Back to Legal & Privacy

Privacy Notice

Effective date: August 16, 2026 · Version 1.0

1. Who we are and scope

TECHSTRIDE S.A. de C.V. ("Striq"), with address at Avenida Bosques del Valle 214, San Pedro Garza García, Nuevo León, Mexico. That address is the domicile referred to as our "registered domicile" in the other Striq legal documents.

This notice describes information handled through Striq websites, restaurant manager accounts, support and lead forms, guest ordering, pickup ordering, receipts, and related local storage. It applies to visitors, restaurant merchants, restaurant staff, and guests.

2. Information we handle

Depending on how you use Striq, we may handle the following categories:

  • Merchant and account information, such as name, email, business and restaurant details, team access, preferences, and account security records.
  • Support and lead information, such as messages, contact details, business context, and communications you choose to send us.
  • Guest and order information, such as a table or session identifier, guest name when provided, order contents, modifiers, staff calls, pickup details, receipt email, order status, and operational notes.
  • Device and local-storage information used to keep a menu language, pickup history, session continuity, or privacy choice on the device. Local storage may remain until it expires or is cleared on the device.
  • Technical and security information, such as IP address, browser and device signals, timestamps, logs, and events needed to operate and protect the service.
  • Advertising and measurement information for the Striq marketing site and merchant signup, such as records of pages viewed and actions taken, advertising cookie identifiers, and a hashed version of an email address you give us. We handle this category only where you have allowed advertising, and it includes conversion events we send from our own servers about trial signups and subscription payments.
  • Limited billing information from payment providers. Striq does not store full card numbers or bank account details.

3. Food and guest-order roles

The restaurant that publishes a menu and receives an order is the controller (or equivalent responsible party) for guest-order data and for the restaurant’s food-service operations. TECHSTRIDE acts as the restaurant’s processor or service provider for that guest-order data under the restaurant’s instructions and the Data Processing Addendum. The restaurant remains responsible for its own notices, lawful instructions, menu, allergen information, fulfillment, refunds, and responses to guests.

4. Purposes and choices

Primary purposes are to provide menus, ordering, pickup, table-session, receipt, support, account, security, and billing features; authenticate and protect accounts; communicate service and legal notices; troubleshoot; prevent abuse; comply with law; and maintain records needed for disputes and audits. These purposes are necessary for the service or the relevant relationship.

Optional analytics and advertising measurement are secondary purposes. Where consent is required, these technologies remain off until you choose to allow them. You may refuse or later withdraw that optional choice through Privacy Choices without losing the core service. We do not intentionally request sensitive personal information. Please do not place sensitive personal information in order notes, support messages, or other free-text fields.

5. Service providers and international processing

We may use infrastructure and service providers, such as Supabase for database and authentication infrastructure, Stripe for merchant billing, and Resend for transactional email. These providers act under our instructions. Processing may occur in countries other than where you live, subject to appropriate contractual, technical, or legal safeguards where required.

Where you allow advertising on our marketing site, we also share measurement information with Meta Platforms, Inc. and, if we enable it, Google LLC. Those companies act as independent controllers for their own advertising purposes under their own policies, not as our processors; section 6 describes what is shared. We do not sell personal information for money. Sharing advertising identifiers for cross-context behavioural advertising may still count as a “sale” or “share” under some laws, including in California. You can stop it at any time through Privacy Choices, and refusing it does not affect the service.

6. Cookies, local storage, analytics, and advertising

Striq uses strictly necessary technologies for site operation, language, security, authentication, and privacy choices. Optional analytics and advertising technologies load only after the matching choice, and you can change that choice at any time through the Privacy Choices control.

Where you allow analytics, Google Analytics loads through Google Tag Manager and sets its own cookies, such as _ga. Where you allow advertising, the Meta pixel loads and sets _fbp and _fbc. In that case we may also send Meta a hashed version of an email address you give us so it can match the activity to an account, and we may send conversion events about trial signups and subscription payments from our own servers rather than from your browser. Those server-side events follow the same choice: if you refuse or later withdraw advertising consent, we do not send them.

Restaurant-controlled guest ordering may use local storage for the functions described above; it is not a promise of permanent device storage.

7. Retention and deletion

We keep information for as long as needed for the purposes described here, the merchant’s instructions, service operations, security, legal obligations, accounting, and dispute resolution. Retention varies by data type and context. You may ask the restaurant about guest-order data, or contact us about data we control. We will assess and handle deletion or other requests subject to applicable law, legal retention, backup cycles, and the restaurant’s instructions; this notice does not promise a fixed deletion deadline.

8. ARCO, withdrawal, and limits on use

If Mexican privacy law applies, you may exercise ARCO rights (access, rectification, cancellation, and opposition), withdraw consent where consent is the legal basis, or ask to limit use or disclosure by emailing contact@striq.net with the subject “Privacy request.” State your name, the right or limitation requested, the relationship or restaurant involved, an email for our response, and information reasonably needed to locate the records. We may request proportionate proof of identity or authority before disclosing or changing data.

We will communicate our determination within the period required by applicable law and, if the request is granted, carry it out within the additional applicable period, subject to lawful extensions and exceptions. For guest-order data processed for a restaurant, we may forward or coordinate the request with the relevant restaurant controller. Cancellation or deletion may be limited by legal retention, security, backup, contractual, or dispute-preservation duties. Optional analytics and advertising choices can also be changed directly through Privacy Choices.

9. Disclosures and transfers

We disclose information to processors and service providers acting under instructions for hosting, authentication, billing, email, support, security, monitoring, and similar operations. We may also disclose information when required by a competent authority, to protect legal rights or service security, or in a corporate transaction subject to applicable safeguards. Where a transfer requires consent, we will request it or rely on an applicable legal exception. Merchant-controlled guest-order data is shared with the relevant restaurant because that is necessary to fulfill the requested restaurant workflow.

10. Security and incidents

We use technical and organizational safeguards appropriate to the service, including encrypted connections, access controls, server-side authorization, logging, and operational controls. No system is completely secure. If we identify an incident affecting information, we will investigate, take reasonable containment and remediation steps, and cooperate with the relevant restaurant and authorities as required.

11. Children

Striq is not directed to children. We do not intentionally collect information from children. A restaurant may have its own obligations for guests and ordering; please contact the restaurant if a child’s information was entered by mistake.

12. Changes and contact

This version is 1.0 and is effective August 16, 2026. We may update this notice prospectively to reflect service, legal, or operational changes. We will publish the new version and effective date at this same legal location and provide additional notice when required. Questions and privacy requests can be sent to contact@striq.net.

TECHSTRIDE S.A. de C.V. ("Striq").