GrabEasy (“we,” “us,” “our”) is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have when you use our online ordering platform, website, and mobile applications (collectively, the “Service”).
We collect information in three contexts:
Restaurant account information: when you sign up, we collect business name, contact person, email, phone number, physical address, and payment details (handled securely by our payment processor).
Menu & content: menus, images, logos, and other materials you upload.
Customer communications: if you contact support, we keep a record of the communication.
Usage data: IP address, browser type, pages visited, time spent, and referring URLs.
Device information: device type, operating system, unique device identifiers.
Cookies & similar technologies: we use essential cookies for authentication, security, and preference storage. Analytics cookies help us understand usage patterns (you can control cookie settings in your browser).
When a customer places an order through your GrabEasy‑powered ordering page, we collect:
This data is processed on your behalf as a data processor; you act as the data controller for your customer’s personal data.
We use the collected information to:
We do not use your end‑customer data for our own marketing or sell it to third parties.
We share information only in the following circumstances:
We retain personal data only as long as necessary to fulfill the purposes outlined in this Policy, or as required by law. Restaurant account data is kept for the life of the account and up to 90 days after termination to allow export. End‑customer order data is retained per the restaurant’s instructions and legal requirements; typically we keep it for 6 years for tax/audit purposes unless the restaurant requests earlier deletion.
We implement industry‑standard security measures, including encryption in transit (TLS) and at rest, firewalls, and access controls. Payment information is tokenized and handled by PCI‑compliant partners. However, no method of transmission or storage is 100 % secure; we cannot guarantee absolute security.
Restaurant account holders: you can access, update, or delete your account information at any time through your dashboard. You may export your data or request complete deletion by contacting us.
End‑customers: if you are a customer of a restaurant using GrabEasy, your data is controlled by that restaurant. To exercise rights like access, correction, or deletion, contact the restaurant directly. If the restaurant cannot assist, we will help facilitate the request as data processor.
Marketing communications: you can opt out of promotional emails via the unsubscribe link. Service‑related messages are still necessary.
Cookies: most browsers allow you to refuse or delete cookies. Disabling essential cookies may affect the functionality of the Service.
The Service is not directed to individuals under 13. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such data, we will delete it.
GrabEasy is based in the United States. If you are located outside the U.S., your data may be transferred to, stored, and processed in the U.S. By using the Service, you consent to such transfers. We take steps to ensure adequate protection, such as standard contractual clauses where applicable.
We may update this Policy periodically. Material changes will be announced via email or prominent notice on our website. The updated date at the top indicates the latest revision.
For any questions, concerns, or data subject requests, please contact: