Privacy policy
Last updated 11 September 2026
This policy explains what personal data Eclyde collects, why, who we share it with, how long we keep it, and the rights you have. It covers eclyde.com, the free restaurant audit, and the Eclyde platform used by restaurants: the dashboard, point of sale, kitchen display, online ordering websites, staff and driver apps.
Who we are
Eclyde Corporation ("Eclyde", "we", "us") is based in Ireland. For anything to do with personal data, email privacy@eclyde.com. For everything else, email hello@eclyde.com or call +353 87 438 8032.
Controller or processor
- Eclyde is the controller for data about people who visit eclyde.com, use the restaurant audit, contact us, or hold an Eclyde account as a restaurant owner or manager.
- The restaurant is the controller for data about its own customers and staff, such as orders, delivery addresses, loyalty points, bookings, gift vouchers and rotas. Eclyde processes that data on the restaurant's behalf, under the restaurant's instructions and a data processing agreement. If you ordered from a restaurant that uses Eclyde, contact that restaurant first about your data.
What we collect
| Where | What |
|---|---|
| Restaurant audit | The restaurant you select; public information about it from Google (name, address, hours, rating, reviews and photos); a scan of its public website; your answers to the audit questions; your mobile number and whether you verified it; a hashed version of your IP address to limit abuse. |
| Enquiries | Your name, email, phone number, restaurant details and anything you tell us. |
| Restaurant accounts | Owner and manager names, contact details and login information; business details, menus, prices and settings; billing records; connected accounts you authorise, such as Stripe, Google Business Profile and Google Ads. |
| Restaurant customers (as processor) | Names, contact details, delivery addresses, order history, loyalty balances, bookings, gift vouchers, marketing consent and payment references. We do not store full card numbers. |
| Restaurant staff and drivers (as processor) | Names, contact details, roles and permissions, shifts, clock-in times, messages and, for drivers on shift, location. |
| Website | Essential technical data such as IP address and browser type, which our hosting provider logs to keep the site running and secure. See the cookie policy. |
Why we use it, and on what legal basis
- Running the audit and showing your report: legitimate interests, because you asked for it.
- Verifying your mobile number before opening a report: legitimate interests in preventing abuse and making sure a real person receives it.
- Following up about your audit or enquiry, including a phone call: legitimate interests. You can ask us to stop at any time.
- Providing the Eclyde platform to restaurants, billing and support: performance of our contract.
- Security, fraud prevention and screening new sign-ups: legitimate interests.
- Marketing emails and texts from Eclyde: your consent, or the rules for existing business customers where they apply. Every message includes a way to opt out.
- Keeping tax and accounting records: legal obligation.
What we never do
- We never sell personal data.
- We never share one restaurant's customer data with another restaurant.
- We never use a restaurant's customer data to market to those customers for anyone else.
- We never use your data to train third-party AI models for their own purposes.
Who we share it with
We use a small number of service providers to run eclyde.com and the platform. Each processes data only on our instructions, under a written agreement.
| Provider | What for |
|---|---|
| Supabase | Database, file storage, sign-in and phone verification |
| Vercel | Hosting eclyde.com and restaurant ordering websites |
| Twilio | Sending verification codes and text messages |
| Public restaurant data, maps and address lookup, website speed tests, and Google Business Profile and Google Ads when a restaurant connects them | |
| Anthropic | Summarising public review text and generating suggestions in the audit and platform |
| Stripe | Payments, processed through the restaurant's own Stripe account or Eclyde's billing |
| Resend | Sending email, such as receipts, confirmations and campaigns |
We may also share data where the law requires it, or with professional advisers under a duty of confidentiality.
International transfers
Our main database is hosted in the European Union. Some providers above may process data outside the European Economic Area or the UK. Where they do, we rely on an adequacy decision or the European Commission's Standard Contractual Clauses, with the UK addendum where UK data is involved.
Google API Services
Eclyde's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We access Google Business Profile data on behalf of restaurant owners to show reviews and manage replies inside Eclyde.
- We access Google Ads data on behalf of restaurant owners to run campaigns and report on them inside Eclyde.
- Google data is used only to provide the service the owner connected. It is never sold, never used for advertising profiles, and never used to train models unrelated to that service.
- Access is limited to the scopes the owner approves. Owners can revoke it at any time in their Google Account settings or by contacting us.
How long we keep it
- Audit data and enquiries: 24 months from your last contact with us.
- Restaurant account data: for as long as the account is active, plus 12 months.
- Billing, order and transaction records: at least six years, to meet Irish and UK tax record-keeping rules.
- Restaurant customer and staff data: as the restaurant instructs, and deleted or returned when the restaurant leaves Eclyde.
- Marketing consent records: while consent is active, plus three years as evidence.
Security
Data is encrypted in transit. Access to production systems is limited to the people who need it. Staff and owner accounts use individual logins with role-based permissions. Card details are handled by Stripe and never stored by Eclyde. No system is completely secure; if a breach puts your rights at risk, we will notify the Data Protection Commission within 72 hours and tell affected people without undue delay.
Your rights
Under the GDPR, the Irish Data Protection Act 2018 and the UK GDPR, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or give it to you in a portable format. You can withdraw consent at any time. Email privacy@eclyde.com. We will reply within one month.
You can complain to the Data Protection Commission in Ireland, or the Information Commissioner's Office in the UK.
Children
Eclyde is a business service. We do not knowingly collect data from children under 16 for our own purposes.
Changes
We will update this page when our practices change and change the date at the top. If a change is significant, we will tell account holders by email before it takes effect.