Overview
Scope: This Policy explains how Yara Data handles personal information when acting for itself and when processing restaurant guest data on behalf of a restaurant brand or other business customer.
Yara Data, Inc. (“Yara Data,” “we,” “us,” or “our”) provides a business-to-business restaurant analytics and intelligence platform. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with https://yaradata.com, our applications and services, and our business relationships.
Yara Data currently markets and provides its Services in the United States. Our platform is intended for restaurant brands, franchise organizations, franchisees, store operators, and their authorized business users age 18 or older. Restaurant guests do not create Yara Data accounts, but their information may be processed through customer-authorized integrations such as point-of-sale, marketing, review, delivery, or other restaurant systems.
1. Our Roles: Business/Controller and Service Provider/Processor
Yara Data handles personal information in two main roles. For information about our own prospects, customers, website visitors, account users, vendors, and business contacts, Yara Data generally determines the purposes and means of processing and may act as a “business” or “controller” under applicable privacy law.
For restaurant guest, consumer, or workforce information that a restaurant brand or other Customer provides to Yara Data for analytics, reporting, segmentation, forecasting, campaign execution, or related Services, the restaurant Customer generally determines why that information is processed. In that context, Yara Data generally acts as the Customer’s service provider, contractor, processor, or similar role. Restaurant guests should ordinarily direct privacy requests about restaurant-controlled data to the restaurant or brand with which they interacted.
When acting in this service-provider or processor role, Yara Data uses Customer-controlled personal information for the limited purposes of hosting and securing the Services; ingesting, storing, normalizing, and organizing Customer-authorized data; providing reports, analytics, forecasting, benchmarking, customer segmentation, recommendations, campaign facilitation, and action tracking; providing implementation, support, troubleshooting, fraud prevention, and security; and carrying out the Customer’s documented instructions. We do not use identifiable restaurant guest information from one Customer to expose or provide identifiable information to another Customer, and cross-brand learning is limited to aggregated or deidentified information as described below.
2. Notice at Collection: Categories, Purposes, and Retention
The following summary describes the categories of personal information Yara Data may collect for its own business purposes, why we use them, and the criteria we use to determine retention. The specific information collected depends on how you interact with us.
Restaurant guest and other Customer-controlled data is addressed separately in Sections 4, 5, and 12. Yara Data does not require Social Security numbers, government IDs, protected health information, biometric identifiers used for identification, or precise geolocation for ordinary use of the Services and asks Customers not to provide such information unless specifically agreed in writing.
Notice at Collection Summary
Category: Business identifiers and contact information; Examples: Name, business email, phone, employer, job title, account identifiers; Purposes: Create and administer accounts; communicate; sales; support; security; contracting; Retention criteria: For the business relationship and as reasonably needed afterward for legal, security, billing, dispute, and recordkeeping purposes.
Category: Account, device, and internet activity; Examples: IP address, approximate location from IP, browser/device information, session data, login activity, feature usage, cookies, logs; Purposes: Authentication; security; fraud prevention; troubleshooting; analytics; product improvement; Retention criteria: For as long as reasonably necessary for security, operations, analytics, and legal obligations, using shorter periods where practical.
Category: Commercial and billing information; Examples: Subscription, locations, plan, invoices, payment status, transaction identifiers, card brand and last four digits if supplied by the processor; Purposes: Billing; accounting; subscription management; fraud prevention; tax and legal compliance; Retention criteria: For the customer relationship and applicable accounting, tax, fraud, audit, chargeback, and legal-retention periods.
Category: Communications and support records; Examples: Emails, support tickets, meeting notes, feedback, survey responses; Purposes: Respond to requests; support; improve the Services; maintain business records; Retention criteria: For as long as reasonably necessary to support the relationship, resolve issues, document commitments, and meet legal needs.
Category: Inferences and analytics; Examples: Product-usage insights, account health, feature preferences, security signals; Purposes: Personalize business-user experience; prioritize support; improve products; security; Retention criteria: For as long as reasonably necessary for the stated business purposes, then deleted or aggregated/deidentified where appropriate.
3. Information We Collect Directly
- Account and business contact information, such as name, business email, phone number, employer, title, user role, assigned stores or groups, and login information.
- Subscription and billing information, such as plan, locations, invoices, payment status, transaction identifiers, and limited payment-card metadata supplied by a payment processor. Yara Data does not intend to store full payment card numbers.
- Communications, support requests, meeting notes, feedback, survey responses, implementation information, and other information you choose to provide.
- Technical and usage information, such as IP address, approximate location derived from IP, browser/device type, login/session activity, pages and features used, cookies or similar technologies, error/crash logs, and security/audit logs.
4. Information We Process for Restaurant Customers
Customers may connect restaurant systems or provide data to Yara Data. Depending on the Customer and enabled features, Customer-controlled data may include:
- restaurant guest identifiers, customer IDs, names, phone numbers, email addresses, loyalty identifiers, and contact preferences;
- orders, transaction history, menu items, modifiers, discounts, coupons, order channels, order times, store/location identifiers, refunds, and related purchase history;
- customer segments, visit frequency, recency, average ticket, retention or churn indicators, offer eligibility, campaign history, redemption, and response information;
- store sales, third-party delivery data, online-ordering data, reviews and ratings, operational metrics, speed-of-service data, and similar restaurant performance information;
- store-level labor or workforce metrics and, if a Customer chooses to provide it, limited identifiable workforce information processed on the Customer’s behalf;
- food cost, inventory, accounting, P&L, expense, projection, or other financial/operational data; and
- data from Customer-authorized third-party integrations such as POS, labor, review, delivery, inventory, accounting, marketing, messaging, or online-ordering providers.
The restaurant or brand that provides or authorizes this information is responsible for its own privacy notices, collection practices, legal basis, customer consents, employee notices, marketing permissions, and responses to individual privacy rights, subject to applicable law. Yara Data processes this information under the Customer’s instructions and applicable contractual terms.
5. How We Use Information
We may use personal information as reasonably necessary to:
- provide, configure, operate, secure, maintain, and support the Services;
- authenticate users and administer role-based access to brands, stores, groups, reports, and administrative functions;
- ingest, normalize, map, analyze, and report restaurant data;
- generate dashboards, alerts, forecasts, customer segments, recommendations, opportunity rankings, projections, benchmarks, and other analytics;
- support Customer-approved email or SMS campaigns through connected marketing or messaging providers;
- track recommendations, tasks, approvals, campaigns, outcomes, and historical performance;
- process subscriptions, invoices, payments, and account administration;
- provide customer service, implementation, training, and troubleshooting;
- detect fraud, abuse, security threats, unauthorized access, and service errors;
- measure usage, improve product design, test features, maintain quality, and develop new capabilities;
- comply with law, enforce agreements, establish or defend legal claims, and protect Yara Data, our Customers, users, and others; and
- perform other purposes disclosed at collection or authorized by the person or Customer providing the information.
6. AI, Forecasting, and Private Brand Intelligence
Yara Data may use statistical methods, machine learning, artificial intelligence, and third-party model or cloud providers to generate reports, explanations, forecasts, recommendations, customer segments, suggested promotions, and other analytics. When identifiable or store-specific Customer Data is used to improve intelligence for a particular Customer, we use it for that Customer’s private brand environment and do not expose that identifiable or store-specific data to unrelated brands.
Yara Data’s current Services are designed for restaurant analytics, operations, forecasting, and marketing decision support. They are not designed to make decisions that produce legal or similarly significant effects on consumers in areas such as lending, housing, insurance, healthcare eligibility, education admission, or access to essential services.
7. Aggregated, Deidentified, and Cross-Brand Network Intelligence
Where permitted by law and contract, we may create aggregated, anonymized, statistical, or deidentified information from data processed through the Services. We may use this information to improve analytics and models, create restaurant or pizza-industry benchmarks, study trends, improve forecasting and recommendations, conduct research, enhance security and reliability, and develop or commercialize generalized network-intelligence products.
We design such information so it does not reasonably identify an individual, Customer, or specific restaurant location. We do not attempt to reidentify information maintained as deidentified except as permitted by law for security, testing, validation, or compliance. Where appropriate, we contractually restrict recipients of deidentified information from attempting reidentification or combining it with other data to identify an individual, Customer, or specific location.
8. How We Disclose Information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy:
- service providers and subprocessors that provide cloud hosting, databases, monitoring, communications, email/SMS delivery, AI/model processing, analytics, customer support, security, payment processing, and related infrastructure;
- Customer-authorized integrations and third-party platforms when necessary to exchange data or perform a requested action;
- professional advisers, auditors, insurers, accountants, and legal counsel where reasonably necessary;
- government authorities, regulators, courts, or other parties where disclosure is required or permitted by law or reasonably necessary to protect rights, safety, security, or the integrity of the Services;
- parties to an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to appropriate confidentiality and legal requirements; and
- other parties at the direction of the applicable Customer or with the relevant person’s authorization.
We do not publish a fixed subprocessor list in this Policy because providers may change as our infrastructure evolves. We use service providers under contracts and restrictions appropriate to the services they perform and the data they process.
9. Sale, Sharing, Targeted Advertising, and Deidentified Data
Yara Data does not intend to sell identifiable restaurant guest personal information or share identifiable restaurant guest personal information for cross-context behavioral advertising. We also do not intend to sell identifiable business-user information to third parties for their independent advertising use.
Our commercialization of Aggregated Data is intended to involve information that does not reasonably identify an individual, Customer, or specific restaurant location. If our practices change in a way that constitutes a “sale,” “sharing,” or targeted advertising under an applicable U.S. state privacy law, we will provide the notices, opt-out methods, and preference-signal handling required by that law.
Some analytics or advertising technologies can be treated as a sale, sharing, or targeted advertising under certain state laws depending on configuration. Yara Data currently intends to use essential and analytics technologies for operation, security, and product measurement. If we deploy advertising or retargeting technologies that trigger a legal opt-out right, we will update our notices and provide the required controls.
10. Cookies and Similar Technologies
We may use cookies, local storage, pixels, SDKs, tags, and similar technologies to keep users signed in, maintain security, remember settings, understand website and product usage, measure performance, diagnose problems, and improve the Services. We may use strictly necessary cookies and analytics technologies. Where consent or an opt-out mechanism is required for a particular technology, we will provide the applicable control.
Browser settings may allow you to block or delete cookies, although some features may not work correctly without necessary cookies. Browser “Do Not Track” signals are not standardized. Where applicable law requires recognition of an opt-out preference signal such as Global Privacy Control (“GPC”), we will honor that signal as required for the browser or device sending it.
11. Yara Data Marketing Communications
We may send business contacts product, educational, event, service, or marketing communications about Yara Data where permitted by law. You can opt out of marketing emails using the unsubscribe method in the message or by contacting support@yaradata.com. We may continue to send transactional or relationship messages such as security, account, billing, legal, or service notices.
12. Restaurant Customer Campaigns
A restaurant Customer may use Yara Data to identify customer segments, recommend offers, or facilitate email/SMS campaigns through third-party marketing or messaging providers. Campaigns are initiated or approved by an authorized store user or Brand Admin unless a separate written agreement provides otherwise. The restaurant Customer is responsible for the lawfulness of its campaign, including required customer consent, sender identification, suppression lists, opt-out handling, disclosures, quiet hours, frequency, and other legal or provider requirements.
Restaurant consumers should generally direct campaign opt-out or privacy requests to the restaurant or brand that sent the communication. Yara Data may assist the Customer with suppression, access, deletion, correction, or other requests as required by contract and applicable law.
13. Data Retention
We retain personal information only for as long as reasonably necessary and proportionate to the purposes described in this Policy, taking into account the relationship, type and sensitivity of information, security needs, legal obligations, tax/accounting requirements, dispute risk, and contractual commitments.
For identifiable/raw Customer Data following termination, Yara Data generally provides a 30-day period during which the Customer may request an export of reasonably available data. After that period, we may delete or deidentify the data from active systems within a reasonable period. Backup copies may remain for up to 90 days through ordinary backup rotation, and limited information may be retained longer when reasonably necessary for legal, billing, fraud prevention, security, audit, dispute, or evidence-preservation purposes. Aggregated or deidentified data may be retained indefinitely where permitted by law and contract.
14. Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, destruction, or disclosure, taking into account the nature of the Services and information. No method of transmission, processing, or storage is completely secure, and we cannot guarantee absolute security.
Authorized Users are responsible for protecting account credentials, restricting access to devices and browsers, using available security controls, and promptly reporting suspected account compromise or security incidents to support@yaradata.com.
15. Your U.S. Privacy Rights
Depending on the state in which you reside, whether the applicable law covers Yara Data, the context in which we process your information, and statutory exceptions, you may have rights to:
- confirm whether we process personal information about you and access or obtain a copy of that information;
- correct inaccurate personal information;
- request deletion of personal information;
- obtain a portable copy of certain personal information;
- opt out of sale, sharing, targeted advertising, or certain profiling where those rights apply;
- limit certain uses or disclosures of sensitive personal information where applicable;
- appeal a denial of a privacy request where applicable; and
- exercise applicable privacy rights without unlawful discrimination.
To submit a request concerning personal information for which Yara Data is the responsible business or controller, email privacy@yaradata.com. We may request information necessary to verify your identity, residency, account, and authority. Authorized agents may submit requests where permitted by law, subject to verification requirements. If applicable law requires Yara Data to offer an additional request method, appeal mechanism, or website control, we will make that method available through https://yaradata.com or the Services.
If your request concerns restaurant order history, loyalty data, a restaurant marketing list, or other personal information controlled by a restaurant Customer, please contact that restaurant or brand directly. We will assist our Customer as required by the applicable agreement and law.
16. California Privacy Notice
If the California Consumer Privacy Act, as amended (“CCPA”), applies to Yara Data’s handling of your personal information, California residents may have the right to know/access categories and specific pieces of personal information; request correction or deletion; receive information about categories of sources, purposes, and disclosures; opt out of sale or sharing; limit certain uses or disclosures of sensitive personal information; and be free from unlawful discrimination for exercising CCPA rights, subject to statutory exceptions.
The categories of personal information we may collect for our own purposes include identifiers, commercial information, internet or electronic network activity, approximate geolocation derived from IP, professional or employment-related information, and inferences derived from those categories. The sources, purposes, categories of recipients, and retention criteria are described throughout this Policy and in Section 2.
Yara Data does not knowingly sell restaurant guest personal information supplied by Customers or knowingly use such guest information for cross-context behavioral advertising. If our own website practices constitute a sale or sharing under the CCPA, we will provide a legally compliant “Do Not Sell or Share My Personal Information” mechanism or equivalent control and honor GPC as required. If we use sensitive personal information for a purpose that triggers a right to limit, we will provide the required mechanism.
The CCPA requires a covered business to provide notice at or before collection. Section 2 of this Policy is intended to provide the core information needed for Yara Data’s online Notice at Collection, and we may provide shorter just-in-time disclosures or direct links to that section at account creation, forms, cookie interfaces, or other collection points where required.
Where Yara Data acts as a service provider, contractor, or processor for a restaurant Customer, the Customer’s instructions and the applicable DPA or other written agreement govern that processing. Restaurant consumers should ordinarily exercise CCPA rights through the restaurant or brand that controls the data.
17. Financial Incentives and Restaurant Promotions
Yara Data does not currently offer its own consumer loyalty program or financial incentive in exchange for a consumer’s personal information. Restaurant Customers may use Yara Data to analyze or administer their own promotions, discounts, loyalty programs, or offers. Those programs are offered by the restaurant Customer, not by Yara Data, and the restaurant is responsible for any privacy notice, financial-incentive notice, loyalty-program terms, or consent required for its program.
18. Children
Yara Data is a business-to-business service for authorized users age 18 or older and is not directed to children. We do not knowingly allow children to create Yara Data business accounts. Restaurant Customers are responsible for determining whether information they provide to Yara Data relates to minors and for complying with laws applicable to their own collection and use of that information. If you believe a child has provided personal information directly to Yara Data inappropriately, contact privacy@yaradata.com.
19. U.S.-Focused Services and Data Processing Locations
Yara Data currently offers the Services to U.S.-based business customers. Information may be processed or stored in the United States and in other locations where our service providers operate. Customers with specific data-residency or international-transfer requirements must address those requirements with Yara Data in an applicable Order Form or DPA before providing data subject to those requirements.
20. Business Transfers
Personal information may be disclosed, transferred, or made available as part of an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, receivership, sale of assets, due diligence process, or similar corporate transaction, subject to applicable confidentiality and legal requirements. Where required by law, we will provide notice before personal information becomes subject to materially different privacy practices.
21. Changes to This Privacy Policy
We may update this Privacy Policy as our Services, technology, legal obligations, or business practices change. We will post the updated version at https://yaradata.com and revise the “Last Updated” date. If required by law, we will provide additional notice or obtain consent before materially different processing takes effect.
22. Contact Us
Yara Data, Inc. Website: https://yaradata.com Privacy requests and questions: privacy@yaradata.com General support and security reports: support@yaradata.com