Privacy Policy
What personal information we collect, why we collect it, and what you can ask us to do with it.
Last updated
1. Introduction
dotbm (“we”, “us”) operates Morsl, the online ordering platform at morsl.food. This policy explains how we handle personal information, in line with the Personal Information Protection Act 2016 (PIPA).
Two different relationships are covered here, and the difference matters. When you visit this website or run a restaurant on Morsl, we decide how your information is used. When you order food from a restaurant using Morsl, the restaurant decides how your order information is used and we handle it on their instructions. Our Data Processing Policy sets that split out in full.
2. Information we collect
When you visit this website
- Technical information your browser sends: IP address, browser and device type, and the pages you view
- What you enter in the demo form: your name, email, restaurant, and how you take orders and payments today. It reaches us by email.
- Anything you choose to tell us when you email us
When you run a restaurant on Morsl
- Business details: restaurant name, address, opening hours, and contact information
- Account details for you and your staff: name, email address, and a hashed password
- Usage information: sign-in times and the actions taken in the dashboard, which we use for support and security
When you order food through Morsl
- Your name and the contact details needed to complete the order, such as a phone number or email address
- The order itself: items, options, notes, and a collection or delivery address where relevant
- Payment confirmation. Card details are entered directly with the restaurant’s payment gateway and are never stored on Morsl’s systems. Payments are processed through the restaurant’s own ecommerce merchant account and settle under its agreement with its bank
3. Why we use it
- To operate the platform and get orders from a phone to a kitchen
- To let restaurants manage their menus, orders, and accounts
- To provide support when something goes wrong
- To keep the platform secure and investigate misuse or fraudulent orders
- To meet our legal, tax, and accounting obligations
- To improve the product, usually from aggregated figures rather than anything that identifies a person
We do not sell personal information, and we do not share it with third parties for their own marketing.
4. Who we share it with
- The restaurant you ordered from. They need your order and contact details to prepare and hand over your food.
- The restaurant’s payment gateway, bank and related payment processors, to take payment and handle refunds and chargebacks.
- The suppliers who host and run the platform (infrastructure and email delivery), each bound to handle the data only as we instruct.
- Authorities, where the law requires it or where it is needed to establish or defend a legal claim.
5. How long we keep it
- Order records: the financial record (what was ordered and what was paid) is kept for seven years, which is what accounting and tax obligations require
- Order details that identify you: your name, phone number, email address and any delivery address are removed from an order after 24 months. The order remains for reconciliation, but it no longer names you.
- Kitchen tablets: a tablet keeps only recent orders it needs to run service, and removes them automatically after seven days
- Restaurant accounts: kept for as long as the account is open, then deleted or anonymised
- Website technical logs: a short retention period, measured in months, for security and diagnostics
6. Keeping it secure
Traffic to and from the platform is encrypted in transit. Passwords are stored hashed, never in a readable form. Access to production data is limited to the people who need it to run the service. No system is perfectly secure, but if a breach affects you we will tell you and the relevant authority as the Personal Information Protection Act 2016 (PIPA) requires.
7. Your rights
Under the Personal Information Protection Act 2016 (PIPA) you can ask us to:
- Tell you what personal information we hold about you
- Correct it if it is wrong
- Delete it, where we have no obligation to keep it
- Stop using it for a particular purpose
Write to hello@morsl.food and we will respond within the statutory period. If your request is about an order you placed with a restaurant, we may need to pass it to that restaurant, since the information is theirs. We will tell you if that happens.
8. Cookies
We use only the cookies and local storage the platform needs to function: keeping you signed in, and holding your basket together while you order. There is no advertising or cross-site tracking on this website. If that ever changes, this policy changes first and you will be asked to consent.
9. Children
Morsl is intended for use by businesses and by adults placing orders. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.
10. Changes to this policy
We will update this policy as the platform develops. The date at the top of this page shows when it last changed; material changes will be communicated to restaurants directly.
11. Contact
dotbm
Privacy enquiries: hello@morsl.food
Web: morsl.food