Privacy Policy
LocalBites is a food ordering and reservation platform operated from Calgary, Alberta, Canada. This Privacy Policy explains what personal information we collect when you use our website, WhatsApp ordering service, and partner tools โ and how we use, share, and protect it. It also describes the rights you have under Canadian, European, and California privacy law.
01Who we are
"LocalBites," "we," "us," and "our" refer to 2166613 Alberta LTD, a corporation registered in the Province of Alberta, Canada, operating the LocalBites platform at localbites.ca.
For the purposes of PIPEDA (Canada's Personal Information Protection and Electronic Documents Act), the GDPR (EU/UK General Data Protection Regulation), and the CCPA/CPRA (California), we are the data controller of the personal information described in this policy.
Our registered address is Calgary, Alberta, Canada. You can reach our Privacy Office at privacy@localbites.ca.
02Information we collect
We collect the information below only to operate LocalBites. We do not collect personal information we don't need.
| Category | What it includes |
|---|---|
| Account & contact information | Name, phone number, email address, and delivery address when you place an order, make a reservation, or chat with our WhatsApp concierge. |
| Order & reservation information | Items ordered, special instructions, order totals, reservation times, party size, and the restaurant you interacted with. |
| Payment information | Payment is processed by Stripe. We do not store full card numbers on our servers. We store a payment token, the last four digits, card brand, and the billing postal code returned by Stripe. |
| WhatsApp conversation data | Messages you exchange with our concierge (including the AI assistant "Maya"), your WhatsApp phone number, and message timestamps, provided to us via the WhatsApp Business Platform operated by Meta. |
| Restaurant partner information | If you are a restaurant owner or staff member, we collect your business name, address, banking/payout details, menu, and portal login credentials. |
| Social media connection data | If you connect a Facebook Page or Instagram Business account to LocalBites, we receive an access token from Meta and the Page/Account identifier and name. See Section 6. |
| Device & usage information | IP address, browser type, device type, pages visited, and approximate location derived from IP โ used for security, analytics, and fraud prevention. |
| Marketing preferences | Whether you have opted in to promotional messages and your opt-in/opt-out timestamps. |
03How we use your information
We use the information we collect to:
- Take your order or reservation, route it to the restaurant, and confirm delivery or pickup.
- Process payments and, where required, issue refunds.
- Send you order confirmations, reservation reminders, and delivery updates by WhatsApp, SMS, or email.
- Operate our AI concierge Maya, who answers menu questions, suggests items, and processes orders through natural conversation.
- Provide restaurant partners with order management, reservation management, and โ where they have enabled it โ social media posting tools.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations, including tax reporting and responding to lawful requests from authorities.
- Improve our services โ for example, by analyzing aggregated order patterns to improve Maya's accuracy.
- Send marketing communications where you have opted in (you can opt out at any time).
We do not sell your personal information. We do not use your conversation data with Maya to train third-party AI models.
04Legal basis for processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we process your personal information on the following legal bases:
- Performance of a contract โ to provide the ordering, reservation, and delivery services you request.
- Legitimate interests โ to operate and improve LocalBites, prevent fraud, and secure our systems, where those interests are not overridden by your rights.
- Consent โ for optional marketing communications and for connecting your social media accounts. You may withdraw consent at any time.
- Legal obligation โ where we must retain records for tax, accounting, or law-enforcement purposes.
06Facebook, Instagram, and Meta Platforms
LocalBites integrates with Meta Platforms in two ways:
WhatsApp Business Platform
When you message our WhatsApp number (+1 403-493-2717), your messages are delivered to us through the WhatsApp Business Platform, which is operated by Meta. Meta's own privacy practices apply to the transport of those messages and are described in the WhatsApp Privacy Policy. We use the WhatsApp Business Platform solely to deliver our ordering, reservation, and concierge service. We do not advertise to you on WhatsApp unless you have opted in to marketing.
Facebook Pages and Instagram Business accounts (Partner feature)
Restaurant partners can choose to connect their Facebook Page and/or Instagram Business account to LocalBites so that promotions, menu updates, and blast messages can be cross-posted automatically. When a partner connects their account via Facebook Login, we request the following permissions, which require approval from Meta through Meta's App Review process:
- pages_show_list โ to display a list of the partner's Pages so they can choose which one to connect.
- pages_read_engagement โ to read Page performance metrics so partners can see how their posts are doing.
- pages_manage_posts โ to publish posts to the connected Page when the partner schedules content.
- pages_manage_metadata โ to configure webhooks so the partner's Page remains in sync with LocalBites.
- instagram_basic โ to identify the Instagram Business account linked to a connected Page.
- instagram_content_publish โ to publish content to the connected Instagram Business account when the partner schedules it.
- business_management โ to operate within the partner's Meta Business Portfolio when they manage multiple Pages through a Business Manager.
We store the access token Meta returns to us, along with the Page and account identifiers. We use these only to perform the actions the partner has explicitly requested (scheduling or publishing content). Partners can disconnect at any time from the Partner Portal, which revokes the token.
Data we receive from Meta is used only to provide the social posting feature and is not sold, rented, or used for any other purpose.
08How long we keep your information
We keep your personal information only as long as we need it for the purposes described in this policy, or as required by law:
- Order and reservation records: 7 years, to comply with Canadian tax and accounting requirements, after which records are anonymized or deleted.
- WhatsApp conversation history: 2 years from last activity, or until you request deletion.
- Marketing opt-in records: For as long as you remain opted in, plus 24 months after opt-out to demonstrate compliance with anti-spam law.
- Security and fraud logs: 13 months.
- Restaurant partner records: For the duration of the partnership, plus 7 years after it ends.
You may request deletion of your information at any time โ see Section 11.
09How we protect your information
We use reasonable technical and organizational safeguards:
- All data in transit is encrypted using TLS 1.2 or higher.
- Databases enforce row-level security so that each restaurant partner can access only their own data.
- Payment card data is handled by Stripe, a PCI-DSS Level 1 certified provider. We do not store full card numbers.
- Access to production systems is restricted to a limited number of authorized personnel and requires strong authentication.
- We monitor for unauthorized access and unusual activity.
No system can be guaranteed 100% secure. If we become aware of a security incident that affects your personal information, we will notify you and the appropriate authorities in accordance with applicable law.
10International data transfers
LocalBites is operated from Canada. Some of our service providers (including Stripe, Supabase, Cloudflare, Meta, Google, and Anthropic) process data in the United States and other countries. When we transfer personal information outside Canada, we rely on legally recognized safeguards โ such as Standard Contractual Clauses for transfers from the EU/UK, and contractual commitments equivalent to PIPEDA for transfers involving Canadian personal information.
11Your rights
Depending on where you live, you have some or all of the following rights:
- Access โ request a copy of the personal information we hold about you.
- Correction โ ask us to correct information that is inaccurate or incomplete.
- Deletion ("right to erasure") โ ask us to delete your personal information, subject to legal retention requirements.
- Restriction or objection โ ask us to stop or limit certain uses of your information, including direct marketing.
- Portability โ request a copy of your information in a commonly used machine-readable format.
- Withdraw consent โ where we process based on consent, you may withdraw it at any time without affecting prior processing.
- Lodge a complaint โ with the Office of the Privacy Commissioner of Canada (priv.gc.ca), your local EU/UK data protection authority, or the California Privacy Protection Agency.
To exercise any of these rights, email privacy@localbites.ca or use our Data Deletion form. We will respond within 30 days (or 45 days in California, as permitted by law). We may need to verify your identity before acting on your request.
12California residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- The right to know what personal information we collect, use, disclose, and sell or share.
- The right to delete personal information we collect from you, subject to exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of your personal information.
- The right to limit the use of sensitive personal information.
- The right to non-discrimination for exercising any of these rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under California law. To exercise your rights, email privacy@localbites.ca.
13Children's privacy
LocalBites is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at privacy@localbites.ca and we will delete it.
14Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. If the changes are material, we will notify you by email or through a prominent notice on our website before they take effect.
15Contact us
Questions, concerns, or requests about this policy or your personal information: