Effective: January 1, 2023
1. Introduction and scope
This Privacy Statement describes how Toast, Inc. and its subsidiaries and affiliates (collectively “Toast”, “we”, “us” and/or “our”) collects and manages your personal information (i.e., any information that relates to an identified or identifiable individual) as part of providing our Services (defined below).
To see our California Privacy Statement, please click the link or scroll down.
This Statement primarily covers:
In addition to the groups above, this Statement also covers individuals that visit our websites, including https://pos.toasttab.com (referred to generally as our “Websites”) and our third-party business partners.
For individuals using our Toast Pay Card and PayOut service, you are authorizing and directing Toast to obtain information (e.g., transaction data) from any Toast Pay Card issuing bank or processor in order for Toast to provide that service to you. We will use and share any information that we collect from you pertaining to that Service in accordance with our Privacy Notice found here or within the MyToast mobile application.
Please note that certain locations where we operate have laws that require us to share specific privacy information and practices with individuals in those locations. To that end, this Privacy Statement is comprised of two sections – a generally applicable statement and a location-specific addendum. Where there are variations for a specific location or additional information that is required to be provided under the applicable country or state law, individuals in that location can refer to the applicable addendum. Links to the pertinent sections, can be found below:
Please note that our Merchants are independent third parties that maintain their own business practices and policies outside of their relationship with Toast and their use of the Services. As a result, unless provided otherwise in this Statement, we are not responsible for the privacy policies or data practices of our Merchants, who may maintain separate policies and practices. If you are a Merchant Employee, your employer is responsible for providing any additional required notices or information to you regarding its privacy practices outside of this Statement.
By using the Services and/or providing us with your personal information, you acknowledge that your personal information will be processed and used in the manner set out in this Privacy Statement. We may amend this Statement from time to time in line with the “Changes to this Privacy Statement” section below.
2. Definitions
Here are a few other terms we use throughout this Privacy Statement that you should know:
3. Personal information we collect
What personal information we collect will depend on the nature of your interaction with the Services and our Websites. While some information is collected automatically or through sources outside of Toast, most is collected when you use our Services or our Websites. A breakdown of the collection has been provided in the sections below.
Personal information collected through the Services
A. Merchants
If you are a Merchant, we will collect personal information from you in connection with your service agreement and use (or prospective use) of the Services, including, as applicable,
As part of our application process and agreement to provide the Services, we will also collect additional information, such as your tax identification number, national identification number (e.g. Social Security number or passport number), your drivers’ license details as well as your banking and payment card information.
For Merchants using the Toast Restaurant Card, in addition to certain information already collected above, Toast will also collect information about your Toast Restaurant Card account, authorized users and transaction history as part of the Service.
If you are a business partner that is looking to integrate with Toast, we will also collect information, such as your name and contact details, as part of your application to integrate with our Services.
B. Merchant Employees
If you are a Merchant Employee, we collect personal information about you through your use of the Services. This includes:
To the extent you are employed by a Merchant that uses the Toast Payroll and Team Management module, we may also collect:
Please note that the actual personal information collected will depend on the specific Toast Payroll and Team Management services that you or your employer has elected to use. Please contact your employer for additional information.
For Merchant Employees using the Toast Pay Card and PayOut Service, in addition to certain information already collected above, Toast will also collect information about your account and transaction history as part of the Service. For more information about this Service, please see the Privacy Notice here or within the MyToast mobile application.
C. Guests
We collect information from you through your use of the Services (as provided and developed by us from time to time), which may include the creation of a Digital Ordering Account, your use of our online ordering features and mobile application(s) and other related products, such as our pickup, delivery and on-premise ordering and payment services, and waitlist and reservation features. We may also collect and/or receive your personal information when you place an order with, make a purchase from (including gift cards), or otherwise complete a transaction with our Merchants or participate in their respective loyalty programs.
Depending on which Service(s) you have used, personal information collected may include:
In all cases, the actual personal information collected will vary depending on the Services being used. Depending on the Services being used, personal information may also be linked to your use of the Services across Toast. For example, as a Guest, your payment card may be linked to a specific loyalty account.
Personal information collected through our Websites
In addition to using the Services, we may also collect personal information when you visit our Websites and request information about our Services, download a white paper, schedule a product demo or subscribe to our media channels (e.g., blogs, podcasts, etc.). This personal information may include:
Certain information may also be collected automatically when you visit our Websites. For more information, please see the section of this Statement entitled “Information collected automatically.”
Please note that additional information beyond what is described here will be collected (described in the Merchant section above) as part of our online Merchant application process or through our e-commerce Website.
Personal information collected from other sources
Depending on whether you are a Merchant, a Merchant Employee, a Guest or a visitor to one of our Websites, we may also collect personal information about you from third parties including our business partners, data providers, identity verification services, credit bureaus (if applicable), banks and other financial institutions and credit card companies. We may also collect information from you that is publicly available. For example, if you interact with us or share your information through various social media channels.
Information collected automatically
We collect information automatically when you visit our Websites, use our mobile application(s), complete a transaction, or use our online services, such as online ordering. For transactions, this may include personal information such as your name when a payment card is used. Information collected automatically by cookies, web beacons or other similar technologies (described in the “Cookies and other tracking technologies” section of this Statement) may include:
Depending on the Services being used or the Websites you access, we may also collect geolocation information through your devices. For example, we may show you what restaurants in your area are available within our mobile application(s). This information may be collected via GPS, Bluetooth, cellular or WiFi technologies. You can adjust your settings at the device or browser level to disable the use of these technologies.
4. How we use personal information
We use personal information to:
Any communications sent to you pursuant to this section shall either be permitted under the applicable law or with your consent. Please see the “Your rights and choices” section of this Statement for more details on opting out of these communications and updating your preferences.
5. How we share personal information
Toast may share personal information as part of providing the Services and for the purposes described within this Statement. This includes:
We may also share aggregated and/or anonymized information derived from the Services that does not directly identify you, including device information and information derived from cookies and log files with third parties for the purposes described in this Statement.
For individuals using the Toast Pay Card and PayOut Service, please see our Privacy Notice here or within the MyToast mobile application for information on how we disclose your information for the purposes of providing that Service.
6. Retention of personal information
We retain personal information as long as reasonably necessary to provide the Services, carry out the purposes described in this Statement or as otherwise required in order to comply with our records retention periods (which reflect the applicable law). For example, we may retain information about users of our Services in order to comply with our legal and regulatory obligations or to protect our interests as part of providing the Services.
7. Cookies and other tracking technologies
Toast and third parties described in this Statement may use cookies, web beacons and other tracking technologies as part of providing the Services and for the purposes described in this Statement.
A “cookie” is a small text file placed and saved in your browser when you access our Websites and potentially the websites of our Merchants, business partners and other third parties. We use both session cookies (i.e., cookies that are stored only for a specific website visit) and persistent cookies (i.e., cookies that are stored beyond a specific website visit) to provide the Services and for the purposes described in this Statement. These cookies may be set by us (first-party cookies) or set by third parties that collect information on our behalf (third-party cookies), such as Google Analytics.
There are other tracking technologies, such as web beacons/GIFs, pixels, page tags, embedded scripts, that consist of small transparent image files or other web programming code that record how you interact with websites, mobile applications and services. They are often used in conjunction with web browser cookies or other identifiers associated with your device.
As part of using the Services, we use these technologies as well as similar technologies within our Services and across our Websites. Examples include:
There are ways to control and/or reject the setting of cookies and similar technologies within your browser settings. As each browser is different, please consult the “help” menu within your browser. For additional information about cookies and how to control their use on various browsers and devices, you can visit http://www.allaboutcookies.org. Please be aware that depending on the Services being used, restricting cookies may prevent you from accessing and using all or part of the Services.
Targeted advertising and your choices
In certain cases, we allow third-party advertising partners to use cookies, web beacons and other tracking technologies on our Websites, mobile applications and within our Services to collect information about you and your activities for interest-based advertising or other targeted content. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services. This information may be shared with ad networks and other content providers.
If you want to opt out of receiving online interest-based advertisements on your internet browser, please visit and follow the instructions at www.aboutads.info/choices, or http://www.networkadvertising.org/choices/ to place an opt-out cookie on your device indicating that you do not want to receive interest-based advertisements. Opt-out cookies only work on the specific internet browser and device that they are downloaded onto. If you want to opt out of interest-based advertisements across all your browsers and devices, you will need to opt out on each browser on each device you actively use. If you delete cookies on your device generally, you will need to set the opt-out cookie again on that device. If you want to opt out of receiving online interest-based advertisements on mobile applications, please follow the instructions at http://www.aboutads.info/appchoices or by visiting the settings in your mobile device.
Please note that when you opt out of receiving interest-based advertisements, this does not mean you will no longer see advertisements from us or on our online services. It means that the online ads that you do see should not be tailored to your interests. We are not responsible for the effectiveness of, or compliance with, any third-parties’ opt-out options or programs or the accuracy of their statements regarding their programs. In addition, third parties may still use cookies to collect information about your use of our online services, including for analytics and fraud prevention purposes.
Do not track
We may use, and we may allow third-party service providers and other third parties to use, cookies or other technologies on our Services that collect information about your browsing activities over time and across different websites following your use of the Services. Do Not Track (“DNT”) is an optional browser setting that allows you to express your preferences regarding tracking across websites. We currently do not respond to DNT signals. We may continue to collect information in the manner described in this Privacy Statement from web browsers that have enabled DNT signals or similar mechanisms.
8. Your rights and choices
Managing your information
We want to ensure that you have the necessary tools at your disposal to manage your personal information. We rely on you to ensure that your information is accurate, complete and up to date and ask that you notify us of any changes to your personal information. Your ability to update and manage your personal information will differ depending on your relationship with Toast and what Services you use. For example,
In other instances, if applicable, see the instructions provided as part of the Services or contact us as described in the “How to contact us” section of this Statement. We may need to verify your identity before changing or correcting your information. In certain instances, we may not be able to make the correction or accommodate the request due to legal, contractual or technical restrictions.
Please note that depending on your status, location and applicable law, you may be entitled to additional information rights in relation to the processing of your personal information. For more information regarding these rights, and the locations/circumstances where these rights are available, please see the applicable addendums in this Statement.
Managing communications
As part of providing the Services, Toast (whether directly or through a third party), may send you:
In certain cases, our Merchants (including those within a Merchant’s management group) may also send you marketing and promotional communications as part of the Services, including when you visit a Merchant using Toast or join a Merchant-specific loyalty program. In these instances, please follow the instructions within those messages to opt out or reach out to the Merchant directly.
For Guests:
For Merchants and Merchant Employees:
In certain cases, depending on the nature of your relationship with Toast and the Services being used, you may also receive messages from third-party service providers and business partners.
For additional information about how we communicate with you, please contact us at privacy@toasttab.com.
9. Security
We implement appropriate administrative, physical and technical security measures to reasonably protect your personal information against unauthorized access, disclosure, damage or loss. However, even though we have taken measures to protect your personal information, we cannot guarantee that the collection, transmission and storage of personal information will always be completely secure.
10. Links to other websites
This Privacy Statement only applies to information collected when visiting our Websites or otherwise using our Services. While visiting our Websites or using the Services, you may be directed through links to third-party websites or services that are not operated or controlled by us. For example, the websites of our Merchants or business partners that provide services as part of this Statement. We are not responsible for the privacy practices and policies of these third parties. As a result, we encourage you to review the privacy policies of these third-party websites as their practices may differ from ours.
11. Children
Our Services are not targeted or directed at children under the age of 13, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 13. If you have reason to believe that a child under the age of 13 has provided personal information to us, we encourage the child’s parent or guardian to contact us as described in the “How to Contact Us” section of this Statement to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 13, we will promptly delete that personal information.
We do, however, process personal information about children when it is necessary for the services we are offering, and you provide it to us. For example, if you are a Merchant Employee, we may collect information relating to children if your employer is using the Toast Payroll and Team Management module and you add them as dependents under your benefits policies.
12. How to contact us
If you have questions or concerns about our Privacy Statement, our practices or our compliance with applicable privacy laws, you can reach us at:
Additional contact points can be found in the addendums.
A downloadable version of this Statement can be found here.
13. Changes to this Privacy Statement
From time to time, we may update, change, modify or amend this Privacy Statement in order to comply with the applicable law or our changing business practices. Unless we are required by the applicable law to provide a prescribed form of notice and/or obtain consent, updated versions of this Statement may be posted on this website with additional communication. An archived version of our previous Privacy Statement can be found here. Please check this website and this Privacy Statement regularly for updates.
Addendum A – United States (California)
Last updated: January 1, 2023
1. Privacy Statement for California Residents as required by the California Consumer Privacy Act of 2018 (including as amended by the California Privacy Act of 2020) (“CCPA”).
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and apply solely to individuals that are residents of California and qualify as a “Consumer” under the CCPA. This California-specific Statement provides additional information about how we collect, use, disclose and otherwise process the personal information of these individuals, either online or offline, within the scope of the CCPA. Any terms defined in the CCPA or as otherwise defined in our Privacy Statement have the same meaning as used in this addendum.
When we use the term “personal information” in this Addendum, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
A. CCPA personal information table
The below table summarizes:
The categories of personal information collected by Toast in the past 12 months;
The sources of collection of the personal information;
How we use your personal information; and
The categories of personal information disclosed for business purposes by Toast (including to third parties) in the past 12 months.
Please see the generally applicable section of this Privacy Statement for additional information on Toast’s information practices, including more detail on how we use and disclose your personal information.
Category of personal information | Collected? | Categories of sources | Commercial or business purpose | How we disclose your personal information |
---|---|---|---|---|
Identifiers | Yes |
|
|
|
California Customer Records (Cal. Civ. Code § 1798.80(e)) | Yes |
|
|
|
Protected Classification Characteristics | Yes |
|
|
|
Commercial Information | Yes |
|
|
|
Biometric Information | No | N/A | N/A | N/A |
Internet/Network Information | Yes |
|
|
|
Geolocation Data | Yes |
|
|
|
Sensory Information | Yes |
|
|
|
Profession/Employment Information | Yes |
|
|
|
Non-Public Education Information (20 U.S.C. § 1232g, 34 C.F.R. Part 99) | No | N/A | N/A | N/A |
Inferences | Yes |
|
|
|
B. Categories of personal information sold or shared
While Toast does not “sell” personal information in the traditional sense, we do, however, sell or share personal information for the purpose of displaying advertisements that are selected based on personal information obtained or inferred over time from an individual’s activities across businesses or distinctly-branded websites, applications or other services (otherwise known as “targeted advertising” or “cross-context behavioral advertising”), for personalization features, for tracking and analytics, and for fraud detection and reporting. The categories of personal information impacted in the preceding 12 months may include:
Identifiers;
Internet/Network Information; and
Inferences.
Each of the above categories of information may be disclosed to third-parties, which may include our business partners depending on the nature of a user’s interactions. Consumers can exercise their right to opt out of these sales or sharing through our cookie management tool that can be accessed by clicking on our “Do not sell or share my personal information” link at the bottom of https://pos.toasttab.com. You may also review our Privacy Statement section titled “Cookies and other tracking technologies” for more information on how Toast uses cookies, analytics and personalized advertising. Toast has no actual knowledge that the “sales” or “sharing” described above include the personal information of individuals under 16 years of age.
C. Description of rights available to Consumers
If you are a resident of the state of California and subject to certain legal limitations and exceptions, you may be able to exercise some or all of the following rights:
The right to know/access: you have the right to request that an in-scope business that collects personal information from you, disclose the following in relation to the preceding 12 month period, upon verification of your identity: (i) the categories of personal information collected about you, (ii) the categories of sources where the personal information was collected, (iii) the business or commercial purposes for collecting (or where applicable, selling or sharing) the personal information, (iv) the categories of personal information that we have disclosed to third parties for a business purpose along with the corresponding recipients, (v) the categories of personal information we have sold or shared along with the corresponding recipients, and (vi) the specific pieces of personal information collected about you.
The right of correction: you have the right to request that an in-scope business correct inaccurate personal information, subject to certain conditions.
The right to opt out of the sale or sharing of personal information: you have the right to request that an in-scope business refrain from selling or sharing personal information it has collected about you to third parties now or in the future. If you are under the age of 16, you have the right to opt in, or to have a parent or guardian opt in on your behalf, to such sales or sharing.
The right to limit the use and disclosure of sensitive personal information: to the extent that we use sensitive personal information for purposes beyond those set forth in subdivision (a) of Section 1798.121, you have the right to limit the use or disclosure of that sensitive personal information subject to the exceptions within the CCPA.
The right of access to and to the ability to opt-out of automated decision-making technology: subject to further regulations being issued, you have the right to access information pertaining to automated decision-making technologies and the ability to opt out.
The right against discrimination and retaliation: you have the right to not be discriminated or retaliated against as a result of exercising any of the above rights.
However, please note that if the exercise of these rights limits our ability to process personal information (such as in the case of a deletion request), we may no longer be able to provide you with our Services or engage with you in the same manner. In addition, the exercise of the rights described above may result in a different price, rate, or quality level of product or service where that difference is reasonably related to the impact the right has on our relationship or is otherwise permitted by law.
Please note that your ability to invoke the rights above are limited pursuant to the scope and limitations of the CCPA, including any available exceptions. For example, an access request can only be made twice by a Consumer within a 12-month period.
D. How to invoke your rights
Toast has established an individual rights portal as well as other channels for the purposes of submitting the individual rights requests above, including the right of access and deletion. Individual rights requests can be submitted to Toast through the below channels:
Web portal: Individual Rights Portal
By email: privacy@toasttab.com
By post: Attn: Toast Privacy Office, Toast, Inc., 401 Park Drive, Suite 801 Boston, MA 02215
By phone (toll-free): +1 (866) 226-4484
Once an individual rights request has been submitted, Toast may ask you for additional information in order to verify your identity or to provide additional details to help us respond to your request. This may include your name, email address, phone number or other details related to your use of Toast’s Services. Where applicable, these requests can be submitted by an authorized agent through the channels described above in accordance with the applicable law. In these instances, we will take steps to verify the authorized agent’s authority to act on your behalf. In order to verify the authorized agent’s authority, we generally require evidence of either (i) a valid power of attorney or (ii) a signed letter containing your name and contact information, the name and contact information of the authorized agent, and a statement of authorization for the request. Depending on the evidence provided, we may still need to separately reach out to you to confirm the authorized agent has permission to act on your behalf and to verify your identity in connection with the request. Please note that in certain circumstances, we may refuse to act or impose limitations on your rights, as permitted by the applicable law in relation to individual rights submissions.
To Exercise the Right to Opt Out of the Selling or Sharing of Personal Information
Unless you have exercised your right to opt out of the sale or sharing of personal information, we may “sell” or “share” your personal data to third parties for targeted or cross-context behavioral advertising purposes, for personalization features, for tracking and analytics, and for fraud detection and reporting. The third parties to whom we sell or share personal information may use such information for their own purposes in accordance with their own privacy statements. In these instances, the right to opt out of the sale of personal information can be invoked through our cookie management tool that can be accessed by clicking on our “Do not sell or share my personal information” link at the bottom of https://pos.toasttab.com. Although Toast does not currently engage in other practices at this time that may constitute a “sale” or “sharing” beyond these instances and the methods above are the most effective methods to manage your preferences, you may also submit your right to opt out of any sales or sharing by clicking here or in instances where you would like additional support. You do not need to create an account with us to exercise your right to opt out of personal information sales or sharing. However, if applicable, we may ask you to provide additional personal information so that we can properly identify you in our dataset and to track compliance with your opt out request. We will only use personal information provided in an opt out request to review and comply with the request. If you choose not to provide this information, we may only be able to process your request to the extent we are able to identify you in our systems. Once you make an opt-out request, you may change your mind and opt back in to future personal information sales at any time by contacting us at privacy@toasttab.com or by managing your preferences within the cookie management tool.
E. Accessibility
In the event you are a user with a disability, or are supporting an individual with a disability, and are having difficulty navigating this Statement or the information linked within this Statement, please contact us at privacy@toasttab.com for support.
F. Sensitive Personal Information
As part of our services, Toast collects “sensitive personal information” as defined by the CCPA as part of our operations and the Services offered to our Merchants. The categories of sensitive personal information are described below along with the use case and whether the information is sold or shared.
Category of sensitive personal information | Use/Purpose | Is the sensitive personal information sold? | Is the sensitive personal information shared? |
---|---|---|---|
Social Security Number |
| No | No |
Driver's license number or state ID |
| No | No |
Account log-in details plus password or credentials |
| No | No |
Precise geolocation |
| No | No |
Race or ethnic origin |
| No | No |
Health data |
| No | No |
G. Retention
We retain personal information as long as reasonably necessary to provide the Services and carry out the purposes described in this Statement. However, if necessary, we may retain personal information for longer periods of time, until set retention periods and deadlines expire, or for instances where we are required to do so in accordance with legal, tax and accounting requirements set by a legislature, regulator or other government authority.
To determine the appropriate duration of the retention of personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of personal information and if we can attain our objectives by other means, as well as our legal, regulatory, tax, accounting and other applicable obligations.
As to each of the categories of personal information collected, the retention period will vary depending on our relationship. For example,
In all cases, the retention will be subject to any additional legal, regulatory, tax, accounting or other applicable obligations.
Once retention of the personal information is no longer necessary for the purposes outlined above, we will either delete or de-identify the personal information or, if this is not possible (for example, because personal information has been stored in backup archives), then we will securely store the personal information and isolate it from further processing until deletion or deidentification is possible.
H. Notice of Financial Incentives and loyalty programs
A core part of our business involves the design and implementation of programs and other offerings intended to provide benefits to eligible participants that are managed by our Merchants. One example of that is that as part of our Services, we provide our Merchants with the ability to provide a loyalty program to its restaurant customers. To the extent that a Merchant is required to provide a notice of financial incentive pursuant to the CCPA, this obligation is the responsibility of the Merchant as part of the set up and administration of its program. Please refer to the terms and privacy notice of the Merchant with which you have a relationship for information regarding any financial incentives they may offer through those loyalty services.
I. Deidentified information
We may at times receive, or process personal information to create, deidentified information that can no longer reasonably be used to infer information about, or otherwise be linked to, a particular individual or household. Where we maintain deidentified information, we will maintain and use the information in deidentified form and not attempt to reidentify the information except as required or permitted by law.
J. Updates to this Statement
We will update this Statement from time to time. When we make changes to this Statement, we will change the "Last updated" date at the beginning of this Statement. All changes shall be effective from the date of publication unless otherwise provided in the notification.
2. California “Shine the Light” disclosure
California residents that have an established business relationship with us have a right to know how their information is disclosed to third parties for their direct marketing purposes under California’s “Shine the Light” law (Civ. Code § 1798.83). Please contact us through any of the communication channels within the “How to contact us” section in the main body of this Statement to invoke these rights.
Addendum B – United States (Virginia)
Last updated: January 1, 2023
1. Privacy Statement for Virginia Residents as required by the Virginia Consumer Data Protection Act (“VCDPA”).
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and apply solely to individuals that are residents of Virginia and qualify as a “Consumer” under the VCDPA. This Virginia-specific Statement provides additional information about how we collect, use, disclose and otherwise process the personal information of these individuals, either online or offline, within the scope of the VCDPA. Any terms defined in the VCDPA or as otherwise defined in our Privacy Statement have the same meaning as used in this addendum.
When we use the term “personal information” in this Addendum, we mean “personal data” pursuant to the VCDPA, including information that is linked or reasonably linkable to an identified or identifiable natural person.
A. Categories of personal information processed
Please refer to the “Personal information we collect” section in the main body of the Statement.
B. Purposes of processing the personal information
Please refer to the “How we use personal information” section in the main body of the Statement.
C. Categories of information disclosed to third parties
Please refer to the “How we share personal information” section in the main body of the Statement.
D. Description of rights available to consumers
A number of individual rights are available to individuals under the VCDPA relating to personal information that we have collected (subject to certain limitations at law), including:
E. How to invoke your rights
Toast has established an individual rights portal as well as other channels for the purposes of submitting the individual rights requests above, including the right of access and deletion. Individual rights requests can be submitted to Toast through the below channels:
Once an individual rights request has been submitted, Toast may ask you for additional information in order to verify your identity or to provide additional details to help us respond to your request. This may include your name, email address, phone number or other details related to your use of Toast’s Services. Where applicable, these requests can be submitted by an authorized agent through the channels described above in accordance with the applicable law. These include requests made on behalf of a minor by the individual’s parent or legal guardian can also be made via the individual rights portal above. In these cases, in order to verify the authorized agent’s authority, we generally require evidence of that individual’s authority to act on behalf of the individual. All individual rights requests will be managed in line with the requirements set out in the VCDPA.
Please note that in certain circumstances, we may refuse to act or impose limitations on your rights, as permitted by the applicable law. In the event we decline to take action on a request, we will notify you within 45 days of receipt of the original request with our justification for declining to take action and how you may appeal that decision (including an overview of the appeals process and how you can initiate an appeal). All appeal requests should be submitted by emailing us at privacy@toasttab.com with the subject line, “Virginia Privacy Request Appeal”.
F. Sale of personal information
Presently, Toast does not carry out any “sales” of personal data as defined by the VCDPA.
G. Targeted advertising
Toast carries out limited targeted advertising (as that term is defined by the VCDPA) via cookies and related tracking technologies. You will only be served with targeted advertising when you visit https://pos.toasttab.com and this can be managed by clicking this link: Opt out of Targeted Advertising,
H. Profiling
Presently, Toast does not carry out any profiling (as defined by the VCDPA) in furtherance of decisions that produce legal or similarly significant effects concerning consumers that are presently in scope for VCDPA purposes.
I . Deidentified information
We may at times receive, or process personal data to create, deidentified information that can no longer reasonably be used to infer information about, or otherwise be linked to, a particular individual. Where we maintain deidentified information, we will maintain and use the information in deidentified form and not attempt to reidentify the information except as required or permitted by law.
J. Updates to this Statement
We will update this Statement from time to time. When we make changes to this Statement, we will change the "Last updated" date at the beginning of this Statement. All changes shall be effective from the date of publication unless otherwise provided in the notification.
Addendum C - Canada
Last updated: September 15, 2022
1. Privacy addendum for individuals located in Canada
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and apply solely to individuals that are residents of Canada or are otherwise covered under any applicable Canadian federal or provincial privacy laws or regulations, including but not limited to the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”), Alberta’s Personal Information Protection Act, and British Columbia’s Personal Information Protection Act. Toast is committed to collecting, using, and disclosing your personal information in accordance with applicable laws and regulations.
A. Consent
By using our Services and accessing our Websites, you accept the terms of this Privacy Statement and consent to the collection, use, processing, disclosure and retention of your information as described in this Privacy Statement. Typically, we will provide notice of the purpose for collecting your personal information and/or seek your consent (which may be express or implied, depending on the nature and sensitivity of the personal information) in line with applicable law at the time that we collect your personal information. In certain circumstances, we may collect non-sensitive personal information automatically. In general, you may change or withdraw your consent at any time subject to legal or contractual obligations and providing reasonable notice. Your withdrawal of consent may impact the ability of Toast to provide you with some or all of the Services. Upon receiving notice that you would like to withdraw your consent, we will inform you of the likely consequences of your withdrawal of consent.
Toast will not collect, use, or disclose your personal information except for the purposes we have identified for collection (including those listed in Section 4 of the Toast Privacy Statement above and/or identified at the time of collection), unless we have received your consent (which may be express or implied, depending on the nature and sensitivity of the personal information) or the processing is authorized without consent.
B. Accessing and correcting your personal information
If you are located in Canada, you have the right to request access to and to correct the personal information that we hold about you, subject to certain conditions and limitations. Subject to the applicable law and the nature of your relationship with Toast, this may include a right to review, correct, update, suppress, delete or otherwise limit our use of your personal information that has been previously provided to us. You may also have the right to access information about the ways in which your personal information is or has been used and the names of individuals and/or organizations to which your information has been disclosed.
Toast has established an individual rights portal for the purposes of submitting such individual rights requests. The link to Toast’s individual rights portal can be found here. Individual rights requests can also be submitted to Toast through the below channels:
In your request, please specify what information you would like to access or have corrected. We will respond to your request as soon as reasonably practicable, and within the time period required by law. The exercise of these rights is free of charge. Once an individual rights request has been submitted, Toast may ask you for additional information in order to verify your identity or to provide additional details to help us respond to your request. This may include your name, email address, phone number or other details related to your use of Toast’s Services or Websites.
If we correct your information, we will also send the corrected information to organizations to which we disclosed the information during the year before the date the correction was made.
Please note that in certain circumstances, we may refuse to act or impose limitations on your rights, as permitted by the applicable law. If we cannot provide you with access to your personal information or are unable to correct your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions, and outline further steps available to you. If we refuse to act on a request to correct your personal information, we will nonetheless annotate the information, noting the correction that was requested but not made.
In certain cases, depending on the nature of your request, there may also be residual information that will remain within our databases and other records, which, due to applicable law or as part of Services that are in the process of being carried out, will not be removed or changed. We will also retain information relating to your request for recordkeeping and compliance purposes.
C. International transfers
We may process, store, and transfer your personal information in and to a foreign country, with different privacy laws that may or may not be as comprehensive as Canadian law. In these circumstances, the governments, courts, law enforcement, or regulatory agencies of that country may be able to obtain access to your personal information through the laws of the foreign country.
Specifically, the personal information collected as part of the Services or as otherwise contemplated by this Statement is primarily processed and stored in the United States. However, as Toast is an international organization with business processes, offices and third parties around the world, your information may be sent to any other country in the world where we do business or maintain third-party relationships. When you provide personal information to us through the Services and as part of this Statement, you consent to the transfer of your information and the processing of your information in this manner. Any international transfers made will be in accordance with this Statement and the applicable law.
We also impose appropriate safeguards for the transfer of personal information among our affiliates and to third-party service providers in various jurisdictions, and have implemented appropriate contractual arrangements or other measures for such purposes.
To obtain a current list of the countries where personal information subject to this Statement is collected, used, disclosed and/or stored, including with our service providers, as well as the purposes for which our service providers outside Canada have been authorized to collect, use or disclose personal information for or on behalf of Toast, please contact privacy@toasttab.com.
D. Right to challenge compliance and file a complaint
If you believe any privacy laws relating to the protection of your personal information or the practices described in this Statement have not been respected, you may file a complaint with our Assistant General Counsel, Privacy at the address listed below:
Toast may ask you for additional information in order to verify your identity or to provide additional details to help us respond to your complaint.
We will investigate all complaints. If, after an investigation, your complaint is deemed justified, Toast will take appropriate steps to correct the situation, including, if necessary, amending our policies and practices. If you are not satisfied with the results of the investigation or the corrective measures taken by Toast, you may exercise the remedies available under law by contacting the Office of the Privacy Commissioner of Canada at the address below:
Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec
K1A 1H3
If you reside in the Province of Alberta, you may also contact the Office of the Information and Privacy Commissioner of Alberta at the address below:
Office of the Information and Privacy Commissioner of Alberta
#410, 9925 - 109 Street NW
Edmonton, Alberta
T5K 2J8
If you reside in the Province of British Columbia, you may also contact the Office of the Information and Privacy Commissioner for British Columbia at the address below:
Office of the Information and Privacy Commissioner for British Columbia
PO Box 9038 Stn. Prov. Govt.
Victoria B.C.
V8W 9A4
We will retain personal information used to make a decision that directly affects you for at least one year after we make that decision.
Addendum D – Ireland
Last updated: January 1, 2023
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and applies where the General Data Protection Regulation (“GDPR”) and local implementing legislation apply, which includes where Toasttab Ireland Limited provides Services. To the extent that there is a conflict between the provisions of this Addendum C and the provisions of the main body of the Privacy Statement, the provisions of this Addendum C shall prevail.
A. Data controller(s)
For the purposes of the processing pursuant to this Statement, the joint data controllers will include:
Toast US is primarily responsible for ensuring that personal information is collected and processed pursuant to the applicable law. These obligations include (a) the implementation of appropriate data protection policies, (b) the management and notification of security incidents involving personal information, (c) the completion of data protection impact assessments (where appropriate) and (d) the implementation of appropriate technical and organizational security measures. Toast US is also responsible for managing any requests that you may make to exercise your rights under the GDPR or other applicable data protection legislation, on behalf of both Toast Ireland and Toast US.
Toast Ireland is responsible for managing aspects of the processing that are within its control as part of the joint controller relationship. This includes support and management pertaining to the provision of the Services, obtaining consents from data subjects (where applicable) as well as support with providing notice to data subjects. Where Toast Ireland receives a data subject request under the GDPR, Toast Ireland will promptly notify Toast US of the request.
As a data controller, we are free to rely on “data processors” (as defined within the GDPR) and have engaged various third-party service providers in order to provide the Services as well as for other purposes described in the main body of the Privacy Statement. For more information, see the “How we share personal information” section of the Privacy Statement.
Toast Ireland and Toast US also act as processors on behalf of our Merchants Employees in connection with certain aspects of our Services. The Merchant is the data controller in respect of this relationship.
B. Purposes and legal basis for processing
We collect and process your personal information based on the following legal bases:
Purpose of processing (as described further in section 4 of this Statement) | Legal basis for processing |
To provide, maintain and support our Services | Where we have a contract with you, necessary for the performance of our contract with you Where we do not have a contract with you, our legitimate interests in operating our business |
To manage our business and for internal operational purposes | Necessary for our legitimate interests of effectively managing our business operations and improving our products and services |
To personalize your experience | Necessary for our legitimate interests of effectively managing our business operations and improving our products and services |
To advertise and market to you | Your consent which is required under law some cases) or as necessary for our legitimate interests of effectively promoting our business, products and services |
To communicate with you or provide information you have requested | Where we have a contract with you, necessary for the performance of our contract with you Where we do not have a contract with you, our legitimate interests in operating our business |
For legal, compliance and security-related purposes, including to: | See below |
| Necessary for compliance with our legal obligations under Irish law |
| Necessary for our legitimate interest in complying with laws, protecting our network and systems, our business and others and establishing, exercising or defending our legal rights |
| Necessary for compliance with our legal obligations under Irish law where required by Irish law or, where not required by Irish law, necessary for our legitimate interest in effective compliance management |
Where we process personal information on the basis of a legitimate interest (as identified above), as required by data protection law, we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals’ interests outweigh our interests in the processing taking place. You can obtain more information about this balancing test by using the contact details at the end of this Addendum.
Where we collect personal information to administer our contract with you or to comply with our legal obligations, this is mandatory and we will not be able to perform the contract we have entered into with you or otherwise provide the Services without this information. In all other cases, provision of the requested personal information is optional, but this may affect your ability to use our Services or our websites.
C. International transfers
We may transfer the personal information we collect about you for the purposes described in this Privacy Statement to countries that have not been found to provide an adequate level of data protection by the European Commission.
In particular, we may transfer your personal information to third parties, including to parties located in the United States. We use appropriate safeguards for the transfer of personal information to third party service providers. Where required, we have implemented the EU/EEA approved standard contractual clauses, rely on a service provider’s processor binding corporate rules or have implemented/rely on other legally recognized safeguards for data transfer purposes.
We also use appropriate safeguards for the transfer of personal information among our affiliates in the United States. We have implemented the EU/EEA approved standard contractual clauses or have implemented/rely on other legally recognized safeguards for data transfer purposes.
To obtain a copy of the standard contractual clauses or other transfer safeguards, please send a request to privacy@toasttab.com.
D. Choice and access
You have additional rights regarding how your personal information is processed, including the right to:
Please note that if you choose to withdraw your consent, you may not be able to participate in or benefit from the programs, services and initiatives for which you provided consent to the processing of your personal information. Your rights will in each case be subject to the restrictions set out in applicable data protection laws.
You may exercise these rights free of charge by submitting your request here or to privacy@toasttab.com. Subject to the applicable law, Toast may charge a reasonable fee or refuse to act on a request if it is manifestly unfounded or excessive, in particular because of its repetitive character. In some situations, Toast may refuse to act or impose limitations on the information disclosed if, for instance, if fulfilling your request would reveal personal information about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.
You also have the right to lodge a complaint about our processing of your personal information with the Irish Data Protection Commission.
E. Retention
We will retain your personal information for only as long as needed for the purpose of the processing activity or where we have a legitimate business need to retain it, subject to our legal and regulatory obligations to retain it longer and our applicable records retention periods. The duration of these periods will vary depending on your relationship with Toast and the Service you are using. For example,
Other periods are set out within Toast’s records retention policy and schedule. Our retention periods are also subject to any rights of individuals or other requirements that might dictate a shorter retention period (e.g., deletion requests). In certain cases, Toast may also maintain information for a longer period of time, such as in cases where the information is subject to a legal claim or complaint. Following those periods and other determinations on the duration of the processing of personal information by Toast, we will delete or take measures to anonymize your personal information.
F. Cookies and other technologies
In addition to the information found in the section of the main body of the Statement titled “Cookies and other tracking technologies”, Toast’s Cookie Policy can be found here and provides some supplemental information for users in the EU/EEA and UK.
G. Children
Our Services are not targeted or directed at children under the age of 16, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 16. If you have reason to believe that a child under the age of 16 has provided personal information to us, we encourage the child’s parent or guardian to contact us as described in the “How to contact us” section within main body of the Privacy Statement to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 16, we will promptly delete that personal information.
H. How to contact Toast Ireland
If you have data protection questions specific to Toast Ireland, you can reach us at:
Attention: Toast Ireland Data Protection OfficeI. Lodging a complaint
If you are not satisfied with the processing of your personal information, you have the right to lodge a complaint with the Data Protection Commission (https://www.dataprotection.ie/).
Addendum E – United Kingdom (“UK”)
Last updated: January 1, 2023
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and applies where the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018 (together the “UK Data Protection Law”) apply, which includes where Toasttab UK Limited provides Services. To the extent that there is a conflict between the provisions of this Addendum D and the provisions of the main body of the Privacy Statement, the provisions of this Addendum D shall prevail.
A. Data controller(s)
For the purposes of the processing pursuant to this Statement, the joint data controllers will include:
Toast US is primarily responsible for ensuring that personal information is collected and processed pursuant to UK Data Protection Law. These obligations include (a) the implementation of appropriate data protection policies, (b) the management and notification of security incidents involving personal information, (c) the completion of data protection impact assessments (where appropriate) and (d) the implementation of appropriate technical and organizational security measures. Toast US is also responsible for managing any requests that you may make to exercise your rights under UK Data Protection Law, on behalf of both Toast UK and Toast US.
Toast UK is responsible for managing aspects of the processing that are within its control as part of the joint controller relationship. This includes support and management pertaining to the provision of the Services, obtaining consents from data subjects (where applicable) as well as support with providing notice to data subjects. Where Toast UK receives a data subject request under UK Data Protection Law, Toast UK will promptly notify Toast US of the request.
As a data controller, we are free to rely on “data processors” (as defined within UK Data Protection Law) and have engaged various third-party service providers in order to provide the Services as well as for other purposes described in the main body of the Privacy Statement. For more information, see the “How we share personal information” section of the Privacy Statement.
Toast UK and Toast US also act as processors on behalf of our Merchants Employees in connection with certain aspects of our Services. The Merchant is the data controller in respect of this relationship.
B. Purposes and legal basis for processing
We collect and process your personal information based on the following legal bases:
Purpose of processing (as described further in section 4 of this Statement) | Legal basis for processing |
To provide, maintain and support our Services | Where we have a contract with you, necessary for the performance of our contract with you Where we do not have a contract with you, our legitimate interests in operating our business |
To manage our business and for internal operational purposes | Necessary for our legitimate interests of effectively managing our business operations and improving our products and services |
To personalize your experience | Necessary for our legitimate interests of effectively managing our business operations and improving our products and services |
To advertise and market to you | Your consent which is required under law some cases) or as necessary for our legitimate interests of effectively promoting our business, products and services |
To communicate with you or provide information you have requested | Where we have a contract with you, necessary for the performance of our contract with you Where we do not have a contract with you, our legitimate interests in operating our business |
For legal, compliance and security-related purposes, including to: | See below |
| Necessary for compliance with our legal obligations under UK law |
| Necessary for our legitimate interest in complying with laws, protecting our network and systems, our business and others and establishing, exercising or defending our legal rights |
| Necessary for compliance with our legal obligations under UK law where required by UK law or, where not required by UK law, necessary for our legitimate interest in effective compliance management |
Where we process personal information on the basis of a legitimate interest (as identified above), as required by data protection law, we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals’ interests outweigh our interests in the processing taking place. You can obtain more information about this balancing test by using the contact details at the end of this Addendum.
Where we collect personal information to administer our contract with you or to comply with our legal obligations, this is mandatory and we will not be able to perform the contract we have entered into with you or otherwise provide the Services without this information. In all other cases, provision of the requested personal information is optional, but this may affect your ability to use our Services or our websites.
C. International transfers
We may transfer the personal information we collect about you for the purposes described in this Privacy Statement to countries that have not been found to provide an adequate level of data protection by UK Data Protection Law.
In particular, we may transfer your personal information to third parties, including to parties located in the United States. We use appropriate safeguards for the transfer of personal information to third party service providers. Where required, we have implemented the UK approved standard contractual clauses or the UK approved addendum to the European Commission approved standard contractual clauses, rely on a service provider’s processor binding corporate rules or have implemented/rely on other legally recognized safeguards for data transfer purposes.
We also use appropriate safeguards for the transfer of personal information among our affiliates in the United States. We have implemented the UK approved standard contractual clauses or the UK approved addendum to the European Commission approved standard contractual clauses or have implemented/rely on other legally recognized safeguards for data transfer purposes.
To obtain a copy of the standard contractual clauses or other transfer safeguards, please send a request to privacy@toasttab.com.
D. Choice and access
You have additional rights regarding how your personal information is processed, including the right to:
Please note that if you choose to withdraw your consent, you may not be able to participate in or benefit from the programs, services and initiatives for which you provided consent to the processing of your personal information. Your rights will in each case be subject to the restrictions set out in UK Data Protection Law.
You may exercise these rights free of charge by submitting your request here or to privacy@toasttab.com. Subject to the applicable law, Toast may charge a reasonable fee or refuse to act on a request if it is manifestly unfounded or excessive, in particular because of its repetitive character. In some situations, Toast may refuse to act or impose limitations on the information disclosed if, for instance, if fulfilling your request would reveal personal information about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.
You also have the right to lodge a complaint about our processing of your personal information with the UK Information Commissioner’s Office.
E. Retention
We will retain your personal information for only as long as needed for the purpose of the processing activity or where we have a legitimate business need to retain it, subject to our legal and regulatory obligations to retain it longer and our applicable records retention periods. The duration of these periods will vary depending on your relationship with Toast and the Service you are using. For example,
Other periods are set out within Toast’s records retention policy and schedule. Our retention periods are also subject to any rights of individuals or other requirements that might dictate a shorter retention period (e.g., deletion requests). In certain cases, Toast may also maintain information for a longer period of time, such as in cases where the information is subject to a legal claim or complaint. Following those periods and other determinations on the duration of the processing of personal information by Toast, we will delete or take measures to anonymize your personal information.
F. Cookies and other technologies
In addition to the information found in the section of the main body of the Statement titled “Cookies and other tracking technologies”, Toast’s Cookie Policy can be found here and provides some supplemental information for users in the EU/EEA and UK.
G. Children
Our Services are not targeted or directed at children under the age of 18, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 18. If you have reason to believe that a child under the age of 16 has provided personal information to us, we encourage the child’s parent or guardian to contact us as described in the “How to contact us” section within main body of the Privacy Statement to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 16, we will promptly delete that personal information.
H. How to contact Toast UK
If you have data protection questions specific to Toast UK, you can reach us at:
Attn: Toast UK Data Protection OfficeI. Lodging a complaint
If you are not satisfied with the processing of your personal information, you have the right to lodge a complaint with the UK Information Commissioner’s Office (https://ico.org.uk/).