DRAFT — NOT YET IN FORCE — NOT LEGAL ADVICE
This policy has been drafted to match what the Flavor on 51 software actually does — every claim in it was read out of the source code — but it has not been reviewed or adopted by the business or its attorney. It is not legal advice and does not bind anyone. Bracketed items below are unresolved and are shown on purpose.
OPEN — NEEDS THE OWNER AND COUNSEL
- The registered legal entity name, the contact email, the phone number, and the effective date — every one of them is a visible placeholder on this page right now.
- ★ Account deletion now EXISTS and section 17 has been rewritten to describe it (14 August 2026). Two things about it are still open. (a) HOW LONG the retained order and sales-tax records are kept — section 12's periods are still bracketed, and section 17 points at them rather than inventing a number. (b) SIGN IN WITH APPLE TOKEN REVOCATION: Apple Guideline 5.1.1(v) requires an app offering Sign in with Apple to revoke the user's Apple token on deletion. We delete the user at our sign-in provider; whether that provider also performs Apple's revocation has NOT been confirmed in writing, and the Apple credentials needed to do it ourselves are not provisioned. That is an engineering and vendor question before the iOS build is submitted, not a drafting one.
- The retention periods in section 12 — how many years order, refund and sales-tax records are kept — need the owner's accountant and Texas record-keeping rules, not a guess.
- ★ Whether F51 is a “small business as defined by the United States Small Business Administration”, because the whole shape of the Texas Data Privacy and Security Act turns on it. Unusually, that Act has NO revenue or record-count threshold — §541.002(a)(3) applies it only to a business that is NOT SBA-small, and for one that is, the single remaining duty is §541.107: do not sell sensitive personal data without prior consent. The test is the business's five-year average receipts against the SBA standard for its NAICS code, which no one can read out of the software. Section 13 grants the rights either way and deliberately does not assert the answer.
- ★ Texas Business & Commerce Code Chapter 121 (SB 2420, the App Store Accountability Act) applies to app DEVELOPERS with no small-business exemption, and it is enforceable now — the Fifth Circuit stayed the injunction against it and the Supreme Court declined to disturb that in July 2026. It requires an age rating for the app and for each in-app purchase, use of the app store's age-category signal, parental consent for a minor, and deletion of app-store-supplied data once verification is done. None of that is built. This is an engineering obligation before the mobile app ships, and counsel should scope it.
- Confirmation that no other state's privacy law is triggered by actual revenue and customer counts (section 14 currently asserts that none is).
- Whether marketing email and SMS will actually be sent, and by which provider — nothing is connected today. SMS consent is materially stricter than email: it must be prior express WRITTEN consent, must never be a condition of purchase, must be revocable by any reasonable means, and the record of it must be provable before the first send.
- ★ Texas SB 140 (effective 1 September 2025) pulled text messages expressly into Business & Commerce Code Chapter 302, and new §305.054 makes a violation of that chapter a deceptive act under the DTPA — where attorney's fees for a prevailing consumer are mandatory. A careless marketing text is therefore a materially bigger exposure in Texas than the federal rules alone suggest. Counsel should sign off on the exact consent wording and the opt-out handling before a single marketing text is sent. (Chapter 302's registration requirement looks inapplicable — §302.057 exempts a person soliciting the sale of food — but that is worth confirming too.)
- Whether the map coordinate we derive from a typed delivery address is “precise geolocation data”, and therefore sensitive data, under §541.001(21). The definition turns on information “derived from technology”, and it is genuinely arguable both ways for a geocoded address as opposed to a device GPS reading; no Texas guidance or case law resolves it. Section 7 deliberately describes how we handle the coordinate instead of asserting its legal category.
- Whether alcohol is or will be sold, which brings real age verification and TABC obligations into scope. The age-verification field in the account record is currently dead — nothing sets it.
- Whether a Data Protection Assessment is required for any processing here, and who signs it.
- The public URL this policy will live at, which is also the URL both app stores require — the production domain is not decided.
- Where a superseded version of this policy will be archived.
Privacy Policy
Effective [PRIVACY EFFECTIVE DATE]
This Privacy Policy explains what personal information Flavor on 51 collects when you use our website, mobile app and ordering services (together, the "Services"), why we collect it, who we share it with, and what you can ask us to do about it. The Services are operated by [LEGAL ENTITY NAME] ("Flavor on 51", "we", "us"). Our operating base is Home Depot · 220 W Interstate 20, Weatherford TX 76086.
We are a restaurant and food truck in Weatherford, Texas. We collect what we need to take your order, cook it, get it to you, support it afterwards, and run a loyalty programme. We do not collect information to build a profile of you, and we do not make money from your data.
This policy covers the Services only. It does not cover a site or app we link to, which has its own policy.
1. The short version
The rest of this document is the precise version. This is the honest summary of it.
- We collect your name, email, phone number, delivery address, order history and loyalty balance.
- We do not run advertising, and we do not sell or share your personal information with anyone for their own purposes.
- There is no analytics or tracking software in our app or website, and no crash-reporting software.
- Our app never asks for your location and cannot read it.
- Your card number never reaches us. It goes straight to our payment processor, and we keep only a reference to the transaction.
- You can ask us what we hold, correct it, get a copy, or have it deleted.
- ★ You can delete your account yourself, in the app or from this website. We keep the record of orders you actually placed because Texas sales-tax law requires it, and we anonymise it — section 17 is precise about what goes and what stays.
2. Where your information comes from
Almost everything we hold, you gave us. You type it into your account, your address book, or an order.
A small amount comes from elsewhere: if you sign in with Apple or Google, that provider tells our sign-in provider your name and email address. If you save a delivery address, we look the address up to get its map coordinates, so we can work out which delivery zone it falls in and what the delivery fee is (section 7).
We do not buy personal information about you from anyone, and we do not collect it from data brokers, social networks or advertising networks.
3. What we collect, why, and who else sees it
Texas law asks a business to state the categories of personal data it processes, what it processes them for, the categories it shares, and the categories of third party that receive them. This table is that statement, and it is also the source the app-store privacy declarations are filled in from.
"Service providers" below means companies that process information on our instructions to run the Services for us — not companies that get your information to use for themselves. They are named in section 5.
| What | Examples | Why we have it | Who else sees it |
|---|---|---|---|
| Account details | Name, email address, phone number, and the account identifier from your sign-in. | To create and secure your account, to identify your order, and to contact you about it. | Our sign-in provider; our hosting providers. |
| Sign-in credentials | Your password or your Apple / Google sign-in. | To let you sign in. | Our sign-in provider only. We never see or hold your password. |
| Delivery addresses | Street, city, state, ZIP, delivery instructions, and the map coordinates of the building. | To decide whether we can deliver to you, to price the delivery, and to get a driver to your door. | Our geocoding provider (street, city, state and ZIP only); our own drivers; our hosting providers. |
| Order details | Items, options, prices, tax, tip, delivery fee, pickup or delivery choice, order notes, curbside spot, and the times your order changed status. | To take, cook, fulfil and support your order, to handle refunds, and to keep the sales-tax records Texas requires. | Our hosting providers. |
| Payment reference | A transaction reference from our payment processor, and the outcome of the payment. | To take payment, to match a payment to your order, and to issue a refund. | Our payment processor. |
| Loyalty and referrals | Points balance, tier, lifetime spend, points earned and spent, rewards redeemed, and referral codes. | To run the loyalty programme and honour referrals. | Our hosting providers. |
| Contact preferences | Whether you agreed to marketing email, and whether you agreed to marketing texts. | To respect your choice, and to prove we had it. | Our hosting providers. |
| App settings | Whether you turned on unlocking the app with Face ID, Touch ID or a fingerprint. This is a yes/no setting and nothing more. | So the app remembers your choice on your other devices. | Our hosting providers. |
| Support messages | Anything you write to us in a support request, and the order it relates to. | To answer you. | Our hosting providers. |
4. What we do not collect
These are worth stating plainly, because a customer has no way to check them and most food apps do the opposite. Each one is a fact about how the Services are built, not a promise about how we behave.
- No advertising. There is no ad network, no advertising identifier, and no ad targeting of any kind.
- No analytics or tracking software. There is no analytics SDK and no crash-reporting SDK in our app or on our website.
- No location. Our app never asks for permission to read your location and has no ability to read it. The only location information we hold is a delivery address you typed in yourself.
- No card numbers, security codes or card magnetic-stripe data — anywhere, ever. See section 6.
- No access to your contacts, photos, camera, microphone, calendar or files.
- No biometric data. Face ID, Touch ID and fingerprint unlock are checked by your phone, on your phone. We are only told yes or no, and we store only whether you switched the feature on.
- No dietary or allergy information. Any dietary filter you set in the app stays on your device and is never sent to us.
- No push notification tokens — the app does not send push notifications yet.
- We do not log your IP address or your browser's user-agent string in our own systems.
5. The companies that help us run this
We use a small number of service providers. Each one gets only what it needs to do its job, and each processes it on our instructions. None of them receives your information to sell, to advertise to you, or to use for their own purposes.
- Sign-in and account security — receives your name, email address, phone number and, if you use them, your Apple or Google sign-in. Our provider is Supabase, which is also the company that hosts our database (see the hosting entry below).
- Payment processing — receives your card details directly from your browser or phone, and returns a reference to us. Our provider is Accept Blue.
- Address lookup (geocoding) — receives a delivery address's street line, city, state and ZIP code in order to return map coordinates. Our provider is the Nominatim service operated by the OpenStreetMap Foundation. It does not receive your name, your apartment or suite number, your phone number or your order.
- Database and application hosting — stores and serves everything described in section 3. Our database is hosted by Supabase; our website is served by Cloudflare.
- Delivery — done by our own drivers, employed or engaged by us. We are not a delivery marketplace and we do not hand your order or your address to a third-party courier company.
- Menu catalogue — we read our menu out of Square. This is a one-way, read-only sync of menu items into our systems. No customer information is ever sent to Square.
| Purpose | What it receives | What it does NOT receive |
|---|---|---|
| Sign-in | Name, email, phone, Apple/Google identity. | Your orders, your addresses, your loyalty balance. |
| Payments | Your card details, entered directly into the processor's own form. | Anything we did not have to send to charge you. |
| Address lookup | Street line, city, state, ZIP. | Your name, apartment or suite number, phone, delivery instructions or order. |
| Hosting | Everything in section 3, stored on our behalf. | Nothing is shared with them for their own use. |
| Menu catalogue | Nothing about you. The sync only reads menu data into our systems. | All customer information. |
6. Payment information
When you pay by card, the card form is served by our payment processor, and your card number, expiry date and security code go directly to them. They never pass through our systems and we could not store them if we wanted to — there is nowhere in our software that holds a card number.
What we receive back is a reference: an identifier for the transaction, whether it was approved, and the last few digits and brand of the card so you can tell one payment from another. We use that reference to match a payment to your order and to issue a refund.
Cash paid at the counter or on delivery is recorded as an amount against your order. Nothing else about it is stored.
7. Delivery addresses and address lookup
When you save a delivery address, we send its street line, city, state and ZIP code to an address-lookup service — Nominatim, operated by the OpenStreetMap Foundation — which returns the coordinates of the building. We need those coordinates because our delivery zones are measured as distances from where your order is cooked; without them we cannot tell you whether we deliver to you or what it costs.
Your apartment or suite number is deliberately not sent. Neither is your name, your phone number, your delivery instructions or anything about your order.
The lookup happens when you add an address or change its lines — not as you type, and not repeatedly. The result is stored on your address so the same lookup is never sent twice.
If the service cannot find your address precisely enough, we tell you so rather than guessing at a coordinate. A guess would put the wrong delivery fee on your order and send a driver to the wrong place.
★ We handle that stored coordinate as one of the most sensitive things we hold, because it points at a building rather than a neighbourhood. We do not sell it, we do not use it for advertising, and nobody outside the service providers in section 5 receives it. We never read your location from your device — the only reason we have a coordinate at all is the address you typed in yourself.
8. Email and text messages
There are two different kinds of message and they work differently, because the law treats them differently.
Messages about your order — a confirmation, a receipt, "your order is ready", a problem with a delivery — are part of the service you asked for. You get these because you placed an order. If you do not want them, the way to stop them is to stop ordering, or to close your account.
Marketing messages — offers, promotions, news — are separate, and they are off unless you switch them on. Marketing email and marketing text messages have their own separate switches in your profile, because agreeing to one is not agreeing to the other. Agreeing to marketing texts is never a condition of buying anything from us, and we will not make it one.
You can withdraw either agreement at any time, and you may do it in any reasonable way — turn the switch off in your profile, reply STOP to a text, use the unsubscribe link in an email, or just tell us at [EMAIL]. You do not have to use a particular word or a particular channel. We will act on it within ten business days at the outside, and normally straight away, and we will apply it to every marketing message rather than to the one you replied to. Withdrawing marketing consent does not stop messages about an order you have placed.
[⚠ FACT ABOUT TODAY, NOT A PROMISE: we currently record your marketing and text-message preferences, but no marketing email or text message is sent by these Services at all — there is no email or SMS provider connected. When one is connected, this section and the app-store declarations must be re-checked before the first message goes out.]
9. Loyalty and referrals
If you join the loyalty programme we keep your points balance, your tier, how much you have spent with us over time, and a record of each time points were added or removed. Points are earned on the food and drink subtotal of a completed order, and are removed proportionally if that order is refunded.
If you refer someone, we keep the referral code and, once it is used, the fact that it was used and by whom. That is how a referral reward can be honoured.
We do not use your loyalty history to build an advertising profile, and we do not share it with anyone outside the service providers in section 5.
11. Selling, sharing and targeted advertising
We do not sell your personal information. Under Texas law "sale" is broader than money changing hands — it covers sharing personal data with a third party for monetary or other valuable consideration — and we do not do it in either sense.
We do not share your personal information for targeted or cross-context behavioural advertising, because we do not advertise to you at all.
We do not use your information for profiling that produces legal or similarly significant effects about you.
We do not sell sensitive personal data, and we do not sell biometric personal data. Texas law requires a business that sells either one to post a specific warning in the same place and the same manner as this policy. We sell neither, so no such warning appears on this page — if you are ever shown one here, it will be because that answer changed.
That last point is the one obligation that binds a business our size regardless of how the size question in section 13 is answered: a small business may not sell sensitive personal data without asking you first. We do not sell it at all.
12. How long we keep it
We keep your account and its contents for as long as your account is open.
Order records, refunds and the tax records built from them are kept for as long as Texas tax and business-records law requires us to be able to produce them, even after an account closes. A sale we cannot evidence is an audit finding.
A delivery address you remove is hidden from your address book and cannot be used on a new order, but the address itself is kept where a past order was delivered to it — otherwise we could not answer where an order actually went.
[RETENTION PERIODS — TO BE SET WITH COUNSEL AND THE OWNER'S ACCOUNTANT. Texas sales-tax record-keeping and the business's own accounting practice determine the actual number of years. It is deliberately not guessed here.]
13. Your privacy rights
We give every customer the rights below, wherever you live. We have written them to the standard the Texas Data Privacy and Security Act sets, including its deadlines and its appeal process.
We are being deliberate about one thing here rather than glossing it. Whether that Act legally obliges a business of our size is a question about the business, not about the software: it applies only to a company that is NOT a small business under the federal Small Business Administration standard, and that test turns on our actual receipts. Our attorney is confirming where we fall. We are publishing these rights either way, because "we were too small to have to" is not an answer we want to give a customer.
To exercise any of them, contact us at [EMAIL] or [PHONE], or write to us at Home Depot · 220 W Interstate 20, Weatherford TX 76086. Tell us which right you are exercising. We may need to check the account is yours before we act — usually by asking you to make the request from the email address on it. We will never require you to create a new account in order to make a request.
We aim to respond within 45 days. If we need longer we will tell you inside that window, say why, and take no more than a further 45 days. A reasonable request is free.
- Confirm whether we are processing your personal data, and get access to it.
- Correct anything inaccurate.
- Delete personal data we hold about you — see section 17 for what is honestly possible today.
- Get a copy of the data you provided to us, in a portable form.
- Opt out of the sale of your personal data, of targeted advertising, and of profiling that produces legal or similarly significant effects. We do none of those three things, so there is nothing running to opt out of — but you may still ask, and we will confirm it in writing.
- ★ Appeal a refusal. If we turn a request down we will tell you why, and you may appeal by replying to that refusal or writing to the same address. We will decide an appeal in writing, with reasons, within 60 days — and if we still say no, we will give you the Texas Attorney General's complaint details in the same message.
14. If you live outside Texas
We are a restaurant and food truck serving a local area in Parker County, Texas. The California Consumer Privacy Act reaches a business only if it does business in California AND meets one of three thresholds — a revenue figure in the tens of millions, buying, selling or sharing the personal information of 100,000 or more consumers or households a year, or earning at least half its revenue from selling or sharing personal information. We meet none of them, and we do not do business in California. We therefore do not claim to be subject to that Act and do not offer rights under it by name.
That is a statement about which law applies, not about how we behave. The rights in section 13 are offered to every customer regardless of where you live, and the "do not sell" answer is the same everywhere: we do not.
[CONFIRM WITH COUNSEL BEFORE ADOPTION. Applicability turns on the business's actual revenue and customer numbers, which we cannot verify from the software. If F51 ever exceeds a state threshold, this section and section 13 must be rewritten, not amended.]
15. Children
The Services are for a general audience and are not directed to children. We do not knowingly collect personal information from a child under 13.
We do not ask anyone their age or date of birth, so in the ordinary course we never learn it.
You need an account to order, and you must be old enough to form a binding contract in Texas to hold one.
If we do learn that an account belongs to a child under 13, we will either obtain a parent's verifiable consent or delete the information — there is no third option and we will not simply carry on. If you believe a child under 13 has given us personal information, contact us at [EMAIL] and we will act on it.
[⚠ HONEST LIMITATION: we do not verify anyone's age. The account record has an age-verification field, but no part of the software sets or checks it, so no age check happens. If alcohol is ever sold, or if the owner wants a real age gate, that is a feature to build — not a sentence to add here.]
16. How we protect it
This section describes what is actually done. It deliberately makes no compliance claim, names no certification, and reaches for no reassuring adjective about the strength of our encryption — no business can promise that information is perfectly secure, and a claim we cannot evidence is worse than none.
We are not able to leak your card number, because we never hold it.
- Traffic between your device and our systems travels over HTTPS.
- Card details are entered directly into our payment processor's own form and never reach our systems.
- Passwords are handled entirely by our sign-in provider. We never see or store one.
- Every request for your data is scoped to your own account by the server, not by the app — asking for someone else's order returns nothing.
- Staff tablets in the restaurant and kitchen sign in with their own per-device key, so one device can be switched off on its own. The key itself is stored only as a one-way hash, so our database does not contain a working key to anything.
- Address lookups are logged without the address in them, because logs travel further than records do.
- Access to customer data is limited to the people who need it to run the restaurant.
17. Closing your account and deleting your data
★ THIS SECTION STATES WHAT IS TRUE TODAY RATHER THAN WHAT IS INTENDED, because a deletion promise a business cannot keep is the most damaging sentence a privacy policy can contain. It was rewritten on 14 August 2026, when self-service deletion was built. Before that date it said, correctly, that you could not do this yourself.
You can delete your account yourself, in the app: Profile → Security & privacy → Delete account. You are shown what will be removed and what will be kept, and you have to type the word DELETE to confirm, because it cannot be undone.
You do not need the app to do it. /account-deletion on this website explains how to request deletion, and you can also contact us at [EMAIL] from the email address on your account, or at [PHONE]. We will confirm when it is done.
WHAT WE DELETE: your name, your email address, your phone number, your sign-in, your saved delivery addresses and their delivery instructions, your saved card references, your notifications, your dietary and accessibility preferences, your loyalty balance, anything still in your basket, and any support messages you sent us. Your sign-in is removed at our sign-in provider as well as here, so you cannot log back in to the account.
WHAT WE KEEP, AND WHY: the record of the orders you actually placed, the items and amounts on them, any refunds, and the sales-tax records built from them. Those are receipts for real sales, Texas requires us to keep them, and the daily sales-tax figures we file are fixed once filed — a deletion that removed a past order would change a number already given to the state. We keep them for as long as the law requires (see section 12, where the exact periods are still to be confirmed).
THOSE RECORDS ARE ANONYMISED, NOT LEFT UNDER YOUR NAME. Your account row survives with no name, no email address, no phone number and no sign-in on it, and the orders stay attached to that anonymous row so they still add up. A delivery address kept because a past order was sent to it has its street line, its delivery instructions and its map coordinates removed; only the town, state and ZIP remain, because that is the tax jurisdiction the sale went to and not your front door.
Deleting your account is not the only right you have. Section 13 covers asking us what we hold and getting a copy of it, which does not require deleting anything.
18. Changes to this policy
We may update this policy. The current version always governs and its effective date is shown at the top of this page. If a change materially affects how we handle information we already hold about you, we will make reasonable efforts to tell you before it takes effect.
[WHERE A SUPERSEDED VERSION IS ARCHIVED — TO BE DECIDED. A policy that changes with no readable history is one a customer cannot hold anyone to.]
19. Contact us
Questions about this policy, or a request under section 13, go to:
[LEGAL ENTITY NAME], trading as Flavor on 51
Home Depot · 220 W Interstate 20, Weatherford TX 76086
[EMAIL] · [PHONE]
If you are a Texas resident and you are not satisfied with how we handled your request, you may complain to the Office of the Texas Attorney General.
END OF DOCUMENT
Last updated: [PRIVACY EFFECTIVE DATE]
© [LEGAL ENTITY NAME]
Terms of service: /terms-of-service · Support: [EMAIL]
