Sapuri logo

Privacy Policy

Last updated: 2026-08-11

This policy explains how Sapuri Food ("Sapuri", "we") handles personal information when you use our website (sapurifood.com) and our Sapuri mobile apps for iOS and Android. The apps and the website are the same service and are covered by this single policy.

Information we collect

  • Order and contact details you provide at checkout: name, email address, phone number, and, for delivery orders, the delivery address and any delivery instructions.
  • Order content: items, options, notes, pickup or delivery choice, scheduled time, promotion or gift-card codes, and order status history.
  • Payment information: card payments are processed by Square. Card numbers are entered into Square's secure payment fields and are sent directly to Square. Sapuri does not receive or store full card numbers or security codes; we store only Square's payment references and non-sensitive details such as amount, status and card brand or last four digits where Square returns them.
  • Loyalty, referral, gift card and promotion data where you take part in those programs, including points balances and reward history.
  • Communication preferences and consent: marketing email and SMS opt-in state, unsubscribe events, and push-notification registrations.
  • Device and usage data: app or browser type, device identifiers used for push notifications, approximate location derived from the delivery address you enter, and basic analytics events about how the ordering flow is used.
  • Marketing attribution data: where you arrive from a campaign link, QR code, referral or affiliate link, we store the associated tracking code and standard advertising click identifiers so orders can be attributed to the campaign.
  • Support communications you send us through the contact form, email, phone or SMS.

We do not ask for and do not knowingly collect government identification numbers, precise background GPS location, health data, or biometric data.

How we use your information

  • To take, prepare, fulfil and deliver your orders, and to contact you about them.
  • To process payments, refunds and chargebacks through Square.
  • To send transactional messages: confirmations, ready-for-pickup, on-the-way and delivery tracking notices, by email, SMS or push notification.
  • To operate loyalty, referral, gift card, birthday and promotional programs you take part in.
  • To send marketing messages only where you have opted in, with an unsubscribe link in every marketing email.
  • To measure business performance, product mix, costs and campaign effectiveness in our internal analytics.
  • To prevent fraud and abuse, secure the service, and meet accounting, tax and legal obligations.

Service providers we share data with

We share only the data each provider needs to perform its function. We do not sell your personal information.

  • SquarePayment processing and card handling for online orders.
  • SupabaseDatabase, authentication and application backend hosting.
  • ResendTransactional and marketing email delivery.
  • TwilioSMS order updates, where SMS is used.
  • OneSignalWeb and mobile push notification delivery.
  • Uber DirectThird-party delivery dispatch and tracking.
  • DoorDashThird-party delivery dispatch and marketplace orders.

For delivery orders dispatched to a third-party courier service, we share the delivery name, phone number, address, delivery instructions and order details needed to complete the drop-off. Orders you place on a third-party marketplace are also subject to that marketplace's own privacy policy.

We may disclose information where required by law, legal process, or to protect our rights, safety, or the integrity of our service.

Push notifications

If you allow notifications, we register your device with our push provider and store a device subscription identifier linked to your customer record so we can send order status updates and, where you opted in, promotional messages. You can turn notifications off at any time in your device settings, and deleting your data removes the device registrations from our systems.

Cookies and local storage

The website and the app use cookies and browser local storage for essential functions — keeping your cart, maintaining a signed-in session for staff accounts, security and fraud prevention — and to remember campaign attribution when you arrive from a tracked link. Blocking essential storage will prevent checkout from working. The mobile apps load the same site inside a secure in-app browser view and use the same mechanisms.

Data retention

We keep order, payment and tax records for as long as required for accounting, tax, refund, chargeback and fraud-prevention purposes, and applicable law. Personal contact details are kept while your customer record is active and are removed or anonymized when you request deletion, except where a record must legally be retained.

Your choices and rights

  • Unsubscribe from marketing email using the link in any marketing message.
  • Stop SMS by replying with the stop keyword indicated in the message.
  • Turn off push notifications in your device or browser settings.
  • Request access to, correction of, or deletion of your personal information by contacting us.

Depending on where you live, you may have additional rights under applicable privacy law, including the right to object to certain processing and the right not to be discriminated against for exercising your rights.

Deleting your data

You can request deletion directly in the app or on the website from the Account page. After you confirm a one-time code sent to your email address, we immediately:

  • Your name, email address, phone number and birthday on your customer record
  • Saved delivery addresses
  • Customer tags, notes and marketing/attribution identifiers
  • All push-notification device registrations (mobile and web)
  • Name, email, phone and delivery address stored on your past order records

What we keep, and why:

  • Order and payment records themselves, without your personal identifiers, for accounting, tax, refund, chargeback and fraud-prevention purposes
  • A permanent suppression entry for your email address, so marketing email can never be sent to it again
  • An internal log entry that a deletion was performed

Security

Data is transmitted over encrypted connections and stored with access controls that restrict customer data to authorised staff accounts. Payment card data is handled by Square within its own PCI-compliant environment. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children

Our service is intended for a general audience and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.

International users

Our service is operated in the United States and information is processed there. If you use the service from elsewhere, you understand your information will be processed in the United States.

Changes to this policy

We may update this policy as the service changes. The revision date at the top always reflects the current version, and material changes will be highlighted in the app or on the website.

Contact us

Questions about this policy or your data can be sent through our contact page.