Legal
Privacy policy.
Your data is yours. Always has been. Always will be. Here's exactly how we protect it across every Eclyde platform.
Updated 20 August 2026
Scope of this policy
This policy covers all Eclyde platforms and services, including our customer-facing website, restaurant management dashboard, staff management tools, point-of-sale systems, online ordering platforms, kitchen display systems, and any associated mobile or web applications. Wherever you interact with Eclyde, this policy applies.
What we collect
We collect only the information necessary to provide our services effectively. The type of data depends on how you interact with Eclyde.
- Website visitors: standard analytics (page views, device type, country-level location) to improve our website. No personally identifiable information is collected without your consent.
- Enquiries: your name, email, phone number, and restaurant details when you contact us, use the restaurant audit tool, or submit a lead form.
- Restaurant operators: business information, menu data, staff details, and operational data necessary to run your restaurant through our platform.
- Restaurant customers: order details, contact information, delivery addresses, and payment references processed on behalf of the restaurant.
- Staff users: name, contact details, role assignments, login credentials (encrypted), and work-related data such as schedules and performance metrics.
How we use your data
Every piece of data we collect serves a specific, legitimate purpose. We never collect data speculatively or 'just in case.'
- Providing and improving our restaurant management services
- Processing orders, payments, and deliveries on behalf of restaurants
- Responding to enquiries and providing customer support
- Generating anonymised analytics and insights for restaurant operators
- Sending service updates and product information (only with explicit consent)
- Maintaining platform security, preventing fraud, and detecting abuse
- Complying with legal obligations and regulatory requirements
What we never do
Trust is non-negotiable. There are things we will never do with your data, regardless of circumstance.
- We never sell your data to third parties. Ever.
- We never share restaurant customer data with competing restaurants.
- We never use your customer data to advertise to your customers on behalf of other businesses.
- We never share your operational data, revenue figures, or business metrics with anyone outside your organisation.
- We never use your data to train external AI models or sell to data brokers.
- We never retain data longer than necessary for the purpose it was collected.
Data protection and security
We implement enterprise-grade security measures across all our platforms to protect your data at every level.
- All data is encrypted at rest using AES-256 encryption standards.
- All data in transit is protected using TLS 1.2 or higher encryption.
- Multi-factor authentication is available for all operator and staff accounts.
- Role-based access controls ensure staff only see data relevant to their role.
- Regular security audits and penetration testing are conducted on all platforms.
- Automated threat detection and monitoring systems run continuously.
- Database backups are encrypted and stored in geographically distributed, SOC 2 compliant data centres within the EU.
- Session management includes automatic timeouts, rate limiting, and brute-force protection.
Staff data and access controls
For restaurants using Eclyde's staff management tools, we take staff privacy seriously. Staff members can only access data appropriate to their assigned role. Managers cannot access data beyond their permission level. All staff actions are logged for accountability. Personal staff data (contact details, schedules, performance) is only visible to authorised personnel within the restaurant and is never shared externally.
Payment data
Eclyde does not store full payment card details on any of our systems. All payment processing is handled through PCI DSS Level 1 certified payment processors. We only retain payment references and transaction identifiers necessary for order reconciliation and refund processing.
Restaurant customer data ownership
For restaurants using any Eclyde platform, customer data belongs entirely to the restaurant. Eclyde acts as a data processor on behalf of the restaurant (the data controller). This means the restaurant decides how their customer data is used. Eclyde processes it solely to deliver the services the restaurant has engaged us for. If a restaurant leaves Eclyde, they can export all their data. We delete restaurant customer data from our systems upon request.
GDPR compliance
We process personal data under the General Data Protection Regulation and the Irish Data Protection Act 2018, and we support the rights those laws give you: access, rectification, erasure, restriction, portability, and objection. The sections below set out what we actually do rather than simply asserting a verdict on ourselves. If you think we have got something wrong, tell us and we will fix it.
- Right of access: request a copy of all personal data we hold about you.
- Right to rectification: correct any inaccurate personal data.
- Right to erasure: request deletion of your personal data ('right to be forgotten').
- Right to restrict processing: limit how we use your data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests or direct marketing.
- Rights related to automated decision-making: we do not make solely automated decisions that produce legal effects concerning you.
Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods vary by data type.
- Website analytics data: 26 months (anonymised).
- Enquiry data: 24 months from last interaction.
- Active restaurant operator data: duration of service agreement plus 12 months.
- Order and transaction data: 7 years (as required by Irish tax and accounting regulations).
- Staff data: duration of employment plus 12 months after offboarding.
- Marketing consent records: retained as long as consent is active, plus 3 years after withdrawal for compliance evidence.
Cookies and analytics
We use cookies and analytics tools to ensure our platforms function properly and to understand how visitors use our website. Analytics tools load only after you accept cookies via our consent banner (Google Consent Mode v2). Until then, no personal identifiers, ad cookies, or session recordings are stored.
- Essential cookies: required for platform functionality (authentication, security, session management). These cannot be disabled.
- Google Analytics 4 (via Google Tag Manager): aggregated, IP-anonymised traffic and event analytics, loaded only with your consent. Used to measure page views, audit completions, and conversions.
- Microsoft Clarity: session replay and heatmap tool used to understand how visitors interact with the site so we can improve UX. Clarity masks all form input by default and never records sensitive fields. Loaded only with your consent.
- We do not run advertising or retargeting cookies (Meta Pixel, TikTok Pixel, Google Ads remarketing) on this site.
- You can withdraw consent at any time by clearing the '_ec_consent_v1' key in your browser storage, which will re-show the consent banner.
Third-party services
We work with a small number of third-party processors to run the platform. Each is bound by a written data processing agreement, and data is held in the European Economic Area or in a country covered by an adequacy decision. If you need the list of processors for your own records, ask us and we will send it.
Google API Services
Eclyde's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We access Google Business Profile data on behalf of restaurant owners to display reviews and manage their online presence within the Eclyde platform.
- We access Google Ads data on behalf of restaurant owners to manage advertising campaigns and provide performance analytics within the Eclyde platform.
- Google API data is used exclusively to provide services to the restaurant owner who authorised the connection. It is never sold, shared with third parties, or used for purposes unrelated to the services requested.
- We do not use Google API data to build user profiles for advertising, serve ads, or train machine learning models unrelated to the restaurant owner's requested services.
- Restaurant owners can revoke Eclyde's access to their Google data at any time through their Google Account permissions settings or by contacting us directly.
- Access to Google user data is limited to the scopes explicitly authorised by the restaurant owner during the connection process.
International data transfers
Your data is primarily stored and processed within the European Union. In the limited cases where data may be processed outside the EEA (for example, for specific third-party integrations you choose to enable), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
Children's privacy
Eclyde's services are designed for business use by restaurant operators, their staff, and their customers. We do not knowingly collect personal data from children under the age of 16. If we become aware that we have inadvertently collected such data, we will delete it promptly.
Data breach notification
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority (the Irish Data Protection Commission) within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Affected individuals will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated via email to registered users and prominently displayed on our website. We encourage you to review this policy periodically. This policy was last updated on 20 August 2026.
Contact and data protection enquiries
For any privacy-related questions, data subject access requests, or concerns about how your data is handled, contact our Data Protection team at privacy@eclyde.com. For general enquiries, email hello@eclyde.com. We take every privacy enquiry seriously and aim to respond within 5 working days. If you are not satisfied with our response, you have the right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie).
Questions, answered straight.
Not covered here? Just ask us.
Does Eclyde own my restaurant's customer data?
No. Your customer data belongs entirely to your restaurant. Eclyde processes it on your behalf as a data processor. You remain the data controller at all times. If you leave Eclyde, you can export all your data and we will delete it from our systems upon request.
Can my staff see all customer data?
No. Eclyde uses role-based access controls. Staff members only see data relevant to their assigned role. A delivery driver, for example, only sees the information needed to complete a delivery, not your full customer database or financial reports.
How does Eclyde handle GDPR?
We process data under GDPR and the Irish Data Protection Act 2018. In practice that means data held in the EU, encryption in transit and at rest, a written processing agreement with every processor we use, and a route for you or your customers to get data exported or deleted on request. Compliance is something a regulator decides, not something we can certify about ourselves, so we would rather tell you what we do and let you judge it.
Does Eclyde sell my data?
Absolutely not. We never sell, trade, or share your data with third parties for their own purposes. Your data is used exclusively to provide and improve the services you've engaged us for.
What happens to my data if I cancel Eclyde?
You can export all your data at any time. Upon cancellation, we retain data only as required by law (e.g., tax records for 7 years). All other personal and operational data is deleted within 30 days of your request.
Where is my data stored?
Your data is stored in SOC 2 compliant data centres within the European Union. We do not disclose specific infrastructure providers for security reasons, but all providers are contractually bound by GDPR-compliant data processing agreements.