Privacy.
What we collect, why we have it, who else sees it, and how to get it back or get rid of it.
Last updated 11 September 2026.
Two different people are described here
Operators are the restaurants and cafés who sign up for Order It Hub. Their data is ours to explain — we decide what we hold and why.
Diners are the people who order from an operator's store. That data belongs to the operator. We hold it on their behalf and act on their instructions; if you ordered from a restaurant and want your record changed or removed, ask that restaurant first. We will help them do it.
What we hold about an operator
- Account details: name, email address, password (stored only as a hash), role, and which branches the account works at.
- Store content you create: menu, prices, photos, branches, tables, staff, opening state.
- Billing state: your plan, whether the subscription is active, trialing or lapsed, and the invoice history Stripe holds for you. We never see or store a card number.
- Support conversations: mail you send to us, and messages sent through the contact form.
What we hold on an operator's behalf
- Order records: items, totals, tax, tips, fulfilment type, status and timestamps.
- Diner accounts an operator's customers create: name, email, phone, saved addresses, loyalty points and order history.
- Marketing state: whether a diner opted out, and, for campaigns an operator sends, whether a message was delivered, opened or clicked.
- SMS consent: for a diner who ticked the text-message box at checkout, the number, the answer given, the exact wording shown, and when and from where it was given.
Text messages
A diner is only texted about an order when they ticked the SMS box at that store's checkout. The box is never ticked for them and is never part of accepting the terms. Those texts are about the order — confirmation and status — and carry no advertising.
Replying STOP to any of them stops them, for that store. Replying HELP returns contact details. Message and data rates may apply, and message frequency varies with how often you order.
Mobile numbers and SMS consent are held apart from everything else here; see Mobile information sharing below for what is, and is not, ever done with them.
Cookies
We use as few as the product can work with, and none of them are sold or shared with an advertising network.
- Session cookie — keeps you signed in and carries the CSRF token that stops somebody else submitting forms as you. It expires when the session does.
oih_ref— set only if you arrive at orderithub.com by clicking a link in an email we sent you. It holds the tracking token of that email so that a form you fill in afterwards can be credited to the campaign that brought you here. It lasts 30 days and it is not readable by JavaScript.- Email tracking — a message we send may contain a one-pixel image and links that pass through our own redirect, which is how opens and clicks are counted. Blocking remote images in your mail client stops the first; you can always reach the destination directly.
Who else sees the data
Only the companies that make the product work, and only the part each of them needs:
- Stripe — payments and subscriptions. Card details go to Stripe directly and never pass through our servers.
- SendGrid — sending email: receipts, account mail, and the email campaigns an operator chooses to run. Email only; no phone number and no SMS consent data goes to SendGrid.
- Twilio — delivering the order text messages a diner opted in to. The phone number goes to Twilio only to carry that message, and for nothing else.
- Nash — delivery dispatch, and only for orders an operator chooses to send to a courier. The diner's name, phone and address go with the job because the driver has to find them and call if the door is locked. Nash never receives SMS consent data, and neither Nash nor its couriers may use any of it to market anything.
- Cloudflare — DNS and inbound email routing for our own domain.
- DigitalOcean — the servers the application and database run on.
Each of them acts on our instructions and only for the job named above; none of them receives data to market anything of their own. We do not sell data, and we do not share it with anybody for their own marketing. Mobile opt-in data and SMS consent are never passed to any of them, or to anyone else, for marketing or promotional purposes.
Mobile information sharing
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
In plain terms: a phone number given for texting reaches exactly two places — our own servers, and Twilio, the messaging provider that puts the text on the network for us. It is never sold, never rented, never handed to an advertiser, and never passed to anybody so they can market something. The record that a diner ticked the SMS box stays with us and goes nowhere at all.
Keeping it, and getting rid of it
Operator data lives as long as the account does. Deleting a store is reversible for a grace period and then permanently purged — every table belonging to that store is erased, not flagged.
You can export orders, customers and products to CSV at any time, on any plan. We do not charge for your data leaving.
A diner can unsubscribe from an operator's marketing from any message we send, in one click. That opt-out applies to that operator only: opting out of one restaurant's mail does not opt you out of an unrelated restaurant that happens to use the same software.
Security
Traffic is encrypted in transit. Passwords are stored as hashes and never in a readable form. Every store's data is isolated by tenant, and staff accounts only reach the branches they are assigned to.
Asking us something
Write to support@orderithub.com and a person will read it. If you are a diner asking about an order, tell us which restaurant it was — we hold that record for them, not for us.