Privacy Policy
Last updated September 12, 2026
If & When Events (“we”, “us”) runs an ordering and event platform for food businesses: the storefront websites customers order from, the tools event organizers use to run markets, and the operator app vendors and organizers use to manage their orders. This policy explains what information the platform collects, what happens to it, and the choices you have. It applies to ifandwhenevents.com, the storefronts we host for businesses, and the If & When Events operator app for iOS and Android.
Who is responsible for your information
Two kinds of organizations handle information on this platform:
- The business you order from — a food vendor or an event organizer — decides what it needs from you to fill your order, run its event, or contact you. We store and process that information on its behalf and follow its instructions, and each business’s data is kept in its own separate partition of our database.
- We are responsible for the information tied to the platform itself: operator and organizer accounts, business registrations, acceptance of the platform terms, and the technical logs that keep the service running.
If you have a question about how a business uses your information, contact that business. If you can’t reach them, or your question is about the platform, contact us (see Contact us).
What we collect
Customers ordering from a storefront
- Your name and email address, so the business can fill your order and send you a confirmation.
- Your mobile number, only if you enter it and opt in to text updates about your order.
- What you ordered, any special instructions you type, and the pickup, table, or delivery details for the order.
- Payment confirmation from our payment processor. Card details are entered directly with Square or Stripe and never pass through our servers; we receive a payment token and the result.
- If you create a customer account: your login email and password (stored only as a one-way hash), your order history, and your notification preferences.
Operators and organizers (people who run a business on the platform)
- The account details you register with: name, email, phone number, role, and your business’s name and contact details.
- What you do in the admin tools and the operator app: your menu, orders, events, staffing, settings, and the payment, messaging and point-of-sale integrations you connect.
Everyone
- Standard technical information sent by your browser or device: IP address, browser or app version, device type, and the pages or screens requested. We keep these in our own server logs, scrubbed of passwords and tokens.
- If something breaks on the web, a report of the error — the message, where it happened, your browser type and a random session identifier — goes to our own logging server. Passwords, tokens and cookies are removed from it before it leaves your browser.
What the operator app stores on your device
The operator app is built to keep as little as possible on the phone:
- Your sign-in token and basic account identity are stored in the operating system’s secure keychain (iOS) or keystore (Android), never in plain files.
- Actions you take while offline — for example, updating an order — wait in an offline queue until the app reconnects. That queue is encrypted on the device with AES-256-GCM, and the encryption key lives in the secure keychain or keystore.
- Cached lists of orders and events keep only operational fields: identifiers, status, totals and times. Customer names, contact details and special instructions are not written to the cache; the app fetches them live when you open the record.
- Cart contents and an anonymous session identifier, which contain no personal information.
What leaves the device: your sign-in credentials when you log in, the orders and events you work on (sent to our servers), your push notification token (see below), and crash reports (see below). Logging out clears the stored token and identity; deleting your account clears the caches as well.
Crash and diagnostic reports
The operator app sends crash and error reports to Sentry, a crash-reporting service, so we can find and fix bugs. Before a report leaves the device we strip personal information from it:
- The user record is reduced to an opaque account identifier — no email, username or IP address is sent.
- Request headers, cookies, request bodies and query strings are removed, and the bodies of network breadcrumbs are dropped.
- Email addresses, phone numbers and authentication tokens are redacted from any extra context attached to the report.
Sentry’s option to send default personal data is switched off. The web app does not use Sentry; browser errors go to our own logging server, as described above.
Push notifications
If you allow notifications in the operator app, the app registers a push token for your device with our servers so we can alert you to new orders, tasks and events for your business. The token is tied to your account and your role, is used only to deliver those alerts, and is deleted from our servers when you log out of the app. You can withdraw permission at any time in your phone’s notification settings.
Text messages and email
Customers receive text updates about an order only after opting in — at checkout, or from the notification preferences on the account page — and can turn them off again from the same place. Texts are sent through Twilio on behalf of the business you ordered from, and if you reply, your reply is delivered to that business. Order confirmations, password resets and invitations are sent by email; these are transactional messages about something you asked for, not marketing.
Payments
Card payments are processed by Square or Stripe, depending on which processor the business has connected. You enter your card details directly into the processor’s secure form on our site; the card number never reaches our servers. We store the amount, the payment status, a reference to the processor’s transaction, and any refunds. Businesses that connect a Toast point-of-sale system have their orders pushed to Toast so the kitchen can work from one screen; Toast receives the order contents, not your payment details.
Deleting your account
Operators and organizers can delete their own account from inside the operator app (Account → Delete account) or on the web (Admin → Settings → Delete account). When you confirm:
- your name, phone number and email are anonymized immediately and your login is disabled;
- your current session is revoked, and any saved sign-in on your devices stops working;
- the business’s order and financial records are retained, with your personal details removed, so the business keeps an accurate history for accounting and legal purposes.
Deletion is permanent. If you are the only owner of a business account, you will be asked to transfer ownership or close the business first, so the business is not left without an owner.
Customers who want their account or order information deleted can ask the business they ordered from, or email us; we will pass the request to the business and handle any platform-level records ourselves.
How long we keep information
We keep your account information for as long as your account is active. Orders and payment records are kept for as long as the business needs them for its books and legal obligations; when an account is deleted, the personal details on those records are anonymized as described above. Server logs and error reports are kept for a limited time to operate and troubleshoot the service.
Security
All traffic uses HTTPS. Passwords are stored as one-way hashes. The credentials a business uses to connect payment, messaging and point-of-sale providers are encrypted at rest. Each business’s data lives in its own database partition, and every request is checked against the business it belongs to. Sign-in tokens are short-lived (they expire after 30 minutes) and are revoked when you delete your account; logging out discards them.
Your choices
- Text updates: opt in or out at checkout or on your account page.
- Push notifications: control them in your phone’s settings; logging out of the operator app also removes the token.
- Access, correction or deletion: email us. Requests about a business’s customer records are forwarded to that business.
- Cookies and tracking: we do not use advertising cookies or third-party analytics on the web app. Sign-in state on the web is kept in your browser’s storage — in local storage if you tick “Remember me”, otherwise only for the current tab — until you log out. Our demo (staging) environment sets one cookie to remember a redeemed invitation code.
Children
The platform is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has provided information to us, contact us and we will delete it.
Changes to this policy
When our data practices change, we update this page and the date at the top.
Contact us
Questions, requests or concerns about this policy: support@ifandwhenevents.com.
