1. Scope and roles
This policy covers OrderTakrPH’s website, business accounts, restaurant ordering pages, Counter, kitchen displays, delivery and reservation workflows, and connected Facebook Messenger services. Features depend on the business’s settings and available integrations.
The restaurant or business generally determines how customer information is used for its orders, reservations, delivery, payment review, rewards, and customer service. OrderTakrPH processes that information to provide the business’s software. The platform operator is responsible for its own account administration, security, support, and service-operation records.
Each business account has its own customer and operational records. Authorized access within that account depends on the person’s role and assigned stores. This policy does not replace the privacy practices of an independent restaurant, Google, Meta, a map service, or a payment provider.
2. Information we collect
- Business and staff information: owner and staff names, email addresses, contact details, sign-in identifiers, memberships, permissions, store details, operating settings, menus, logos, photographs, and uploaded menu files.
- Customer and fulfillment information: names, phone numbers, delivery addresses, map locations when supplied, delivery instructions, reservation guest names and contact details, dates, times, party sizes, and order notes. Staff may enter details for walk-in or telephone customers.
- Transaction information: order items and choices, quantities, prices, discounts, tax breakdowns, payment methods, amounts and references, uploaded payment proof, payment-review decisions, cancellations, refunds, and status history.
- Benefits information: account-linked rewards, promo usage, point earnings and redemptions. Where a store offers Senior/PWD discounts, authorized staff can record beneficiary and proof-reference information, the eligible portion, and verification evidence used for the calculation. Proof references are excluded from ordinary receipts and kitchen tickets.
- Connected-service information: selected Facebook Page details, authorization credentials, Page-scoped Messenger identifiers, messages or postbacks, direct webapp order conversations, timestamps, and conversation state used for ordering assistance.
- Technical and operational information: sessions, browser/device information, IP addresses and request/security logs, named kitchen-device access requests and approvals, print settings and outcomes, audit events, and service-usage records.
We do not ask for Google or Facebook passwords, e-wallet PINs, online-banking passwords, or payment one-time passwords. Avoid including unnecessary sensitive information in order notes, conversations, menu uploads, or payment screenshots.
You can save more than one delivery address, including a recipient name and phone number, map pin, address text, house or building details, landmark, and Home, Work or Other label. Place search and map pin lookup use the configured map provider; address text remains editable. Saved addresses belong to your verified customer access within the business account.
3. Purposes and processing
Information is used to provide the service you request: authenticate business members; publish menus; create and fulfill orders; manage kitchen preparation, table service and reservations; assign delivery work; review manual payments; maintain customer records, rewards and reports; and answer customer requests.
We also use limited operational records to secure accounts, prevent duplicate transactions and abuse, investigate failures, provide authorized support, and keep an audit trail. Processing may be necessary for a requested transaction or service, applicable legal duties, or legitimate security and operational purposes. Optional permissions, such as sharing your device’s location, can be declined; supply the required delivery information manually instead.
When AI menu import is enabled, uploaded menu pages are sent to the configured AI provider to extract menu information. The merchant reviews the result before saving or publishing. This feature does not approve payments or make fulfillment decisions. The current structured Messenger ordering flow does not send customer conversations to the menu-import AI provider.
OrderTakrPH does not sell customer records or use order and Messenger information for third-party targeted advertising.
5. Google sign-in
When you choose Google sign-in, OrderTakrPH verifies Google’s ID token and uses your Google account identifier, verified email address, and name to create or access a merchant identity. Business membership and permissions are checked separately.
Customers can also choose Google sign-in before checkout to access their saved addresses and orders for the selected store. The same Google account has separate customer profiles at different stores, including stores belonging to the same business. Customer Google identities are separate from merchant logins and never grant business-management access. Browser history is linked only after verifying both the Google identity and possession of the browser's existing access proof.
We do not request access to your Google contacts, Gmail, Drive, calendar, or unrelated Google activity. Customers may also use guest checkout where the store allows it, or a verified Messenger entry. Stores that disable guest checkout require Google sign-in or a verified Messenger identity before reviewing and placing an order. Signing out of OrderTakrPH does not sign you out of Google.
6. Facebook Pages and Messenger
A business owner can authorize OrderTakrPH to connect a Page and select the stores available through it. The requested permissions are:
- pages_show_list: list managed Pages so the owner can choose one.
- pages_messaging: receive and respond to the connected Page’s ordering conversations and send eligible order updates.
- pages_manage_metadata: subscribe the Page to the ordering webhook and configure Messenger entry actions.
Page access tokens are encrypted in server-side storage. Connection records include Page identifiers, selected-store mappings, health checks, authorization times, and a one-way hash of the authorizing app-scoped Facebook user identifier. Temporary OAuth credentials support the Page-selection step; they are not public business or customer data.
When a customer messages a connected Page, Meta supplies the Page identifier, a Page-scoped Messenger identifier, message/postback details, and timestamps. OrderTakrPH uses these to maintain the ordering conversation, provide menu or help links, avoid duplicate processing, support staff replies, and send updates allowed by Meta’s rules. We do not request a customer’s Facebook password, friends list, or unrelated posts.
Personal ordering links establish verified customer access and expire after five minutes or use. Do not forward them. A public store link permits guest ordering without proving ownership of another customer’s history.
Disconnecting a Page or processing a valid Facebook removal callback revokes the matching stored authorization credentials. It does not automatically erase all conversations, customer records, or orders. See the data deletion instructions for the separate customer-record process.
7. Cookies, customer access, and kitchen devices
Essential session cookies and browser storage keep sign-in, carts, checkout recovery, private order access, and device settings working. Guest history belongs to the business and the browser that created it, or to a verified Messenger identity. An encrypted, HttpOnly browser-access cookie preserves guest access for up to 90 days after creation or renewal, independently of the shorter application session. A matching name or phone number alone does not grant access to private customer history. Clearing browser data can remove access to guest orders.
Merchant Google sign-in remembers the device for up to one year using Laravel's encrypted remember-me cookie. Customer Google sign-in uses a separate encrypted, HttpOnly cookie for each store, lasting up to 90 days. Sign-out removes the matching remembered access; disabling a merchant or revoking membership still blocks business access.
A dedicated kitchen browser can request access using a device name. A manager approves its view, status-update, and printing permissions and can revoke access. Pending requests expire after fifteen minutes; approved grants currently last thirty days unless revoked sooner. The device stores access and printer settings locally. Printed tickets and screenshots create copies outside the platform, which the business must protect and dispose of appropriately.
8. Retention and security
Records are retained according to their purpose, the business’s transaction and accounting obligations, dispute and security needs, and applicable law. The current service does not automatically erase every order, payment, conversation, or audit record after a fixed number of days. Disconnecting an integration, signing out, or submitting a profile-removal request is not a full-record deletion action.
Reviewed customer profile removal clears stored customer names, phone numbers and saved delivery addresses. You can also edit or remove an individual saved address in checkout. Original order snapshots may still contain contact/address information; order conversations, payment, refund, points, ownership and audit evidence remain for authorized review. Requests concerning those retained records require a separate assessment with the business. Eligible information should be removed or de-identified when its legitimate retention purpose ends; backup copies and independently held provider or printed records also need to be considered.
Safeguards include account/store access controls, private payment-proof access, encrypted integration credentials, verified identity checks, and audit records. Businesses must also protect staff accounts, shared devices, exported reports, and printed tickets. No internet service can guarantee absolute security.
9. Your privacy rights
Subject to applicable Philippine law and verification, you may request information about processing, access or correction, object to applicable processing, or request erasure or blocking. You may also raise a complaint with the National Privacy Commission. Some information may need to be retained for a lawful purpose; we will distinguish eligible profile removal from retained transaction evidence.
In the ordering page, open My Orders → My rewards & privacy to download the information linked to your current verified access and submit a Request profile removal. This export does not expose another customer’s records or every internal operational record. For other access, corrections, deletion, or a lost guest session, contact the business or platform contact below. Requests require reasonable verification, not another person’s name or phone number alone.
10. Contact and policy changes
OrderTakrPH is the service name used in these pages. Platform operator: Baluartech.
For platform privacy, deletion, account, or terms questions, email hello@ordertakr.ph. Include the business or Page name, the relevant order reference if available, and a description of your request.
For a particular order, reservation, payment, delivery, or customer record, contact the business using the contact details on its ordering page or your order. The business can verify your request and coordinate any platform assistance needed.
Send only what is needed to locate the record. Do not send passwords, payment PINs, one-time passwords, or complete identity documents in an initial request.
We will update this page when relevant practices change and revise its effective date. Material changes may also be communicated through the service. Read the Terms of Service for the rules that apply to using OrderTakrPH.