TECHSTRIDE S.A. de C.V. ("Striq"), with address at Avenida Bosques del Valle 214, San Pedro Garza García, Nuevo León, Mexico. That address is the domicile referred to as our "registered domicile" in the other Striq legal documents.
This notice describes information handled through Striq websites, restaurant manager accounts, support and lead forms, guest ordering, pickup ordering, receipts, and related local storage. It applies to visitors, restaurant merchants, restaurant staff, and guests.
Depending on how you use Striq, we may handle the following categories:
The restaurant that publishes a menu and receives an order is the controller (or equivalent responsible party) for guest-order data and for the restaurant’s food-service operations. TECHSTRIDE acts as the restaurant’s processor or service provider for that guest-order data under the restaurant’s instructions and the Data Processing Addendum. The restaurant remains responsible for its own notices, lawful instructions, menu, allergen information, fulfillment, refunds, and responses to guests.
Primary purposes are to provide menus, ordering, pickup, table-session, receipt, support, account, security, and billing features; authenticate and protect accounts; communicate service and legal notices; troubleshoot; prevent abuse; comply with law; and maintain records needed for disputes and audits. These purposes are necessary for the service or the relevant relationship.
Optional analytics and advertising measurement are secondary purposes. Where consent is required, these technologies remain off until you choose to allow them. You may refuse or later withdraw that optional choice through Privacy Choices without losing the core service. We do not intentionally request sensitive personal information. Please do not place sensitive personal information in order notes, support messages, or other free-text fields.
We may use infrastructure and service providers, such as Supabase for database and authentication infrastructure, Stripe for merchant billing, and Resend for transactional email. These providers act under our instructions. Processing may occur in countries other than where you live, subject to appropriate contractual, technical, or legal safeguards where required.
Where you allow advertising on our marketing site, we also share measurement information with Meta Platforms, Inc. and, if we enable it, Google LLC. Those companies act as independent controllers for their own advertising purposes under their own policies, not as our processors; section 6 describes what is shared. We do not sell personal information for money. Sharing advertising identifiers for cross-context behavioural advertising may still count as a “sale” or “share” under some laws, including in California. You can stop it at any time through Privacy Choices, and refusing it does not affect the service.
Striq uses strictly necessary technologies for site operation, language, security, authentication, and privacy choices. Optional analytics and advertising technologies load only after the matching choice, and you can change that choice at any time through the Privacy Choices control.
Where you allow analytics, Google Analytics loads through Google Tag Manager and sets its own cookies, such as _ga. Where you allow advertising, the Meta pixel loads and sets _fbp and _fbc. In that case we may also send Meta a hashed version of an email address you give us so it can match the activity to an account, and we may send conversion events about trial signups and subscription payments from our own servers rather than from your browser. Those server-side events follow the same choice: if you refuse or later withdraw advertising consent, we do not send them.
Restaurant-controlled guest ordering may use local storage for the functions described above; it is not a promise of permanent device storage.
We keep information for as long as needed for the purposes described here, the merchant’s instructions, service operations, security, legal obligations, accounting, and dispute resolution. Retention varies by data type and context. You may ask the restaurant about guest-order data, or contact us about data we control. We will assess and handle deletion or other requests subject to applicable law, legal retention, backup cycles, and the restaurant’s instructions; this notice does not promise a fixed deletion deadline.
If Mexican privacy law applies, you may exercise ARCO rights (access, rectification, cancellation, and opposition), withdraw consent where consent is the legal basis, or ask to limit use or disclosure by emailing contact@striq.net with the subject “Privacy request.” State your name, the right or limitation requested, the relationship or restaurant involved, an email for our response, and information reasonably needed to locate the records. We may request proportionate proof of identity or authority before disclosing or changing data.
We will communicate our determination within the period required by applicable law and, if the request is granted, carry it out within the additional applicable period, subject to lawful extensions and exceptions. For guest-order data processed for a restaurant, we may forward or coordinate the request with the relevant restaurant controller. Cancellation or deletion may be limited by legal retention, security, backup, contractual, or dispute-preservation duties. Optional analytics and advertising choices can also be changed directly through Privacy Choices.
We disclose information to processors and service providers acting under instructions for hosting, authentication, billing, email, support, security, monitoring, and similar operations. We may also disclose information when required by a competent authority, to protect legal rights or service security, or in a corporate transaction subject to applicable safeguards. Where a transfer requires consent, we will request it or rely on an applicable legal exception. Merchant-controlled guest-order data is shared with the relevant restaurant because that is necessary to fulfill the requested restaurant workflow.
We use technical and organizational safeguards appropriate to the service, including encrypted connections, access controls, server-side authorization, logging, and operational controls. No system is completely secure. If we identify an incident affecting information, we will investigate, take reasonable containment and remediation steps, and cooperate with the relevant restaurant and authorities as required.
Striq is not directed to children. We do not intentionally collect information from children. A restaurant may have its own obligations for guests and ordering; please contact the restaurant if a child’s information was entered by mistake.
This version is 1.0 and is effective August 16, 2026. We may update this notice prospectively to reflect service, legal, or operational changes. We will publish the new version and effective date at this same legal location and provide additional notice when required. Questions and privacy requests can be sent to contact@striq.net.
TECHSTRIDE S.A. de C.V. ("Striq").