Privacy Policy
Welcome to Costa Vida. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website food-costavida.rest, place orders, or interact with our services in any way. Please read this policy carefully. If you disagree with its terms, please discontinue use of our site and services.
This Privacy Policy applies to all information collected through our website, mobile applications, and any related services, sales, marketing, or events (collectively, the "Services"). By using our Services, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy.
1. About Us
Costa Vida is a food service business operating in the United States. We are dedicated to providing our customers with high-quality food experiences. Your trust is important to us, and we take the protection of your personal data seriously.
| Company Name | Costa Vida |
|---|---|
| Website | food-costavida.rest |
| [email protected] |
For any questions or concerns about this Privacy Policy or our data practices, please contact us using the details listed above or refer to the Contact Us section at the end of this document.
2. Information We Collect
We collect various types of information in connection with the Services we provide. The categories of information we collect include, but are not limited to, the following:
2.1 Personal Information You Provide Directly
When you interact with our Services — including placing an order, creating an account, signing up for our newsletter, participating in promotions, or contacting us — you may voluntarily provide us with personal information, including:
- Identification Data: Full name, username, or similar identifiers.
- Contact Data: Email address, mailing address, billing address, phone number.
- Account Credentials: Password and other security information used for authentication.
- Payment Data: Credit card numbers, debit card information, billing details, and other financial information necessary to process your transactions. Note: Payment information is processed by third-party payment processors and is not stored directly on our servers.
- Order Information: Details about the food items you ordered, delivery preferences, special dietary requests, and order history.
- Communications Data: Any messages, feedback, reviews, or other content you submit to us via email, contact forms, or customer service channels.
- Marketing Preferences: Your preferences for receiving marketing from us and your communication preferences.
2.2 Information Collected Automatically
When you visit our website or use our Services, certain information is collected automatically through cookies, web beacons, log files, and similar tracking technologies. This information may include:
- Usage Data: Pages you visit, links you click, features you use, search queries you enter, and your interactions with our website.
- Log Data: Internet Protocol (IP) address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our site.
- Device Information: Hardware model, unique device identifiers, mobile network information, and device settings.
- Location Data: General geographic location based on your IP address. With your consent, we may also collect more precise location data to provide delivery services or locate nearby restaurants.
- Cookie and Tracking Data: Information collected via cookies, pixel tags, web beacons, and similar tracking technologies. Please see our Cookie Usage section (Section 8) for more details.
- Referral Data: The URL of the website that referred you to our site, if applicable.
2.3 Information From Third Parties
We may receive information about you from third parties, including:
- Social Media Platforms: If you choose to connect your social media account (such as Facebook, Google, or Instagram) to our Services, we may receive certain profile information from those platforms, including your name, email address, profile picture, and friend list, depending on the permissions you grant.
- Business Partners and Delivery Services: Third-party food delivery platforms, loyalty program partners, or other business partners who share your information with us to fulfill orders or provide joint services.
- Analytics Providers: We may receive aggregated or de-identified data from analytics companies that help us understand how users interact with our Services.
- Advertising Networks: Information from advertising networks that help us understand which of our marketing campaigns were effective.
3. How We Use Your Information
We use the information we collect for a variety of business and operational purposes. Specifically, we may use your information to:
3.1 Provide and Manage Our Services
- Process and fulfill your food orders, including delivery and payment processing.
- Create and manage your account on our website or app.
- Communicate with you about your orders, reservations, or inquiries.
- Send you transactional messages such as order confirmations, receipts, and delivery updates.
- Provide customer support and respond to your requests, questions, and complaints.
3.2 Improve and Personalize Our Services
- Analyze usage patterns and preferences to improve our website, menu offerings, and overall customer experience.
- Personalize your experience and deliver content, recommendations, and offers tailored to your interests and past orders.
- Conduct research and development to improve our products and services.
- Test new features, functionality, and user interfaces.
3.3 Marketing and Promotional Communications
- Send you marketing emails, newsletters, promotional offers, and information about new menu items, special deals, or events — but only where you have given us permission or where we have a legitimate business interest and applicable law allows us to do so.
- Display targeted advertising on third-party platforms based on your interests and behavior.
- Administer contests, promotions, surveys, and loyalty programs.
- Measure the effectiveness of our marketing campaigns.
You may opt out of receiving marketing communications from us at any time by clicking the "unsubscribe" link in any email we send, adjusting your account settings, or contacting us directly at [email protected].
3.4 Legal Compliance and Safety
- Comply with applicable federal, state, and local laws and regulations, including those governing food safety, consumer protection, and data privacy.
- Enforce our Terms of Service and other agreements.
- Detect, investigate, and prevent fraudulent transactions, unauthorized access, and other illegal activities.
- Protect the rights, property, or safety of Costa Vida, our customers, or others.
- Respond to legal requests, court orders, and government investigations.
4. Legal Basis for Processing (United States)
Costa Vida operates in the United States and complies with applicable U.S. federal and state privacy laws, including but not limited to:
- The Federal Trade Commission (FTC) Act, which prohibits unfair or deceptive practices, including misrepresentations about data privacy and security.
- The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), which grants specific rights to California residents regarding their personal information.
- Other applicable state privacy laws, including those enacted in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and other states that have enacted comprehensive privacy legislation.
- The Children's Online Privacy Protection Act (COPPA), which governs the collection of personal information from children under 13.
- The CAN-SPAM Act, governing commercial email communications.
We process your personal information based on one or more of the following grounds: your consent, the performance of a contract with you, our legitimate business interests, or compliance with a legal obligation.
5. Sharing Your Information With Third Parties
We do not sell your personal information to third parties for their own direct marketing purposes without your explicit consent. However, we may share your information in the following circumstances:
5.1 Service Providers and Business Partners
We engage trusted third-party companies and individuals to perform functions and provide services on our behalf. These may include:
- Payment processors and financial institutions to handle transactions securely.
- Delivery service providers who fulfill and ship your orders.
- Cloud hosting and IT infrastructure providers who store and process data on our behalf.
- Email marketing platforms used to send promotional communications.
- Analytics companies who help us understand user behavior and improve our Services.
- Customer relationship management (CRM) software providers.
- Advertising networks and social media platforms for targeted advertising campaigns.
All service providers are contractually obligated to use your personal information only as directed by us and in accordance with this Privacy Policy. They are prohibited from using or disclosing your information for any other purpose.
5.2 Legal Requirements and Law Enforcement
We may disclose your information if required to do so by law or in response to valid legal processes, including:
- Complying with a court order, subpoena, or other legal obligation.
- Responding to requests from law enforcement or government authorities.
- Protecting and defending the legal rights or property of Costa Vida.
- Investigating suspected fraud or security breaches.
- Acting in urgent circumstances to protect the personal safety of users or the public.
5.3 Business Transfers
In the event that Costa Vida undergoes a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of its assets, your personal information may be transferred to the acquiring entity as part of that transaction. We will notify you via email and/or a prominent notice on our website of any such change in ownership or use of your personal information, and of any choices you may have regarding your information.
5.4 With Your Consent
We may share your information with third parties for purposes not described in this Privacy Policy when we have your explicit consent to do so.
6. Data Security
We take the security of your personal information very seriously. We implement a variety of industry-standard technical, administrative, and physical security measures designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption: All data transmitted between your browser and our servers is encrypted using Secure Socket Layer (SSL) / Transport Layer Security (TLS) technology.
- Access Controls: Access to personal information is restricted to employees and service providers who need it to perform their job functions. All authorized personnel are bound by confidentiality obligations.
- Firewalls and Intrusion Detection: We employ firewalls, intrusion detection systems, and other network security technologies to protect our infrastructure.
- Data Minimization: We collect only the information necessary to fulfill the purposes outlined in this Privacy Policy.
- Regular Security Audits: We conduct periodic reviews and assessments of our security practices to identify and address vulnerabilities.
- Payment Security: Payment card information is processed through PCI-DSS compliant payment processors. We do not store full credit card numbers on our servers.
Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach that may compromise your personal information, we will notify you in accordance with applicable federal and state breach notification laws, including those applicable in the state(s) where we operate.
7. Your Privacy Rights
Depending on where you reside, you may have certain rights with respect to your personal information. We honor all applicable rights under U.S. federal and state law.
7.1 Rights Available to All Users
- Right to Access: You may request a copy of the personal information we hold about you.
- Right to Correction: You may request that we correct inaccurate or incomplete personal information we hold about you.
- Right to Deletion: You may request that we delete your personal information, subject to certain legal exceptions (e.g., where we are required to retain it by law or for legitimate business purposes).
- Right to Opt-Out of Marketing: You may opt out of receiving marketing communications from us at any time.
7.2 Additional Rights for California Residents (CCPA/CPRA)
California residents have the following additional rights under the CCPA and CPRA:
- Right to Know: The right to know what categories of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to Data Portability: The right to receive a copy of your personal information in a portable, machine-readable format.
- Right to Opt-Out of Sale/Sharing: The right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: The right to limit the use and disclosure of sensitive personal information (such as precise geolocation, financial data, or health information) to what is necessary to perform the services you requested.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights. We will not deny you goods or services, charge you different prices, or provide a different quality of service because you exercised your rights under the CCPA/CPRA.
7.3 How to Exercise Your Rights
To exercise any of your privacy rights, please submit a request to us by:
- Email: [email protected]
- Website: food-costavida.rest (via our Contact page)
We will respond to your request within the timeframe required by applicable law — generally within 45 days for most state privacy laws, or within 45 business days under the CCPA/CPRA. We may request that you verify your identity before processing certain requests to protect your security. We will not fulfill a request if we cannot verify your identity or authority to make the request.
If you have an authorized agent making a request on your behalf, we may require documentation confirming the agent's authority to act on your behalf.
8. Cookie Usage
Our website uses cookies and similar tracking technologies (such as web beacons, pixel tags, and local storage) to enhance your browsing experience, analyze site traffic, and deliver personalized content and advertisements.
8.1 Types of Cookies We Use
| Cookie Type | Purpose |
|---|---|
| Essential / Strictly Necessary | Required for the basic operation of our website, such as maintaining your session, processing orders, and enabling secure login. These cannot be disabled. |
| Performance / Analytics | Help us understand how visitors interact with our website by collecting anonymous usage data (e.g., Google Analytics). |
| Functional | Enable enhanced functionality and personalization, such as remembering your preferences, language settings, and past orders. |
| Marketing / Advertising | Used to track visitors across websites and display relevant advertisements based on your interests and browsing history. |
8.2 Managing Cookie Preferences
Most web browsers allow you to control cookies through their settings. You may set your browser to refuse cookies or alert you when cookies are being sent. However, if you disable certain cookies, some features of our website may not function properly.
For more detailed information about the specific cookies we use and how to manage your preferences, please refer to our full Cookie Policy, available on our website at food-costavida.rest.
9. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including to comply with our legal, accounting, and reporting obligations, resolve disputes, and enforce our agreements. The specific retention periods we apply depend on the type of data and the purpose for which it is used:
| Data Category | Retention Period |
|---|---|
| Account and registration information | Duration of your account plus 3 years after account closure |
| Order and transaction records | 7 years (to comply with tax and financial record-keeping requirements) |
| Customer support communications | 3 years from the date of the interaction |
| Marketing preferences and consent records | Until you opt out or withdraw consent, plus 2 years |
| Analytics and usage data | Up to 26 months in aggregated or de-identified form |
| Security and fraud prevention logs | Up to 2 years |
When personal information is no longer needed for the purposes for which it was collected, and we have no legal obligation to retain it, we will securely delete or anonymize it in accordance with our data destruction procedures.
10. Children's Privacy
Our Services are intended for individuals who are 18 years of age or older. Costa Vida does not knowingly collect, solicit, or process personal information from children under the age of 13 without verifiable parental consent, in compliance with the Children's Online Privacy Protection Act (COPPA).
We do not knowingly target or market our Services to children. If we learn that we have inadvertently collected personal information from a child under the age of 13, we will take immediate steps to delete that information from our records.
If you are a parent or guardian and you believe your child has provided us with personal information without your consent, please contact us immediately at [email protected] so that we can take appropriate action.
Users between the ages of 13 and 17 may only use our Services with the direct supervision and consent of a parent or legal guardian. By allowing a minor to use our Services, you agree to the terms of this Privacy Policy on behalf of that minor.
11. International Data Transfers
Costa Vida is based in the United States, and your personal information is primarily collected, stored, and processed within the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to and stored in the United States, where data protection laws may differ from those in your country of residence.
By using our Services, you acknowledge and consent to the transfer of your personal information to the United States. We take steps to ensure that any international transfers of personal data are conducted in compliance with applicable laws and that appropriate safeguards are in place to protect your information.
If you are located in a jurisdiction with stricter data transfer requirements (such as the European Economic Area), please contact us at [email protected] for information about the specific safeguards we have in place for such transfers.
12. Third-Party Links and Services
Our website may contain links to third-party websites, applications, or services that are not owned or controlled by Costa Vida. These may include social media platforms, delivery service apps, payment processors, and promotional partners. This Privacy Policy applies solely to information collected by Costa Vida and does not govern the privacy practices of third parties.
We encourage you to review the privacy policies of any third-party websites or services you visit or use. Costa Vida is not responsible for the privacy practices, content, or security of third-party websites or services.
13. Do Not Track Signals
Some web browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want your online activity tracked. Currently, there is no uniform standard for recognizing and implementing DNT signals. At this time, Costa Vida does not respond to browser DNT signals. However, you can manage cookie and tracking preferences through your browser settings or by contacting us directly.
We will continue to monitor developments regarding DNT standards and update this policy if our practices change.
14. How to File a Complaint
We take privacy complaints seriously. If you have concerns about how we handle your personal information, we encourage you to contact us first so that we can address your issue directly.
14.1 Contact Us
To file a privacy complaint or concern with Costa Vida, please contact our privacy team:
- Email: [email protected]
- Website: food-costavida.rest
We will investigate your complaint and respond within a reasonable timeframe, generally within 30 days of receipt.
14.2 Regulatory Complaints
If you are a California resident and believe your rights under the CCPA/CPRA have been violated, you may also file a complaint with:
Website: cppa.ca.gov
The CPPA is responsible for enforcing the CCPA/CPRA and adjudicating consumer complaints.
For general consumer protection complaints regarding deceptive or unfair data practices, you may also contact:
Website: ftc.gov
The FTC enforces the FTC Act, which prohibits unfair or deceptive acts or practices in commerce, including misrepresentations about data privacy and security.
Residents of other states may have the right to file complaints with their respective state attorney general's office or data protection authority. We encourage you to consult the laws applicable in your state for guidance.
15. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by:
- Posting the updated Privacy Policy on our website with a new "Last Updated" date.
- Sending an email notification to the address associated with your account (if you have one).
- Displaying a prominent notice on our website for a reasonable period following the update.
Your continued use of our Services following the posting of any changes constitutes your acceptance of such changes. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to reach out to us. We are committed to addressing your concerns promptly and transparently.
| Company | Costa Vida |
|---|---|
| [email protected] | |
| Website | food-costavida.rest |
Privacy Policy Version: 1.0
Effective Date: May 6, 2026
Governing Law: This Privacy Policy is governed by the laws of the United States, including applicable federal statutes (FTC Act, COPPA, CAN-SPAM Act) and applicable state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).