The software is free to your restaurant. No monthly fee, no card to sign up.We make our money from a small service fee on the customer's bill, shown to them at checkout.How it works
← All policies

Privacy Policy

What we collect, why, who it is shared with, and how to get a copy of it or have it deleted.

Blue Obsidian · Last updated


1. What this covers

This policy covers Blue Obsidian - our marketing site, the ordering pages we host for restaurants, the order status pages, and the dashboards restaurants use. It does not cover a restaurant's own website, its social accounts, or anything it does with your details outside our service.

Blue Obsidian is a trading name of blueobsidian io LLC, 11000 W McNichols Rd, Ste 323, Detroit, MI 48221, United States, which operates blueobsidian.io. Where this policy says we decide what happens to your data, blueobsidian io LLC is the company that decides. You can reach us at hello@blueobsidian.io or (313) 246-3280.

2. Who is responsible for your data

Two different answers, depending on which data you mean.

DataWho decides what happens to itOur role
Your order, phone number, name, and messaging consent at a restaurantThat restaurantWe process it on their instructions
Your account with us, our billing records, security logs, and aggregate platform statisticsUsWe decide

If you want a restaurant to forget you, ask the restaurant - it is their list, and we will help them do it. If you want us to delete your platform account, ask us.

The customer list belongs to the restaurant. We do not sell it, rent it, share it with other restaurants on the platform, or use it to market anything of our own to you.

3. What we collect

  • Order details - items, notes, totals, pickup time, and the restaurant you ordered from.
  • Contact details - your phone number, which the restaurant uses to identify your order at the counter; your name and email address if you give them. An email address is optional and is what an order update is sent to.
  • Email preferences - whether you have unsubscribed from a restaurant's emails, and when. We keep that record because an unsubscribe has to be provable, and it is what stops the messages coming back.
  • Payment status - whether a charge succeeded, the amount, and the last four digits and brand of the card. We never receive or store your full card number; Stripe handles the card itself.
  • Account details - if you sign in with Google or Apple, the name, email address and stable identifier those providers return. We never receive your password with them.
  • Usage analytics - pages viewed on a restaurant's ordering page, how long a visit lasted, and whether it ended in an order. See section 5.
  • Support messages - anything you send us through the contact form or a support ticket.
  • Technical data - IP address, browser and device type, and timestamps, kept for security and fraud prevention.

We do not collect precise device location, and we never sell personal information. If you ordered from a restaurant, nothing about you is shared for advertising: there are no third-party trackers on any restaurant's ordering page, and there is no setting anywhere that turns them on. The one exception applies only to visitors of our own marketing site, where we advertise to restaurant owners - see section 6.

4. Why we use it

PurposeData usedBasis
Taking and fulfilling your orderOrder, contact, payment statusPerformance of a contract
Order updates by emailEmail address, orderPerformance of a contract
Giving a restaurant the customer list built from its own ordersEmail address, phone, order historyOur and the restaurant's legitimate interests. What the restaurant then does with that list is theirs, and they are responsible for it
Fraud prevention and platform securityTechnical data, order patternsOur legitimate interests
Improving the product and reporting to restaurantsUsage analytics, aggregatedOur legitimate interests
Tax, accounting and dispute recordsOrder and payment recordsLegal obligation

5. Analytics, and what we deliberately do not do

We measure how restaurant ordering pages are used so owners can see which items get looked at and where people give up. Three limits are built into how this works, not just promised here:

  1. 1.The identifier used to group a visit is random, generated in your browser, different for every restaurant, and never joined to your customer record. It tells a restaurant that one person visited four times rather than four people visited once, and nothing else. It is not a fingerprint and we do not attempt device fingerprinting.
  2. 2.Analytics events carry a fixed set of typed fields. There is no free-form field, deliberately, so a phone number or an order note cannot end up in an analytics table and from there into every backup.
  3. 3.Restaurants see their own numbers. We see platform totals and per-restaurant summaries. No restaurant can see another restaurant's data.

6. Who we share it with

  • The restaurant you ordered from - your order, name and contact details, so they can make and hand over your food.
  • Service providers who run parts of the platform for us. We will tell you the current list, and what each one receives, if you email hello@blueobsidian.io.
  • Law enforcement or regulators, where we are legally required to, and only to the extent required.
  • A buyer, if the business is sold or merged - with notice to you beforehand, and with this policy continuing to apply until it is replaced.

That is the whole list for anyone who ordered from a restaurant. We do not share your data with advertisers, data brokers, or other restaurants.

Visitors to our own marketing site are the single exception, and it does not reach diners. If you accept cookies on that site, Google and Meta receive the pages you viewed and a random identifier so we can tell which of our adverts brought a restaurant owner to us. Under US state privacy laws that counts as sharing for cross-context behavioral advertising. Declining the cookie notice, or sending a Global Privacy Control signal, stops it before anything loads, and you can change your mind from the Cookie choices link in the footer at any time. None of this happens on a restaurant's ordering page, whether or not you accepted anything on ours.

6a. Mobile numbers and text messages

We do not sell, rent, or share mobile numbers, or consent to be messaged, with any third party for their own marketing or promotional purposes. Mobile opt-in data and consent are never shared with anyone outside of delivering the messages you asked for.

If you gave us your mobile number through the chat widget on our website, https://blueobsidian.io, and ticked the consent box, we use it to reply to you and to send you the messages described in the Text Messaging Terms at https://blueobsidian.io/legal/sms. Message frequency varies. Message and data rates may apply. Reply STOP to any message to unsubscribe, or HELP for help. Consent is not a condition of purchase.

What we collect when you opt in, and nothing beyond it:

  • Your mobile number, your name, and the question you typed on the same form.
  • The record of your consent - the wording you agreed to, the page you agreed on, and the date and time. We keep this because consent has to be provable, not asserted.
  • The messages sent to and from that number, and whether they were delivered.
  • Your opt-out, if you send one, so that we do not contact you again by mistake.

The only third parties that see your number are LeadConnector, which runs the chat widget and our messaging platform, and the carriers that deliver the message. They act on our instructions only. LeadConnector is our processor, not a separate controller of your number: its own privacy policy covers its relationship with us as its customer, and this policy - not that one - is what governs the number you gave us. Ask us and we delete your number; unsubscribing keeps only the record that you unsubscribed, so that we do not contact you again by mistake.

7. How long we keep it

DataKept for
Order and payment records7 years, for tax and dispute purposes
Messaging consent and opt-out recordsAs long as the number is on the list, then 4 years after opt-out - an opt-out record has to outlive the consent it revokes, or the number gets re-added
Analytics visits and events13 months, then deleted
Support tickets and contact messages3 years
Security and access logs12 months
Your accountUntil you delete it, then 30 days

8. Your rights

Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to some uses, or ask us not to sell or share it. We never sell it. The only sharing we do for advertising is on our own marketing site, and you can switch that off yourself from the Cookie choices link in the footer without emailing anyone.

Email hello@blueobsidian.io and say which restaurant you ordered from. We answer within 45 days, usually much sooner, and we will not treat you differently for asking. If you ask us to delete data a restaurant controls, we pass the request to them and confirm when it is done.

If you are in the EU or UK: our legal bases are in section 4, you may lodge a complaint with your supervisory authority, and where data is transferred outside your region we rely on Standard Contractual Clauses.

9. Children

The service is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has given us information, email hello@blueobsidian.io and we will delete it.

10. Security

Data is encrypted in transit and at rest. Passwords are stored hashed, never in a recoverable form. Access to production data is limited to staff who need it and is logged. Each restaurant's data is separated at the query layer so one cannot read another's.

No system is perfect. If you find a vulnerability, email hello@blueobsidian.io rather than disclosing it publicly, and we will not pursue you for a good-faith report.

11. Changes

We update this page when what we do changes. The date at the top changes with it. Material changes get notice through the service before they take effect.

12. How to contact us

Privacy questions, requests for a copy of your data, and deletion requests: hello@blueobsidian.io.

blueobsidian io LLC, 11000 W McNichols Rd, Ste 323, Detroit, MI 48221, United States. Telephone (313) 246-3280.


Questions about this policy? Email hello@blueobsidian.io or use the contact form. See all policies at /legal.