08 per text. Rates vary by provider. Twilio’s published price for an outbound SMS to Ireland was US$0.0779 when checked in September 2026.
- Offer: €5 off the next direct order over €25, valid for 7 days.
- Response: 8% of recipients order.
- Average order value: €32.
- Food and packaging cost: 32% of order value.
| Line | Maths | Result |
|---|---|---|
| Texts | 350 × €0.08 | €28.00 |
| Orders | 350 × 8% | 28 orders |
| Sales | 28 × €32 | €896.00 |
| Food and packaging | €896 × 32% | €286.72 |
| Discounts | 28 × €5 | €140.00 |
| Contribution before labour and card fees | €896 − €286.72 − €140 − €28 | €441.28 |
Suppose half of those 28 customers return to ordering once a month for three more months at full price. That is 14 × 3 = 42 more orders. Each contributes €32 × 68% = €21.76, so 42 × €21.76 = €913.92 more.
Now the risk side. If the same 350 texts went to people who never consented, each text in Ireland would be a separate offence under Regulation 13(13), with a fine of up to €5,000 per summary conviction.
Example in sterling
The same takeaway in England, with UK inputs:
- SMS cost: £0.06 per text. Twilio’s published price for an outbound SMS to the UK was US$0.056 when checked in September 2026.
- Offer: £4 off the next direct order over £22.
- Response: 8%. Average order value: £27. Food and packaging: 32%.
| Line | Maths | Result |
|---|---|---|
| Texts | 350 × £0.06 | £21.00 |
| Orders | 350 × 8% | 28 orders |
| Sales | 28 × £27 | £756.00 |
| Food and packaging | £756 × 32% | £241.92 |
| Discounts | 28 × £4 | £112.00 |
| Contribution before labour and card fees | £756 − £241.92 − £112 − £21 | £381.08 |
In both versions the campaign only exists because the takeaway owned the 350 records, knew who had lapsed, and could prove permission. A takeaway that only sells through marketplaces cannot run it.
Restaurant CRM options compared
Prices come from each company’s own pricing page, checked in September 2026. Prices change and may exclude VAT, so ask for a written quote before signing.
| Option | Examples | What the customer record contains | Published price | Best fit |
|---|---|---|---|---|
| Spreadsheet plus email tool | A shared spreadsheet and a free email plan | Whatever staff type or export | Low; varies with contact numbers | A café with under 100 regulars |
| POS add-ons | Square Marketing and Square Loyalty | Customers who pay or join through Square | Square Marketing from £9 a month; Square Loyalty £25, £45 or £65 a month per location, by loyalty visits | UK sites already using Square POS |
| Loyalty apps with member lists | Stamp Me, Loyalzoo | Members who join the app | Stamp Me Lite £39 or €29 a month; Loyalzoo Grow US$77 a month | Cafés with mostly walk-in trade |
| Hospitality CRM for groups | Specialist guest data platforms | Guest data pulled from several systems | Ask for a written quote | Multi-site groups with a marketing team |
| Ordering platform with CRM built in | Eclyde | Every direct order from the website and POS | €499 to launch, then €99 a month, no commission on direct orders (pricing) | Independents who want orders, customers and marketing in one system |
| Marketplace dashboards | Just Eat, Deliveroo, Uber Eats | Order data inside each app | Part of the commission you pay | Discovery, not a customer list you control |
Three things to weigh beyond price:
- Where orders come from. A loyalty app only knows the customers who open it. A CRM inside your ordering system and POS sees every direct order.
- Consent records. Ask to see the stored consent record for a test customer: date, wording and source.
- Leaving. Confirm in writing that you can export all customers, orders and permissions in a standard file, at no charge, if you move provider.
Questions to ask a restaurant CRM provider
- Does every online, in-store and phone order attach to a customer profile automatically, or do staff have to search and select?
- How are duplicates merged when the same person uses two email addresses?
- For each customer and channel, what consent evidence is stored: date, wording, source?
- Can I set email, SMS and push permissions separately?
- When a customer replies STOP or unsubscribes, how quickly does that apply to every channel?
- Can you import my existing customer list, and how do you handle records with no consent evidence?
- Can staff roles hide customer lists and block exports?
- Can I build segments by recency, frequency, spend and favourite items myself?
- What does each SMS cost, and is there a monthly cap?
- Where is the data hosted, and will you sign a data processing agreement?
- Can I export everything in a standard file if I leave, and is there a fee?
- Is there a charge per customer, per contact or per order as the list grows?
- What is the contract length and notice period?
Common restaurant CRM mistakes
- Pre-ticked boxes. The DPC says pre-ticked boxes, silence and inactivity are not consent. Every consent box starts unticked.
- Consent hidden in terms and conditions. The DPC’s case studies include a prosecution of Pulse Gym, trading as Energie Fitness Dublin 8, which said members had agreed to terms that referred to consent to electronic marketing. Keep marketing consent as its own box.
- Old tick boxes reused without review. In the DPC’s case study on Supermac’s Ireland Limited, a customer complained about marketing texts. The company said the customer had ticked the box when registering for online ordering in 2018 and was added to an active SMS list after ordering again in 2023. The case is listed as a prosecution. Keep dated consent records and review old lists before reusing them.
- Opt-outs that fail. The DPC prosecuted Shop Direct Ireland, trading as Littlewoods Ireland, after a customer texted STOP five times and kept receiving marketing texts. It also prosecuted Just-Eat Ireland Limited after a technical fault stopped an unsubscribe from working, an issue that affected 391 customers in Ireland. Test your opt-out every month.
- Messaging marketplace customers. Deliveroo and Uber Eats UK terms restrict their order data to fulfilling orders. Copying numbers into your SMS tool breaks the terms and, without consent, the law.
- Treating Wi-Fi or competition sign-ups as customers. In Ireland the existing-customer route needs a sale. Use specific consent for these lists.
- “Forward to a friend” campaigns. The ICO treats encouraging forwarding as instigating the message.
- Promoting someone else’s offer. The existing-customer route only covers your own similar products. A text about a partner’s deal needs consent.
- One list for everything. Mixing order updates and marketing means an unsubscribe can stop delivery texts, or delivery texts drift into marketing.
- Shared logins. When five people use one login, nobody can tell who exported the list.
Restaurant customer data checklist
- A privacy notice linked from checkout, booking and loyalty sign-up.
- Separate, unticked consent boxes for each marketing channel.
- Consent stored with date, wording, source and channel.
- A phone script for asking permission, with the POS box ticked only on a clear yes.
- Your restaurant name and an opt-out in every marketing message.
- One opt-out applied to email, SMS and push.
- A monthly STOP and unsubscribe test.
- No marketing to marketplace customers using marketplace order data.
- Individual staff logins, with exports limited to managers.
- A named person for access, correction and erasure requests.
- A written breach plan, including the 72-hour DPC deadline for Irish sites.
- A retention period in the privacy notice, applied at least once a year.
- For UK sites, the ICO data protection fee paid.
- Segments for new, lapsed and regular customers checked every month.
Customer management in Eclyde
Eclyde is the restaurant growth platform for independent restaurants, starting in Ireland and the UK. The customer record sits in the same system that takes the orders, so there is no export step between them.
- Data ownership. The restaurant owns its customer data: who customers are, what they order, how often, favourite items and purchasing behaviour.
- Customer profiles with order history and insights, from orders on the branded ordering website on your own domain and on the Eclyde POS.
- Customer import is part of the €499 launch set-up, alongside menu build, website and ordering set-up, POS and printer configuration, staff onboarding, testing and go-live support.
- Loyalty is points-based with rewards, plus referral rewards and discount codes.
- Marketing covers email and SMS campaigns, push notifications, and review requests after orders. Every customer is asked for a review; there is no review gating.
- Analytics include a sales dashboard and AI insights.
- POS details relevant to customer data: caller ID on incoming phone calls, and role-based staff permissions.
- Payments go through the restaurant’s own Stripe account, connected during set-up. Eclyde does not offer card processing.
After the €499 launch fee, which is refunded in full within 30 days if Eclyde is not right for the restaurant, the whole platform is €99 a month. There is no Eclyde commission on direct orders and no limit on orders or customers. Marketplaces stay useful for discovery. The aim is to turn the customers they bring into direct, repeat customers on your own channels, within the marketplace rules set out above.
If you run a large group and need a dedicated hospitality CRM that pulls guest data from many separate systems, a specialist CRM platform may suit you better.
Your restaurant’s customer data
Before choosing any restaurant CRM, look at where your customers order today and how much of that trade you can reach directly. The free Eclyde restaurant audit takes about two minutes. It checks your Google profile, your website and how much your restaurant depends on the marketplaces, then shows what direct ordering is worth to you. Use the result alongside the checklist above to decide what to fix first.
Questions
What is a restaurant CRM?
A restaurant CRM is the customer database behind your tills and ordering website. It links each customer to their orders, visits, spend and marketing permissions, so you can see who your regulars are, who has stopped ordering and who you are allowed to contact. For most independents it sits inside the POS or online ordering system rather than in a separate sales tool.
Do I need consent to text my restaurant customers in Ireland?
Usually yes. S.I. No. 336 of 2011 requires consent for marketing texts and emails to individuals. There is a narrow exception for existing customers: you collected the details during a sale, you market your own similar products, you offered an easy opt-out at collection and in every message, and the sale or your last marketing use of the details was within 12 months.
What is the soft opt-in for restaurants in the UK?
The soft opt-in lets you email or text people who bought, or negotiated to buy, a similar product or service from you, as long as you gave them a simple way to opt out when you collected their details and in every message since. It does not cover people who never ordered, bought-in lists or anyone who has opted out.
Can I use customer details from Deliveroo or Uber Eats for marketing?
Not under the UK terms checked in September 2026. Deliveroo's UK partner terms limit order information to fulfilling the order it relates to. Uber Eats' UK merchant terms limit personal data to providing items to customers and bar merging it with other data for targeted marketing. Read your own agreement, including Just Eat's, before contacting any marketplace customer.
How much does restaurant CRM software cost?
It depends on whether the CRM is bundled with something else. Published prices checked in September 2026 start at £9 a month for Square Marketing, £25 a month per location for Square Loyalty and £39 a month for Stamp Me. Platforms that combine ordering, POS and customer data charge one fee; Eclyde is €99 a month after a €499 launch fee.
Does GDPR apply to a small takeaway?
Yes. The core rules apply to any business that holds customer data, whatever its size. You need a lawful basis for each use, a clear privacy notice, a way to handle access and deletion requests, sensible security and a retention period. In the UK most businesses processing personal data also pay the ICO data protection fee, £52 or £78 a year for most organisations.
How long can a restaurant keep customer data?
No single legal number fits restaurant marketing data. Choose a period you can justify, state it in your privacy notice and apply it. One workable approach is to remove marketing permissions for customers with no orders for two years and anonymise their order history for reporting, while keeping transaction records for as long as your accountant says tax law requires.
What happens if a restaurant breaks the marketing rules?
In Ireland each unlawful message is a separate offence under S.I. No. 336 of 2011, with a fine of up to €5,000 on summary conviction and up to €250,000 for a company on indictment. The Data Protection Commission has prosecuted food businesses. In the UK the ICO says the Data (Use and Access) Act lets it fine up to £17.5 million or 4% of global turnover under PECR.