Privacy Policy

Effective Date: June 13, 2026  |  Last Updated: June 13, 2026

1. Introduction and Who We Are

Welcome to Papa Ginos ("we," "us," "our," or "the Company"). We operate the website located at papaginos-meals.rest and provide food ordering, delivery, and related services to our valued customers across the United States. We are committed to protecting your privacy and handling your personal information with transparency, integrity, and care.

This Privacy Policy applies to all individuals who visit our website, create an account, place food orders, subscribe to our newsletters, participate in promotions, or otherwise interact with Papa Ginos through any digital or physical channel. By accessing or using our services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

This policy has been prepared in accordance with applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Federal Trade Commission Act (FTC Act), and other applicable consumer protection regulations.

You may contact us regarding privacy matters at:

2. Information We Collect

We collect various categories of personal information depending on how you interact with our website and services. Below is a comprehensive overview of the types of data we may collect from you.

2.1 Personal Identification Information

When you register for an account, place an order, or contact us directly, we may collect the following personal identification details:

  • Full name
  • Email address
  • Phone number
  • Mailing and delivery address
  • Date of birth (for age verification purposes)
  • Username and password (encrypted)
  • Profile photo (if voluntarily provided)

2.2 Payment and Financial Information

To process your food orders and transactions, we collect payment-related information. We do not store full credit card numbers on our servers. Payment data is processed securely through PCI-DSS compliant third-party payment processors. We may collect:

  • Billing address
  • Payment method type (credit card, debit card, digital wallet)
  • Last four digits of your card number (for reference purposes)
  • Transaction history and order records
  • Gift card or promotional code usage

2.3 Order and Dietary Information

As a food service provider, we collect information related to your food preferences and order history, including:

  • Food and beverage orders placed
  • Dietary preferences and restrictions you voluntarily provide
  • Favorite menu items and saved orders
  • Special instructions or customization requests
  • Delivery preferences and scheduling information

2.4 Usage and Technical Data

When you visit our website, we automatically collect certain technical and behavioral data about your interaction with our platform, including:

  • IP address
  • Browser type and version
  • Operating system and device type
  • Pages visited and time spent on each page
  • Referring website or source URL
  • Clickstream data and navigation paths
  • Search queries performed on our website
  • Error logs and crash reports
  • Date and time of access

2.5 Location Data

To provide accurate delivery services and show you nearby restaurant locations, we may collect:

  • Precise geolocation data (with your explicit consent through your browser or device settings)
  • Approximate location derived from your IP address
  • Delivery address history

2.6 Communications and Customer Support Data

When you contact our customer support team, leave reviews, or communicate with us, we may collect:

  • Content of your messages, emails, or chat transcripts
  • Feedback and reviews you submit about our food or service
  • Survey responses
  • Social media interactions related to our brand

2.7 Cookies and Tracking Technologies

We use cookies, web beacons, pixel tags, and similar tracking technologies to enhance your experience on our website. Please refer to Section 8 of this policy for detailed information about our cookie practices. The types of tracking data collected through these technologies include:

  • Session cookies for maintaining your logged-in status
  • Preference cookies for remembering your settings
  • Analytics cookies for understanding website usage patterns
  • Marketing cookies for delivering relevant advertisements

3. How We Use Your Information

Papa Ginos uses the personal information we collect for a variety of lawful purposes. We process your data only when we have a legitimate legal basis to do so, including your consent, contractual necessity, compliance with legal obligations, or our legitimate business interests.

3.1 Providing and Managing Our Services

  • Processing and fulfilling your food orders
  • Coordinating delivery logistics and providing estimated delivery times
  • Managing your account registration, login, and profile settings
  • Sending order confirmations, receipts, and status updates
  • Facilitating payments and processing refunds or chargebacks
  • Maintaining your order history and saved preferences

3.2 Customer Support and Communications

  • Responding to your questions, complaints, and service requests
  • Notifying you of changes to our menu, pricing, or policies
  • Sending important service-related announcements and alerts
  • Following up on feedback and reviews you provide

3.3 Marketing and Promotional Activities

With your consent or where permitted by applicable law, we may use your information to:

  • Send you promotional emails, offers, and newsletters about our menu items, discounts, and special events
  • Deliver personalized marketing content based on your order history and preferences
  • Notify you about loyalty program rewards, points, and benefits
  • Display targeted advertisements on our website and third-party platforms
  • Conduct sweepstakes, contests, or promotional campaigns

You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at [email protected].

3.4 Analytics and Service Improvement

  • Analyzing website traffic, usage patterns, and user behavior to improve our platform
  • Conducting internal research and analytics to understand customer preferences
  • Testing new features, menu items, and website functionalities
  • Monitoring and improving website performance and security
  • Generating aggregated, anonymized reports and statistics

3.5 Legal Compliance and Safety

  • Complying with applicable federal, state, and local laws and regulations
  • Responding to lawful requests from government authorities or law enforcement agencies
  • Detecting, preventing, and investigating fraud, unauthorized access, and other illegal activities
  • Enforcing our Terms of Service and other agreements
  • Protecting the rights, property, and safety of Papa Ginos, our customers, and the public

4. Sharing Your Information with Third Parties

Papa Ginos does not sell your personal information to third parties. However, we may share your information with carefully selected third parties under the circumstances described below.

4.1 Service Providers and Business Partners

We engage trusted third-party service providers who assist us in operating our business and delivering our services. These providers are contractually obligated to protect your information and use it solely for the purposes we specify. Categories of service providers include:

Service Category Purpose
Payment Processors Securely processing credit card and digital payments
Delivery Logistics Providers Coordinating food delivery to your address
Cloud Hosting Providers Storing website data and application infrastructure
Email Marketing Platforms Sending promotional emails and newsletters
Analytics Providers Analyzing website performance and user behavior
Customer Support Tools Managing customer service interactions and tickets
Advertising Networks Displaying targeted advertisements on our and third-party platforms
Fraud Prevention Services Detecting and preventing fraudulent transactions

4.2 Legal Requirements and Law Enforcement

We may disclose your personal information when required or permitted by law, including:

  • In response to a valid court order, subpoena, or legal process
  • To comply with applicable federal or state laws and regulations
  • To respond to requests from law enforcement agencies or government authorities
  • To protect the vital interests of individuals where disclosure is necessary

4.3 Business Transfers

In the event that Papa Ginos undergoes a merger, acquisition, restructuring, sale of assets, or bankruptcy proceeding, your personal information may be transferred to the acquiring entity as part of that transaction. We will notify you via email or a prominent notice on our website prior to your information becoming subject to a different privacy policy.

4.4 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you with third parties for research, analytics, marketing, or other business purposes without restriction.

5. Data Security

The security of your personal information is a top priority at Papa Ginos. We implement a comprehensive range of technical, administrative, and physical security measures designed to protect your data against unauthorized access, disclosure, alteration, loss, or destruction.

5.1 Technical Security Measures

  • SSL/TLS Encryption: All data transmitted between your browser and our website is encrypted using industry-standard Secure Socket Layer (SSL) / Transport Layer Security (TLS) protocols.
  • Password Hashing: User passwords are stored using one-way cryptographic hashing algorithms and are never stored in plain text.
  • Secure Payment Processing: Payment transactions are processed through PCI-DSS compliant payment processors to ensure your financial data is protected.
  • Firewalls and Intrusion Detection: Our servers are protected by firewalls and intrusion detection systems that monitor for suspicious activity.
  • Regular Security Audits: We conduct periodic security assessments and vulnerability scans of our systems.
  • Access Controls: Access to personal data is restricted to authorized personnel only, on a need-to-know basis.

5.2 Administrative and Organizational Measures

  • Employee training on data protection and privacy best practices
  • Confidentiality agreements with staff and contractors who handle personal data
  • Data breach response plans and incident management procedures
  • Regular review and updating of privacy and security policies

6. Your Privacy Rights

Depending on your state of residence, you may have specific rights regarding your personal information. Papa Ginos respects and honors these rights in accordance with applicable law.

6.1 Rights Under the California Consumer Privacy Act (CCPA/CPRA)

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

Right Description
Right to Know You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the purposes for which it is used, and the categories of third parties with whom it is shared.
Right to Delete You have the right to request that we delete personal information we have collected from you, subject to certain exceptions permitted by law.
Right to Correct You have the right to request that we correct inaccurate personal information we maintain about you.
Right to Opt-Out of Sale/Sharing You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising purposes.
Right to Limit Use of Sensitive Personal Information You have the right to limit our use and disclosure of sensitive personal information to only what is necessary to perform the requested services.
Right to Non-Discrimination We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny services, charge different prices, or provide a different level of quality based on your exercise of these rights.
Right to Data Portability You have the right to receive your personal information in a portable, structured, and machine-readable format.

6.2 General Privacy Rights for All Users

Regardless of your state of residence, all Papa Ginos users have the following rights:

  • Right to Access: You may request a copy of the personal information we hold about you.
  • Right to Correction: You may request that we update or correct inaccurate information in your account.
  • Right to Deletion: You may request the deletion of your personal data, subject to legal retention requirements.
  • Right to Withdraw Consent: Where we rely on your consent to process your data, you may withdraw that consent at any time without affecting the lawfulness of prior processing.
  • Right to Opt-Out of Marketing: You may unsubscribe from marketing communications at any time.

6.3 How to Exercise Your Rights

To exercise any of the privacy rights described above, please contact us using the following methods:

  • Email: [email protected] with the subject line "Privacy Rights Request"
  • Website: papaginos-meals.rest (through our contact or privacy request form)

We will respond to verified requests within 45 days as required by applicable law. In certain circumstances, we may extend this period by an additional 45 days, in which case we will notify you in writing. We may need to verify your identity before processing your request to ensure the security of your personal information.

7. Data Retention

We retain your personal information only for as long as is necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, resolve disputes, and enforce our agreements. The specific retention periods we apply vary based on the type of data and the purpose for which it was collected.

Data Category Retention Period
Account Registration Information Duration of account plus 3 years after account closure
Order and Transaction History 7 years (for tax, accounting, and legal compliance)
Payment Records 7 years (as required by financial regulations)
Customer Support Communications 3 years from the date of last interaction
Marketing Preferences and Opt-Out Records 5 years from last interaction
Website Analytics and Usage Data 24 months from collection
Cookie and Tracking Data As defined in our Cookie Policy (typically 1-24 months)
Legal and Compliance Records As required by applicable law (up to 10 years)

When personal information is no longer needed, we will securely delete or anonymize it in accordance with our data disposal procedures. Where anonymization is not possible, we will isolate the data from further processing until deletion is feasible.

8. Cookies and Tracking Technologies

Papa Ginos uses cookies and similar tracking technologies to enhance your experience on our website, analyze usage patterns, and deliver relevant marketing content. This section provides a brief overview of our cookie practices.

8.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the website to function properly, including maintaining your session and shopping cart. These cannot be disabled.
  • Performance and Analytics Cookies: Help us understand how visitors interact with our website by collecting anonymous usage statistics (e.g., Google Analytics).
  • Functional Cookies: Remember your preferences such as language settings, delivery address, and order history to provide a personalized experience.
  • Targeting and Advertising Cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns on our website and third-party platforms.

8.2 Managing Your Cookie Preferences

You can manage your cookie preferences at any time through:

  • Our cookie consent banner displayed when you first visit our website
  • Your browser settings (most browsers allow you to refuse or delete cookies)
  • Opt-out tools provided by analytics and advertising networks (e.g., Google Analytics Opt-out)

Please note that disabling certain cookies may affect the functionality and performance of our website. For full details about our cookie practices, including a complete list of cookies we use and instructions for managing them, please refer to our dedicated Cookie Policy available on our website.

9. Children's Privacy

Papa Ginos' services are intended for use by individuals who are 18 years of age or older. We do not knowingly collect, use, or disclose personal information from children under the age of 13, in compliance with the Children's Online Privacy Protection Act (COPPA), or from individuals under the age of 18 without verifiable parental consent where required by applicable law.

If you are a parent or guardian and believe that your child under the age of 13 has provided us with personal information without your consent, please contact us immediately at [email protected]. Upon receiving such a request, we will promptly investigate and take appropriate steps to delete the information from our records.

We do not knowingly create accounts for, market to, or provide services to minors. If we become aware that we have inadvertently collected personal information from a person under 13 years of age, we will take immediate steps to delete that information from our systems.

10. International Data Transfers

Papa Ginos is based in the United States and primarily processes personal information within the United States. However, some of our third-party service providers may be located in or operate from countries outside the United States. If your personal information is transferred to, stored in, or processed in a country other than the United States, we take steps to ensure that adequate protections are in place to safeguard your data.

Such safeguards may include:

  • Data processing agreements with standard contractual clauses
  • Vendor assessments to verify that service providers maintain appropriate data protection standards
  • Ensuring transfers are made only to countries with adequate data protection laws or to companies that have implemented appropriate safeguards

By using our services, you acknowledge and consent to the transfer of your personal information to countries outside your country of residence, including the United States, which may have different data protection standards than your country.

11. Third-Party Links and Services

Our website may contain links to third-party websites, social media platforms, or applications that are not operated by Papa Ginos. These third-party services have their own privacy policies and data collection practices, which we do not control and for which we are not responsible. We encourage you to review the privacy policies of any third-party websites you visit before providing any personal information.

Common third-party integrations on our website may include:

  • Social media sharing buttons (e.g., Facebook, Instagram, Twitter/X)
  • Payment gateway portals
  • Google Maps or similar location services
  • Review platforms and ratings services
  • Delivery partner tracking systems

12. Do Not Track Signals

Some web browsers offer a "Do Not Track" (DNT) setting that sends signals to websites requesting that your activity not be tracked. Currently, there is no universally accepted standard for how websites should respond to DNT signals. At this time, our website does not alter its data collection or use practices in response to DNT browser signals. However, you may manage your tracking preferences through our cookie consent tools and browser settings as described in Section 8.

13. California Privacy Rights – Additional Disclosures

In addition to the rights described in Section 6, California residents are entitled to the following additional disclosures under the CCPA/CPRA:

13.1 Categories of Personal Information Collected in the Past 12 Months

  • Identifiers (name, email address, IP address, account credentials)
  • Commercial information (order history, transaction records, purchase preferences)
  • Internet or other electronic network activity information (browsing history, website interactions)
  • Geolocation data (delivery addresses, approximate location)
  • Inferences drawn from personal information to create a profile about consumer preferences
  • Sensitive personal information (payment card information processed by third parties)

13.2 Business Purpose for Collecting Personal Information

We collect the above categories of personal information for the business purposes described in Section 3 of this Privacy Policy, including service provision, order fulfillment, customer support, analytics, marketing, fraud prevention, and legal compliance.

13.3 "Shine the Light" Law

California Civil Code Section 1798.83 permits California residents to request information about personal information disclosed to third parties for their direct marketing purposes. To make such a request, please contact us at [email protected].

14. FTC Act Compliance

Papa Ginos complies with the Federal Trade Commission Act (FTC Act), which prohibits unfair or deceptive acts or practices in or affecting commerce. We are committed to:

  • Providing truthful and transparent disclosures about our data collection and use practices
  • Honoring the privacy promises made to consumers in this Privacy Policy
  • Maintaining reasonable security measures to protect consumer data
  • Not engaging in deceptive or unfair practices in connection with personal information
  • Complying with applicable FTC guidance on endorsements, advertising, and consumer privacy

15. How to File a Complaint

If you have concerns about our privacy practices that we have not adequately addressed, you have the right to file a complaint with relevant regulatory authorities.

15.1 Complaint to Papa Ginos

We encourage you to first contact us directly so we have an opportunity to resolve your concern:

We will acknowledge receipt of your complaint within 5 business days and endeavor to provide a full response within 30 days.

15.2 Complaint to the Federal Trade Commission (FTC)

If you are a resident of the United States and believe your privacy rights have been violated, you may file a complaint with the Federal Trade Commission:

  • Website: ftc.gov/complaint
  • Phone: 1-877-382-4357
  • Address: Federal Trade Commission, 600 Pennsylvania Avenue, NW, Washington, DC 20580

15.3 Complaint to the California Privacy Protection Agency (CPPA)

If you are a California resident and believe your CCPA/CPRA rights have been violated, you may file a complaint with the California Privacy Protection Agency:

  • Website: cppa.ca.gov
  • Address: California Privacy Protection Agency, 2101 Arena Blvd., Sacramento, CA 95834

15.4 Complaint to Your State Attorney General

Depending on your state of residence, you may also have the right to file a privacy complaint with your state's Attorney General office. Most state Attorneys General maintain consumer protection divisions that handle privacy-related complaints.

16. Changes to This Privacy Policy

Papa Ginos reserves the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal requirements, or business operations. When we make material changes to this policy, we will notify you through one or more of the following methods:

  • Posting an updated version of this Privacy Policy on our website with a revised "Last Updated" date
  • Sending an email notification to the address associated with your account
  • Displaying a prominent notice on our website homepage

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

17. Contact Information for Privacy Inquiries

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact our privacy team. We are committed to addressing your inquiries promptly and transparently.

Papa Ginos – Privacy Contact Information

Company: Papa Ginos

Website: papaginos-meals.rest

Privacy Inquiries Email: [email protected]

Subject Line: "Privacy Policy Inquiry" or "Privacy Rights Request"

We strive to respond to all privacy-related inquiries within 10 business days. For formal privacy rights requests (such as data access, deletion, or correction requests), we will respond within the timeframes required by applicable law.