Privacy Policy
Effective date: July 5, 2026
1. What we collect
When you place an order we collect your name, email address, and phone number (optional). Payment card details are handled entirely by Square and are never stored on our servers.
2. How we store your data
Account, order, loyalty, and authentication data is stored in Supabase with row-level security enabled so each user can only access their own records. Passwords are hashed by Supabase Auth and are not accessible to ZubesGrub staff.
3. How we use your data
- Process and fulfill your pickup orders via Square.
- Send order confirmations, status updates, loyalty updates, and catering-related notifications via email or SMS.
- Respond to catering inquiries you submit.
- Improve the site and service through aggregated, non-identifying usage data.
4. Third-party services
We share data with the following services only as needed:
- Square -- payment processing. Subject to Square's Privacy Policy.
- Supabase -- database hosting and authentication. Account, order, loyalty, and auth data is stored with row-level security.
- Novu -- may be used to deliver order, status, loyalty, and catering notifications via email or SMS.
We do not sell your personal data. Third-party delivery platforms such as Uber Eats or DoorDash are not currently integrated; if added in the future, this policy will be updated accordingly.
5. Cookies and local storage
We use cookies and browser local storage for authentication sessions and preferences. We do not use third-party advertising trackers.
6. Sandbox and test mode
During development or testing, the site may operate in Square sandbox mode. Any data entered in sandbox mode is used for testing purposes only and is not sent to live payment systems.
7. Admin access
ZubesGrub administrators can view orders, customer accounts, and loyalty data to operate the business. Admin access is restricted to authorized staff.
8. Data retention
We retain your account and order data for as long as your account is active. You may request deletion of your account and associated data by contacting us.
9. Your rights
You may request access to, correction of, or deletion of your personal data at any time by contacting ZubesGrub directly.
10. Children
ZubesGrub is not directed at children under 13. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy at any time. Changes take effect when posted to this page.
12. Contact
Privacy questions can be directed to us through the catering inquiry form or by contacting ZubesGrub directly.