Privacy Policy

This Privacy Policy describes how Cafe Rio ("we," "us," or "our") collects, uses, discloses, and protects the personal information of individuals ("you" or "your") who visit or interact with our website located at caferiomexican.top (the "Site"), place orders, subscribe to our communications, or otherwise engage with our food services. We are committed to protecting your privacy and handling your personal data with transparency, integrity, and in compliance with applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the Federal Trade Commission Act (FTC Act).

Please read this Privacy Policy carefully. By accessing or using our Site, placing an order, or providing us with your personal information, you acknowledge that you have read, understood, and agree to the practices described in this policy. If you do not agree with any part of this Privacy Policy, please discontinue your use of our services immediately.

We reserve the right to update or modify this Privacy Policy at any time. Any changes will be posted on this page with a revised effective date. We encourage you to review this page periodically to stay informed about how we are protecting your information.


1. About Us / Data Controller

The entity responsible for the collection and processing of your personal data under this Privacy Policy is:

For all privacy-related inquiries, requests, or concerns, please contact us at the email address listed above. We will make every effort to respond to your inquiry promptly and in accordance with applicable law.


2. Information We Collect

We collect various types of information in connection with your use of our Site and services. This information falls into the following categories:

2.1 Personal Information You Provide Directly

When you interact with Cafe Rio — whether by creating an account, placing a food order, signing up for our newsletter, filling out a contact form, or otherwise communicating with us — you may voluntarily provide us with personal information, including but not limited to:

  • Identity Information: Your full name, username, or similar identifiers.
  • Contact Information: Email address, telephone number, and mailing or delivery address.
  • Account Credentials: Username and password if you create an account on our Site.
  • Order and Transaction Information: Details of the food items you order, delivery instructions, order history, and payment-related information (note: we do not store full credit card numbers; payment processing is handled by third-party payment processors).
  • Communication Data: Any messages, feedback, reviews, or other correspondence you send to us through email, contact forms, or other channels.
  • Marketing Preferences: Your preferences for receiving promotional communications from us, including your subscription status to our newsletters or promotional emails.
  • Dietary and Food Preferences: Any dietary restrictions, allergies, or food preferences you share with us to customize your experience.

2.2 Information Collected Automatically

When you visit or interact with our Site, we and our third-party service providers may automatically collect certain technical and usage information, including:

  • Device Information: IP address, browser type and version, operating system, device type, hardware model, and unique device identifiers.
  • Usage Data: Pages visited on our Site, time and date of your visit, time spent on each page, links clicked, referring URLs, and other clickstream data.
  • Location Information: General geographic location derived from your IP address. If you grant us permission, we may also collect more precise location data to facilitate local restaurant discovery or delivery services.
  • Log Data: Server log files that record access to our Site, including error logs and access timestamps.
  • Cookie and Tracking Data: Information collected through cookies, web beacons, pixel tags, and similar tracking technologies. Please see Section 8 of this policy for more details on our use of cookies.

2.3 Information from Third Parties

We may also receive information about you from third-party sources, including:

  • Social Media Platforms: If you connect your social media account to our Site, or interact with us through a social media platform, we may receive information from that platform in accordance with its privacy settings and terms.
  • Payment Processors: Our third-party payment processing partners may share transactional data with us to confirm completed payments or flag potential fraud.
  • Analytics Providers: We use third-party analytics tools (such as Google Analytics) that may provide us with aggregated and anonymized insights about how users interact with our Site.
  • Delivery Partners: If your order is fulfilled through a third-party delivery platform, we may receive information necessary to process and fulfill your order.

3. How We Use Your Information

We use the personal information we collect for a variety of legitimate business purposes. Specifically, we use your information to:

3.1 Provide and Manage Our Services

  • Process and fulfill your food orders, including communicating order confirmations, updates, and delivery notifications.
  • Create and manage your account on our Site.
  • Respond to your inquiries, customer support requests, and feedback.
  • Facilitate payment transactions through our third-party payment processors.
  • Accommodate your dietary preferences or food allergy requirements.

3.2 Improve and Personalize Our Services

  • Analyze usage patterns and trends on our Site to understand how our services are being used and to improve the overall user experience.
  • Develop new menu items, services, or features based on customer preferences and feedback.
  • Personalize the content and offers you see on our Site based on your past orders, preferences, and browsing behavior.
  • Conduct internal research, testing, and quality assurance activities.

3.3 Marketing and Promotional Communications

  • Send you promotional emails, newsletters, special offers, and information about new menu items or events at Cafe Rio, where you have opted in to receive such communications or where we have a legitimate interest in doing so.
  • Serve you targeted advertisements on our Site or on third-party platforms based on your browsing and order history.
  • Conduct customer satisfaction surveys and solicit reviews or testimonials.

You may opt out of receiving marketing emails at any time by clicking the "unsubscribe" link found in any promotional email we send you, or by contacting us directly at [email protected]. Please note that even if you opt out of marketing communications, we may still send you transactional or service-related communications (such as order confirmations).

3.4 Legal Compliance and Safety

  • Comply with applicable federal, state, and local laws and regulations, including food safety regulations and tax reporting obligations.
  • Detect, prevent, and investigate fraud, security incidents, and other potentially illegal or prohibited activities.
  • Enforce our Terms of Service and other applicable agreements.
  • Respond to legal process, court orders, subpoenas, or lawful requests from government authorities.
  • Protect the rights, property, and safety of Cafe Rio, our customers, employees, and the public.

4. How We Share Your Information

We do not sell your personal information to third parties for their own independent marketing purposes. However, we may share your information with third parties in the following circumstances:

4.1 Service Providers and Business Partners

We engage trusted third-party companies and individuals to provide services on our behalf, including:

  • Payment Processors: Companies that handle payment transactions securely on our behalf (e.g., Stripe, Square, or similar providers).
  • Delivery Services: Third-party delivery companies or platforms that fulfill delivery orders placed through our Site.
  • Email and Marketing Platforms: Service providers that manage our email marketing campaigns and customer communications.
  • Web Hosting and IT Providers: Companies that host our website infrastructure and provide technical support.
  • Analytics Providers: Tools such as Google Analytics that help us understand website traffic and usage patterns.
  • Customer Support Tools: Platforms that assist us in managing customer inquiries and support tickets.

These service providers are authorized to use your personal information only to the extent necessary to provide their services to us and are contractually obligated to protect your information with appropriate security measures.

4.2 Legal Requirements and Law Enforcement

We may disclose your personal information if required to do so by law or in the good-faith belief that such disclosure is necessary to:

  • Comply with a legal obligation, court order, or governmental request.
  • Enforce our Terms of Service or other applicable policies.
  • Protect and defend the rights or property of Cafe Rio.
  • Prevent or investigate possible wrongdoing in connection with our services.
  • Protect the personal safety of users of our services or the public.

4.3 Business Transfers

In the event that Cafe Rio undergoes a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our business assets, your personal information may be transferred to the acquiring entity or successor. We will notify you of any such change by posting a notice on our Site and/or sending you an email, and we will inform you of any choices you may have regarding your information.

4.4 With Your Consent

We may share your personal information with other third parties with your explicit consent, or at your direction, in ways not described in this Privacy Policy.


5. Data Security

Cafe Rio takes the security of your personal information seriously. We implement a range of technical, administrative, and physical security measures designed to protect your information from unauthorized access, use, alteration, disclosure, or destruction. These measures include:

  • Encryption: Our Site uses Secure Socket Layer (SSL) / Transport Layer Security (TLS) encryption to protect data transmitted between your browser and our servers.
  • Access Controls: Access to personal information is restricted to authorized personnel who require it to perform their job functions. We use role-based access controls and require strong password management.
  • Secure Payment Processing: All payment transactions are processed through PCI-DSS compliant third-party payment processors. We do not store full credit card numbers on our servers.
  • Regular Security Assessments: We conduct periodic security reviews and assessments of our systems and practices to identify and address potential vulnerabilities.
  • Data Minimization: We collect only the personal information that is necessary for the purposes described in this policy and do not retain it for longer than needed.
  • Employee Training: Our staff members receive training on data protection best practices and our internal privacy policies.

Despite our best efforts, no method of data transmission over the Internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected individuals and relevant authorities as required by applicable law.


6. Your Privacy Rights

Depending on your location and applicable law, you may have certain rights with respect to your personal information. We are committed to honoring these rights. The specific rights available to you may include:

6.1 Right to Know / Access

You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, the purposes for which it is used, and the categories of third parties with whom we share it.

6.2 Right to Correction / Rectification

You have the right to request that we correct any inaccurate or incomplete personal information we hold about you. You may also update certain information directly through your account settings on our Site.

6.3 Right to Deletion

You have the right to request that we delete personal information we have collected from you, subject to certain exceptions (such as where retention is required by law, necessary to complete a transaction, or necessary for legitimate business purposes).

6.4 Right to Data Portability

Where technically feasible, you have the right to receive a copy of the personal information you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that information to another service provider.

6.5 Right to Opt Out of Sale or Sharing (CCPA/CPRA)

Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents have the right to opt out of the "sale" or "sharing" of their personal information. While we do not sell personal information in the traditional sense, we may engage in data practices that could be considered "sharing" for cross-context behavioral advertising purposes. You may opt out of such sharing by contacting us at [email protected].

6.6 Right to Limit Use of Sensitive Personal Information (CPRA)

California residents have the right to limit our use and disclosure of sensitive personal information (such as precise geolocation data, health and financial information) to uses that are necessary to perform the services you have requested or as otherwise permitted by law.

6.7 Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights. We will not deny you goods or services, charge you different prices, provide a lower quality of service, or otherwise penalize you for exercising your rights under applicable privacy law.

6.8 How to Submit a Privacy Rights Request

To exercise any of the rights described above, please contact us at:

Email: [email protected]
Website: caferiomexican.top

We will verify your identity before processing your request to protect your information. We may ask you to provide additional information to confirm your identity, such as your name and email address associated with your account. We will respond to verified requests within 45 days, or as otherwise required by applicable law. In some cases, we may need to extend this period, in which case we will notify you of the extension and the reason for it.

You may designate an authorized agent to submit a privacy rights request on your behalf. Authorized agents must provide written proof of authorization, and we may still require you to verify your own identity directly.


7. Cookie Usage

Our Site uses cookies and similar tracking technologies (such as web beacons, pixel tags, and local storage) to enhance your browsing experience, analyze website traffic, and deliver relevant marketing content. Cookies are small text files that are placed on your device when you visit a website.

We use the following types of cookies:

Cookie Type Purpose
Strictly Necessary Cookies Essential for the operation of our Site, including enabling you to log in, place orders, and navigate the Site securely.
Performance / Analytics Cookies Collect anonymous information about how visitors use our Site, helping us improve functionality and user experience.
Functionality Cookies Remember your preferences (such as your location, language, or past orders) to provide a more personalized experience.
Marketing / Advertising Cookies Track your browsing behavior to deliver targeted advertisements and promotional content relevant to your interests.

You can control and manage cookies through your browser settings. Most browsers allow you to block, delete, or restrict cookies. However, please be aware that disabling certain cookies may affect the functionality of our Site and your ability to use certain features. For more detailed information about our use of cookies, please refer to our Cookie Policy, which is available on our website at caferiomexican.top.


8. Data Retention

We retain your personal information for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our specific data retention practices are as follows:

  • Account Information: We retain account information for as long as your account remains active, plus a reasonable period thereafter to allow for account reactivation or to resolve any outstanding issues. If you delete your account, we will delete or anonymize your personal information within 90 days, unless retention is required by law.
  • Order and Transaction Data: We retain order and payment records for a minimum of seven (7) years for accounting, tax, and legal compliance purposes, as required by applicable United States tax laws and regulations.
  • Marketing Data: We retain marketing preferences and communication history for as long as you remain subscribed to our communications or for up to three (3) years after your last interaction with us, whichever comes first.
  • Usage and Analytics Data: Aggregated and anonymized analytics data may be retained indefinitely as it does not identify individual users.
  • Legal and Compliance Records: Records required for legal compliance purposes will be retained for the minimum period required by applicable law.

Upon expiration of the applicable retention period, we will securely delete or anonymize your personal information. If deletion is not immediately possible (for example, because your information has been stored in backup archives), we will isolate your information from further processing and delete it as soon as it becomes possible to do so.


9. Children's Privacy

Our Site and services are not directed to individuals under the age of 18. We do not knowingly collect, use, or disclose personal information from children under 18 years of age. By using our Site, you represent and warrant that you are at least 18 years old.

If you are a parent or legal guardian and believe that your child under the age of 18 has provided us with personal information without your consent, please contact us immediately at [email protected]. We will investigate the matter and, if confirmed, take steps to delete the child's information from our records as promptly as possible.

We comply with the Children's Online Privacy Protection Act (COPPA), which prohibits the collection of personal information from children under the age of 13 without verified parental consent. As our services are intended for adults only, we do not target our marketing or services to minors.


10. International Data Transfers

Cafe Rio is based in the United States and primarily processes personal information within the United States. However, some of our third-party service providers, including analytics platforms, cloud hosting providers, and email marketing tools, may operate in or transfer data to countries outside the United States.

If we transfer your personal information to other countries, we will ensure that appropriate safeguards are in place to protect your information, such as entering into data processing agreements with our service providers that incorporate standard contractual clauses or other lawful transfer mechanisms.

Please be aware that the data protection laws of other countries may differ from those in your home country, and may provide different levels of protection. By providing us with your personal information and using our services, you acknowledge and consent to the potential transfer of your information to countries outside your country of residence, including the United States, in accordance with this Privacy Policy.


11. Third-Party Links and Services

Our Site may contain links to third-party websites, applications, or services that are not owned or operated by Cafe Rio. These links are provided for your convenience and informational purposes only. We are not responsible for the privacy practices, content, or security of these third-party sites.

We encourage you to review the privacy policies of any third-party sites you visit. The inclusion of a link on our Site does not imply our endorsement of the linked site or its operators. Your interactions with third-party sites are governed solely by the terms and privacy policies of those sites.

Additionally, third-party services embedded in our Site (such as social media sharing buttons, embedded maps, or online ordering platforms) may collect information about your interactions with those features, independent of our data collection. We recommend reviewing the privacy practices of these third-party providers directly.


12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA), which became effective January 1, 2023. These rights include:

  • Right to Know: The right to know what personal information we have collected, used, disclosed, and sold about you over the past 12 months.
  • Right to Delete: The right to request the deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to Correct: The right to request correction of inaccurate personal information we maintain about you.
  • Right to Opt-Out: The right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: The right to limit the use and disclosure of sensitive personal information.
  • Right to Non-Discrimination: The right not to be discriminated against for exercising your CCPA/CPRA rights.

To exercise your California privacy rights, please contact us at [email protected]. We will verify your identity and respond within the timeframes required by California law (generally 45 days, with the possibility of a 45-day extension where reasonably necessary).

Do Not Sell or Share My Personal Information: California residents may also exercise their right to opt out of the sale or sharing of their personal information. If you wish to exercise this right, please contact us directly at the email address above.


13. Nevada Privacy Rights

Nevada residents have the right to opt out of the sale of their personal information to third parties under Nevada Revised Statutes Chapter 603A. We do not sell personal information as defined under Nevada law; however, if you are a Nevada resident and wish to make such a request, you may contact us at [email protected].


14. How to File a Complaint

If you have concerns about our privacy practices or believe we have not complied with this Privacy Policy or applicable data protection laws, we encourage you to first contact us directly so we can address your concerns:

Email: [email protected]
Website: caferiomexican.top

We will make every effort to resolve your complaint promptly and fairly. If you are not satisfied with our response or believe we are not processing your personal information in accordance with applicable law, you may file a complaint with the relevant data protection authority.

In the United States, privacy matters related to unfair or deceptive trade practices may be reported to:

Depending on your state of residence, other state attorneys general offices may also have jurisdiction to address privacy-related complaints. We encourage you to consult your applicable state's consumer protection resources.


15. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes to this policy, we will:

  • Post the updated Privacy Policy on our Site with a new effective date prominently displayed at the top of the page.
  • Notify registered users via email of significant changes, where required by applicable law.
  • Where required, seek your consent before applying material changes to the way we process your personal information.

Your continued use of our Site and services after the posting of any updated Privacy Policy constitutes your acknowledgment of and agreement to the updated terms. We encourage you to review this page regularly to stay informed about our privacy practices.


16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us. We are committed to working with you to resolve any privacy-related issues:

Our privacy team will endeavor to respond to all inquiries within a reasonable timeframe, and in any event within the timeframes required by applicable law. When contacting us regarding a privacy rights request, please include sufficient information for us to verify your identity and locate your records in our system.

We value your trust and are committed to being a transparent and responsible steward of your personal information. Thank you for choosing Cafe Rio.