Privacy Policy
Last updated
Who we are and what this policy covers
Sabal Pay LLC, a Florida limited liability company doing business as Wuntab ("Wuntab", "we", "us"), provides Wuntab, a platform for restaurants. Wuntab builds and runs a restaurant's own website and menu, takes online orders for pickup and delivery, routes those orders to the restaurant's kitchen, arranges delivery through a third-party delivery partner, takes payment, and provides the tools the restaurant uses to manage its menu, its orders and its customers. Wuntab also publishes an app on the Clover App Market that connects a restaurant's Clover account to that service.
This policy explains what information we collect, how we use it, and who we share it with. It covers the Wuntab platform, the Wuntab Clover app, and the restaurant storefronts we operate.
We process most of this information on behalf of our customers, who are the restaurants. The restaurant decides what is collected through its storefront and what it is used for. We act on the restaurant's instructions. Where a restaurant has its own privacy policy, that policy governs the restaurant's own handling of its customers' information.
Wuntab is free to the restaurant. There is no monthly charge, no setup fee, and no per-order commission charged to the restaurant. When a customer places an online order, the customer pays a service fee of 5% of the order. The fee is shown to the customer at checkout before payment is taken. It is collected by our payment processor and routed to Wuntab at settlement.
Information we collect
From a customer placing an order on a restaurant's storefront, we collect an email address, a phone number and a name, together with the name, phone number and email address given on that particular order. We collect the contents of the order: the items, quantities, modifiers, totals and any tip. We collect free-text instructions attached to the order and free-text notes attached to individual items. We collect the times at which the order moves through its stages, and we generate a token used for the public order-tracking link. We store a rendered copy of the kitchen ticket, which contains the information above.
For a delivery order we also collect the dropoff address, the first and last name of the person receiving the order, a phone number and any dropoff instructions.
For payment we collect the amount authorised, the amount captured and the amount refunded, the payment method type, the card brand, the last four digits of the card, and the reference our payment processor assigns to the transaction.
We do not store card numbers, expiry dates or security codes. Card details are entered by the customer and go to our payment processor. We keep the card brand and the last four digits only, so that restaurant staff and our support team can match a charge to a line on a statement. We hold no stored card credential and no reusable payment token, so we cannot charge a customer again. A repeat purchase requires the customer to enter card details afresh.
From a person who submits a form on a restaurant's website, such as a catering enquiry, a contact message or a job application, we collect a name, an email address and a phone number, a free-text message of up to 4,000 characters, and, where the form asks for them, an event date, an event time, a guest count, an event type, a postal address and a country. A job application may include a résumé file and its filename.
The message field on these forms is free text. Please do not include medical details in it. We do not ask for health information and we do not need it.
From the restaurant we collect the organisation name, the legal name, a billing email address, the plan and account status, each location's address, public phone number and kitchen phone number, the tax rate, the menu and its prices, item and modifier details, photos, website draft and published content, custom domain names, promotion codes and any menu file uploaded for import.
From restaurant staff and our own administrators we collect identity information through our authentication provider, which holds the email address, name and password or single sign-on credentials. Wuntab itself stores the identifier that provider issues, a display name, an email address, the email address an invitation was sent to, the time a person was last seen, and a record of the actions that person takes. Audited changes are stored as before-and-after copies of the affected record, which means that where the record contained customer information, the audit entry contains a copy of it.
Where a restaurant connects Clover, we collect the Clover merchant identifier, a snapshot of the Clover catalog, the mappings between Clover items and modifiers and our own, the link between a Wuntab order and a Clover order, and encrypted Clover access and refresh tokens.
For platform administration we record support sessions, including the reason a session was opened and when it started, expired and ended, an audit log of administrator actions, free-text notes about a restaurant, the reason for any suspension, and counts of artificial-intelligence usage attributed to a user.
How we use the information
We use the information to provide the service: to publish the restaurant's website and menu, to take and track orders, to route orders to the kitchen by printed ticket and, where Clover is connected, into Clover, to arrange delivery, to take payment, and to send order notifications by text message.
We use it to support the restaurant and its customers, including matching a charge to a line on a statement, which is the reason we keep the card brand and last four digits.
We use it to operate and secure the service, through error monitoring, audit logging and the prevention of abuse.
We submit the restaurant's menu and website copy to our artificial-intelligence provider when the restaurant asks us to draft content. No customer information is sent for this purpose, and nothing is published without a person at the restaurant approving it.
We use the information processed through Wuntab to provide and support the service for the restaurant: to publish the restaurant's website and menu, to take and track orders, to route orders to the kitchen and to Clover where Clover is connected, to arrange delivery, to take payment, to send order notifications to customers, and to keep the service secure and working. We act on the restaurant's instructions. We do not sell personal information and we do not use customer information for our own advertising. We keep information for as long as the restaurant uses Wuntab; after that it is not deleted automatically, and we will delete it by hand within 30 days of a written request to support@wuntab.com.
How we share information
We share information with the restaurant whose storefront the information came from.
We use the following service providers, and each receives only what it needs.
Our database provider, Neon, stores all of the information described in this policy.
Our hosting provider, Vercel, runs the platform, keeps runtime logs, and stores uploaded files, which are menu photos, logos, menu-import files and résumés.
Our authentication provider, Clerk, holds staff and administrator identity, which is an email address, a name and a password or single sign-on credentials.
Our text-message provider, Twilio, receives a customer's phone number and the text of each message we send.
Clover receives the order number, special instructions, item names, quantities and totals. Clover does not receive a customer's name, phone number or email address from us.
Our payment processor, NMI, receives the card details entered by the customer and the amount. It does not receive menu contents.
Our delivery partner, DoorDash, receives the dropoff address, the customer's first and last name, phone number and dropoff instructions. It does not receive card details.
Our error-monitoring provider, Sentry, receives error and trace data. Personal information is switched off in that integration, request cookies, headers and bodies are removed before anything is sent, and session replay is not enabled.
Our artificial-intelligence provider, Anthropic, receives menu and website copy submitted for drafting. It does not receive customer information.
Google Search Console receives the addresses of pages on the restaurant's website. It does not receive customer or order information.
We also share information where the law requires it, and we may transfer it as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to the information transferred.
Storefront customer information
Wuntab operates the restaurant's own website and its checkout. When someone places an order there, they give their information to the restaurant through a storefront that we run. We receive and store that information at the moment it is entered, before any part of it reaches Clover, and we would hold it whether or not the restaurant uses Clover at all.
What Clover receives is a subset: the order number, special instructions, item names, quantities and totals. Clover does not receive the customer's name, phone number or email address from us.
The restaurant is the merchant of record for these orders. The restaurant decides what is collected on its storefront and what it is used for, and we act on its instructions. Payments settle to the restaurant's own account.
How long we keep information
We keep information for as long as the restaurant uses Wuntab.
If a restaurant ends its account, its information is not deleted automatically. It stays until someone asks us to remove it.
We delete information on written request to support@wuntab.com. We handle these requests by hand and complete them within 30 days of receiving them. We do not offer an automated deletion tool today, and we do not promise one.
Three things are removed automatically. An expired Clover sign-in state record is deleted within ten minutes. A résumé file and its filename are cleared 90 days after the application is submitted. The encrypted Clover access and refresh tokens are cleared when a restaurant disconnects Clover or the app is uninstalled.
Nothing else has a set retention period. Deactivating a staff member, archiving a promotion or removing a custom domain changes the record's status and keeps the record.
Our database provider keeps backups. Information we have deleted can remain in those backups until they age out, and our deletion of a record does not reach into them.
How we protect information
Access to a restaurant's information is restricted to that restaurant's own account, and the restriction is enforced by the database itself rather than by application code alone. A test in our build checks that the restriction holds across accounts.
Clover access and refresh tokens are encrypted where they are stored, with a separate nonce for each record bound to the organisation and location it belongs to. A restaurant may disconnect its Clover account at any time, and disconnecting clears those tokens.
Printer device tokens and website preview tokens are stored as hashes rather than in a form we can read back.
Provider API keys are held as environment configuration and are never written into source code. A test in our build checks that API tokens are not written to application logs.
No system is completely secure, and we do not claim that ours is.
Your rights and choices
If you placed an order with a restaurant that uses Wuntab, the restaurant decides how your information is used. You can contact the restaurant directly, or you can write to us at support@wuntab.com and we will pass your request to the restaurant where the decision is theirs.
You may ask for a copy of the information we hold about you, ask us to correct it, or ask us to delete it. We handle these requests by hand and complete them within 30 days.
If you want to complain about how your information has been handled, write to support@wuntab.com.
We may update this policy. When we do, the date at the top of this page changes. Where a change is significant we will tell the restaurants that use Wuntab.
Contact us
Sabal Pay LLC
1802 N Alafaya Trail, Orlando, FL 32826
(407) 655-8761
support@wuntab.com
Additional information for merchants located in Europe
Controller and processor. The restaurant is the controller of the information described in this policy. We are a processor and act on the restaurant's documented instructions.
Legal basis for processing. The restaurant, as controller, establishes the legal basis on which the information is processed.
Cross-border transfer. Our service providers are named above. Where information is transferred outside the European Economic Area or the United Kingdom, the transfer is made under the mechanism set out in the relevant provider's data processing terms.
Data retention. Retention is described under "How long we keep information" above. In short: we keep information while the restaurant uses Wuntab, nothing is deleted automatically when an account ends, and we delete by hand within 30 days of a written request.
Data subject rights. Subject to local law, a person may ask for access to their information, correction of it, erasure of it, restriction of its processing, portability of it, or may object to its processing, and may complain to a supervisory authority. Requests should go to the restaurant, or to support@wuntab.com, and are handled by hand within 30 days.
Your California privacy rights
If you are a California resident, you may ask what personal information we have collected about you, the sources it came from, the purposes we collected it for, and the categories of third party we shared it with. You may ask for a copy of that information. You may ask us to delete it. We will not treat you differently for exercising any of these rights.
How to exercise your rights. Write to support@wuntab.com or call (407) 655-8761. We will verify your identity by matching your request against information we already hold, such as the email address or phone number used on an order. If you use an authorised agent, we will ask for proof that you authorised them.
Sale of personal information. We do not sell personal information, and we have not sold personal information in the preceding twelve months.
Sensitive personal information. We do not ask for sensitive personal information. The free-text message field on a restaurant's website forms accepts whatever a person chooses to type, and we ask people not to include medical details in it.
Categories of personal information we collect
Everything we collect is stored with our database provider and our hosting provider, which act as service providers on our behalf. The list below says whether we collect each category defined by California law, and whether we disclose it to a third party for a business purpose beyond that storage.
Identifiers, such as a name, email address, postal address, phone number and account identifier. Collected: yes. Disclosed for a business purpose: yes, to Clover, our payment processor, our delivery partner, our text-message provider and our authentication provider, each as described above.
Personal information listed in the California Customer Records statute, such as a name, address, phone number and payment information limited to the card brand and last four digits. Collected: yes. Disclosed for a business purpose: yes.
Protected classification characteristics, such as age, race or gender. Collected: no.
Commercial information, such as the orders placed, the items purchased, the amounts and any tip. Collected: yes. Disclosed for a business purpose: yes, to Clover and our payment processor.
Biometric information. Collected: no.
Internet or other network activity. Collected: yes, limited to server logs and error telemetry. Disclosed for a business purpose: yes, to our hosting provider and our error-monitoring provider.
Geolocation data. Collected: yes, limited to a delivery address a customer enters. Disclosed for a business purpose: yes, to our delivery partner.
Audio, electronic, visual or similar information. Collected: no.
Professional or employment-related information. Collected: yes, limited to what a person submits through a job application form on a restaurant's website, including a résumé. Disclosed for a business purpose: no.
Non-public education information. Collected: no.
Inferences drawn to create a profile. Collected: no.
Glossary
"Personal information" means information that identifies, relates to, or could reasonably be linked with a particular person or household.
"Identifiers" means items such as a real name, an alias, a postal address, a unique personal identifier, an email address or a phone number.
"Commercial information" means records of products or services purchased, obtained or considered.
"Service provider" means a company that processes information on our behalf and for our purposes, under a contract that limits what it may do with that information.
"Controller" and "processor" have the meanings given to them in European and United Kingdom data protection law. The controller decides why and how information is processed; the processor acts on the controller's instructions.
"Sale" means disclosing personal information to a third party for money or other valuable consideration. We do not do this.