1Who we are
OrderWithMe Pty Ltd (ABN
16 309 697 278),
referred to here as we, us or OrderWithMe. We operate the
software at orderwithme.com.au and every venue ordering page beneath
it.
This policy is the statement APP 1 requires, and it covers everything we do.
A note on whether we have to. The Privacy Act 1988 (Cth) exempts some small businesses under a turnover threshold. We may fall under it. We do not rely on that exemption: we handle personal information as though the Act and all thirteen Australian Privacy Principles bind us, because the exemption is about our size rather than about what you are entitled to expect, and because it can stop applying without anyone noticing.
Privacy Officer. Privacy questions, access requests and complaints go to hello@orderwithme.com.au, marked for the Privacy Officer. A person answers it.
2Us and your venue are two different handlers
This distinction decides who you should ask for what, so it comes before the detail rather than after it.
When you order at a venue, the venue decides what is on its menu, what it does with your order, whether it runs a loyalty programme, and how it treats you as a customer. We provide the software the order travels through, and we hold the data on the venue's behalf as well as for our own purposes as the platform.
So questions about a specific order, a refund, or how a particular café is using your details go to that venue. Questions about the platform itself — what we store, how long, who processes it — come to us. If you ask us something that is really the venue's to answer, we will tell you that rather than leave you waiting, and we will help you find the right contact.
Each venue is separately responsible for meeting its own privacy obligations. Our agreement with venues requires it.
3If you are ordering food
You can order without an account. Most of what follows is optional, and the page works if you give none of it beyond a name.
Always, because an order cannot exist without them
- What you ordered, and what it cost — items, sizes, extras, any tip and any venue surcharge. This is the sale record.
- Which venue, and when.
- Your table, if you scanned a table code rather than ordering from your own phone elsewhere.
Usually, because staff have to hand the food to someone
- A name. A first name is enough, and it is the name called out or printed on the docket. It does not have to be your legal name.
- An email address, where you want a receipt or tax invoice sent, or where you have an account.
Only if you choose to
- An account — an email address and a password, held by our authentication provider. Passwords are stored hashed; we never see them in readable form.
- A profile — a display name and, if you enter one, a phone number. Both are optional and both can be cleared at any time from the profile screen.
- A tab — if you open or join a shared bill, we record that you are on that tab, and the other people on it can see the orders placed against it.
- Membership of a venue's programme — that you joined, when, and which orders counted toward member pricing or a stamp card. Rewards are worked out from your order history at that venue rather than from a stored balance.
- Notes you type — allergy notes or special requests go to the kitchen as written. Please do not put anything in a note you would not want printed on a docket and read by kitchen staff.
Age confirmation
If a venue sells alcohol, alcoholic items stay hidden until you confirm you are eighteen or over. That confirmation is stored in your own browser, against that venue, and is never sent to us. We do not record your date of birth, and we keep no record that you were shown the question.
4What happens if you would rather not say
APP 5 says we should tell you the consequence of not giving us something, rather than just marking a field required. So:
You may deal with us anonymously or under a pseudonym wherever that is practicable (APP 2). Ordering without an account under a first name of your choosing is a supported path, not a workaround.
5If you run a venue
- Business details — trading name, email, phone, address and ABN. A tax invoice has to carry them, and we need to be able to reach you.
- Your login — email address and password, plus a two-factor secret if you turn two-factor on.
- Liquor licence number, state and expiry, if you sell alcohol. This is regulatory paperwork; it is stored on your venue record and is never exposed on your public ordering page.
- Your menu and branding — items, prices, descriptions, dietary flags, photographs, logo, cover image and colours.
- Your orders, including the customer details attached to them.
- Payout and bank details are held by Stripe, not by us. We never receive them. We store your Stripe account identifier and whether Stripe has enabled charges, and nothing more about your banking.
- Operational records — how many times your account called our menu-reading endpoint on a given day, so we can apply a fair daily ceiling to a service that costs us money per call.
Decisions we make about your business are logged. When your venue is approved or rejected, and when an order changes status, we write an entry recording who did it and when. That log cannot be edited or deleted by anyone, including us — the database refuses the operation. It is readable only by OrderWithMe staff, and exists so that "why was this venue turned down" has an answer that does not depend on somebody's memory.
Images you upload are public. Logos, cover photos, category pictures and item photographs are served from a public bucket so they can appear on your ordering page to people who are not signed in to anything. Treat anything you upload there as published. Do not upload documents, licences, or anything identifying a person.
6If you were invited to a venue's team
We store your email address, the venue that invited you, the role you were given and whether you have accepted. The venue that invited you can see and remove it. If you were added without your knowledge, tell us and we will remove you.
7Information we did not ask for
Sometimes information arrives that we never sought — a customer types a medical detail into an allergy note, or a venue photographs a menu with a person in the shot, or someone puts something in an email to support.
Where we receive personal information we did not solicit and could not have collected ourselves under this policy, we destroy or de-identify it as soon as practicable, provided it is lawful to do so (APP 4). We do not add it to a profile and we do not use it for anything.
8Why we collect it
Each of these is a purpose we act on, not a category kept open in case it is useful later.
- To send an order to a kitchen and let staff match food to the person who ordered it.
- To take payment, through Stripe, and to tell the venue the order is paid.
- To send receipts and tax invoices.
- To run the venue's dashboard — its live orders, its history, its takings.
- To operate loyalty programmes a venue has turned on, where you joined one.
- To keep the service standing up — diagnosing errors, preventing fraud and abuse, applying rate limits and daily ceilings.
- To meet our own legal obligations, principally tax and business record keeping. Some of what we hold, we are required by law to hold.
We will not use your information for a new purpose unrelated to these without telling you first (APP 6).
We do not build advertising profiles, we do not do behavioural tracking, and we do not sell personal information. There is no advertising network, analytics tag or social pixel anywhere on this service.
9What we never collect
- Your card number. Payment happens on Stripe's own hosted checkout page. Card details are entered on Stripe's page, not ours, and never pass through our servers.
- Your date of birth. The alcohol gate asks a yes-or-no question and keeps the answer in your browser.
- Your home address. There is no delivery in this product and nowhere to enter one.
- Location data. Geolocation is disabled at the browser level by our own permissions policy, along with camera, microphone and USB access.
- Government identifiers — no driver licence, passport, tax file or Medicare numbers, and we will not adopt one as our own identifier for you (APP 9). A venue's ABN and liquor licence are business identifiers, not personal ones.
- Sensitive information in the Privacy Act's sense — health, race, religion, political opinions, sexual orientation, criminal record. We do not ask for it and have nowhere to put it. The one place it could arrive is a note you type yourself, which is why we ask you not to, and why section 7 applies when it happens.
10Cookies and what is kept in your browser
There are no advertising or analytics cookies on this service, which is why there is no cookie banner asking you to accept any. What is stored is stored because the thing you are doing cannot work otherwise.
11Who else sees it
These are our service providers. Each is listed with what it actually receives — not with what it would be entitled to receive.
On session replay, plainly. When a page throws an error, Sentry records what happened on screen so the bug can be found. It is set to record only those sessions and never to attach your identity. We check that setting rather than assume it — it was once silently overridden by our own security policy on the marketing pages, and we found it by measuring the live site.
Beyond these, we disclose personal information only where the law requires it — a court order, a warrant, or a regulator acting within its powers — or where it is necessary to prevent a serious threat to someone's life, health or safety. If our business is ever sold, information may transfer with it, and this policy binds whoever receives it until they publish their own.
We do not sell personal information. No provider on this list is permitted to use what it processes for its own purposes.
12Where it is stored, and when it leaves Australia
The database, the file storage and the servers running our code are all in Sydney. Your orders live in Australia.
Storage and access are different questions, and the honest answer covers both. Supabase and Vercel are overseas companies. Data at rest stays in the Sydney region, but their staff can access systems for support and maintenance from outside Australia under their own controls.
These providers handle information outside Australia (APP 8):
- Stripe — United States and Ireland, for payment processing.
- Resend — United States, for sending email.
- Sentry — United States or European Union, for error reports.
- Anthropic — United States, for menu reading only.
- hCaptcha — United States, for bot protection.
- Have I Been Pwned and Google Fonts — served globally.
We take reasonable steps to ensure each handles the information consistently with the Australian Privacy Principles, principally through their data processing agreements. Using the service involves this happening.
13How long we keep it
Two rules pull in opposite directions here, and the honest answer is that we keep the sale and drop the person.
Australian tax law expects business records to be retained for five years, and an order is one. The Privacy Act says personal information should not be kept longer than the purpose it was collected for. Your name was collected so a barista could call out a coffee, and that purpose expires when the coffee is handed over.
So:
- The sale is kept for at least five years — the items, the total, the GST, the date.
- The person is not. Every night we strip the name, the email address and the link to any account from every order more than twelve months old. What is left is an anonymous sale. The venue keeps its books; we stop keeping you. This runs on a schedule rather than when somebody remembers, which is the only version of this promise worth making.
- Accounts are kept while in use, and removed on request.
- Venue records are kept while the venue trades with us, and for as long afterwards as tax and record-keeping law requires.
- Error reports and session replays are kept on our provider's retention schedule, currently 90 days.
- The decision log in section 5 is permanent by design. It records decisions about businesses and contains no customer information.
- Backups are taken nightly, encrypted, and rotate out. A record you asked us to remove may persist in a backup until that backup expires; it will not be restored into the live system.
14Keeping it accurate
We take reasonable steps to ensure the personal information we hold is accurate, up to date and complete, having regard to what it is used for (APP 10).
In practice most of it is entered by you and can be corrected by you: a venue edits its own details, a diner edits their own profile. The rest is a record of something that happened — what was ordered, and when — which we do not alter, because a sale record that can be rewritten is not a record. If you think we hold something wrong about you, section 17 is how to have it fixed.
15How it is protected
- Every table has row-level security. Access is enforced by the database itself rather than by the application asking nicely — a venue can read its own orders and nobody else's, and that rule holds even if our own code has a bug.
- Encrypted in transit and at rest, with HTTPS forced across the site.
- Two-factor authentication is available on venue accounts and required for OrderWithMe staff accounts.
- New passwords are checked against known breaches and refused if they appear in one, using a method that never transmits the password.
- Bot protection on sign-in, sign-up and password reset.
- Nightly encrypted backups, using AES-256-GCM.
- A strict content security policy, so the pages cannot load code from anywhere we have not listed, and cannot be embedded in another site.
- Card data never reaches us, which means it cannot leak from us.
- When information is no longer needed and we are not required to keep it, we destroy or de-identify it (APP 11).
No system is perfectly secure, and we would rather say so than imply otherwise.
16Where AI is used, and where it is not
There is exactly one place. When a venue uploads a photograph or PDF of its own menu, we send that file to Anthropic to read the items, prices and descriptions out of it, so the venue does not have to type a hundred rows by hand.
What that means in practice:
- It is menus only. No customer information, no order, no email address and no payment data is ever sent to an AI service.
- It happens only when a venue asks for it, by uploading a file.
- The result is a suggestion. Nothing is written to the menu until the venue reviews it and confirms.
- It makes no decisions about people. There is no profiling, no automated decision-making with legal or similarly significant effects, and no AI anywhere near an order, a price charged, or an account.
If a venue photographs a menu with a person in the shot, that photograph goes to Anthropic along with the menu. Photograph the menu, not the room — and see section 7 for what we do when it happens anyway.
17Seeing it, fixing it, or being removed
Email hello@orderwithme.com.au. You can ask us to:
- Tell you what we hold about you (APP 12). We respond within 30 days and do not charge you for asking.
- Correct it if it is wrong (APP 13). If we have disclosed the wrong information to someone else, we will tell them about the correction where you ask us to and it is reasonable to do so.
- Remove you. We strip your name, your email address and the link to your account from every order, close your profile, and rename any tab that carried your name.
- Give you a copy of your data in a portable form.
Removing you leaves the sales themselves in place with nothing identifying you attached. That is the part we are not permitted to delete, and the part that is no longer about you once your name is off it.
When we might say no. We may need to confirm who you are first, so that a request about somebody's history cannot be made by somebody else. We may refuse access where the law allows or requires it — for example where giving it would unreasonably affect another person's privacy (an order on a shared tab involves other people), where it would prejudice an investigation, or where it is frivolous. If we refuse, we will tell you why, in writing, and how to complain about that decision.
18If something goes wrong
We keep a data breach response plan. If personal information is lost or disclosed in a way likely to cause serious harm, we will assess it promptly, contain it, and notify the people affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
We will tell you what happened, what information was involved, and what you can do about it — in plain terms, and without waiting until we have a tidy explanation.
19Children
This service is not aimed at children, and an account is not needed to order. We do not knowingly collect information from a child under 15 beyond the name and order any walk-in customer would give. Alcoholic items are hidden until age is confirmed. If you believe a child has created an account, tell us and we will remove it.
20Marketing
We do not send marketing email to diners (APP 7). The emails we send you are receipts, tax invoices and account notices — the things you asked for by ordering or by signing up. Venue account holders also receive service notices, such as a change to these policies, which are not marketing and cannot be opted out of while the account is open.
A venue may separately market to its own customers where it has the consent the Spam Act 2003 requires. That is the venue's responsibility, using the venue's own systems, and its unsubscribe link is the venue's to honour. If you cannot get a venue to stop, tell us and we will raise it with them.
21Other sites we send you to
Paying takes you to Stripe's own checkout page, and a few links here go to outside sites such as the OAIC. Once you are on someone else's site you are under their privacy policy, not ours. We have no control over what they collect.
22Changes to this policy
If this page changes in a way that affects what we collect, who sees it, or how long it is kept, the version number and date at the top change with it, and venue accounts are notified by email. Continuing to use the service after a change means the current version applies. We keep previous versions and will provide one on request.
23Contact, and how to complain
OrderWithMe Pty Ltd — Privacy Officer
ABN 16 309 697 278
hello@orderwithme.com.au
If you are unhappy with how we have handled your information, email us at that address first. We will acknowledge it promptly and respond within 30 days.
If that does not resolve it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. You do not need our permission, and you can go to them at any time.