Toast Privacy Statement

Effective date: April 28, 2026
Cliquez ici pour la version française / Click here for the French version
This Privacy Statement describes how Toast, Inc. and its subsidiaries and affiliates (collectively “Toast”, “we”, “us” and/or “our”) collects and manages your personal information (i.e., any information that relates to an identified or identifiable individual) as part of providing our Services (defined below). To see our California Privacy Statement, please click the link or scroll down.

Quick Links:

Country-specific Addendums:

1. Scope

This Statement primarily covers:
  • Merchants: businesses that have expressed interest in using the Services or have contracted with Toast to provide the Services within their restaurants (where this term is used in this Statement in the context of the processing of the personal information of a Merchant, it refers to a Merchant that is an individual);
  • Merchant Employees: employees of our Merchants that use the Services; and
  • Guests: individuals that use the Services at one of our Merchant’s restaurants, through a business partner or directly through Toast.
In addition to the groups above, this Statement also covers individuals that visit our websites, including https://pos.toasttab.com (referred to generally as our “Websites”) and our third-party business partners. We may also process information from other individuals for additional purposes, including for research purposes, sweepstakes and events-related purposes that might be separately collected from time to time but are covered as part of this Statement.
For individuals using our Toast Pay Card, Toast Cash and PayOut service, you are authorizing and directing Toast to obtain information (e.g., transaction data) from any Toast Pay Card issuing bank or processor in order for Toast to provide that service to you. We will use and share any information that
we collect from you pertaining to that Service in accordance with our Privacy Notice for Toast Pay Card found here. Toast Cash found here or within the MyToast mobile application.
Please note that certain locations where we operate have laws that require us to share specific privacy information and practices with individuals in those locations. To that end, this Privacy Statement is comprised of two sections – a generally applicable statement and a location-specific addendum. Where there are variations for a specific location or additional information that is required to be provided under the applicable country or state law, individuals in that location can refer to the applicable addendum. Links to the pertinent sections, can be found below:
Please note that our Merchants are independent third parties that maintain their own business practices and policies outside of their relationship with Toast and their use of the Services. As a result, unless provided otherwise in this Statement, we are not responsible for the privacy policies or data practices of our Merchants, who may maintain separate policies and practices. If you are a Merchant Employee, your employer is responsible for providing any additional required notices or information to you regarding its privacy practices outside of this Statement.
By using the Services and/or providing us with your personal information, you acknowledge that your personal information will be processed and used in the manner set out in this Privacy Statement. We may amend this Statement from time to time in line with the “Changes to this Privacy Statement” section below.

2. Definitions

Here are a few other terms we use throughout this Privacy Statement that you should know:
  • “Toast Payroll and Team Management” refers to a module offered as part of the Services directed to Merchant Employees that includes a number of HR-focused services, including, but not limited to, payroll, benefits administration, card services, scheduling and applicant tracking services.
  • Services” refers to services and products (including both hardware and software) developed or administered by us from time-to-time, including:
    • our core point-of-sale (POS) system; payment processing services;
    • our application programming interfaces (“APIs”);
    • associated modules provided as part of our POS system, such as our loyalty, marketing, waitlist and reservations, delivery and Toast Payroll and Team Management modules;
    • other restaurant management services, such as our inventory, invoicing and Bill Pay services;
    • our digital ordering services, such as online ordering, pickup and delivery services, contactless order and pay at the table functionality, gift cards and our mobile application(s);
    • accounts created through our digital ordering services (“Digital Ordering Account(s)”);
    • other mobile application(s) developed as part of the Services, including our Merchant and Merchant Employee-facing mobile applications (e.g., the MyToast and Toast Now mobile applications) and our Guest-facing mobile applications (e.g. Local by Toast);
    • Health, wellness and other benefit products or services developed, or offered, by Toast or its third-party business partners from time to time for Merchant Employees;
    • Insurance-related services; and
    • Merchant financing (including, but not limited to, Toast Capital Loans), card products, such as the Toast Pay Card (as issued by Sutton Bank, Member FDIC, pursuant to license by Mastercard International Incorporated, or any subsequent issuer) and other financial products offered by Toast or its business partners, including, without limitation, banks and other financial institutions.
(collectively referred to as the “Services”). Please note that certain Services may be facilitated through our Websites or through our third-party business partners.
  • “You” and/or “your” is a Merchant, a Merchant Employee, a Guest, a visitor to one of our Websites or other covered data subject.

3. Personal information we collect

The personal information we collect depends on how you interact with our Services and Websites. This includes information about Merchants, Merchant Employees involved in their operations, and Guests who transact with or otherwise engage with our Merchants. While some information is collected automatically or from external sources, most is collected when you use our Services or Websites. The sections below outline these collection methods in more detail.
Personal information collected through the Services
A. Merchants
If you are a Merchant, we will collect personal information from you in connection with your service agreement and use (or prospective use) of the Services, including, as applicable,
  • your name;
  • address;
  • email;
  • date of birth;
  • phone number
  • Tax and national identification numbers; and
  • Information you choose to share when using the Services such as when you are communicating through mobile applications or in support tickets.
When you apply for and enter into an agreement to use our Services, we may collect additional information such as your tax or national identification numbers, drivers’ license details, and banking and payment card information.
If you are a business partner seeking to integrate with Toast, we will also collect your name and contact details, as part of the integration application process.
B. Merchant Employees
If you are a Merchant Employee, we may collect personal information about you when you use the Services. This may include:
  • your name;
  • email;
  • phone number;
  • employee identification number;
  • address;
  • date of birth; and
  • information relating to your role, such as your job title, wage rates and salary and hours worked.
To the extent you are employed by a Merchant that uses the Toast Payroll and Team Management module, we may also collect:
  • your Social Security number or other national identification number;
  • banking information as part of payroll;
  • your professional and educational history;
  • tax documentation such as your W2 and 1095 tax forms;
  • your benefit elections;
  • driver’s license information;
  • gender;
  • marital status;
  • disability status;
  • ethnicity; and
  • your dependent and beneficiary information.
Please note that the actual personal information collected will depend on the specific Toast Payroll and Team Management services that you or your employer has elected to use. Please contact your employer for additional information.
For Merchant Employees using the Toast Pay Card and PayOut Service, in addition to certain information already collected above, Toast will also collect information about your account and transaction history as part of the Service. For more information about this Service, please see the Privacy Notice here or within the MyToast mobile application.
C. Guests
We collect information through your use of the Services (as provided and updated by us over time), including when you create a Digital Ordering Account, use our online ordering features, mobile applications, or related products such as pickup, delivery, on-premise ordering and payment tools, and waitlist or reservation features. We also collect or receive personal information when you place orders, make purchases (including gift cards), complete transactions with our Merchants, or participate in their loyalty programmes.
Depending on which Service(s) you have used, personal information collected may include:
  • your name;
  • contact details such as your phone number and email;
  • your address and other general location details;
  • your payment card information, such as the brand, card number, security code and expiration date;
  • transaction information and order history details (e.g., goods/services ordered, date, payment method and amount of payment);
  • your date of birth (if you choose to provide it);
  • information about your vehicle (for users of our curbside pickup service);
  • account and profile information such as your username and password;
  • if you are a member of a Merchant’s loyalty program, information in relation to your points balance and redemptions;
  • waitlist or reservation details, including dining preferences, special requests and dietary restrictions; and
  • your feedback in relation to your experience at our Merchants’ establishments (if you choose to provide it).
  • Information you choose to share when using the Services such as when you are communicating through mobile applications or in support tickets
The personal information collected will depend on the specific Services you use. In some cases, information may be linked across Toast Services for example, a Guest’s payment card or contact details may be associated with order history, a Toast account, a loyalty account, or a Merchant-specific profile.
Merchants may also choose to collect dietary or allergy-related information. If a Guest provides dietary preferences or requirements as part of a reservation or dining experience and this information is considered health-related under applicable law, providing it constitutes consent to its use for that purpose. Toast processes this information to provide the Services to the Merchant.
Personal information collected through our Websites
We also collect personal information when you visit our Websites and, for example, request information about our Services, download a white paper, schedule a product demo, or subscribe to our media channels (such as blogs or podcasts). This may include:
  • your name;
  • email; and
  • phone number.
Certain information may also be collected automatically when you visit our Websites. For more information, please see the section of this Statement entitled “Information collected automatically.”
Please note that additional information beyond what is described here will be collected (described in the Merchant section above) as part of our online Merchant application process or through our e-commerce Website.
Personal information collected from other sources
Depending on whether you are a Merchant, Merchant Employee, Guest, or Website visitor, we may also collect personal information about you from third parties such as business partners, data providers, identity verification services, credit bureaus (where applicable), banks, financial institutions, and payment card companies. We may likewise collect publicly available information, including information you share or interactions you have with us on social media.
Information collected automatically
We automatically collect information when you visit our Websites, use our mobile applications, complete a transaction, or use our online services, such as online ordering. For transactions, this may include personal information such as your name when a payment card is used. Information collected automatically by cookies, web beacons or other similar technologies (described in the “Cookies and other tracking technologies” section) may include:
  • information about your device, such as your device type/model, number and device ID (e.g., MAC address);
  • information about your browser, settings (e.g., language) and operating system;
  • your internet protocol (IP) address (including, in some instances, your perceived location);
  • unique advertising and related identifiers;
  • transactional and purchase information; and
  • browsing and usage activity, such as the referring domain, what websites/content you have viewed or actions you have taken on a particular website.
Depending on the Services you use or the Websites you access, we may collect geolocation information from your device when location settings are enabled. For example, we may use this information to show you nearby restaurants in our mobile applications. Location data may be collected through GPS, Bluetooth, cellular or WiFi technologies. If you do not wish to share this information, you can disable location access in your device or browser settings.

4. How we use personal information

We use your personal information primarily to provide our Services and manage our business operations. This includes communicating with you as part of the Services and, where permitted by law or with your consent, using your information for advertising and marketing. We also use personal information to meet legal, compliance, and security obligations. How we use your information depends on the specific Services involved and whether you are a Guest, Merchant, Merchant Employee, or other covered individual. A detailed breakdown of these uses is provided below.
We use personal information to:
  • Provide, maintain and support our Services, including
    • to provide updates, support and training related to the Services;
    • to determine the eligibility of individuals in relation to their use of certain Services; for contracting and agreement purposes;
    • to process transactions and payments through the Services, maintaining an order history of your interactions with Toast;
    • to enable our Merchants and our Merchants Employees to access and use the Services, including information that you have provided as part of using the Services; and
    • to improve, develop, and provide Services, develop, train and deploy algorithms and artificial intelligence (AI) models, used to develop, provide, and personalize our Services, and generate insights to enhance our Services for Merchants and Guests;
    • to provide online services, including verifying your identity, as well as diagnosing technical and service issues.
    • If you are a Merchant Employee, to enable our Merchants to manage their workforce
  • Manage our business and for internal operational purposes, including   analyzing the performance of our Services;
    • workforce and service development;
    • creating and developing analytics for the benefit of our business and the business of our Merchants;
    • research purposes, including the development of new products;   assessing the effectiveness of Services; and
    • improving our Services and Websites.
  • Personalize your experience, including by
    • Creating a Merchant-specific profile based on your interactions with our Guest-facing Services, such as making a payment, joining a waitlist or reservation, placing a digital order, or participating in a Merchant’s loyalty programme. Guest profiles apply only to the specific Merchant or Merchant management group you interact with.
    • Using information associated with your Toast account to personalize your experience across our Services;
    • Using transactional data and order history to offer recommendations within our Services or those of our Merchants;
    • Using information about your dining experience (including waitlist and reservation details) to enhance current and future dining experiences at our Merchants’ restaurants
    • Using analytics and profiling technologies to personalize your experience.
    • Using general location information inferred from your IP address to customize content (for example, to display nearby restaurants). This reflects only an approximate area, not a precise location.
  • Advertise and market to you, including
    • sending you marketing communications, either directly or through a third-party service provider, in relation to our existing or new Services that we think might interest you;
    • displaying advertisements for Toast or third-party services in our digital ordering services and mobile applications; and
    • Based on instructions from our Merchants or our business partners as applicable, either directly or through a third party, to advertise their products and services to you; and
    • promoting our Services.
Any communications sent to you pursuant to this section shall either be permitted under the applicable law or with your consent. Please see the “Your rights and choices” section of this Statement for more details on opting out of these communications and updating your preferences.
  • Communicate with you or provide information you have requested, including providing notifications in relation to your purchases or the Services;
    • sending you white papers and other materials from our Websites;
    • providing you with our newsletters, podcasts and other subscription materials;
    • sending you digital receipts; and
    • responding to feedback that you have provided in relation to our products or Services or those of our Merchants.
  • For legal, compliance and security-related purposes, including to
    • comply with our legal obligations, including under anti-money laundering, know- your-customer or similar laws in any relevant jurisdiction;
    • secure and protect our network and systems;
    • identify and protect against fraud and other crimes;
    • establish, exercise or defend legal claims;
    • perform our contractual obligations; and
    • monitor and report compliance issues.

5. How we share personal information

In certain circumstances, we share personal information to provide our Services or to fulfil the purposes described in this Statement. For Guests, this includes sharing information with Merchants, their Employees, and authorised third-party partners. We also work with third-party service providers and business partners who help us deliver, support, and improve our Services
Toast may share personal information as part of providing the Services and for the purposes outlined in this Statement, including:
  • With our Merchants and their Employees to provide the Services, fulfil your requests, and support the purposes described in this Statement. For example, when you complete a transaction, place a digital order, join a waitlist, or make a reservation, Toast shares relevant order or reservation details with the Merchant. This may include your name, contact information, and information about your dining experience, such as reservation details, preferences, and special requests. Where a Merchant is part of a larger management group, this information may also be shared with other restaurants in that group to support future dining experiences.
  • With our third-party business partners in order to provide, maintain, improve and expand our Services;
  • With third-party integration partners selected by the Merchant or with whom you do business where Toast is instructed to share your information as part of the Services;
  • With our parent, subsidiary, or affiliate companies, agents (if any) for the purposes outlined in this Privacy Statement;
  • With third parties that help us provide, maintain, and improve our Services. These service providers may access personal information to perform functions on our behalf or on behalf of our Merchants, such as hosting and IT services, payment processing, identity verification and fraud prevention, marketing and advertising, data analytics and personalization, and customer support. Please note:
    • If you are a Merchant Employee whose employer use the Toast Payroll and Team Management module, we will share your information with benefits, payroll and other employment-related service providers.
    • If you are a Merchant applying for financing through the Toast platform, we share your information (including personal information) with the lender, and a credit report may be obtained from third-party credit bureaus to assess your eligibility.
    • If you are a Merchant using a Toast Finance Suite product, we may share identity verification data with banking partners for AML/KYC purposes.
  • in connection with, or during the negotiation of, any merger, sale of company stock or assets, financing, acquisition, divestiture or dissolution of all or a portion of our business; or
  • if we believe it is authorized or necessary to:
    • protect our rights or property, or the security or integrity of our Services or our Websites;
    • enforce the terms of our terms of service or other applicable agreements or policies;
    • protect us, users of our Services or the public from harm or potentially prohibited or illegal activities;
    • investigate, detect and prevent fraud and security breaches; or
    • comply with any applicable law, regulation, legal process or governmental request (including, for example, a court order, subpoena, or search warrant).
We may also share aggregated or anonymized information derived from the Services such as device data or information from cookies and log files with third parties for the purposes described in this Statement. This information does not directly identify you.
For individuals using the Toast Pay Card and PayOut Service, please see our Privacy Notice here or within the MyToast mobile application for information on how we disclose your information for the purposes of providing that Service.

6. Retention of personal information

We retain personal information as long as reasonably necessary to provide the Services, carry out the purposes described in this Statement or as otherwise required in order to comply with our records retention periods (which reflect the applicable law). For example, we may retain information about users of our Services in order to comply with our legal and regulatory obligations or to protect our interests as part of providing the Services.

7. Cookies and other tracking technologies

Toast and third parties described in this Statement may use cookies, web beacons and other tracking technologies for the purposes described in this Statement. We may use these technologies within our Services and across our Websites, for example to:
  •  to provide our Services (e.g., authentication within the check-out process);   to uniquely identify you and/or your device;
  • to store your preferences as part of providing the Services;
  • for personalization, ad measurement and analytics, and targeted advertising purposes (including across your devices and applications);
  • for security and fraud-prevention purposes;
  • to analyze and monitor the performance of our Services;  
  • to improve and develop new Services; and
  • to understand your use of the Services over time.
Information on how to manage cookies and similar technologies is provided below, along with a more detailed description of how we use them.
A “cookie” is a small text file stored in your browser when you visit our Websites and, in some cases, the websites of our Merchants, business partners, or other third parties. We use session cookies (stored only during a single visit) and persistent cookies (stored beyond a single visit) to provide our Services and for the purposes described in this Statement. Cookies may be set by Toast (first-party cookies) or by third parties acting on our behalf (third-party cookies), such as Google Analytics.
We also use other tracking technologies such as web beacons, pixels, page tags, and embedded scripts which record interactions with websites, mobile applications, and services. These tools often work alongside cookies or other device identifiers.
Pixels and similar technologies are additionally used in connection with session replay services on certain Websites to help analyze and improve site functionality and user experience.
In some cases, Toast provides Merchants with digital advertising and related services that use cookies, pixels, and similar technologies through integrated third-party tools. Merchants manage their own accounts with these third parties.
You can control or block cookies and related technologies through your browser settings. As each browser is different, please refer to your browser’s help menu. More information on cookies and how to manage them across browsers and devices is available at www.allaboutcookies.org. Please note that disabling cookies may limit your ability to access or use certain features of the Services, depending on the Services you rely on.

Targeted advertising and your choices

In certain cases, we permit third-party advertising partners to use cookies, web beacons, and similar tracking technologies on our Websites, mobile applications, and within our Services to collect information about you and your activities for interest-based advertising or other targeted content. The information collected may be linked to your personal information, or may include personal information gathered over time and across different websites and online services. This information may be shared with ad networks and other content providers
Opting out of interest-based advertising
  • To opt out of interest-based advertising in your internet browser, please visit www.aboutads.info/choices or www.networkadvertising.org/choices and follow the instructions to place an opt-out cookie on your device.
  • Opt-out cookies apply only to the browser and device where they are installed. You must opt out separately on each browser and device you use. If you delete cookies, you will need to reapply the opt-out cookie.
  • To opt out of interest-based advertising in mobile applications, follow the instructions at www.aboutads.info/appchoices or adjust the settings on your mobile device.
Please note that opting out of interest-based advertising does not mean you will stop seeing advertisements from us or on our online services. It simply means that the ads you see should no longer be tailored to your interests. We are not responsible for the effectiveness or compliance of any third party’s opt-out tools or programmes, nor for the accuracy of their statements about those programmes. Third parties may still use cookies to collect information about your use of our online services for purposes such as analytics and fraud prevention.

Do not track

We and certain third parties may use cookies and similar technologies on our Services to collect information about your browsing activities over time and across different websites. Do Not Track (“DNT”) is a browser setting that allows you to indicate your preference regarding such tracking. Except where required under applicable laws such as recognising Global Privacy Control signals noted in our state-specific addendums, we do not currently respond to DNT signals. We may continue to collect information as described in this Privacy Statement from browsers that have enabled DNT or similar mechanisms

8. Your rights and choices

As part of the Services and the processing activities described in this Statement, we recognize that you may wish to update, correct or otherwise manage your personal information, as well as manage how Toast communicates with you. This includes communications relevant to the Services or fulfilling a particular interaction by law. Depending on your relationship with Toast, you may be able to manage your personal information directly through the Services or by contacting us.
Managing your information
We aim to provide you with the tools necessary to manage your personal information. We rely on you to ensure your information is accurate, complete, and up to date, and ask that you notify us of any changes. Your ability to update or manage your information will vary depending on your relationship with Toast and the specific Services you use. For example:
  • As a Merchant, for certain services, you may access, change or correct certain account information at any time by logging into your account. In other instances, please contact our customer success team.
  • As a Merchant Employee using the Toast Payroll and Team Management module or other Merchant Employee-facing Services, you have the ability in many cases to access and update your information through the Services. In other instances, please reach out to your Merchant Employer.
  • As a Guest, depending on the Services you use, you may be able to access, change and update your information through an account created as part of the Services (e.g., a Digital Ordering Account). If you are a Guest and have questions about your Digital Ordering Account or need customer support, please contact the guest support team on this page or navigate to the “Get Help” section of the Local by Toast app. In certain cases (e.g., Local by Toast), you can also submit a request for deletion of your Digital Ordering Account from directly within the mobile application.
In other cases, where applicable, please follow the instructions provided within the relevant Service or contact us using the details in the ‘How to contact us’ section. We may need to verify your identity before updating or correcting your information. In some circumstances, we may be unable to fulfil a request due to legal, contractual, or technical limitations.
Please note that, depending on your status, location, and applicable law, you may have additional rights relating to the processing of your personal information. For details on these rights and where they apply, please refer to the relevant addendums in this Statement.

Managing communications

As part of providing the Services, Toast (directly or through third-party service providers), may send you various types of communications:
  • Marketing communications: Depending on your relationship with us and the Services you use, we may send marketing or promotional messages about new or existing Services that may be of interest to you. These may include marketing text messages where you have opted in. You can opt out of marketing communications by following the instructions in the message, adjusting your communication preferences in your account or device settings, or submitting a request through our Individual Rights Portal. Please note that opting out of one marketing channel does not automatically opt you out of all marketing communications. You may still receive non-marketing communications after opting out. These may include transaction-related messages, loyalty programme communications, or account-specific updates. If you are located outside the United
    States, we will not send you direct marketing communications without your opt-in consent or as otherwise permitted under the applicable law.
In certain cases, our Merchants (including those within a Merchant’s management group) may send you marketing and promotional communications as part of the Services, for example when you visit a Merchant using Toast or join a Merchant's loyalty program. To opt out of these communications, please follow the instructions in the message or contact the Merchant directly.
  • Other communications: As part of your interaction with our Services, you may receive various non-marketing communications from Toast that may be sent via email or text message. These include:
  • For Guests:
    • sending you digital receipts or other messages in relation to Services you engage with; notifications sent by Merchants, our business partners and/or third-party service providers as part of our Services, such as order status, delivery or pick up notifications and information pertaining to our reservation and waitlist services;
    • responding to feedback that you have provided in relation to the Services of Toast or one of our Merchants;
    • account or program-specific messages as part of your use of the Services (e.g., loyalty accounts with our Merchants or by setting up a Digital Ordering Account); or
    • messages associated with contests, competitions or promotions that you have elected to participate in.
  • For Merchants and Merchant Employees:
    • messages relating to Toast’s services and demo requests (for prospective Merchants); on-boarding related messages pertaining to setting up the Services; or
    • messages pertaining to Services that you are using or are under your account.

In certain cases, depending on the nature of your relationship with Toast and the Services being

9. Security

We implement appropriate administrative, physical and technical security measures to reasonably protect your personal information against unauthorized access, disclosure, damage or loss. However, even though we have taken measures to protect your personal information, we cannot guarantee that the collection, transmission and storage of personal information will always be completely secure.

10. Links to other websites

This Privacy Statement only applies to information collected when visiting our Websites or otherwise using our Services. While visiting our Websites or using the Services, you may be directed through links to third-party websites or services that are not operated or controlled by us. For example, the websites of our Merchants or business partners that provide services as part of this Statement. We are not responsible for the privacy practices and policies of these third parties. As a result, we encourage you to review the privacy policies of these third-party websites as their practices may differ from ours.

11. Children

Our Services are not targeted or directed at children under the age of 13, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 13. If you have reason to believe that a child under the age of 13 has provided personal information to us, we encourage the child’s parent or guardian to contact us as described in the “How to Contact Us” section of this Statement to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 13, we will promptly delete that personal information.
We do, however, process personal information about children when it is necessary for the services we are offering, and you provide it to us. For example, if you are a Merchant Employee, we may collect information relating to children if your employer is using the Toast Payroll and Team Management module and you add them as dependents under your benefits policies.

12. How to contact us

If you have questions or concerns about our Privacy Statement, our practices or our compliance with applicable privacy laws, you can reach us at:
  • By post:
    Attn: Toast Privacy Office
    Toast, Inc.
    333 Summer St. Boston, MA 02210
  • By phone: (866) 226-4484
Additional contact points can be found in the addendums. If you need customer support that is unrelated to Privacy, please contact the guest support team on this page or navigate to the “Get Help” section of the Local by Toast app.
A downloadable version of this Statement can be found here.

13. Changes to this Privacy Statement

From time to time, we may update, change, modify or amend this Privacy Statement in order to comply with the applicable law or our changing business practices. Unless we are required by the applicable law to provide a prescribed form of notice and/or obtain consent, updated versions of this Statement may be posted on this website with additional communication. An archived version of our previous Privacy Statement can be found here . Please check this website and this Privacy Statement regularly for updates.

Addendum A – United States (California)

Last updated: December 18, 2025
1. Privacy Statement for California Residents as required by the California Consumer Privacy Act of 2018 (including as amended by the California Privacy Rights Act of 2020)(“CCPA”).
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and apply solely to individuals that are residents of California and qualify as a “Consumer” under the CCPA. This California-specific Statement provides additional information about how we collect, use, disclose and otherwise process the personal information of these individuals, either online or offline, within the scope of the CCPA. Any terms defined in the CCPA or as otherwise defined in our Privacy Statement have the same meaning as used in this addendum.
When we use the term “personal information” in this Addendum, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
  • CCPA personal information table
    The below table summarizes:
    • The categories of personal information collected by Toast in the past 12 months;
    • The sources of collection of the personal information;
    • How we use your personal information; and
    • The categories of personal information disclosed for business purposes by Toast (including to third parties) in the past 12 months.
    • Please see the generally applicable section of this Privacy Statement for additional information on Toast’s information practices, including more detail on how we use and disclose your personal information.
Category of personal information
Collected?
Examples of personal information collected*
Categories of sources
Commercial or business purpose
How we disclose your personal information
Identifiers
Yes
Merchants: Name, unique personal identifiers, IP address, email address, social security number

Guests: Name, unique personal identifiers, IP address, email address

Merchant Employees: Name, unique personal identifiers, IP address, email address
Provided directly to Toast
Automatically collected
Provided to Toast by our business partners
Provided to Toast by our service providers
Provided to Toast by our Merchants
To provide, maintain and support our Services
To manage our business and for internal operational purposes
To advertise and market to you
To personalize your experience
To communicate with you or provide information you have requested
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees
With our business partners
With our service providers
With legal and other regulatory authorities
California Customer Records (Cal. Civ. Code § 1798.80(e))
Yes
Merchants: Name, telephone number, bank account number, credit or debit card number, social security number

Guests: Name, telephone number, address, credit or debit card number
Provided directly to Toast
Provided to Toast by our business partners
Provided to Toast by our service providers
Provided to Toast by our Merchants
To provide, maintain and support our Services
To manage our business and for internal operational purposes
To advertise and market to you
To communicate with you or provide information you have requested
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees
With our business partners
With our service providers
With legal and other regulatory authorities
Protected Classification Characteristics
Yes
Merchant Employees: (using Toast Payroll and Team Management): Race, gender, age
Provided directly to Toast
Provided to Toast by our Merchants
To provide, maintain and support our Services
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees
With our service providers
Commercial Information
Yes
Merchants: Records of products or services purchased

Guests: Records of products or services purchased
Provided directly to Toast
Provided to Toast by our business partners
Provided to Toast by our service providers
Provided to Toast by our Merchants
To provide, maintain and support our Services
To manage our business and for internal operational purposes
To personalize your experience
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees
With our business partners
With our service providers
With legal and other regulatory authorities
Biometric Information
No
N/A
N/A
N/A
N/A
Internet/Network Information
Yes
Website browsing activity and interactions, advertisement interactions
Provided directly to Toast
Automatically collected
Provided to Toast by our service providers
To provide, maintain and support our Services
To manage our business and for internal operational purposes
To personalize your experience
To advertise and market to you
With our Merchants and our Merchant Employees
With our service providers
Geolocation Data
Yes
Course or precise geolocation information
Provided directly to Toast
Automatically collected
Provided to Toast by our service providers
To provide, maintain and support our Services
To personalize your experience
To advertise and market to you
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees
With our business partners
With our service providers
Sensory Information
Yes
Merchants and Merchant Employees: Audio recordings as part of support services or customer calls

Guests: Audio as part of support services
Provided directly to Toast
Provided to Toast by our service providers
To provide, maintain and support our Services
For legal, compliance and security-related purposes
With our service providers
Profession/Employment Information
Yes
Merchant Employees (using Toast Payroll and Team Management): Employment backgrounds, resumes
Provided directly to Toast
To provide, maintain and support our Services
With our Merchants and our Merchant Employees
With our service providers
Non-Public Education Information (20 U.S.C. § 1232g, 34 C.F.R. Part 99)
No
N/A
N/A
N/A
N/A
Inferences
Yes
Guests: Preferences and behavior as part of using the Services
Provided directly to Toast
Provided to Toast by our business partners
Provided to Toast by our service providers
Provided to Toast by our Merchants
To provide, maintain and support our Services
To manage our business and for internal operational purposes
To personalize your experience
To advertise and market to you
With our Merchants and our Merchant Employees
With our business partners
With our service providers
*Note that the actual personal information collected will depend on the nature of the individual relationship and the specific Services provided.
B.  Categories of personal information sold or shared
While Toast does not “sell” personal information in the traditional sense, we do, however, sell or share personal information for the purpose of displaying advertisements that are selected based on personal information obtained or inferred over time from an individual’s activities across businesses or distinctly-branded websites, applications or other services (otherwise known as “targeted advertising” or “cross-context behavioral advertising”), for personalization features and for tracking and analytics purposes.   The categories of personal information impacted in the preceding 12 months may include:
  • Identifiers;
  • Internet/Network Information; and
  • Inferences.
Each of the above categories of information may be disclosed to third-parties, which may include our business partners depending on the nature of a user’s interactions. Consumers can exercise their right to opt out of these sales or sharing through our cookie management tool that can be accessed by clicking on our “Your Privacy Choices” link at the bottom of https://pos.toasttab.com. You can also opt out of the “sale” of personal information or “sharing” for targeted advertising purposes by enabling the Global Privacy Control or a similar opt-out preference setting within the browser you use to access our Websites. Please note that your opt out will be specific to the device and browser you use when you opt out, and our Websites will recognize opt-out preference settings only on domains of our Websites where any “selling” or “sharing” occurs. Your request to opt out of “sale” / “sharing” will be linked to your browser identifier only and not linked to any account information because the connection between your browser and the account is not known to us. If you want to opt-out of other types of “sales” or “sharing” please complete an opt-out privacy request here.
You may also review our Privacy Statement section titled “Cookies and other tracking technologies” for more information on how Toast uses cookies, analytics and personalized advertising.  Toast has no actual knowledge that the “sales” or “sharing” described above include the personal information of individuals under 16 years of age.

C. Description of rights available to Consumers 
If you are a resident of the state of California and subject to certain legal limitations and exceptions, you may be able to exercise some or all of the following rights: 
  • The right to know/access: you have the right to request that an in-scope business that collects personal information from you, disclose the following upon verification of your identity: (i) the categories of personal information collected about you, (ii) the categories of sources where the personal information was collected, (iii) the business or commercial purposes for collecting (or where applicable, selling or sharing) the personal information, (iv) the categories of personal information that we have disclosed to third parties for a business purpose along with the corresponding recipients, (v) the categories of personal information we have sold or shared along with the corresponding recipients, and (vi) the specific pieces of personal information collected about you.
  • The right of deletion: you have the right to request that an in-scope business delete personal information that it has collected from you, subject to certain exceptions.
  • The right of correction: you have the right to request that an in-scope business correct inaccurate personal information, subject to certain conditions. 
  • The right to opt out of the sale or sharing of personal information: you have the right to request that an in-scope business refrain from selling or sharing personal information it has collected about you to third parties now or in the future. If you are under the age of 16, you have the right to opt in, or to have a parent or guardian opt in on your behalf, to such sales or sharing. 
  • The right to limit the use and disclosure of sensitive personal information: to the extent that we use sensitive personal information for purposes beyond those set forth in subdivision (a) of Section 1798.121, you have the right to limit the use or disclosure of that sensitive personal information subject to the exceptions within the CCPA.
  • The right of access to and to the ability to opt-out of automated decision-making technology: subject to further regulations being issued, you have the right to access information pertaining to automated decision-making technologies and the ability to opt out.
  • The right against discrimination and retaliation: you have the right to not be discriminated or retaliated against as a result of exercising any of the above rights. 
However, please note that if the exercise of these rights limits our ability to process personal information (such as in the case of a deletion request), we may no longer be able to provide you with our Services or engage with you in the same manner. In addition, the exercise of the rights described above may result in a different price, rate, or quality level of product or service where that difference is reasonably related to the impact the right has on our relationship or is otherwise permitted by law.
Please note that your ability to invoke the rights above are limited pursuant to the scope and limitations of the CCPA, including any available exceptions. For example, an access request can only be made twice by a Consumer within a 12-month period. 
D.   How to invoke your rights
Toast has established an individual rights portal as well as other channels for the purposes of submitting the individual rights requests above, including the right of access and deletion. Individual rights requests can be submitted to Toast through the below channels:
  • By post:
    Attn: Toast Privacy Office
    Toast, Inc.
    333 Summer St. Boston, MA 02210
  • By phone (toll-free): (866) 226-4484

Once an individual rights request has been submitted, Toast may ask you for additional information in order to verify your identity or to provide additional details to help us respond to your request. This may include your name, email address, phone number or other details related to your use of Toast’s Services. Where applicable, these requests can be submitted by an authorized agent through the channels described above in accordance with the applicable law.  In these instances, we will take steps to verify the authorized agent’s authority to act on your behalf. In order to verify the authorized agent’s authority, we generally require evidence of either (i) a valid power of attorney or (ii) a signed letter containing your name and contact information, the name and contact information of the authorized agent, and a statement of authorization for the request. Depending on the evidence provided, we may still need to separately reach out to you to confirm the authorized agent has permission to act on your behalf and to verify your identity in connection with the request. Please note that in certain circumstances, we may refuse to act or impose limitations on your rights, as permitted by the applicable law in relation to individual rights submissions.   

To Exercise the Right to Opt Out of the Selling or Sharing of Personal Information 
In certain instances, transfers of data by Toast (including at the direction of Merchants) to third parties may constitute “selling’/’sales” or “sharing” personal information as defined under Applicable State Law. The purpose of certain transfers is to display targeted advertisements which may be selected based on personal information obtained or inferred over time from an individual’s activities, for personalization features and for tracking and analytics purposes. You can opt-out of these sales as explained below.
If you want to opt out of targeted advertising and “sales” and/or “sharing” of data (as defined under relevant State law) with respect to cookies, pixels and other tracking technologies on websites where such technologies are deployed, this can be managed by clicking the “Your Privacy Choices” link at the bottom of websites (such as pos.toasttab.com). Therefore, your opt out will be specific to the device and browser you use when you opt out, and websites will recognize opt-out preference settings only on domains of our websites where any “selling” or “sharing” occurs. Your request to opt out of “sale” / “sharing” will be linked to your browser identifier only and not linked to any account information because the connection between your browser and the account is not known to us. If you want to opt-out of other types of “sales” or “sharing” please complete an opt-out privacy request here.
You may also review the Privacy Statement section titled “Cookies and other tracking technologies” for more information on how Toast uses cookies, analytics and personalized advertising.
Consumers can also exercise their right to opt out of other sale types these sales by submitting a request via one of the methods described in Section D above. If you share your email address with us as part of your request, we will opt your email address (and other known identifiers) out of targeted advertising and “sales” of data (as defined under Applicable State Law). You can also opt out of the “sale” of personal information or “sharing” for targeted advertising purposes by enabling the Global Privacy Control  or a similar opt-out preference setting within the browser you use to access our Websites. Unless you have exercised your right to opt out of the sale or sharing of personal information, we may “sell” or “share” your personal data to third parties for targeted or cross-context behavioral advertising purposes, for personalization features and for tracking and analytics purposes. The third parties to whom we sell or share personal information may use such information for their own purposes in accordance with their own privacy statements. You do not need to create an account with us to exercise your right to opt out of personal information sales or sharing. However, if applicable, we may ask you to provide additional personal information so that we can properly identify you in our dataset and to track compliance with your opt out request. We will only use personal information provided in an opt out request to review and comply with the request. If you choose not to provide this information, we may only be able to process your request to the extent we are able to identify you in our systems.
E. Accessibility
In the event you are a user with a disability, or are supporting an individual with a disability, and are having difficulty navigating this Statement or the information linked within this Statement, please contact us at compliance@toasttab.com for support. 
F. Sensitive Personal Information
As part of our services, Toast collects “sensitive personal information” as defined by the CCPA as part of our operations and the Services offered to our Merchants. The categories of sensitive personal information are described below along with the use case and whether the information is sold or shared. 

Category of 
sensitive personal information 
Use/Purpose
Is the sensitive personal information sold?
Is the sensitive personal information shared? 
Social Security Number
Merchants - required as part of the sign up to the Services 
Merchant Employees - required for Payroll and Team Management services

X
X

Driver’s license number or state ID
Merchants - required as part of the sign up to the Services
Merchant Employees - required for Payroll and Team Management services


X

X


Account log-in details plus password or credentials
Merchants - needed to access the Merchant’s Toast account
Merchant Employees – needed to access the Toast services or Payroll and Team Management services
Guests – needed for Toast Digital Account purposes


X
X


Precise geolocation 

Guests - needed for certain digital ordering services and as part of the Services requested by a Guest or with the consent of the individual

X
X


Race or ethnic origin

Merchant Employees – collected with the consent of the individual by the Merchant as part of the Payroll & Team Management services


X

X


Health data


Guests – to the extent that allergy and dietary restrictions qualify as “health data”, the Guest may voluntarily elect to provide this as part of a reservation or their dining experience in the “additional information” section or other free form fields


X
X

Presently, Toast does not use or discloses an individual’s sensitive personal information for purposes other than those specified in subdivision (a) of section 1798.121 of the CCPA and as a result, has not included a Notice of Right to Limit.
 G. Retention
We retain personal information as long as reasonably necessary to provide the Services and carry out the purposes described in this Statement. However, if necessary, we may retain personal information for longer periods of time, until set retention periods and deadlines expire, or for instances where we are required to do so in accordance with legal, tax and accounting requirements set by a legislature, regulator or other government authority.  
To determine the appropriate duration of the retention of personal information, we consider the amount, nature and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of personal information and if we can attain our objectives by other means, as well as our legal, regulatory, tax, accounting and other applicable obligations. 
 As to each of the categories of personal information collected, the retention period will vary depending on our    relationship. For example,
  • For Merchants and Merchant Employees, we will generally retain their personal information for the duration of our agreement with the Merchant plus a period following termination as provided for in our retention schedules. 
  • For Guests that have Toast Digital Ordering Accounts, Toast will generally maintain these accounts for the duration of the individual’s use of service plus a period of inactivity.
  • In other cases, Guest information that is collected by the Merchant but stored by Toast will be retained for the duration of our agreement with the Merchant plus a period following termination as provided for in our retention schedules. 
  • Information pertaining to support calls are generally retained for one (1) year but may be retained for longer based on the nature of the relationship between Toast and the individual. 
 In all cases, the retention will be subject to any additional legal, regulatory, tax, accounting or other applicable obligations. 
Once retention of the personal information is no longer necessary for the purposes outlined above, we will either delete or de-identify the personal information or, if this is not possible (for example, because personal information has been stored in backup archives), then we will securely store the personal information and isolate it from further processing until deletion or deidentification is possible.
H. Notice of Financial Incentives and loyalty programs
We may offer or enable Merchants to offer various programs, promotions, or features that may be considered a "financial incentive" under privacy laws such as the CCPA.
Toast Programs: These include discounts, special offers, or other benefits we provide directly in exchange for certain actions such as using Toast services or providing information.
Merchant Programs: Merchants may use Toast services to run their own loyalty and rewards programs (e.g., discounts, rewards, etc.). Please note that Toast merely provides the platform and the Merchant manages these programs. Contact the specific Merchant for details or questions about their programs.
Valuation of Personal Information:  We do not assign a precise monetary value to the personal information collected through these programs. The value is derived from the increased customer engagement and loyalty that helps us improve our services.  The value may differ based on the customer and their usage of the relevant Toast and Merchant programs.
Right to Withdraw: You have the right to withdraw from any Toast-offered financial incentive program at any time. To withdraw from a Toast-offered program, please submit a request should be submitted via the portal (available here), and include the phrase  "Financial Incentive Program Withdrawal” in the body of your request. To withdraw from a Merchant  program, please contact the Merchant directly.
I. Deidentified information 
We may at times receive, or process personal information to create, deidentified information that can no longer reasonably be used to infer information about, or otherwise be linked to, a particular individual or household. Where we maintain deidentified information, we will maintain and use the information in deidentified form and not attempt to reidentify the information except as required or permitted by law.
J.     Updates to this Statement
We will update this Statement from time to time. When we make changes to this Statement, we will change the "Last updated" date at the beginning of this Statement. All changes shall be effective from the date of publication unless otherwise provided in the notification.
  • California “Shine the Light” disclosure
California residents that have an established business relationship with us have a right to know how their information is disclosed to third parties for their direct marketing purposes under California’s “Shine the Light” law (Civ. Code § 1798.83). Please contact us through any of the communication channels within the “How to contact us” section in the main body of this Statement to invoke these rights. 


Addendum B – United States (State Law)

Last updated: Demember 17, 2025
1. Privacy Statement for residents of Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia (the “States”) as required by the Colorado Privacy Act, Delaware Personal Data Privacy Act,  Indiana Consumer Data Protection Act, Iowa Act Relating to Consumer Data Protection, Kentucky Consumer Data Protection Act, Maryland Online Data Privacy Act, Minnesota Consumer Data Privacy Act, Nebraska Data Privacy Act, New Hampshire Privacy Act, New Jersey New Jersey Data Protection Act, Oregon Consumer Privacy Act, Rhode Island Data Transparency and Privacy Protection Act, Tennessee Information Protection Act, Texas Data Privacy and Security Act, Privacy Statement for Utah Residents as required by the Utah Consumer Privacy Act, Virginia Residents as required by the Virginia Consumer Data Protection Act, (“Applicable State Law”).
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and apply solely to individuals that are residents of The states and qualify as a “Consumer”, or equivalent term under the Applicable State Law respectively. This State-specific Statement provides additional information about how we collect, use, disclose and otherwise process the personal information of these individuals, either online or offline, within the scope of the Applicable State Law. Any terms defined in the Applicable State Law or as otherwise defined in our Privacy Statement have the same meaning as used in this Addendum.
When we use the term “personal information” in this Addendum, we mean “personal data”, and equivalent terms used the Applicable State Law, including information that is linked or reasonably linkable to an identified or identifiable natural person.
2. Categories of personal information processed
Please refer to the “Personal information we collect” section in the main body of the Statement.
In addition, Toast may collect “sensitive data” as defined by Applicable State Law (including the TDPSA) as part of our operations and the Services offered to our Merchants. The following categories of data may be collected from Guests: -Personal data revealing mental or physical health diagnosis, to the extent that allergy and dietary restrictions are capable of revealing a mental or physical health diagnosis (“Health data”)
-Precise geolocation data
3. Purposes of processing the personal information
Please refer to the “How we use personal information” section in the main body of the Statement. In addition, Toast may collect “sensitive data” as defined by the Applicable State Law (including the TDPSA) for the following purposes
-Health data: a Guest may voluntarily elect to provide this as part of a reservation or their dining experience in the “additional information” section or other free form fields
-Precise geolocation data: needed for certain digital ordering services and as part of the Services requested by a Guest or with the consent of the individual
4. Categories of information disclosed to third parties and a description of those third parties
Please refer to the “How we share personal information” section in the main body of the Statement. With respect to sensitive data, Toast may share precise geolocation data with partners and/or service providers in order to support certain digital ordering services and as part of the Services requested by a Guest, or with the consent of the individual.
5. Categories of third parties with which we share personal information
Please refer to the “How we share personal information” section in the main body of the Statement.
6. Description of rights available to consumers
A number of individual rights are available to individuals under the Applicable State Law relating to personal information that we have collected (subject to certain limitations), depending on your State of residence may include:
  • The right to correction: you have the right to correct inaccuracies in your personal information, taking into account the nature of the personal information and purposes of the processing.
  • The right to deletion: you have the right to delete your personal information you have provided or that has been collected.
  • The right to obtain a portable copy of your personal information: you have the right to obtain a copy of your personal information that was previously provided in a portable, and to the extent technically feasible, readily usable format that can be transmitted to another entity.
  • The right to opt out: you have the right to opt out of (as defined by the Applicable State Law) (i) targeted advertising, (ii) the sale of personal information and (iii) profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.
  • For residents of Delaware & Oregon: The right to be informed of third party disclosures: you have the right to obtain a list of specific third parties, other than natural persons, to which Toast has disclosed personal information.
  • For residents of Minnesota:
    The right to question the result of profiling: if your personal data is profiled in furtherance of decisions that produce legal effects concerning you, you have the right to question the result of the profiling, to be informed of the reason that the profiling resulted in the decision, and, if feasible, to be informed of what actions you might have taken to secure a different decision and the actions that you might take to secure a different decision in the future. You have the right to review your personal data used in the profiling. If the decision is determined to have been based upon inaccurate personal data, taking into account the nature of the personal data and the purposes of the processing of the personal data, you have the right to have the data corrected and the profiling decision reevaluated based upon the correct data. 
  • For Residents of Rhode Island:
    The right to be informed of data sale recipients: you have the right to obtain a list of third parties to whom your personally identifiable information has been or may be sold.
7. How to invoke your rights
Toast has an established process for handling individual rights requests. Individual rights requests can be submitted to Toast through the below channels:
  • Web portal:
    Individual Rights Portal
    *If you do not see the State where you reside listed in the portal but this addendum applies, please contact us using one of the other methods listed here (e.g. post or phone).
  • By post:
    Attn: Toast Privacy Office
    Toast, Inc.
    333 Summer St. Boston, MA 02210
  • By phone (toll-free): (866) 226-4484
Once an individual rights request has been submitted, Toast may ask you for additional information in order to verify your identity or to provide additional details to help us respond to your request. This may include your name, email address, phone number or other details related to your use of Toast’s Services. Where applicable, these requests can be submitted by an authorized agent through the channels described above in accordance with the applicable law. These include requests made on behalf of a minor by the individual’s parent or legal guardian can also be made via the individual rights portal above. In these cases, in order to verify the authorized agent’s authority, we generally require evidence of that individual’s authority to act on behalf of the individual. All individual rights requests will be managed in line with the requirements set out in the Applicable State Law.
Please note that in certain circumstances, we may refuse to act or impose limitations on your rights, as permitted by the applicable law. In the event we decline to take action on a request, we will notify you within the relevant statutory period (typically between 30-90 days from receipt of the original request with our justification for declining to take action and how you may appeal that decision (including an overview of the appeals process and how you can initiate an appeal). All appeal requests should be submitted via the portal (available here), and include the phrase “Privacy Request Appeal” in the body of your request.
8. Sale of personal information
In certain instances, transfers of data by Toast (including at the direction of Merchants) to third parties may constitute "selling"/"sales" or sharing personal information as defined under Applicable State Law. The purpose of certain transfers is to display targeted advertisements which may be selected based on personal information obtained or inferred over time from an individual’s activities, for personalization features and for tracking and analytics purposes. You can opt-out of these sales as explained below.
If you want to opt out of targeted advertising and “sales” and/or “sharing” of data (as defined under relevant State law) with respect to cookies, pixels and other tracking technologies on websites where such technologies are deployed, this can be managed by clicking the “Your Privacy Choices” link at the bottom of websites (such as pos.toasttab.com). Therefore, your opt out will be specific to the device and browser you use when you opt out, and websites will recognize opt-out preference settings only on domains of our websites where any “selling” or “sharing” occurs. Your request to opt out of “sale” / “sharing” will be linked to your browser identifier only and not linked to any account information because the connection between your browser and the account is not known to us. If you want to opt-out of other types of “sales” or “sharing” please complete an opt-out privacy request here.
You may also review the Privacy Statement section titled “Cookies and other tracking technologies” for more information on how Toast uses cookies, analytics and personalized advertising.
Consumers can also other exercise their right to opt out of other types of sales by submitting a request via one of the methods described in Section 7 above. If you share your email address with us as part of your request, we will opt your email address (and other known identifiers) out of targeted advertising and “sales” of data (as defined under Applicable State Law). You can also opt out of the “sale” of personal information or “sharing” for targeted advertising purposes by enabling the Global Privacy Control or a similar opt-out preference setting within the browser you use to access our Websites.
9. Targeted advertising
Toast carries out limited targeted advertising (as that term is defined by the Applicable State Law) via cookies and related tracking technologies, and Merchants may direct targeted advertising activities on Toast Services. You can manage your cookie-based targeted advertising preferences by clicking the “Your Privacy Choices” link or the "Cookie Settings" (where applicable) at the bottom of the website you are visiting. Your request to opt out of “sale” / “sharing” will be linked to your browser identifier only and not linked to any account information because the connection between your browser and the account is not known to us. If you want to opt-out of other types of “sales” or “sharing” please complete an opt-out privacy request here.
10. Profiling
Presently, Toast does not carry out any profiling (as defined by the Applicable State Law) in furtherance of decisions that produce legal or similarly significant effects concerning consumers that are presently in scope for Applicable State Law purposes.
11. Deidentified information
We may at times receive, or process personal information to create, deidentified information that can no longer reasonably be used to infer information about, or otherwise be linked to, a particular individual. Where we maintain deidentified information, we will maintain and use the information in deidentified form and not attempt to reidentify the information except as required or permitted by law.
12. Contact
Should you need to contact the Toast privacy office, please phone (toll-free): (866) 226-4484, or submit a request to the portal here. For tech/customer support and other questions that do not relate to privacy, Merchants should contact Toast Customer Care, and Guests should contact the guest support team on this page or navigate to the “Get Help” section of the Local by Toast app.
13. Updates to this Statement
We will update this Statement from time to time. When we make changes to this Statement, we will change the "Last updated" date at the beginning of this Statement. All changes shall be effective from the date of publication unless otherwise provided in the notification.

Addendum C – Canada

Last updated: January 1, 2025
1. Privacy addendum for individuals located in Canada
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and apply solely to individuals that are residents of Canada or are otherwise covered under any applicable Canadian federal or provincial privacy laws or regulations, including but not limited to the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”), Alberta’s Personal Information Protection Act, and British Columbia’s Personal Information Protection Act. Toast is committed to collecting, using, and disclosing your personal information in accordance with applicable laws and regulations.
  • Consent
    By using our Services and accessing our Websites, you accept the terms of this Privacy Statement and consent to the collection, use, processing, disclosure and retention of your information as described in this Privacy Statement. Typically, we will provide notice of the purpose for collecting your personal information and/or seek your consent (which may be express or implied, depending on the nature and sensitivity of the personal information) in line with applicable law at the time that we collect your personal information. In certain circumstances, we may collect non-sensitive personal information automatically. In general, you may change or withdraw your consent at any time subject to legal or contractual obligations and providing reasonable notice. Your withdrawal of consent may impact the ability of Toast to provide you with some or all of the Services. Upon receiving notice that you would like to withdraw your consent, we will inform you of the likely consequences of your withdrawal of consent.
    Toast will not collect, use, or disclose your personal information except for the purposes we have identified for collection (including those listed in section 4 of the Toast Privacy Statement above and/or identified at the time of collection), unless we have received your consent (which may be express or implied, depending on the nature and sensitivity of the personal information) or the processing is authorized without consent.
  • Accessing and correcting your personal information
    If you are located in Canada, you have the right to request access to and to correct the personal information that we hold about you, subject to certain conditions and limitations. Subject to the applicable law and the nature of your relationship with Toast, this may include a right to review, correct, update, suppress, delete or otherwise limit our use of your personal information that has been previously provided to us. You may also have the right to access information about the ways in which your personal information is or has been used and the names of individuals and/or organizations to which your information has been disclosed.
    Toast has established an individual rights portal for the purposes of submitting such individual rights requests. The link to Toast’s individual rights portal can be found here. Individual rights requests can also be submitted to Toast through the below channels:
    • By post:
      Attn: Toast Privacy Office
      Toast, Inc.
      333 Summer St. Boston, MA 02210
      United States of America
    In your request, please specify what information you would like to access or have corrected. We will respond to your request as soon as reasonably practicable, and within the time period required by law. The exercise of these rights is free of charge. Once an individual rights request has been submitted, Toast may ask you for additional information in order to verify your identity or to provide additional details to help us respond to your request. This may include your name, email address, phone number or other details related to your use of Toast’s Services or Websites.
    If we correct your information, we will also send the corrected information to organizations to which we disclosed the information during the year before the date the correction was made.
    Please note that in certain circumstances, we may refuse to act or impose limitations on your rights, as permitted by the applicable law. If we cannot provide you with access to your personal information or are unable to correct your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions, and outline further steps available to you. If we refuse to act on a request to correct your personal information, we will nonetheless annotate the information, noting the correction that was requested but not made.
    In certain cases, depending on the nature of your request, there may also be residual information that will remain within our databases and other records, which, due to applicable law or as part of Services that are in the process of being carried out, will not be removed or changed. We will also retain information relating to your request for recordkeeping and compliance purposes.
  • Cross-border transfers
    We may process, store, and transfer your personal information in and to a foreign jurisdiction, with different privacy laws that may or may not be as comprehensive as Canadian law. In these circumstances, the governments, courts, law enforcement, or regulatory agencies of that jurisdiction may be able to obtain access to your personal information through the laws of the foreign jurisdiction.
    Specifically, the personal information collected as part of the Services or as otherwise contemplated by this Statement is primarily processed and stored in the United States. However, as Toast is an international organization with business processes, offices and third parties around the world, your information may be sent to any other jurisdiction in the world where we do business or maintain third-party relationships. When you provide personal information to us through the Services and as part of this Statement, you consent to the transfer of your information and the processing of your information in this manner. Any international transfers made will be in accordance with this Statement and the applicable law.
    We also impose appropriate safeguards for the transfer of personal information among our affiliates and to third-party service providers in various jurisdictions, and have implemented appropriate contractual arrangements or other measures for such purposes.
    To obtain a current list of the jurisdictions where personal information subject to this Statement is collected, used, disclosed and/or stored, including with our service providers, please visit Toast’s sub-processor page.
  • Right to challenge compliance and file a complaint
    If you believe any privacy laws relating to the protection of your personal information or the practices described in this Statement have not been respected, you may file a complaint with our Assistant General Counsel, Privacy at the address listed below:
    • By post:
      Attn: Assistant General Counsel, Privacy
      Toast, Inc.
      333 Summer St. Boston, MA 02210
      United States of America
    • By phone (toll-free): +1 (866) 226-4484
    Toast may ask you for additional information in order to verify your identity or to provide additional details to help us respond to your complaint.
    We will investigate all complaints. If, after an investigation, your complaint is deemed justified, Toast will take appropriate steps to correct the situation, including, if necessary, amending our policies and practices. If you are not satisfied with the results of the investigation or the corrective measures taken by Toast, you may exercise the remedies available under law by contacting the Office of the Privacy Commissioner of Canada at the address below:
    Office of the Privacy Commissioner of Canada
    30 Victoria Street
    Gatineau, Quebec
    K1A 1H3
    https://www.priv.gc.ca
    If you reside in the Province of Alberta, you may also contact the Office of the Information and Privacy Commissioner of Alberta at the address below:
    Office of the Information and Privacy Commissioner of Alberta
    #410, 9925 - 109 Street NW
    Edmonton, Alberta
    T5K 2J8
    https://www.oipc.ab.ca/
    If you reside in the Province of British Columbia, you may also contact the Office of the Information and Privacy Commissioner for British Columbia at the address below:
    Office of the Information and Privacy Commissioner for British Columbia
    PO Box 9038 Stn. Prov. Govt.
    Victoria B.C.
    V8W 9A4
    https://www.oipc.bc.ca/
If you reside in the Province of Quebec, you may also contact
The Commission d'accès à 'information Québec
525, boulevard René-Lévesque Est,
bureau 2.36
Québec (Québec)  G1R 5S9
https://www.cai.gouv.qc.ca
5. For individuals in Quebec, the table below summarizes:
  • The categories of personal information collected by Toast in the past 12 months;
  • The sources of collection of the personal information; 
  • How we use your personal information; and
  • The categories of personal information disclosed for business purposes by Toast (including to third parties) in the past 12 months.
Please see the generally applicable section of this Privacy Statement for additional information on Toast’s information practices, including more detail on how we use and disclose your personal information.
Category of personal information
Examples of personal information collected*
Categories of sources
Commercial or business purpose
How we disclose your personal information
Identifiers
Merchants: Name, unique personal identifiers, IP address, email address, social security number
Guests: Name, unique personal identifiers, IP address, email address
Merchant Employees: Name, unique personal identifiers, IP address, email address
Provided directly to Toast
Automatically collected
Provided to Toast by our business partners
Provided to Toast by our service providers
Provided to Toast by our Merchants
To provide, maintain and support our Services 
To manage our business and for internal operational purposes
To advertise and market to you
To personalize your experience
To communicate with you or provide information you have requested 
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees 
With our business partners
With our service providers
With legal and other regulatory authorities
Protected Classification Characteristics
Merchant Employees:  (using Toast Payroll and Team Management): Race, gender, age
Provided directly to Toast
Provided to Toast by our Merchants
To provide, maintain and support our Services
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees
With our service providers
Commercial Information
Merchants: Records of products or services purchased
Guests: Records of products or services purchased
Provided directly to Toast
Provided to Toast by our business partners
Provided to Toast by our service providers
Provided to Toast by our Merchants
To provide, maintain and support our Services 
To manage our business and for internal operational purposes
To personalize your experience
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees
With our business partners
With our service providers
With legal and other regulatory authorities
Internet/Network Information
Website browsing activity and interactions, advertisement interactions
Provided directly to Toast
Automatically collected
Provided to Toast by our service providers
To provide, maintain and support our Services 
To manage our business and for internal operational purposes
To personalize your experience
To advertise and market to you
With our Merchants and our Merchant Employees
With our service providers
Geolocation Data
Course or precise geolocation information
Provided directly to Toast
Automatically collected
Provided to Toast by our service providers
To provide, maintain and support our Services 
To personalize your experience
To advertise and market to you
For legal, compliance and security-related purposes
With our Merchants and our Merchant Employees
With our business partners
With our service providers
Sensory Information
Merchants and Merchant Employees: Audio recordings as part of support services or customer calls
Guests: Audio as part of support services
Provided directly to Toast
Provided to Toast by our service providers
To provide, maintain and support our Services 
For legal, compliance and security-related purposes
With our service providers
Profession/Employment Information
Merchant Employees (using Toast Payroll and Team Management): Employment backgrounds, resumes
Provided directly to Toast
To provide, maintain and support our Services
With our Merchants and our Merchant Employees
With our service providers
Inferences
Guests: Preferences and behavior as part of using the Services
Provided directly to Toast
Provided to Toast by our business partners
Provided to Toast by our service providers
Provided to Toast by our Merchants
To provide, maintain and support our Services 
To manage our business and for internal operational purposes
To personalize your experience
To advertise and market to you
With our Merchants and our Merchant Employees
With our business partners
With our service providers

*Note that the actual personal information collected will depend on the nature of the individual relationship and the specific Services provided.
We will retain personal information used to make a decision that directly affects you for at least one year after we make that decision.


Addendum D – Ireland

Last updated: January 1, 2025
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and applies where the General Data Protection Regulation (“GDPR”) and local implementing legislation apply, which includes where Toasttab Ireland Limited provides Services. To the extent that there is a conflict between the provisions of this Addendum G and the provisions of the main body of the Privacy Statement, the provisions of this Addendum G shall prevail.
1. Data controller(s)
For the purposes of the processing pursuant to this Statement, the joint data controllers will include:
  • Toasttab Ireland Limited (“Toast Ireland”)
    124 St Stephen’s Green
    Dublin 2
    Ireland
    D02 C628
  • Toast, Inc. (“Toast US”)
    333 Summer St.
    Boston, MA 02210
    United States of America
  • Toast US is primarily responsible for ensuring that personal information is collected and processed pursuant to the applicable law. These obligations include (a) the implementation of appropriate data protection policies, (b) the management and notification of security incidents involving personal information, (c) the completion of data protection impact assessments (where appropriate) and (d) the implementation of appropriate technical and organizational security measures. Toast US is also responsible for managing any requests that you may make to exercise your rights under the GDPR or other applicable data protection legislation, on behalf of both Toast Ireland and Toast US.
  • Toast Ireland is responsible for managing aspects of the processing that are within its control as part of the joint controller relationship. This includes support and management pertaining to the provision of the Services, obtaining consents from data subjects (where applicable) as well as support with providing notice to data subjects. Where Toast Ireland receives a data subject request under the GDPR, Toast Ireland will promptly notify Toast US of the request. As a data controller, we are free to rely on “data processors” (as defined within the GDPR) and have engaged various third-party service providers in order to provide the Services as well as for other purposes described in the main body of the Privacy Statement. For more information, see the “How we share personal information” section of the Privacy Statement.
Toast Ireland and Toast US also act as processors on behalf of Merchants as to certain Services provided to Guests as well as our Merchants Employees in connection with certain aspects of our Services. The Merchant is the data controller in respect of this relationship.
2. Purposes and legal basis for processing
We collect and process your personal information based on the following legal bases:
Purpose of processing (as described further in section 4 of this Statement)
Legal basis for processing
To provide, maintain and support our Services
Where we have a contract with you, necessary for the performance of our contract with you
Where we do not have a contract with you, our legitimate interests in operating our business
To manage our business and for internal operational purposes
Necessary for our legitimate interests of effectively managing our business operations and improving our products and services
To personalize your experience
Necessary for our legitimate interests of effectively managing our business operations and improving our products and services
To advertise and market to you
Your consent which is required under law some cases) or as necessary for our legitimate interests of effectively promoting our business, products and services
To communicate with you or provide information you have requested
Where we have a contract with you, necessary for the performance of our contract with you
Where we do not have a contract with you, our legitimate interests in operating our business
For legal, compliance and security-related purposes, including to:
comply with our Irish legal obligations, including under anti-money laundering, know-your-customer or similar laws
comply with our legal obligations outside Ireland, including under anti-money laundering, know-your-customer or similar laws in any relevant jurisdiction
secure and protect our network and systems
identify and protect against fraud and other crimes
establish, exercise or defend legal claims
monitor and report compliance issues
See below
Necessary for compliance with our legal obligations under Irish law
Necessary for our legitimate interest in complying with laws, protecting our network and systems, our business and others and establishing, exercising or defending our legal rights
Necessary for compliance with our legal obligations under Irish law where required by Irish law or, where not required by Irish law, necessary for our legitimate interest in effective compliance management


Where we process personal information on the basis of a legitimate interest (as identified above), as required by data protection law, we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals’ interests outweigh our interests in the processing taking place. You can obtain more information about this balancing test by using the contact details at the end of this Addendum.

Where we collect personal information to administer our contract with you or to comply with our legal obligations, this is mandatory and we will not be able to perform the contract we have entered into with you or otherwise provide the Services without this information. In all other cases, provision of the requested personal information is optional, but this may affect your ability to use our Services or our websites.
3. International transfers
We may transfer the personal information we collect about you for the purposes described in this Privacy Statement to countries that have not been found to provide an adequate level of data protection by the European Commission.
In particular, we may transfer your personal information to third parties, including to parties located in the United States. We use appropriate safeguards for the transfer of personal information to third party service providers. Where required, we have implemented the EU/EEA approved standard contractual clauses, rely on a service provider’s processor binding corporate rules or have implemented/rely on other legally recognized safeguards for data transfer purposes.
We also use appropriate safeguards for the transfer of personal information among our affiliates in the United States. We have implemented the EU/EEA approved standard contractual clauses or have implemented/rely on other legally recognized safeguards for data transfer purposes.
To obtain a copy of the standard contractual clauses or other transfer safeguards, please call (toll-free): +1 (866) 226-4484. A summary of these safeguards is set out here.
Summary of safeguards
When we transfer personal data outside the European Economic Area, including to the United States, we rely on the European Commission’s Standard Contractual Clauses (SCCs) under Article 46 of the GDPR. These clauses provide a legally recognised mechanism to ensure that any personal data transferred outside the EEA continues to benefit from a level of protection essentially equivalent to that guaranteed within the EU.
The SCCs include safeguards such as:
  • Contractual commitments requiring the recipient to process personal data only on documented instructions and in compliance with the GDPR’s core principles.
  • Obligations regarding confidentiality and security, including requirements to implement appropriate technical and organisational measures to protect the data.
  • Restrictions on onward transfers, ensuring that data can only be shared with further third parties if they are subject to equivalent protection.
  • Transparency requirements, enabling data subjects to understand how their data is handled when transferred internationally.
  • Data minimisation and purpose limitation, ensuring that data is used only for the specific purposes for which it was provided.
  • Mechanisms for data subject rights, including requirements on the recipient to assist us in responding to requests to access, delete or correct personal data.
  • Requirements to assess and document risks, including conducting transfer impact assessments (TIAs) where relevant.
  • Commitments relating to government access requests, including notifying us (where legally permitted) and challenging disproportionate or unlawful requests.
4. Choice and access
You have additional rights regarding how your personal information is processed, including the right to:
  • request access to and obtain a copy of your personal information;
  • request the transfer of your personal information you have provided to us to you or another company in a structured, commonly used and machine-readable format;
  • request rectification of your personal information when it is inaccurate or incomplete;
  • request erasure of your personal information where permitted under the applicable law, such as where the information is no longer necessary or lawful for us to store or where your information is outdated;
  • restrict or object to the processing of your personal information (as applicable), including to object to the processing of personal information for direct marketing purposes; and
  • withdraw your consent at any time where this is the legal basis on which we are processing your personal information. If you ask to withdraw your consent, this will not affect any processing which has already taken place at that time.
  • Please note that if you choose to withdraw your consent, you may not be able to participate in or benefit from the programs, services and initiatives for which you provided consent to the processing of your personal information. Your rights will in each case be subject to the restrictions set out in applicable data protection laws.
You may exercise these rights free of charge by submitting your request here. Subject to the applicable law, Toast may charge a reasonable fee or refuse to act on a request if it is manifestly unfounded or excessive, in particular because of its repetitive character. In some situations, Toast may refuse to act or impose limitations on the information disclosed if, for instance, if fulfilling your request would reveal personal information about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.
You also have the right to lodge a complaint about our processing of your personal information with the Irish Data Protection Commission.
5. Retention
We will retain your personal information for only as long as needed for the purpose of the processing activity or where we have a legitimate business need to retain it, subject to our legal and regulatory obligations to retain it longer and our applicable records retention periods. The duration of these periods will vary depending on your relationship with Toast and the Service you are using. For example,
  • Merchants: Merchant account and ownership information will generally be maintained for seven (7) years following the termination of the relationship absent a legal or regulatory obligation to retain longer;
  • Merchant Employees: Merchant employee information will generally be maintained for seven (7) years following the termination of the relationship with the Merchant unless removed sooner by the Merchant; and
  • Guests: Digital ordering accounts created by our Guests will be maintained for the duration of their use of the service and removed following five (5) years of inactivity. Transactional information and other Guest information held by our Merchants as part of their operations will be retained for the duration of our relationship with the Merchant plus a period of seven (7) years.
  • Other periods are set out within Toast’s records retention policy and schedule. Our retention periods are also subject to any rights of individuals or other requirements that might dictate a shorter retention period (e.g., deletion requests). In certain cases, Toast may also maintain information for a longer period of time, such as in cases where the information is subject to a legal claim or complaint. Following those periods and other determinations on the duration of the processing of personal information by Toast, we will delete or take measures to anonymize your personal information.
6. Cookies and other technologies
In addition to the information found in the section of the main body of the Statement titled “Cookies and other tracking technologies”, Toast’s Cookie Policy can be found here and provides some supplemental information for users in the EU/EEA and UK.
7. Children
Our Services are not targeted or directed at children under the age of 16, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 16. If you have reason to believe that a child under the age of 16 has provided personal information to us, we encourage the child’s parent or guardian to contact us as described in the “How to contact us” section within the main body of the Privacy Statement to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 16, we will promptly delete that personal information.
8. How to contact Toast Ireland
If you have data protection questions specific to Toast Ireland, you can reach us at:
Attention:
Toast Ireland Data Protection Office
Toasttab Ireland Limited
124 St Stephen’s Green
Dublin 2
Ireland
D02 C628
9. Lodging a complaint
If you are not satisfied with the processing of your personal information, you have the right to lodge a complaint with the Data Protection Commission (https://www.dataprotection.ie/).

Addendum E – United Kingdom (“UK”)

Last updated: January 1, 2025
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and applies where the UK General Data Protection Regulation (“UK GDPR”) and the UK Data Protection Act 2018 (together the “UK Data Protection Law”) apply, which includes where Toasttab UK Limited provides Services. To the extent that there is a conflict between the provisions of this Addendum H and the provisions of the main body of the Privacy Statement, the provisions of this Addendum H shall prevail.
1. Data controller(s)
For the purposes of the processing pursuant to this Statement, the joint data controllers will include:
  • Toasttab UK Limited (“Toast UK”)
    3rd Floor, 1 Ashley Road
    Altrincham
    Cheshire
    WA14 2DT
    United Kingdom
  • Toast, Inc. (“Toast US”)
    333 Summer St.
    Boston, MA 02210
    United States of America
  • Toast US is primarily responsible for ensuring that personal information is collected and processed pursuant to UK Data Protection Law. These obligations include (a) the implementation of appropriate data protection policies, (b) the management and notification of security incidents involving personal information, (c) the completion of data protection impact assessments (where appropriate) and (d) the implementation of appropriate technical and organizational security measures. Toast US is also responsible for managing any requests that you may make to exercise your rights under UK Data Protection Law, on behalf of both Toast UK and Toast US.
Toast UK is responsible for managing aspects of the processing that are within its control as part of the joint controller relationship. This includes support and management pertaining to the provision of the Services, obtaining consents from data subjects (where applicable) as well as support with providing notice to data subjects. Where Toast UK receives a data subject request under UK Data Protection Law, Toast UK will promptly notify Toast US of the request.
As a data controller, we are free to rely on “data processors” (as defined within UK Data Protection Law) and have engaged various third-party service providers in order to provide the Services as well as for other purposes described in the main body of the Privacy Statement. For more information, see the “How we share personal information” section of the Privacy Statement.
Toast UK and Toast US also act as processors on behalf of Merchants as to certain Services provided to Guests as well as our Merchants Employees in connection with certain aspects of our Services. The Merchant is the data controller in respect of this relationship.
2. Purposes and legal basis for processing
We collect and process your personal information based on the following legal bases:
Purpose of processing (as described further in section 4 of this Statement)
Legal basis for processing
To provide, maintain and support our Services
Where we have a contract with you, necessary for the performance of our contract with you
Where we do not have a contract with you, our legitimate interests in operating our business
To manage our business and for internal operational purposes
Necessary for our legitimate interests of effectively managing our business operations and improving our products and services
To personalize your experience
Necessary for our legitimate interests of effectively managing our business operations and improving our products and services
To advertise and market to you
Your consent which is required under law some cases) or as necessary for our legitimate interests of effectively promoting our business, products and services
To communicate with you or provide information you have requested
Where we have a contract with you, necessary for the performance of our contract with you
Where we do not have a contract with you, our legitimate interests in operating our business

For legal, compliance and security-related purposes, including to:
comply with our UK legal obligations, including under anti-money laundering, know-your-customer or similar laws
comply with our non-UK legal obligations, including under anti-money laundering, know-your-customer or similar laws in any relevant jurisdiction
secure and protect our network and systems
identify and protect against fraud and other crimes
establish, exercise or defend legal claims
monitor and report compliance issues
See below
Necessary for compliance with our legal obligations under UK law
Necessary for our legitimate interest in complying with laws, protecting our network and systems, our business and others and establishing, exercising or defending our legal rights
Necessary for compliance with our legal obligations under UK law where required by UK law or, where not required by UK law, necessary for our legitimate interest in effective compliance managemen

Where we process personal information on the basis of a legitimate interest (as identified above), as required by data protection law, we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals’ interests outweigh our interests in the processing taking place. You can obtain more information about this balancing test by using the contact details at the end of this Addendum.
Where we collect personal information to administer our contract with you or to comply with our legal obligations, this is mandatory and we will not be able to perform the contract we have entered into with you or otherwise provide the Services without this information. In all other cases, provision of the requested personal information is optional, but this may affect your ability to use our Services or our websites.
3. International transfers
We may transfer the personal information we collect about you for the purposes described in this Privacy Statement to countries that have not been found to provide an adequate level of data protection by UK Data Protection Law.
In particular, we may transfer your personal information to third parties, including to parties located in the United States. We use appropriate safeguards for the transfer of personal information to third party service providers. Where required, we have implemented the UK approved standard contractual clauses or the UK approved addendum to the European Commission approved standard contractual clauses, rely on a service provider’s processor binding corporate rules or have implemented/rely on other legally recognized safeguards for data transfer purposes.
We also use appropriate safeguards for the transfer of personal information among our affiliates in the United States. We have implemented the UK approved standard contractual clauses or the UK approved addendum to the European Commission approved standard contractual clauses or have implemented/rely on other legally recognized safeguards for data transfer purposes.
To obtain a copy of the standard contractual clauses or other transfer safeguards, please call (toll-free): +1 (866) 226-4484. A summary of these safeguards is set out here
4. Choice and access
You have additional rights regarding how your personal information is processed, including the right to:
  • request access to and obtain a copy of your personal information;
  • request the transfer of your personal information you have provided to us to you or another company in a structured, commonly used and machine-readable format;
  • request rectification of your personal information when it is inaccurate or incomplete;
  • request erasure of your personal information where permitted under the applicable law, such as where the information is no longer necessary or lawful for us to store or where your information is outdated;
  • restrict or object to the processing of your personal information (as applicable), including to object to the processing of personal information for direct marketing purposes; and
  • withdraw your consent at any time where this is the legal basis on which we are processing your personal information. If you ask to withdraw your consent, this will not affect any processing which has already taken place at that time.
  • Please note that if you choose to withdraw your consent, you may not be able to participate in or benefit from the programs, services and initiatives for which you provided consent to the processing of your personal information. Your rights will in each case be subject to the restrictions set out in UK Data Protection Law.
You may exercise these rights free of charge by submitting your request here. Subject to the applicable law, Toast may charge a reasonable fee or refuse to act on a request if it is manifestly unfounded or excessive, in particular because of its repetitive character. In some situations, Toast may refuse to act or impose limitations on the information disclosed if, for instance, if fulfilling your request would reveal personal information about another person, or if you ask us to delete information which we are required by law or have compelling legitimate interests to keep.
You also have the right to lodge a complaint about our processing of your personal information with the UK Information Commissioner’s Office.
5. Retention
We will retain your personal information for only as long as needed for the purpose of the processing activity or where we have a legitimate business need to retain it, subject to our legal and regulatory obligations to retain it longer and our applicable records retention periods. The duration of these periods will vary depending on your relationship with Toast and the Service you are using. For example,
  • Merchants: Merchant account and ownership information will generally be maintained for seven (7) years following the termination of the relationship absent a legal or regulatory obligation to retain longer;
  • Merchant Employees: Merchant employee information will generally be maintained for seven (7) years following the termination of the relationship with the Merchant unless removed sooner by the Merchant; and
  • Guests: Digital ordering accounts created by our Guests will be maintained for the duration of their use of the service and removed following five (5) years of inactivity. Transactional information and other Guest information held by our Merchants as part of their operations will be retained for the duration of our relationship with the Merchant plus a period of seven (7) years.
  • Other periods are set out within Toast’s records retention policy and schedule. Our retention periods are also subject to any rights of individuals or other requirements that might dictate a shorter retention period (e.g., deletion requests). In certain cases, Toast may also maintain information for a longer period of time, such as in cases where the information is subject to a legal claim or complaint. Following those periods and other determinations on the duration of the processing of personal information by Toast, we will delete or take measures to anonymize your personal information.
  • Cookies and other technologies
    In addition to the information found in the section of the main body of the Statement titled “Cookies and other tracking technologies”, Toast’s Cookie Policy can be found here and provides some supplemental information for users in the EU/EEA and UK.
  • Children
    Our Services are not targeted or directed at children under the age of 18, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 18. If you have reason to believe that a child under the age of 18 has provided personal information to us, we encourage the child’s parent or guardian to contact us as described in the “How to contact us” section within the main body of the Privacy Statement to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 18, we will promptly delete that personal information.
  • How to contact Toast UK
    If you have data protection questions specific to Toast UK, you can reach us at:
    Attn: Toast UK Data Protection Office
    3rd Floor, 1 Ashley Road
    Altrincham
    Cheshire
    WA14 2DT
    United Kingdom
  • Lodging a complaint
    If you are not satisfied with the processing of your personal information, you have the right to lodge a complaint with the UK Information Commissioner’s Office (https://ico.org.uk/).

Addendum F – Australia

Last updated: May 16, 2025
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and apply where the Privacy Act 1988 (Cth of Australia) applies, which includes where Toast Australia Pty Ltd provides Services. To the extent that there is a conflict between the provisions of this Addendum F and the provisions of the main body of the Privacy Statement, the provisions of this Addendum F shall prevail.
1. Collection of information
As outlined in other sections of this Privacy Statement, we may collect information about you, including personal information and sensitive information. For example, if you are a Guest, sensitive information may include information about allergies or if you are a Merchant Employee, sensitive information may include information about sick leave you have taken or your professional associations. If you provide this information to us, we may process (including hold, use and disclose) that information in accordance with this Privacy Statement and as otherwise permitted by applicable law.
We may also collect personal information about you from third parties or as required by law depending on the circumstances. For example:
(a) if you are a Merchant Employee, we will collect information about you from your employer, the Merchant; and
(b) if you are a Guest, we will collect information about you from the relevant Merchant and your interaction with them, as well as your interaction directly with Toast.
Where you provide us another person’s personal information, you must make them aware you are doing so, ensure they are aware of this Privacy Statement and that we will collect, hold, use and disclose personal information in accordance with this Privacy Statement. If you provide us with another person’s sensitive information, you must also ensure they consent to our collection, holding, use and disclosure of that personal information.
In some instances, you may be able to interact and deal with us anonymously or using a pseudonym, such as when using our Services to order as a Guest or when browsing our website. However, in other instances, if we do not have access to your personal information we are unable to deal with you, such as in the context of Merchant Employees and Merchant use of our Toast Payroll and Team Management module.
2. Use and sharing of information
In addition to the purposes outlined in section 4 and 5, we may:
  • use your information to create anonymised, de-identified and/or aggregated data. For example, we may do this to help protect your privacy in the context of the conduct of analytics by us or third parties; and
  • otherwise use and disclose your information for secondary purposes where permitted by applicable law.
3. International transfers and how we hold data
As Toast is an international organization with affiliates, business processes, offices and third parties around the world, your information may be sent to or accessible from any other country in the world where we do business or maintain affiliate or third-party relationships. It is not practical to list all the countries in which they are located, however they include the United States of America, the United Kingdom, Ireland and Canada.
Your personal information may be disclosed to and stored in those locations and others in connection with our interactions with those third parties and affiliates.
However, we primarily store information in servers and facilities located in the United States. We use reputable third party services providers for such data storage, and they are subject to security obligations in our contracts with them.
4. Retention
We will destroy or de-identify your personal information if we no longer need it for any purpose permitted under this Privacy Statement or law, subject to our legal and regulatory obligations to retain it longer. The duration of these periods will vary depending on your relationship with Toast and the Service you are using.
5. Cookies and other tracking technologies
Where any cookies or other tracking technologies referred to in section 7 above constitute personal information, we will handle and process such personal information in accordance with the other sections of this Privacy Statement. For example, this includes only using cookies which constitute personal information for marketing and targeted advertising where permitted by applicable law or consented to by you.
6. Children
Our Services are not targeted or directed at children under the age of 15, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 15. If you have reason to believe that a child under the age of 15 has provided personal information to us, we encourage the child’s parent or guardian to contact us as described in the “How to contact us” section within the main body of the Privacy Statement to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 15, we will promptly delete that personal information.
7. Contact information, access, correction and complaints
As outlined in section 8, you may utilise the Services or contact us (or the relevant Merchant, if applicable) to exercise your rights under applicable law to access and/or correct your personal information. We may seek to verify your identity before we allow access, or make changes, to your personal information and there may be circumstances where the law permits us to refuse a request.
In addition, if you have any queries or complaints with regards to our collection, storage, use or disclosure of your personal information, please contact us at:
  • By post:
    Attn: Assistant General Counsel, Privacy
    Toast, Inc.
    333 Summer St. Boston, MA 02210
    United States of America
  • By phone: (toll-free): +1 (866) 226-4484
If you make a complaint, we will endeavour to respond within a reasonable time, and as required by applicable law.
If you are dissatisfied with our response, you may make a complaint to the Office of the Australian Information Commissioner by phoning 1300 363 992 or by email at enquiries@oaic.gov.au.

Addendum G – New Zealand

Last updated: January 7, 2025
The provisions below supplement the information provided in the generally applicable portion of our Privacy Statement and apply where the New Zealand Privacy Act 2020 applies, which includes where Toasttab New Zealand Limited provides Services. To the extent that there is a conflict between the provisions of this Addendum G and the provisions of the main body of the Privacy Statement, the provisions of this Addendum G shall prevail.
Collection of information
As outlined in other sections of this Privacy Statement, we may collect personal information about you from our group entities or other third parties who are entitled to disclose that information to us, or from whom you authorise us to collect your personal information, or as required by law. For example:
  • if you are a Merchant Employee, we will collect information about you from your employer, the Merchant; and
  • if you are a Guest, we will collect information about you from the relevant Merchant and your interaction with them, as well as your interaction directly with Toast.
If you provide us another person’s personal information, you must make them aware you are doing so, ensure they are aware of this Privacy Statement and that we will collect, hold, use and disclose personal information in accordance with this Privacy Statement.
What happens if you do not provide personal information
You are not required to provide us with the personal information we have requested. However, if you do not provide to us all the personal information we request from you, you may not be able to access and use, and we may be unable to provide to you, all of our products and services. For example, we may be required as a matter of law to collect your identity information, and if you do not provide us with that information, we may be unable as a matter of law to provide our products or services to you.
Use and sharing of information
Where we need to use your personal information in a way that we have not anticipated elsewhere in this Privacy Statement, or that we have not otherwise notified you of before or at the time your personal information is provided, we will only do so if required or permitted by law or with your authorisation.
International transfers and how we hold data
As referred to in section 5, your information may be disclosed outside New Zealand with our parent, subsidiary, or affiliates companies, or third parties. It may also be accessed from any other country in the world where we do business or maintain affiliate or third-party relationships.
Your personal information may be disclosed to and stored in those locations and others in connection with our interactions with those third parties and affiliates. However, we primarily store information in servers and facilities located in the United States. We use reputable third party services providers for such data storage, and they are subject to security obligations in our contracts with them.
Some of these jurisdictions may not be legally required to protect information in a manner that, overall, provides comparable safeguards to those under the Privacy Act 2020. We take reasonable steps to ensure that third parties to whom we disclose personal information, or third parties who access the personal information, are bound to protect the privacy of that personal information in a way that, overall, provides comparable safeguards to those required under New Zealand privacy laws.
Cookies and other tracking technologies
Where any cookies or other tracking technologies referred to in section 7 above collect personal information, we will handle and process such personal information in accordance with the other sections of this Privacy Statement.
Children
Our Services are not targeted or directed at children under the age of 18, and we do not intend to, or knowingly, collect or solicit personal information from children under the age of 18. If you have reason to believe that a child under the age of 18 has provided personal information to us, we encourage the child’s parent or guardian to contact us as described in the “How to Contact Us” section of this Statement to request that we remove the information from our systems. If we learn that any personal information we collected has been provided by a child under the age of 18, we will promptly delete that personal information.
Contact information, access, correction and complaints
As outlined in section 8, you may utilise the Services or contact us (or the relevant Merchant, if applicable) to exercise your rights under applicable law to access and/or correct your personal information.
You may request access to your personal information that we hold by contacting us on the details below. If you request access to, or a copy of, your personal information, we will provide you with a copy of the personal information we keep about you, subject to any lawful grounds that may be available to us for withholding the information. We reserve the right to charge you a reasonable amount for providing copies of any personal information you request, to take into account reasonable time, cost and effort involved in us complying with your request.
You may request that the personal information we hold about you be corrected by contacting us on the details below. If you request a correction to your personal information and we agree that your personal information needs correcting, an amended record of your personal information will be provided back to you. If we do not agree to your request for a correction, you have the right to provide us with a statement of the correction sought but not made (statement of correction), and request that we attach the statement of correction to the personal information the request relates to.
In addition, if you have any queries or complaints with regards to our collection, storage, use or disclosure of your personal information, please contact us at:
By post:
  • Attn: Assistant General Counsel, Privacy
    Toast, Inc.
    333 Summer St. Boston, MA 02210
    United States of America
By phone: (toll-free): +1 (866) 226-4484
If you make a complaint, we will endeavour to respond within a reasonable time, and as required by applicable law.
If you are dissatisfied with our response, you may make a complaint to the Office of the Privacy Commissioner by phoning 0800 803 909 or by email at enquiries@privacy.org.nz.

Déclaration de confidentialité de Toast

Entrée en vigueur : 28 avril 2026

Cette déclaration de confidentialité décrit la manière dont Toast, Inc. et ses filiales et entreprises affiliées (collectivement « Toast », « nous », « notre » et/ou « nos ») recueille et gère vos renseignements personnels (c’est-à-dire toute information se rapportant à un individu identifié ou identifiable) dans le cadre de la fourniture de nos services (définis ci-dessous).

Pour consulter notre Déclaration de confidentialité de la Californie, veuillez cliquer sur le lien ou faire défiler l’écran vers le bas.

Pour consulter la version française de la déclaration de confidentialité de Toast, veuillez cliquer sur le lien.

1. Portée

 Cette déclaration porte principalement sur :
  • Marchands : entreprises qui ont manifesté leur intérêt pour l’utilisation des services ou qui ont signé un contrat avec Toast pour fournir les services au sein de leurs restaurants (lorsque ce terme est utilisé dans la présente Déclaration dans le contexte du traitement des renseignements personnels d’un marchand, il fait référence à un marchand qui est un individu);
  • Employés des marchands : employés de nos marchands qui utilisent les services; et
  • Clients : personnes qui utilisent les services dans l’un des restaurants de notre marchand, par le biais d’un partenaire commercial ou directement par le biais de Toast.
Outre les groupes mentionnés ci-dessus, la présente déclaration s’applique également aux personnes qui visitent nos sites Web, y compris https://pos.toasttab.com (ci-après « nos sites Web ») et nos partenaires commerciaux tiers. Nous pouvons également traiter des renseignements provenant d’autres personnes à des fins supplémentaires, notamment à des fins de recherche, de loteries et d’événements qui peuvent être collectées séparément de temps à autre, mais qui sont couvertes par la présente déclaration.
Pour les personnes utilisant nos services Toast Pay Card, Toast Cash et PayOut, vous autorisez Toast à obtenir des renseignements (par exemple, des données de transaction) auprès de toute banque émettrice de la carte Toast Pay ou de tout organisme de traitement afin que Toast puisse vous fournir le service en question. Nous utiliserons et partagerons tout renseignement que nous recueillons auprès de vous concernant ce service conformément à notre avis de confidentialité pour la carte Toast Pay qui se trouve ici. Toast Cash se trouve ici ou dans l’application mobile MyToast.
Veuillez noter que dans certains pays où nous exerçons nos activités, des lois nous obligent à partager des informations et des pratiques spécifiques en matière de confidentialité avec les personnes qui s’y trouvent. À cette fin, la présente déclaration de confidentialité se compose de deux articles, une déclaration d’application générale et un addenda spécifique à chaque lieu. S’il existe des variations pour un lieu spécifique ou des informations supplémentaires qui doivent être fournies en vertu de la législation du pays, de l’État ou de la province concerné(e), les personnes se trouvant dans ce lieu peuvent se référer à l’addenda applicable. Des liens vers les articles pertinents se trouvent ci-dessous :
Veuillez noter que nos marchands sont des tiers indépendants qui maintiennent leurs propres pratiques et politiques commerciales en dehors de leur relation avec Toast et de leur utilisation des services. Par conséquent, sauf indication contraire dans la présente déclaration, nous ne sommes pas responsables des politiques de confidentialité ou des pratiques en matière de données de nos marchands, qui peuvent avoir des politiques et des pratiques distinctes. Si vous êtes un employé d’un marchand, il revient à votre employeur de vous fournir tout avis ou information supplémentaire requis concernant ses pratiques en matière de confidentialité en dehors de la présente déclaration.
En utilisant les services et/ou en nous fournissant vos renseignements personnels, vous reconnaissez que vos renseignements personnels seront traités et utilisés de la manière décrite dans la présente déclaration de confidentialité. Nous pouvons modifier cette déclaration de temps à autre, conformément à l’article « Modifications de la présente déclaration de confidentialité » ci-dessous. 

2. Définitions

Voici quelques autres termes que nous utilisons dans la présente déclaration de confidentialité qu’il est important de connaître :
  • « Gestion de la paie et Gestion de l’équipe Toast » fait référence à un module offert dans le cadre des services destinés aux employés du marchand, qui comprend un certain nombre de services axés sur les ressources humaines, y compris, mais sans s’y limiter, la paie, l’administration des avantages sociaux, les services de cartes, les services de planification et de suivi des candidats.
  • « Services » désigne les services et les produits (y compris le matériel et les logiciels) que nous élaborons ou gérons de temps à autre, y compris :
    • notre principal système de point de vente (PDV);
    • nos services de traitement des paiements;
    • nos interfaces de programmation d’applications (« API »);
    • les modules associés fournis dans le cadre de notre système de point de vente, tels que nos modules de fidélité, de marketing, de liste d’attente et de réservation, de livraison et de gestion de la paie et gestion de l’équipe proposés par Toast;
    • d’autres services de gestion de restaurants, tels que nos services de gestion des stocks, de facturation et de paiement des factures;
    • nos services de commande numérique, tels que Commander en ligne, les services de retrait et de livraison, la fonctionnalité de commande et de paiement sans contact à la table, les cartes-cadeaux et notre (nos) application(s) mobile(s);
    • les comptes créés par le biais de nos services de commande numérique (« compte(s) de commande numérique »);
    • d’autre(s) application(s) mobile(s) élaborée(s) dans le cadre des services, y compris nos applications mobiles destinées aux marchands et aux employés des marchands (par ex. les applications mobiles MyToast et Toast Now) et nos applications mobiles destinées aux clients
      (p. ex. Local by Toast);
    • les produits ou services de santé, de bien-être et autres avantages mis au point ou proposés par Toast ou ses partenaires commerciaux tiers de temps à autre pour les employés du marchand;
    • les services liés aux assurances; et
    • le financement des marchands (y compris, mais sans s’y limiter, les prêts Toast Capital), les produits de carte, tels que la carte Toast Pay (émise par Sutton Bank, membre de la FDIC, sous licence de Mastercard International Incorporated, ou tout autre émetteur ultérieur) et d’autres produits financiers offerts par Toast ou ses partenaires commerciaux, y compris, mais sans s’y limiter, les banques et d’autres institutions financières.
  • (collectivement appelés « Services »). Veuillez noter que certains services peuvent être fournis par le biais de nos sites Web ou de nos partenaires commerciaux tiers.
  • « Vous » et/ou « votre » désigne un marchand, un employé d’un marchand, un client, un visiteur de l’un de nos sites Web ou toute autre personne concernée.

3. Les renseignements personnels que nous collectons

Les renseignements personnels que nous collectons dépendent de la nature de votre interaction avec les services et nos sites Web. Cela comprend les marchands qui s’inscrivent pour utiliser nos services ainsi que les employés des marchands qui sont impliqués dans les activités de ces derniers. Cela comprend également les clients qui peuvent avoir recours à nos services de manière indépendante, effectuer une transaction ou interagir avec l’un de nos marchands. Bien que certains renseignements soient collectées automatiquement ou par des sources extérieures à Toast, la plupart sont collectés lors de l’utilisation de nos services ou de nos sites Web. Une ventilation de la collecte a été fournie dans les articles ci-dessous. 
Les renseignements personnels collectés par le biais des services
A. Les marchands
Si vous êtes un marchand, nous collecterons des renseignements personnels auprès
de vous dans le cadre de votre entente commerciale et de l’utilisation (ou de l’utilisation potentielle) des services, y compris, le cas échéant,
  • votre nom,
  • votre adresse,
  • votre courriel,
  • votre date de naissance, 
  • votre numéro de téléphone, et
  • les renseignements que vous choisissez de partager lors de l’utilisation des services, par exemple lorsque vous communiquez par le biais d’applications mobiles ou de tickets d’assistance.
Dans le cadre de notre procédure de candidature et de notre entente pour la fourniture des services, nous pouvons également collecter des renseignements supplémentaires, tels que votre numéro d’identification fiscale, votre numéro d’identification national (par ex. numéro de sécurité sociale ou numéro de passeport), les détails de votre permis de conduire ainsi que vos informations bancaires et de carte de paiement.
Si vous êtes un partenaire commercial qui cherche à intégrer Toast, nous collecterons également des renseignements, tels que votre nom et vos coordonnées, dans le cadre de votre demande d’intégration de nos services. 
A. Les employés des marchands
Si vous êtes un employé d’un marchand, nous pouvons être amenés à collecter des renseignements personnels vous concernant dans le cadre de votre utilisation des services. Cela comprend :
  • votre nom,
  • votre courriel,
  • votre numéro de téléphone,
  • votre numéro d’identification de l’employé,
  • votre adresse,
  • votre date de naissance, et
  • des renseignements concernant votre fonction, tels que le titre de votre poste, les taux de rémunération, le salaire et les heures travaillées.
Dans la mesure où vous êtes employé par un marchand qui utilise le module de gestion de la paie et gestion de l’équipe Toast, nous pouvons également collecter :
  • votre numéro de sécurité sociale ou autre numéro d’identification national;
  • vos informations bancaires dans le cadre de la paie,
  • votre parcours professionnel et scolaire,
  • vos documents fiscaux tels que les formulaires fiscaux W2 et 1095,
  • vos choix d’avantages sociaux,
  • les informations relatives à votre permis de conduire,
  • votre genre,
  • votre état civil,
  • votre statut d’invalidité,
  • votre ethnicité, et
  • les informations sur les personnes à votre charge et vos bénéficiaires.
Veuillez noter que les renseignements personnels effectivement collectés dépendront des services spécifiques de gestion de la paie et de gestion l’équipe Toast que vous ou votre employeur avez choisi d’utiliser. Veuillez contacter votre employeur pour plus d’informations. 
Pour les employés des marchands utilisant la carte Toast Pay et le service PayOut, en plus de certains renseignements déjà collectés ci-dessus, Toast recueillera également des renseignements sur l’historique de votre compte et de vos transactions dans le cadre du service. Pour plus d’informations sur ce service, veuillez consulter l’avis de confidentialité ici ou dans l’application mobile MyToast.
C. Clients
Nous collectons des renseignements auprès de vous dans le cadre de votre utilisation des services (tels que nous les fournissons et les développons de temps à autre), ce qui peut inclure la création d’un compte de commande numérique, votre utilisation de nos fonctionnalités de commande en ligne et de nos applications mobiles, ainsi que d’autres produits connexes, tels que nos services de ramassage, de livraison et de commande et de paiement sur place, et nos fonctionnalités de liste d’attente et de réservation. Nous pouvons également collecter et/ou recevoir vos renseignements personnels lorsque vous passez une commande auprès de, effectuez un achat auprès de (y compris des cartes-cadeaux), ou effectuez une autre transaction avec nos marchands ou participez à leurs programmes de fidélité respectifs.
Selon le ou les services que vous avez utilisés, les renseignements personnels collectés peuvent inclure :
  • votre nom,
  • vos coordonnées, telles que votre numéro de téléphone et votre courriel,
  • votre adresse et d’autres informations générales sur votre emplacement,
  • les informations relatives à votre carte de paiement, telles que la marque, le numéro de la carte, le code de sécurité et la date d’expiration,
  • les informations relatives aux transactions et à l’historique des commandes
    (p. ex. les biens/services commandés, la date, le mode de paiement et le montant du paiement),
  • votre date de naissance (si vous choisissez de la fournir),
  • des informations sur votre véhicule (pour les utilisateurs de notre service de ramassage en bordure de trottoir),
  • des informations relatives à votre compte et à votre profil, telles que votre nom d’utilisateur et votre mot de passe,
  • si vous êtes membre d’un programme de fidélité proposé par un marchand, les informations relatives à votre solde de points et à vos échanges,
  • les détails de la liste d’attente ou des réservations, y compris les préférences en matière de restauration, les demandes spéciales et les restrictions alimentaires, et
  • vos commentaires concernant votre expérience dans les établissements de nos marchands (si vous choisissez de les fournir).
  • Les renseignements que vous choisissez de partager lors de l’utilisation des services, par exemple lorsque vous communiquez par le biais d’applications mobiles ou de tickets d’assistance.
Dans tous les cas, les renseignements personnels effectivement collectés varieront en fonction des services utilisés. En fonction des services utilisés, les renseignements personnels peuvent également être liés à votre utilisation des services à travers Toast. Par exemple, en tant que client, votre carte de paiement ou vos coordonnées peuvent être liées à un historique de commande, à votre compte Toast, à un compte de fidélité spécifique ou à un profil spécifique au marchand autour de vos interactions avec ce marchand ou le groupe de gestion du marchand.
Les marchands Toast peuvent également choisir de collecter des renseignements sur les régimes alimentaires et les allergies dans le cadre des services. Dans la mesure où un client choisit de fournir des informations relatives à ses besoins alimentaires dans le cadre d’une réservation ou de son expérience de restauration, qui peuvent être considérées comme des informations relatives à la santé ou au domaine médical en vertu de la loi applicable, cette personne consent à ce que ces informations soient utilisées dans le cadre de cette expérience et du service. Dans ces cas, Toast traite ces informations pour fournir les services au marchand.
Les renseignements personnels collectés par le biais de nos sites Web
Outre l’utilisation des services, nous pouvons également collecter des renseignements personnels lorsque vous visitez nos sites Web et demandez des informations sur nos services, téléchargez un document de présentation technique, planifiez une démonstration de produit ou vous abonnez à nos canaux médiatiques (p. ex. blogues, balados, etc.). Ces renseignements personnels peuvent inclure :
  • votre nom,
  • votre courriel, et
  • votre numéro de téléphone.
Certaines informations peuvent également être collectées automatiquement lorsque vous visitez nos sites Web. Pour plus d’informations, veuillez consulter la section du présent article intitulée « Renseignements collectés automatiquement ».
Veuillez noter que des renseignements supplémentaires à ceux décrits ici seront collectés (décrits dans l’article Marchand ci-dessus) dans le cadre de notre processus de candidature en ligne des marchands ou par le biais de notre site Web de commerce électronique.
Renseignements personnels collectés auprès d’autres sources
Tout dépendant si vous êtes un marchand, un employé d’un marchand, un client ou un visiteur de l’un de nos sites Web, nous pouvons également collecter des renseignements personnels vous concernant auprès de tiers, y compris nos partenaires commerciaux, fournisseurs de données, services de vérification d’identité, agences d’évaluation du crédit (le cas échéant), banques et autres institutions financières et entreprises émettrices de cartes de crédit. Nous pouvons également collecter auprès de vous des informations accessibles au public. Par exemple, si vous interagissez avec nous ou si vous partagez vos informations par le biais de divers réseaux sociaux.
Renseignements collectés automatiquement
Nous collectons automatiquement des informations lorsque vous visitez nos sites Web, utilisez notre (nos) application(s) mobile(s), effectuez une transaction ou utilisez nos services en ligne, tels que les commandes en ligne. Pour les transactions, il peut s’agir de renseignements personnels tels que votre nom lorsqu’une carte de paiement est utilisée. Les renseignements collectés automatiquement par des témoins, des pixels espions ou d’autres technologies similaires (décrites dans la section « Témoins et autres technologies de suivi » du présent article) peuvent inclure :
  • des informations sur votre appareil, telles que le type/modèle, le numéro et l’identifiant de votre appareil (p. ex. l’adresse MAC),
  • des informations sur votre navigateur, vos paramètres (p. ex. la langue) et votre système d’exploitation,
  • votre adresse de protocole Internet (IP) (y compris, dans certains cas, la localisation perçue),
  • la publicité unique et les identifiants connexes,
  • les informations transactionnelles et les informations relatives aux achats, et
  • les activités de navigation et d’utilisation, telles que le domaine de référence, les sites Web/contenus que vous avez consultés ou les actions que vous avez effectuées sur un site Web particulier.
En fonction des services utilisés ou des sites Web auxquels vous accédez, nous pouvons également collecter des informations de géolocalisation par l’intermédiaire de vos appareils lorsque l’accès à la localisation est activé sur votre appareil. Par exemple, nous pouvons vous montrer quels restaurants de votre région sont disponibles dans notre (nos) application(s) mobile(s). Ces informations peuvent être collectées par le biais de technologies GPS, Bluetooth, cellulaires ou Wi-Fi. Si vous n’y consentez pas, vous pouvez ajuster vos paramètres au niveau de l’appareil ou du navigateur pour désactiver l’utilisation de ces technologies. 

4. Notre utilisation des renseignements personnels

Nous utilisons vos renseignements personnels avant tout pour vous fournir nos services et pour gérer nos activités commerciales. Cela comprend la communication avec vous dans le cadre de ces services ainsi qu’à des fins de publicité et de marketing lorsque la loi applicable le permet ou lorsque nous avons votre consentement. Dans tous les cas, les renseignements sont utilisés pour nous aider à respecter nos obligations légales, de conformité ou de sécurité. La nature réelle de l’utilisation des renseignements personnels dépend de la nature des services qui vous sont fournis et peut varier selon que vous êtes un client, un marchand, un employé d’un marchand ou toute autre personne visée par la présente déclaration. Vous trouverez ci-dessous une description plus détaillée de notre utilisation des renseignements personnels. 
 Nous utilisons les renseignements personnels pour :
  • Fournir, entretenir et soutenir nos services, y compris
    • fournir des mises à jour, une assistance et une formation relatives aux services,
    • déterminer l’admissibilité des personnes en fonction de leur utilisation de certains services,
    • à des fins de contrats et d’ententes,
    • traiter les transactions et les paiements par le biais des services, en conservant un historique de vos interactions avec Toast,
    • permettre à nos marchands et aux employés de nos marchands d’accéder aux services et de les utiliser, y compris les renseignements que vous avez fournis dans le cadre de l’utilisation des services, et 
    • améliorer, développer et fournir des services, développer, former et déployer des algorithmes et des modèles d’intelligence artificielle (IA), utilisés pour développer, fournir et personnaliser nos services, et générer des analyses pour améliorer nos services pour les marchands et les clients, 
    • fournir des services en ligne, y compris la vérification de l’identité, ainsi que le diagnostic des problèmes techniques et de service. 
    • Si vous êtes un employé d’un marchand, pour permettre à nos marchands de gérer leur personnel
  • Gérer nos activités et à des fins opérationnelles internes, y compris
    • l’analyse des performances de nos services,
    • le développement de la main-d’œuvre et des services,
    • la création et le développement d’analyses au profit de nos activités et de celles de nos marchands,
    • à des fins de recherche, y compris le développement de nouveaux produits,
    • l’évaluation de l’efficacité des services, et
    • l’amélioration de nos services et sites Web.
  • Personnaliser votre expérience, y compris
    • la création d’un profil spécifique au marchand en fonction de vos interactions sur nos différents services destinés aux clients, y compris, mais sans s’y limiter, lorsque vous effectuez un paiement dans l’un des restaurants de notre marchand, que vous vous inscrivez sur une liste d’attente ou que vous faites une réservation, que vous passez une commande numérique ou que vous adhérez à l’un des programmes de fidélité proposés par notre marchand. Les profils des clients sont limités à un marchand spécifique ou à un groupe de gestion des marchands que vous avez visité ou utilisé dans le cadre des services.
    • en utilisant les données associées à votre compte Toast pour personnaliser votre expérience sur nos services, 
    • en utilisant les données transactionnelles et l’historique des commandes pour fournir des recommandations lors de l’utilisation de nos services ou de ceux de nos marchands,
    • en utilisant les renseignements sur votre expérience de restauration (y compris les renseignements sur les listes d’attente et les réservations) pour personnaliser votre expérience dans les restaurants de notre marchand (y compris en ce qui concerne vos futures expériences de restauration), et
    • en utilisant des technologies d’analyse et de profilage pour personnaliser votre expérience.
  • Faire de la publicité et du marketing auprès de vous, y compris
    • vous envoyer des communications marketing, soit directement, soit par le biais d’un fournisseur de services tiers, en rapport avec nos services existants ou nouveaux qui, selon nous, pourraient vous intéresser,
    • afficher des publicités pour Toast ou des services de tiers dans nos services de commande numérique et nos applications mobiles, et
    • en fonction des instructions de nos marchands ou de nos partenaires commerciaux le cas échéant, directement ou par le biais d’un tiers, pour faire de la publicité pour leurs produits et services à votre intention, et 
    • faire la promotion de nos services. 
Toute communication qui vous est envoyée en vertu du présent article doit être autorisée en vertu de la loi applicable ou avec votre consentement. Veuillez consulter la section « Vos droits et vos choix » de la présente déclaration pour plus de détails sur le retrait de ces communications et la mise à jour de vos préférences.
  • Communiquer avec vous ou fournir les informations que vous avez demandées, y compris pour
    • fournir des notifications relatives à vos achats ou aux services,
    • vous envoyer des documents de présentation techniques et d’autres documents provenant de nos sites Web,
    • vous fournir nos infolettres, balados et autres documents d’abonnement,
    • vous envoyer des reçus numériques, et
    • répondre aux commentaires que vous avez fournis concernant nos produits ou services ou ceux de nos marchands.
  • À des fins juridiques, de conformité et de sécurité, notamment pour
    • nous conformer à nos obligations légales, y compris dans le cadre de la lutte contre le blanchiment d’argent, de la connaissance du client ou de lois similaires dans toute juridiction concernée,
    • sécuriser et protéger notre réseau et nos systèmes,
    • identifier les fraudes et autres délits et nous en protéger,
    • établir, exercer ou défendre des créances légales,
    • exécuter nos obligations contractuelles, et
    • surveiller et signaler les problèmes de conformité. 

5. Notre partage des renseignements personnels


Dans certains cas, Toast partagera les renseignements personnels collectés auprès de vous ou traités d’une autre manière afin de fournir nos services ou d’atteindre les autres objectifs de la présente déclaration. Si vous êtes un client, cela comprend le partage de renseignements personnels avec nos marchands et les employés des marchands, ainsi qu’avec des partenaires tiers qui sont autorisés par le marchand à accéder à vos renseignements. Nous travaillons également avec des fournisseurs de services tiers et des partenaires commerciaux que nous utilisons pour fournir, soutenir et améliorer nos services. 
Toast peut partager des renseignements personnels dans le cadre de la fourniture des services et aux fins décrites dans la présente déclaration. Cela comprend :
  • avec nos marchands et les employés de nos marchands dans le but de vous fournir les services, de répondre à vos demandes et aux autres fins décrites dans la présente déclaration. Dans le cadre de la fourniture des services (par exemple, lorsque vous effectuez une transaction dans un restaurant d’un marchand ou par le biais de nos services de commande numérique, que vous rejoignez une liste d’attente ou que vous effectuez une réservation), Toast partagera avec le marchand les informations relatives à votre commande ou les détails de votre réservation. Il peut s’agir de renseignements personnels tels que votre nom, vos coordonnées ainsi que des informations sur votre expérience de restauration, notamment les détails de votre réservation, vos préférences en matière de restauration et vos demandes spéciales. Dans certains cas, lorsqu’un marchand fait partie d’un groupe de gestion plus important, cela peut inclure le partage de ces renseignements avec d’autres restaurants de ce groupe dans le cadre de vos futures expériences de restauration,
  • avec nos partenaires commerciaux tiers afin de fournir, maintenir, améliorer et développer nos services,
  • avec des partenaires d’intégration tiers sélectionnés par le marchand ou avec lesquels vous faites affaire lorsque Toast est chargé de partager vos renseignements dans le cadre des services,
  • avec nos entreprises mères, filiales ou affiliées, nos mandataires (le cas échéant) aux fins décrites dans la présente déclaration de confidentialité,
  • avec des tiers pour fournir, maintenir et améliorer nos services, y compris les fournisseurs de services qui accèdent aux informations vous concernant pour fournir des services en notre nom ou au nom de nos marchands, tels que les services d’hébergement et de technologie de l’information, les services de paiement, les services de vérification de l’identité et de prévention de la fraude, les services de marketing et de publicité, les services d’analyse de données et de personnalisation et les services d’assistance à la clientèle. Veuillez noter :
    • Si vous êtes un employé d’un marchand dont l’employeur utilise les modules de gestion de la paie et de gestion de l’équipe Toast, nous partagerons vos renseignements avec les fournisseurs d’avantages sociaux, de paie et d’autres fournisseurs de services liés à l’emploi.
    • Si vous êtes un marchand qui fait une demande de financement via la plateforme de Toast, nous partagerons vos informations (y compris les renseignements personnels) avec le prêteur. Dans le cadre de la demande, un rapport de solvabilité sera également demandé à des bureaux de crédit tiers afin de déterminer votre admissibilité à un tel financement.
  • en rapport avec une fusion, une vente d’actions ou d’actifs de l’entreprise, un financement, une acquisition, une cession ou une dissolution de l’ensemble ou d’une partie de nos activités, ou au cours de la négociation d’une telle fusion, vente d’actions ou d’actifs de la société, financement, acquisition, cession ou dissolution, ou
  • si nous pensons qu’il est autorisé ou nécessaire de le faire :
    • protéger nos droits ou nos biens, ou la sécurité ou l’intégrité de nos services ou de nos services ou sites Web,
    • faire respecter les dispositions de nos conditions d’utilisation ou d’autres ententes ou politiques applicables,
    • nous protéger, protéger les utilisateurs de nos services ou le public contre les préjudices ou les activités potentiellement interdites ou illégales,
    • enquêter, détecter et prévenir les fraudes et les atteintes à la sécurité, ou
    • nous conformer à toute loi, réglementation, procédure judiciaire ou demande gouvernementale applicable (y compris, par exemple, une ordonnance d’un tribunal, une citation à comparaître ou un mandat de perquisition).
Nous pouvons également partager avec des tiers des informations agrégées et/ou anonymisées dérivées des services qui ne vous identifient pas directement, y compris des informations sur les appareils et des informations dérivées de témoins et de fichiers journaux, aux fins décrites dans la présente déclaration.
Pour les personnes utilisant la carte Toast Pay et le service Toast PayOut, veuillez consulter notre Avis de confidentialité ici ou au sein de l’application mobile MyToast pour savoir comment nous divulguons vos informations dans le cadre de la fourniture de ce service. 

6. Conservation des renseignements personnels


Nous conservons les renseignements personnels aussi longtemps qu’il est raisonnablement nécessaire pour fournir les services, réaliser les objectifs décrits dans la présente déclaration ou pour respecter nos périodes de conservation des dossiers (qui reflètent la loi applicable). Par exemple, nous pouvons conserver des renseignements sur les utilisateurs de nos services afin de nous conformer à nos obligations légales et réglementaires ou de protéger nos intérêts dans le cadre de la fourniture des services. 

7. Les témoins et autres technologies de suivi 


Toast et les tiers décrits dans la présente déclaration peuvent utiliser des témoins, des pixels espions et d’autres technologies de suivi aux fins décrites dans la présente déclaration. Nous pouvons utiliser ces technologies dans le cadre de nos services et sur nos sites Web, par exemple :
  • pour fournir nos services (p. ex. l’authentification dans le cadre du processus de paiement),
  • pour vous identifier de manière unique, vous et/ou votre appareil,
  • pour enregistrer vos préférences dans le cadre de la fourniture des services,
  • à des fins de personnalisation, de mesure et d’analyse des publicités et de publicité ciblée (y compris sur vos appareils et applications),
  • à des fins de sécurité et de prévention de la fraude,
  • pour analyser et contrôler les performances de nos services,
  • pour améliorer et mettre au point de nouveaux services, et
  • comprendre l’utilisation que vous faites des services au fil du temps.
Vous trouverez ci-dessous des informations sur la gestion des témoins et des technologies connexes dans votre navigateur et, plus généralement, une description plus détaillée de la manière dont nous utilisons ces technologies. 
Un « témoin » est un petit fichier texte placé et enregistré dans votre navigateur lorsque vous accédez à nos sites Web, et potentiellement aux sites Web de nos marchands, partenaires commerciaux ou autres tiers. Nous utilisons à la fois des témoins temporaires (c’est-à-dire des témoins qui ne sont stockés que pour une visite spécifique du site Web) et des témoins permanents (c’est-à-dire des témoins qui sont stockés au-delà d’une visite spécifique du site Web) afin de fournir les services et aux fins décrites dans la présente déclaration. Ces témoins peuvent être définis par nous (témoins de première partie) ou définis par des tiers qui collectent des renseignements en notre nom (témoins de tiers), tels que Google Analytics.
Il existe d’autres technologies de suivi, telles que les pixels espions/GIF, les pixels, les étiquettes de page, les scripts intégrés, qui consistent en de petits fichiers images transparents ou d’autres codes de programmation Web qui enregistrent la façon dont vous interagissez avec les sites Web, les applications mobiles et les services. Ils sont souvent utilisés conjointement avec les témoins du navigateur Web ou d’autres identifiants associés à votre appareil.
Nous utilisons également des pixels et des technologies connexes dans le cadre de services de relecture de session sur certains sites Web, afin de comprendre et d’améliorer la fonctionnalité et l’expérience d’un individu sur ces sites.
Dans certains cas, Toast peut fournir à nos marchands de la publicité numérique et des services connexes qui impliquent la collecte et l’utilisation de témoins, de pixels et de technologies connexes par le biais d’intégrations. Dans ces cas, les marchands ouvrent des comptes indépendants auprès de ces tiers.
Il existe des moyens de contrôler et/ou de refuser la mise en place de témoins et de technologies similaires dans les paramètres de votre navigateur. Chaque navigateur étant différent, veuillez consulter le menu « aide » de votre navigateur. Pour obtenir plus d’informations sur les témoins et sur la manière de contrôler leur utilisation sur différents navigateurs et appareils, vous pouvez consulter le site http://www.allaboutcookies.org. Sachez qu’en fonction des services utilisés, la restriction des témoins peut vous empêcher d’accéder et d’utiliser tout ou partie des services.
La publicité ciblée et vos choix
Dans certains cas, nous autorisons des partenaires publicitaires tiers à utiliser des témoins, des pixels espions et d’autres technologies de suivi sur nos sites Web, nos applications mobiles et au sein de nos services pour collecter des renseignements sur vous et vos activités à des fins de publicité ciblée par centres d’intérêt ou d’autres contenus ciblés. Les renseignements qu’ils collectent peuvent être associés à vos renseignements personnels ou ils peuvent collecter des renseignements, y compris des renseignements personnels, sur vos activités en ligne au fil du temps et sur différents sites Web et autres services en ligne. Ces renseignements peuvent être partagées avec des réseaux publicitaires et d’autres fournisseurs de contenu.
Si vous souhaitez refuser de recevoir des publicités en ligne ciblées par centres d’intérêt sur votre navigateur internet, veuillez visiter le site www.aboutads.info/choices, ou http://www.networkadvertising.org/choices/ et suivre les instructions afin de placer un témoin d’exclusion sur votre appareil indiquant que vous ne souhaitez pas recevoir de publicités ciblées par centres d’intérêt. Les témoins de désactivation ne fonctionnent que sur le navigateur internet et l’appareil sur lesquels ils sont téléchargés. Si vous souhaitez ne pas recevoir de publicités ciblées par centres d’intérêt sur l’ensemble de vos navigateurs et appareils, vous devrez le faire sur chaque navigateur et sur chaque appareil que vous utilisez activement. Si vous supprimez les témoins sur votre appareil en général, vous devrez à nouveau paramétrer le témoin d’exclusion sur cet appareil. Si vous souhaitez ne pas recevoir de publicités en ligne ciblées par centres d’intérêt sur les applications mobiles, veuillez suivre les instructions à l’adresse http://www.aboutads.info/appchoices ou en visitant les paramètres de votre appareil mobile.
Veuillez noter que lorsque vous refusez de recevoir des publicités ciblées, vous ne cesserez pas pour autant de voir des publicités de notre part ou sur nos services en ligne. Autrement dit, les publicités en ligne que vous voyez ne seront pas ciblées en fonction de vos centres d’intérêt. Nous ne sommes pas responsables de l’efficacité ou du respect des options ou programmes d’exclusion des tiers, ni de l’exactitude de leurs déclarations concernant leurs programmes. En outre, des tiers peuvent toujours utiliser des témoins pour collecter des renseignements sur votre utilisation de nos services en ligne, notamment à des fins d’analyse et de prévention de la fraude.
Do Not Track
Nous pouvons utiliser, et nous pouvons autoriser des fournisseurs de services tiers et d’autres tiers à utiliser, des témoins ou d’autres technologies sur nos services qui collectent des renseignements sur vos activités de navigation au fil du temps et sur différents sites Web suite à votre utilisation des services. Do Not Track (« DNT ») est un paramètre facultatif du navigateur qui vous permet d’indiquer vos préférences en matière de suivi sur les sites Web. À l’exception de certains paramètres de préférence d’exclusion dans le navigateur utilisé pour accéder à nos sites Web, tels que le contrôle global de la confidentialité mentionné dans les addenda spécifiques aux États, nous ne répondons pas actuellement aux signaux DNT et nous pouvons continuer à collecter des informations de la manière décrite dans la présente déclaration de confidentialité à partir de navigateurs web qui ont activé les signaux DNT ou des mécanismes similaires.

8. Vos droits et choix 


Dans le cadre des services et autres traitements décrits dans la présente déclaration, nous reconnaissons que vous pouvez souhaiter mettre à jour, corriger ou gérer d’une autre manière vos renseignements personnels que nous traitons, ainsi que gérer la manière dont Toast communique avec vous. Il s’agit notamment de communications relatives aux services ou à une interaction particulière avec vous, ainsi que de communications marketing lorsque nous avons votre consentement ou lorsque la loi applicable le permet. Selon la nature de votre relation avec Toast, nous pouvons vous donner la possibilité de gérer vos renseignements personnels directement dans le cadre des services ou en contactant Toast. 
La gestion de vos renseignements
Nous voulons nous assurer que vous disposez des outils nécessaires pour gérer vos renseignements personnels. Nous comptons sur vous pour veiller à ce que vos renseignements soient exacts, complets et à jour et nous vous demandons de nous informer de toute modification de vos renseignements personnels. Votre capacité à mettre à jour et à gérer vos renseignements personnels variera en fonction de votre relation avec Toast et des services que vous utilisez. Par exemple,
  • En tant que marchand, pour certains services, vous pouvez accéder, modifier ou corriger certaines informations de votre compte à tout moment en vous connectant à votre compte. Dans les autres cas, veuillez contacter notre équipe du service à la clientèle.
  • En tant qu’employé d’un marchand utilisant les modules de gestion de la paie et de gestion de l’équipe Toast ou d’autres services destinés aux employés d’un marchand, vous avez la possibilité, dans de nombreux cas, d’accéder à vos informations et de les mettre à jour par le biais des services. Dans les autres cas, veuillez contacter votre employeur marchand.
  • En tant que client, selon les services que vous utilisez, vous pouvez être en mesure d’accéder à vos renseignements, de les modifier et de les mettre à jour par le biais d’un compte créé dans le cadre des services (p. ex. un compte de commande numérique). Si vous êtes un client et que vous avez des questions sur votre compte de commande numérique ou que vous avez besoin d’une assistance, veuillez contacter support@toasttakeout.zendesk.com et/ou consulter les informations figurant sur cette page. Dans certains cas (p ex. Local by Toast), vous pouvez également soumettre une demande de suppression de votre compte de commande numérique directement à partir de l’application mobile.
Dans d’autres cas, le cas échéant, consultez les instructions fournies dans le cadre des services ou contactez-nous comme indiqué dans l’article « Nous contacter » de la présente déclaration. Il se peut que nous devions vérifier votre identité avant de modifier ou de corriger vos renseignements. Dans certains cas, il se peut que nous ne soyons pas en mesure d’effectuer la correction ou d’accéder à la demande en raison de restrictions légales, contractuelles ou techniques.
Veuillez noter qu’en fonction de votre statut, de votre lieu de résidence et du droit applicable, vous pouvez bénéficier de droits à l’information supplémentaires en ce qui concerne le traitement de vos renseignements personnels. Pour plus d’informations concernant ces droits et les lieux/circonstances où ils sont disponibles, veuillez consulter les addenda applicables de la présente déclaration.
La gestion des communications
Dans le cadre de la fourniture des services, Toast (directement ou par le biais d’un fournisseur de services tiers) peut vous envoyer :
  • Des communications marketing : En fonction de la nature de notre relation et des services utilisés, nous pouvons vous envoyer des communications marketing et autres communications promotionnelles concernant des services nouveaux ou existants qui, selon nous, pourraient vous intéresser. Ces communications marketing peuvent inclure des SMS si vous avez choisi de les recevoir. Vous pouvez refuser ou vous désabonner de toute communication marketing en suivant les instructions contenues dans ces messages, en modifiant vos préférences de communication dans votre compte ou par le biais de votre appareil. Vous pouvez également vous désinscrire en nous contactant à l’adresse courriel : privacy@toasttab.com. Le fait de vous désinscrire d’une communication ne signifie pas nécessairement que vous ne recevrez pas toutes les communications marketing. Veuillez noter que vous pouvez continuer à recevoir certaines communications non marketing après vous être désinscrit. Ces messages peuvent comprendre des communications spécifiques à une transaction, des messages dans le cadre d’un programme de fidélité ou des communications spécifiques à un compte. Si vous êtes situé en dehors des États-Unis, nous ne vous enverrons pas de communications de marketing direct sans votre consentement ou si la loi applicable le permet. 
Dans certains cas, nos marchands (y compris ceux qui font partie du groupe de gestion d’un marchand) peuvent également vous envoyer des communications marketing et promotionnelles dans le cadre des services, notamment lorsque vous visitez un marchand à l’aide de Toast ou que vous adhérez à un programme de fidélité propre au marchand. Dans ce cas, veuillez suivre les instructions contenues dans ces messages pour vous désinscrire ou contacter directement le marchand.
  • Autres communications : Dans le cadre de votre interaction avec nos services, vous pouvez recevoir diverses communications non marketing de Toast qui peuvent être envoyées par courriel ou par SMS. Celles-ci comprennent :
Pour le clients :
  • de vous envoyer des reçus numériques ou d’autres messages en rapport avec les services que vous utilisez,
  • des notifications envoyées par les marchands, nos partenaires commerciaux et/ou des fournisseurs de services tiers dans le cadre de nos services, telles que l’état de la commande, les notifications de livraison ou de retrait et les informations relatives à nos services de réservation et de liste d’attente,
  • des réponses aux commentaires que vous avez fournis en rapport avec les services de Toast ou de l’un de nos marchands,
  • des messages spécifiques à un compte ou à un programme dans le cadre de votre utilisation des services (p. ex. comptes de fidélité auprès de nos marchands ou en créant un compte de commande numérique),
  • les messages associés aux concours, compétitions ou promotions auxquels vous avez choisi de participer.
Pour les marchands et les employés des marchands :
  • les messages relatifs aux services de Toast et les demandes de démonstration (pour les marchands potentiels),
  • les messages relatifs à la mise en place des services,
  • les messages relatifs aux services que vous utilisez ou qui sont sous votre compte.
Dans certains cas, en fonction de la nature de votre relation avec Toast et des services utilisés, vous pouvez également recevoir des messages de fournisseurs de services tiers et de partenaires commerciaux.
Pour plus d’informations sur nos communications avec vous, veuillez nous contacter à l’adresse courriel : privacy@toasttab.com

9. Sécurité


Nous mettons en œuvre des mesures de sécurité administratives, physiques et techniques appropriées pour protéger raisonnablement vos renseignements personnels contre tout accès, toute divulgation, tout dommage ou toute perte non autorisés. Toutefois, même si nous avons pris des mesures pour protéger vos renseignements personnels, nous ne pouvons pas garantir que la collecte, la transmission et le stockage des renseignements personnels seront toujours totalement sûrs. 

10. Liens vers d’autres sites Web

La présente déclaration de confidentialité ne s’applique qu’aux renseignements recueillis lors de la visite de nos sites Web ou de l’utilisation de nos services. Lorsque vous visitez nos sites Web ou utilisez les services, vous pouvez être dirigé vers des liens vers des sites Web ou des services de tiers qui ne sont pas exploités ou contrôlés par nous. Par exemple, les sites Web de nos marchands ou partenaires commerciaux qui fournissent des services dans le cadre de la présente déclaration. Nous ne sommes pas responsables des pratiques et politiques de ces tiers en matière de confidentialité. Par conséquent, nous vous encourageons à consulter les politiques de confidentialité de ces sites Web tiers, car leurs pratiques peuvent différer des nôtres. 

11. Enfants

Nos services ne sont pas destinés aux enfants de moins de 13 ans et nous n’avons pas l’intention de collecter ou de solliciter sciemment des renseignements personnels auprès d’enfants de moins de 13 ans. Si vous avez lieu de croire qu’un enfant de moins de 13 ans nous a fourni des renseignements personnels, nous encourageons le parent ou le tuteur de l’enfant à nous contacter comme indiqué à l’article « Nous contacter » du présent article pour demander que nous supprimions ces renseignements de nos systèmes. Si nous apprenons que des renseignements personnels que nous avons collectés ont été fournis par un enfant de moins de 13 ans, nous supprimerons rapidement ces renseignements personnels.
Nous traitons toutefois des renseignements personnels concernant des enfants lorsque cela est nécessaire pour les services que nous proposons et que vous nous les fournissez. Par exemple, si vous êtes un employé d’un marchand, nous pouvons collecter des renseignements relatifs aux enfants si votre employeur utilise les modules gestion de la paie et gestion de l’équipe Toast et que vous les ajoutez en tant que personnes à charge dans le cadre de vos polices d’avantages sociaux.   

12. Nous contacter

Si vous avez des questions ou des préoccupations concernant notre déclaration de confidentialité, nos pratiques ou notre respect des lois applicables en matière de confidentialité, vous pouvez nous contacter par les moyens suivants :
  • Par courriel :  privacy@toasttab.com
  • Par la poste : À l’attention de : Toast Privacy Office
    Toast, Inc. 333 Summer St. Boston, MA 02210
  • Par téléphone : 66 226-4484
D’autres points de contact se trouvent dans les addenda. Si vous avez besoin d’une assistance qui n’est pas liée à la confidentialité, veuillez contacter support@toasttakeout.zendesk.com et/ou consulter les informations figurant sur cette page.
Une version téléchargeable de cette déclaration est disponible ici.

13. Modifications à cette déclaration de confidentialité

De temps à autre, nous pouvons mettre à jour, changer, modifier ou amender la présente déclaration de confidentialité afin de nous conformer à la législation applicable ou à l’évolution de nos pratiques commerciales. Sauf si la loi applicable nous oblige à fournir une forme prescrite de notification et/ou à obtenir un consentement, des versions mises à jour de la présente déclaration peuvent être publiées sur ce site Web avec une communication supplémentaire. Une version archivée de notre dernière déclaration de confidentialité se trouve ici. Veuillez consulter régulièrement ce site Web et la présente déclaration de confidentialité pour prendre connaissance des mises à jour.

Addenda C – Canada

Dernière mise à jour : 1 janvier 2025
1. Addenda sur la confidentialité pour les personnes situées au Canada
Les dispositions ci-dessous complètent les informations fournies dans la partie généralement applicable de notre déclaration de confidentialité et s’appliquent uniquement aux personnes qui résident au Canada ou qui sont autrement couvertes par les lois ou réglementations fédérales ou provinciales canadiennes applicables en matière de protection de confidentialité, y compris, mais sans s’y limiter, la Loi sur la protection des renseignements personnels et les documents électroniques (« PIPEDA »), la loi sur la protection des renseignements personnels de l’Alberta et la loi sur la protection des renseignements personnels de la Colombie Britannique. Toast s’engage à collecter, utiliser et divulguer vos renseignements personnels conformément aux lois et réglementations en vigueur. 
  1. Consentement
    En utilisant nos services et en accédant à nos sites Web, vous acceptez les conditions de la présente déclaration de confidentialité et consentez à la collecte, à l’utilisation, au traitement, à la divulgation et à la conservation de vos informations comme décrit dans la présente déclaration de confidentialité. En règle générale, nous vous informons de l’objectif de la collecte de vos renseignements personnels et/ou vous demandons votre consentement (qui peut être explicite ou implicite, en fonction de la nature et de la sensibilité des renseignements personnels) conformément à la législation applicable au moment où nous recueillons vos renseignements personnels. Dans certaines circonstances, nous pouvons collecter automatiquement des renseignements personnels non sensibles. En général, vous pouvez modifier ou retirer votre consentement à tout moment, sous réserve d’obligations légales ou contractuelles et moyennant un préavis raisonnable. Le retrait de votre consentement peut avoir un impact sur la capacité de Toast à vous fournir tout ou partie des services. Dès réception de l’avis de votre souhait de retirer votre consentement, nous vous informerons des conséquences probables de ce retrait.
    Toast ne collectera, n’utilisera ni ne divulguera vos renseignements personnels qu’aux fins que nous avons identifiées pour la collecte (y compris celles énumérées à l’article 4 de la déclaration de confidentialité de Toast ci-dessus et/ou identifiées au moment de la collecte), sauf si nous avons reçu votre consentement (qui peut être explicite ou implicite, selon la nature et la sensibilité des renseignements personnels) ou si le traitement est autorisé sans consentement.
  2. Accès et correction de vos renseignements personnels 
    Si vous êtes situé au Canada, vous avez le droit de demander l’accès aux renseignements personnels que nous détenons à votre sujet et de les corriger, sous réserve de certaines conditions et limitations. Sous réserve de la législation applicable et de la nature de votre relation avec Toast, ceci peut inclure un droit de révision, de correction, de mise à jour, de suppression, d’effacement ou de limitation de l’utilisation de vos renseignements personnels qui nous ont été précédemment fournis. Vous pouvez également avoir le droit d’accéder à des informations sur la manière dont vos renseignements personnels sont ou ont été utilisés et sur les noms des personnes et/ou des organisations auxquelles vos renseignements ont été divulgués.
    Toast a mis en place un portail de droits individuels afin de soumettre de telles demandes de droits individuels. Le lien vers le portail Toast sur les droits individuels se trouve ici. Les demandes de droits individuels peuvent également être soumises à Toast par le biais des canaux ci-dessous :
    • Par courriel : privacy@toasttab.com
    • Par la poste :
      À l’attention de : Toast Privacy Office
      Toast, Inc.
      333 Summer St. Boston, MA 02210
      États-Unis d’Amérique
  3. Dans votre demande, veuillez préciser les renseignements auxquels vous souhaitez accéder ou que vous souhaitez faire corriger. Nous répondrons à votre demande dès que cela sera raisonnablement possible et dans les délais requis par la loi. L’exercice de ces droits est gratuit. Une fois qu’une demande de droits individuels a été soumise, Toast peut vous demander des informations supplémentaires afin de vérifier votre identité ou de fournir des détails supplémentaires pour nous aider à répondre à votre demande. Il peut s’agir de votre nom, de votre adresse courriel, de votre numéro de téléphone ou d’autres détails liés à votre utilisation des services ou des sites Web de Toast.
    Si nous corrigeons vos renseignements, nous enverrons également les renseignements corrigés aux organisations auxquelles nous avons divulgué les renseignements au cours de l’année précédant la date à laquelle la correction a été apportée.
    Veuillez noter que dans certaines circonstances, nous pouvons refuser d’agir ou imposer des limitations à vos droits, comme le permet la loi applicable. Si nous ne pouvons pas vous donner accès à vos renseignements personnels ou si nous ne sommes pas en mesure de les corriger, nous vous en informerons, sous réserve des restrictions légales ou réglementaires, et nous vous indiquerons les autres mesures à votre disposition. Si nous refusons de donner suite à une demande de correction de vos renseignements personnels, nous ferons néanmoins une annotation sur les renseignements, en notant la correction qui a été demandée mais qui n’a pas été effectuée.
    Dans certains cas, en fonction de la nature de votre demande, il peut également y avoir des renseignements résiduels qui resteront dans nos bases de données et autres registres et qui, en raison de la loi applicable ou dans le cadre de services en cours d’exécution, ne seront pas supprimés ou modifiés. Nous conserverons également les renseignements relatifs à votre demande à des fins d’archivage et de conformité.
  4. Transferts internationaux
    Nous pouvons traiter, stocker et transférer vos renseignements personnels dans et vers une juridiction étrangère, avec des lois sur la confidentialité différentes qui peuvent ou non être aussi complètes que la loi canadienne. Dans ces circonstances, les gouvernements, les tribunaux, les services de police ou les organismes de réglementation de cette juridiction peuvent être en mesure d’obtenir l’accès à vos renseignements personnels en vertu des lois de la juridiction étrangère.
    Plus précisément, les renseignements personnels collectés dans le cadre des services ou de toute autre manière prévue par la présente déclaration sont principalement traités et stockés aux États-Unis. Cependant, Toast étant une organisation internationale avec des processus commerciaux, des bureaux et des tiers dans le monde entier, vos informations peuvent être envoyées à toute autre juridiction dans le monde où nous faisons des affaires ou entretenons des relations avec des tiers. Lorsque vous nous fournissez des renseignements personnels par le biais des services et dans le cadre de la présente déclaration, vous consentez au transfert de vos informations et à leur traitement de cette manière. Tout transfert international effectué sera conforme à la présente déclaration et à la législation applicable.
    Nous imposons également des garanties appropriées pour le transfert de renseignements personnels entre nos entreprises affiliées et à des fournisseurs de services tiers dans diverses juridictions, et nous avons mis en œuvre des ententes contractuelles ou d’autres mesures appropriées à ces fins.
    Pour obtenir une liste actualisée des juridictions dans lesquelles les renseignements personnels soumis à la présente déclaration sont collectés, utilisés, divulgués et/ou stockés, y compris auprès de nos fournisseurs de services, ainsi que les raisons pour lesquelles nos fournisseurs de services en dehors du Canada ont été autorisés à collecter, utiliser ou divulguer des renseignements personnels pour Toast ou en son nom, veuillez contacter privacy@toasttab.com
  5. Droit de contester le respect de la législation et de déposer une plainte
    Si vous estimez que les lois relatives à la protection de vos renseignements personnels ou les pratiques décrites dans la présente déclaration n’ont pas été respectées, vous pouvez déposer une plainte auprès de notre avocat général adjoint, chargé de la confidentialité, à l’adresse indiquée ci-dessous : 
    • Par courriel : privacy@toasttab.com
    • Par la poste :
      À l’attention de : Avocat général adjoint, confidentialité
      Toast, Inc.
      333 Summer St. Boston, MA 02210
      États-Unis d’Amérique
    • Par téléphone (sans frais) : +1 866 226-4484
  6. Toast peut vous demander des renseignements supplémentaires afin de vérifier votre identité ou de fournir des détails supplémentaires pour nous aider à répondre à votre plainte.
    Nous enquêtons sur toutes les plaintes. Si, après enquête, votre plainte est jugée justifiée, Toast prendra les mesures appropriées pour corriger la situation, y compris, si nécessaire, en modifiant ses politiques et pratiques. Si vous n’êtes pas satisfait des résultats de l’enquête ou des mesures correctives prises par Toast, vous pouvez exercer les recours prévus par la loi en contactant le Commissariat à la protection de la vie privée du Canada à l’adresse ci-dessous :
    Bureau du Commissariat à la protection de la vie privée du Canada
    30, rue Victoria
    Gatineau, Québec
    K1A 1H3
    https://www.priv.gc.ca/fr/Si vous résidez dans la province de l’Alberta, vous pouvez également contacter le bureau du Commissariat à l’information et à la protection de la vie privée de l’Alberta à l’adresse ci-dessous :
    Bureau du Commissariat à la protection de la vie privée de l’Alberta
    #410, 9925 – 109 Street NW
    Edmonton, Alberta
    T5K 2J8
    https://www.oipc.ab.ca/
    Si vous résidez dans la province de la Colombie-Britannique, vous pouvez également contacter le bureau du Commissariat à l’information et à la protection de la vie privée de la Colombie-Britannique à l’adresse ci-dessous :
    Bureau du Commissariat à la protection de la vie privée de la Colombie-Britannique
    PO Box 9038 Stn. Prov. Govt.
    Victoria, C.-B.
    V8W 9A4 
    https://www.oipc.bc.ca/

    Si vous résidez dans la province de Québec, vous pouvez également contacter la Commission d’accès à l’information
    Québec
    525, boulevard René-Lévesque Est,
    bureau 2.36
    Québec (Québec) G1R 5S9
    https://www.cai.gouv.qc.ca

    Nous conserverons les renseignements personnels utilisés pour prendre une décision qui vous concerne directement pendant au moins un an après la prise de cette décision.
  7.  Pour les personnes au Québec : Le tableau ci-dessous résume :
  • les catégories de renseignements personnels collectés par Toast au cours des 12 derniers mois,
  • les sources de collecte des renseignements personnels, 
  • notre utilisation des renseignements personnels, et
  • les catégories de renseignements personnels divulgués à des fins commerciales par Toast (y compris à des tiers) au cours des 12 derniers mois.
Veuillez consulter l’article de la présente déclaration de confidentialité qui s’applique de manière générale pour obtenir plus d’informations sur les pratiques de Toast en matière d’information, y compris plus de détails sur la manière dont nous utilisons et divulguons vos renseignements personnels. 
Catégorie de renseignements personnels
Exemples de renseignements personnels collectés*
Catégories de sources
Fin commerciale ou d’entreprise
Notre divulgation des renseignements personnels
Identifiants
Marchands : Nom, identifiants personnels uniques, adresse IP, adresse courriel, numéro de sécurité sociale
Clients : Nom, identifiants personnels uniques, adresse IP, adresse courriel
Employés des marchands : Nom, identifiants personnels uniques, adresse IP, adresse courriel
Fournis directement à Toast
Collectés automatiquement
Fournis à Toast par nos partenaires commerciaux
Fournis à Toast par nos fournisseurs de services
Fournis à Toast par nos marchands
Pour fournir, entretenir et soutenir nos services 
Pour gérer nos activités et à des fins opérationnelles internes
Pour faire de la publicité et du marketing auprès de vous
Pour personnaliser votre expérience
Pour communiquer avec vous ou fournir les informations que vous avez demandées 
À des fins juridiques, de conformité et de sécurité
Avec nos marchands et les employés de nos marchands 
Avec nos partenaires commerciaux
Avec nos fournisseur de services
Avec les autorités légales et autres autorités de régulation
Caractéristiques de classement protégées
Employés des marchands : (en utilisant Gestion de la paie et Gestion de l’équipe Toast) : Race, genre, âge
Fournis directement à Toast
Fournis à Toast par nos marchands
Pour fournir, entretenir et soutenir nos services
À des fins juridiques, de conformité et de sécurité
Avec nos marchands et les employés de nos marchands
Avec nos fournisseur de services
Informations commerciales
Marchands : Registres des produits ou services achetés
Clients : Registres des produits ou services achetés
Fournis directement à Toast
Fournis à Toast par nos partenaires commerciaux
Fournis à Toast par nos fournisseurs de services
Fournis à Toast par nos marchands
Pour fournir, entretenir et soutenir nos services 
Pour gérer nos activités et à des fins opérationnelles internes
Pour personnaliser votre expérience
À des fins juridiques, de conformité et de sécurité
Avec nos marchands et les employés de nos marchands
Avec nos partenaires commerciaux
Avec nos fournisseur de services
Avec les autorités légales et autres autorités de régulation
Informations sur l’Internet/le réseau
Activité et interactions de navigation sur le site Web, interactions publicitaires
Fournis directement à Toast
Collectés automatiquement
Fournis à Toast par nos fournisseurs de services
Pour fournir, entretenir et soutenir nos services 
Pour gérer nos activités et à des fins opérationnelles internes
Pour personnaliser votre expérience
Pour faire de la publicité et du marketing auprès de vous
Avec nos marchands et les employés de nos marchands
Avec nos fournisseur de services
Données de géolocalisation
Renseignements sur le plat ou la géolocalisation précise
Fournis directement à Toast
Collectés automatiquement
Fournis à Toast par nos fournisseurs de services
Pour fournir, entretenir et soutenir nos services 
Pour personnaliser votre expérience
Pour faire de la publicité et du marketing auprès de vous
À des fins juridiques, de conformité et de sécurité
Avec nos marchands et les employés de nos marchands
Avec nos partenaires commerciaux
Avec nos fournisseur de services
Informations sensorielles
Marchands et employés des marchands : Enregistrements audio dans le cadre de services d’assistance ou d’appels de clients
Clients : Audio dans le cadre de services d’assistance ou d’appels de clients
Fournis directement à Toast
Fournis à Toast par nos fournisseurs de services
Pour fournir, entretenir et soutenir nos services 
À des fins juridiques, de conformité et de sécurité
Avec nos fournisseur de services
Informations sur le métier/l’emploi
Employés des marchands : (en utilisant Gestion de la paie et Gestion de l’équipe Toast) : Expérience professionnelle, curriculum vitae
Fournis directement à Toast
Pour fournir, entretenir et soutenir nos services
Avec nos marchands et les employés de nos marchands
Avec nos fournisseur de services
Déductions
Clients : Préférences et comportement dans le cadre de l’utilisation des services
Fournis directement à Toast
Fournis à Toast par nos partenaires commerciaux
Fournis à Toast par nos fournisseurs de services
Fournis à Toast par nos marchands
Pour fournir, entretenir et soutenir nos services 
Pour gérer nos activités et à des fins opérationnelles internes
Pour personnaliser votre expérience
Pour faire de la publicité et du marketing auprès de vous
Avec nos marchands et les employés de nos marchands
Avec nos partenaires commerciaux
Avec nos fournisseur de services
*Veuillez noter que les renseignements personnels effectivement collectés dépendent de la nature de la relation individuelle et des services spécifiques fournis.

Ready to get started?

Talk to a restaurant expert today and learn how Toast can help your business.

Get a Demo