1. Who is responsible
Eaziflow | TakeOut (“Eaziflow”, “we”, “us”) provides the ordering platform at eaziflowtakeout.co.za. Privacy requests can be sent to eaziflowtakeout@gmail.com.
This notice applies to restaurant owners and team members who use the dashboard, customers who place or track an order, and website visitors. For an order, the restaurant receives and uses the information as the food supplier. Eaziflow processes it to operate and secure the platform. Depending on the activity, Eaziflow and the restaurant may each be a responsible party under POPIA.
2. Information we collect
Customer order information can include name, mobile number, optional email address, delivery address and suburb, order notes, selected items, fulfilment and payment methods, order value, status history and a private tracking reference.
Restaurant-account information can include a person’s name, email address, authentication profile, restaurant membership and role, account status, storefront content, subscription records, activity logs and uploaded images.
Technical information can include timestamps, IP address and device or browser information in request, authentication and security logs. The customer cart and checkout draft are also stored locally in the customer’s browser.
3. Where information comes from
We collect information directly from customers, restaurant owners and team members when they use the service. Authentication providers such as Google or OpenAI may provide the name, email address, profile image and account identifier needed for the selected sign-in method. Restaurants also create order-status updates and account or menu records about their own operations.
4. Required and optional information
A customer’s name and mobile number are required to place an order. A delivery address and suburb are required for delivery. Email and order notes are optional. Without the required details, the restaurant cannot accept or fulfil the order.
An owner’s name, email address and authentication details are required to create and protect an account. Restaurant setup also requires the operational information displayed to customers. Other profile, branding and menu fields are optional unless the interface marks them as required.
5. Why and on what basis we use it
We use information to send an order to the selected restaurant, provide tracking, authenticate users, administer restaurant accounts, operate subscriptions, deliver support, prevent fraud and abuse, secure and troubleshoot the service, enforce our terms, keep business records and comply with law.
Depending on the activity, processing is necessary to perform or prepare a contract, comply with a legal obligation, pursue legitimate interests in operating and securing the service, or act on consent where consent is required. We do not use solely automated decisions that produce legal or similarly significant effects.
We do not collect customer card numbers or process online card payments. Payment is made directly to the restaurant by cash or its card machine.
6. Who receives information
Order details are shared with the selected restaurant and its authorised team. We use service providers for cloud hosting and storage, authentication, transactional email, security and technical support. These currently include OpenAI Sites and Cloudflare infrastructure, Google for optional owner sign-in, OpenAI for administrator sign-in and Resend for account emails.
We may disclose information when required by law, to investigate misuse or protect rights and safety, or as part of a properly managed business transfer. We do not sell personal information and do not share it for third-party behavioural advertising.
7. International processing
Some service providers may process or store information outside South Africa. We select providers and use contractual, organisational and technical safeguards intended to provide protection consistent with POPIA’s cross-border requirements.
8. Retention and deletion
We keep information only while it is reasonably needed for the purposes described here, to resolve disputes, protect the service and meet legal, tax, accounting or recordkeeping duties. Order records are ordinarily targeted for deletion or de-identification after 24 months unless a longer period is required for a dispute or legal obligation. Account and subscription records are kept while the account is active and ordinarily for up to 90 days after closure, except for records that must be retained longer. Security and audit logs are ordinarily kept for up to 12 months, and residual backup copies may remain for up to 30 additional days.
Uploaded storefront media remains until it is replaced, removed or the account is closed. Device-local cart and checkout information remains in the browser until it is cleared or replaced and is not the authoritative order record.
9. Security and incidents
We use access controls, tenant checks, private tracking references, server-side order-total validation, rate limits and managed cloud infrastructure to protect information. No system can guarantee absolute security. We will investigate suspected compromises and notify the Information Regulator and affected people when POPIA requires it.
Report a suspected privacy or security incident promptly to eaziflowtakeout@gmail.com.
10. Your choices and rights
Subject to applicable law, a person may ask whether personal information is held, request access or correction, object to certain processing, withdraw consent where processing relies on consent, ask for deletion where appropriate, or complain about how information is handled. We may need to verify identity and may retain information where law or a valid legal reason requires it.
Start a request by emailing eaziflowtakeout@gmail.com. Customers can also contact the restaurant about a particular order. If a concern is not resolved, a POPIA complaint can be submitted through the Information Regulator of South Africa.
11. Browser storage and cookies
The customer storefront uses browser storage to remember an in-progress cart and checkout draft on that device. Restaurant and administrator sign-in uses strictly necessary authentication cookies or equivalent session technology. The current platform does not use advertising or cross-site tracking cookies.
12. Children
The service is not directed to children and Eaziflow does not knowingly seek to collect children’s personal information. A person placing an order must be legally able to do so or act with a parent or guardian’s involvement. Contact us if you believe a child supplied information without appropriate involvement.
13. Changes and legal framework
We may update this notice as the service, providers or legal requirements change. The updated date at the top shows when this version took effect. Material changes will be communicated through the website, dashboard, account email or another reasonable channel.
This notice is designed around South Africa’s Protection of Personal Information Act 4 of 2013. It does not claim certification or replace advice from a qualified South African privacy professional.