Privacy Policy

Last updated: 1 April 2026

1. Who We Are

OrderGrid ("we", "our", "us") is a social media marketing automation platform for restaurants, operated by OrderGrid Pty Ltd, Australia. Contact us at privacy@ordergrid.app. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services at marketing.ordergrid.app.

2. Information We Collect

We collect information you provide directly: • Account information: name, email address, restaurant name, and password. • Brand settings: restaurant name, cuisine type, location, brand tone, and keywords. • Menu data: dish names, descriptions, prices, and categories. • Post content: photos, captions, and scheduling information. • Payment information: processed securely by Stripe — we never store card details. We collect automatically: • Usage data: pages visited, features used, actions taken. • Device information: browser type, IP address, operating system.

3. Social Media Permissions

When you connect Instagram, Facebook, or Google Business Profile to OrderGrid, we request: Meta (Instagram & Facebook): • instagram_business_basic — Read basic profile information • instagram_business_content_publish — Publish content to your Instagram Business account • pages_show_list — View your Facebook Pages • pages_read_engagement — Read page engagement metrics • pages_manage_posts — Publish posts to your Facebook Page Google Business Profile: • business.manage — Manage your Google Business Profile posts We use these permissions solely to publish content you create and approve. We never access followers' private data, send direct messages, or perform unauthorised actions. Access tokens are stored in encrypted form and never shared with third parties.

4. How We Use Your Information

We use your information to: • Provide and operate the OrderGrid service • Publish content to connected social media platforms on your behalf • Generate AI-written captions using Anthropic's Claude API • Enhance photos using Cloudinary • Send transactional emails • Improve our service • Comply with legal obligations We do not sell your personal information. We do not use your content to train AI models.

5. Third-Party Services

OrderGrid uses: Supabase (database/auth), Anthropic (AI captions), Cloudinary (image hosting), Stripe (payments), Meta Graph API, Google Business Profile API, and Vercel (hosting). Each has their own privacy policy.

6. Data Retention

We retain your data while your account is active. If you delete your account, we delete your personal data within 30 days. Request deletion at marketing.ordergrid.app/data-deletion or email privacy@ordergrid.app.

7. Your Rights

Under Australian Privacy Law and GDPR you have the right to: access your data, correct inaccuracies, request deletion, withdraw consent, and lodge a complaint with the OAIC. Contact privacy@ordergrid.app.

8. Security

We implement SSL/TLS encryption, encrypted storage of access tokens, and regular security audits. No method of internet transmission is 100% secure.

9. Children

OrderGrid is not directed to children under 13. We do not knowingly collect personal information from children.

10. Changes

We may update this policy and will notify you of significant changes by email or in-app notice.

11. Contact

Email: privacy@ordergrid.app Website: marketing.ordergrid.app/contact OrderGrid Pty Ltd, Australia