Mon-Fri: 9AM-9PM | Sat-Sun: 10AM-10PM Order Now

Privacy Policy

Effective Date: June 21, 2026  |  Last Updated: June 21, 2026

1. Introduction and Who We Are

Welcome to Costa Vida. We are a food service business operating in the United States, committed to providing our customers with fresh, high-quality food and an outstanding dining experience. We recognize that your privacy is extremely important, and we take our responsibility to protect your personal information seriously.

This Privacy Policy governs our data practices for all visitors, customers, and users who interact with our website located at costavida-cafe.click, including any related mobile applications, online ordering platforms, loyalty programs, and any other digital or in-person services we provide (collectively, the "Services").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree with the terms described herein, please discontinue use of our Services immediately.

1.1 Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below:

Company Name Costa Vida
Website costavida-cafe.click
Email Address [email protected]
Country United States

2. Scope of This Privacy Policy

This Privacy Policy applies to all personal information we collect through the following channels:

  • Our website at costavida-cafe.click and any subdomains thereof
  • Online food ordering platforms or third-party delivery integrations linked to our business
  • Email communications, newsletters, and promotional messages sent by Costa Vida
  • Social media interactions on platforms such as Facebook, Instagram, and Twitter/X
  • In-store data collection, such as loyalty programs, comment cards, and Wi-Fi usage
  • Surveys, contests, sweepstakes, and promotional campaigns
  • Customer support interactions via phone, email, or chat

This policy does not cover third-party websites, applications, or services that may be linked from our website. We encourage you to review the privacy policies of those third parties independently.

3. Information We Collect

We collect several categories of personal information depending on how you interact with our Services. Below is a detailed breakdown of the types of data we may collect.

3.1 Personal Identification Information

When you create an account, place an order, join our loyalty program, or contact us, we may collect the following personally identifiable information:

  • Full name — to identify and address you properly
  • Email address — for order confirmations, account communications, and marketing (if opted in)
  • Phone number — for order status updates or customer support follow-up
  • Mailing and billing address — for delivery orders and payment processing purposes
  • Date of birth — to verify eligibility for certain promotions or age-restricted items
  • Profile photo — if voluntarily submitted as part of your user account

3.2 Payment and Financial Information

When you make a purchase through our website or mobile platform, payment information is collected to complete the transaction. This may include:

  • Credit or debit card numbers (last four digits only stored on our systems)
  • Billing address associated with the payment method
  • Payment processor tokens or identifiers generated by secure third-party processors

We do not store full credit card numbers on our servers. All payment transactions are processed through PCI-DSS-compliant third-party payment processors.

3.3 Order and Transaction Data

We collect information related to the orders you place and transactions you complete, including:

  • Items ordered, customizations, and special instructions
  • Order history and frequency
  • Delivery addresses and pickup preferences
  • Coupon and promotional code usage
  • Loyalty points earned and redeemed

3.4 Usage and Behavioral Data

When you visit our website, we automatically collect certain information about your interaction with our digital Services, including:

  • Pages visited, time spent on each page, and navigation paths
  • Search queries entered on our website
  • Links and buttons clicked
  • Referral URLs (how you arrived at our website)
  • Scroll depth and engagement metrics
  • Shopping cart behavior, including abandoned carts

3.5 Device and Technical Information

We may collect information about the device you use to access our Services, including:

  • IP address and approximate geographic location (city/region level)
  • Browser type and version
  • Operating system and device type (desktop, mobile, tablet)
  • Screen resolution and language settings
  • Unique device identifiers
  • Mobile network provider (for mobile users)

3.6 Communication Data

If you contact us via email, live chat, phone, or any other communication channel, we may collect and retain:

  • The content of your messages and inquiries
  • Your contact details provided in the communication
  • Records of customer support interactions
  • Responses to surveys or feedback forms

3.7 Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your browsing behavior. Please refer to Section 9 of this Privacy Policy for detailed information about our use of cookies and how to manage your preferences.

3.8 Information from Third Parties

We may receive information about you from third parties, including:

  • Social media platforms, if you connect your social accounts or interact with our social media content
  • Third-party delivery partners (e.g., DoorDash, Uber Eats) who transmit order data to us
  • Analytics providers and marketing platforms
  • Fraud prevention and identity verification services

4. How We Use Your Information

We use the personal information we collect for a variety of legitimate business purposes. Below is a comprehensive list of how we may use your data:

4.1 Providing and Managing Services

  • Processing and fulfilling your food orders, both online and in-store
  • Creating and managing your customer account
  • Sending order confirmations, receipts, and status updates
  • Facilitating delivery or pickup coordination
  • Managing loyalty program memberships and reward redemption

4.2 Customer Communication and Support

  • Responding to your inquiries, complaints, and feedback
  • Sending service-related notifications and important updates
  • Providing customer support and resolving disputes
  • Following up on unresolved issues or concerns

4.3 Marketing and Promotional Activities

  • Sending promotional emails, newsletters, and special offers (with your consent where required)
  • Personalizing our marketing messages based on your ordering history and preferences
  • Running targeted advertising campaigns on social media and digital platforms
  • Conducting contests, giveaways, and promotional events
  • Sending SMS or push notifications about new menu items or deals (where you have opted in)

You may opt out of marketing communications at any time by clicking the "unsubscribe" link in our emails or contacting us at [email protected].

4.4 Analytics and Business Improvement

  • Analyzing website traffic patterns and user behavior to improve our digital experience
  • Understanding customer preferences to enhance our menu and service offerings
  • Measuring the effectiveness of marketing campaigns and promotions
  • Conducting internal research and business intelligence activities
  • Improving our operational efficiency and supply chain management

4.5 Legal Compliance and Security

  • Complying with applicable federal, state, and local laws and regulations
  • Detecting, preventing, and investigating fraud, unauthorized activity, and security incidents
  • Enforcing our Terms of Service and other applicable agreements
  • Responding to lawful requests from government authorities and law enforcement
  • Protecting the rights, property, and safety of Costa Vida, our employees, and our customers

5. Legal Basis for Processing Your Data

Costa Vida operates in the United States and complies with all applicable federal and state privacy laws, including but not limited to:

  • The Federal Trade Commission (FTC) Act — which prohibits unfair or deceptive practices relating to data collection and privacy
  • The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) — applicable to California residents
  • The CAN-SPAM Act — governing commercial email communications
  • The Children's Online Privacy Protection Act (COPPA) — protecting the privacy of children under 13
  • Any other applicable state privacy laws, including Virginia's Consumer Data Protection Act (CDPA), Colorado Privacy Act (CPA), and other emerging state legislation

We process your personal data on the basis of your consent, the performance of a contract (such as fulfilling your food order), our legitimate business interests, or compliance with a legal obligation, as applicable under each law.

6. Sharing Your Information with Third Parties

We do not sell your personal information to third parties. However, we may share your information with trusted partners and third parties under the following circumstances:

6.1 Service Providers and Business Partners

We work with third-party service providers who assist us in operating our business and delivering our Services. These providers are contractually bound to use your information only as directed by us and in compliance with this Privacy Policy. Categories of service providers include:

  • Payment processors — to securely handle financial transactions
  • Delivery and logistics partners — to fulfill food delivery orders
  • Cloud hosting and IT providers — to maintain our website and data infrastructure
  • Email and SMS marketing platforms — to send communications on our behalf
  • Analytics providers (e.g., Google Analytics) — to help us understand website usage
  • Customer relationship management (CRM) platforms — to manage customer interactions
  • Fraud prevention services — to protect against unauthorized transactions

6.2 Legal Requirements and Law Enforcement

We may disclose your personal information if required to do so by law or in good faith belief that such action is necessary to:

  • Comply with a legal obligation, court order, subpoena, or government request
  • Protect and defend the rights or property of Costa Vida
  • Prevent or investigate possible wrongdoing in connection with our Services
  • Protect the personal safety of users or the public
  • Protect against legal liability

6.3 Business Transfers

In the event of a merger, acquisition, sale of assets, reorganization, or other business transfer involving Costa Vida, your personal information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website of any such change in ownership and any applicable changes to this Privacy Policy.

6.4 With Your Consent

We may share your information with other third parties when you have given us explicit consent to do so, such as when participating in co-branded promotions or partner loyalty programs.

6.5 Aggregated and De-Identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you, for purposes such as industry research, marketing analysis, or business reporting.

7. Your Privacy Rights

Depending on where you reside, you may have various rights regarding the personal information we hold about you. We are committed to honoring these rights in compliance with applicable law.

7.1 Rights Available to All Users

  • Right to Know: You have the right to know what personal information we collect about you, how it is used, and with whom it is shared.
  • Right to Access: You may request a copy of the personal information we hold about you.
  • Right to Correction: You have the right to request that we correct inaccurate or incomplete personal information.
  • Right to Deletion: You may request that we delete your personal information, subject to certain legal exceptions.
  • Right to Opt-Out of Marketing: You may opt out of receiving promotional communications from us at any time.

7.2 Rights for California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:

  • Right to Know (Detailed): The right to request disclosure of the specific pieces of personal information we have collected about you over the past 12 months.
  • Right to Delete: The right to request deletion of personal information we have collected from you, with limited exceptions.
  • Right to Correct: The right to request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: Although we do not sell your personal information, you have the right to opt out of the sharing of your personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: You may have the right to limit our use and disclosure of your sensitive personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights. We will not deny you goods or services, charge different prices, or provide a different quality of service based solely on your exercise of these rights.
  • Right to Data Portability: You have the right to receive your personal information in a portable, commonly used format.

7.3 How to Submit a Privacy Rights Request

To exercise any of the rights described above, please submit a request by:

We will verify your identity before processing your request. You may be required to provide additional information to confirm your identity. We will respond to verified requests within 45 days, with an optional 45-day extension where reasonably necessary, as permitted by applicable law.

You may also designate an authorized agent to submit requests on your behalf. The authorized agent must provide written proof of authorization, and we may still verify your identity directly.

8. Data Security

We take the security of your personal information seriously and implement a range of technical, administrative, and physical safeguards to protect your data from unauthorized access, use, disclosure, alteration, or destruction.

8.1 Security Measures We Employ

  • Encryption: All data transmitted between your browser and our website is encrypted using Secure Sockets Layer (SSL) / Transport Layer Security (TLS) technology.
  • Access Controls: Access to personal information is restricted to authorized personnel who have a legitimate business need for such access.
  • Secure Payment Processing: All payment transactions are handled by PCI-DSS-compliant third-party payment processors. We do not store full credit card numbers on our systems.
  • Regular Security Audits: We conduct periodic reviews of our data security practices and systems to identify and address vulnerabilities.
  • Employee Training: Our team members receive regular training on data privacy and security best practices.
  • Firewall and Intrusion Detection: Our systems are protected by firewalls and monitoring tools to detect and prevent unauthorized access.

8.2 Data Breach Response

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected individuals and relevant authorities as required by applicable law. Notifications will be provided in a timely manner and will include information about the nature of the breach, the data affected, and recommended steps you can take to protect yourself.

9. Cookie Policy and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and deliver personalized content and advertising.

9.1 Types of Cookies We Use

Cookie Type Purpose Duration
Strictly Necessary Essential for the website to function properly (e.g., shopping cart, login sessions) Session / Short-term
Performance / Analytics Collect anonymous data on how visitors use our website to improve functionality Up to 2 years
Functional Remember your preferences, such as language or location settings Up to 1 year
Marketing / Targeting Deliver relevant advertising and track campaign performance Up to 2 years

9.2 Managing Cookie Preferences

You can manage your cookie preferences at any time through your browser settings. Most browsers allow you to refuse or delete cookies. Please note that disabling certain cookies may affect the functionality of our website and your ability to place orders or access your account.

You may also opt out of interest-based advertising through the Digital Advertising Alliance at www.aboutads.info or the Network Advertising Initiative at www.networkadvertising.org.

10. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy, or as required by applicable law.

10.1 Retention Periods

Category of Data Retention Period
Account information and profile data Duration of account activity + 3 years after account closure
Order and transaction history 7 years (for tax and financial compliance)
Customer support communications 3 years from date of last interaction
Marketing preferences and consent records Duration of consent + 3 years
Website usage and analytics data Up to 26 months
Legal and compliance records As required by applicable law (typically 5–7 years)

After the applicable retention period, we will securely delete or anonymize your personal information in accordance with our data disposal procedures.

11. Children's Privacy

Costa Vida's website, online ordering system, and digital services are not directed to children under the age of 13. We do not knowingly collect, use, or disclose personal information from children under 13 years of age. If we become aware that we have inadvertently collected personal information from a child under 13, we will take immediate steps to delete such information from our records.

If you are a parent or guardian and believe that your child has provided personal information to us without your consent, please contact us immediately at [email protected] so that we can investigate and take appropriate action.

In compliance with the Children's Online Privacy Protection Act (COPPA), we will not knowingly collect information from minors without verifiable parental consent where required by law.

12. International Data Transfers

Costa Vida is based in the United States, and your personal information will be stored and processed in the United States. If you are accessing our Services from outside the United States, please be aware that your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence.

By using our Services, you consent to the transfer of your personal information to the United States in accordance with this Privacy Policy. We will take appropriate safeguards to ensure that your information is treated securely and in accordance with this Privacy Policy and applicable law when it is transferred internationally.

Where required by law, we implement appropriate safeguards for international data transfers, such as standard contractual clauses or other legally recognized mechanisms.

13. Third-Party Links and Services

Our website may contain links to third-party websites, applications, and services that are not operated or controlled by Costa Vida. These may include food delivery platforms, social media platforms, payment gateways, and partner websites. We are not responsible for the privacy practices of these third parties, and this Privacy Policy does not apply to them.

We encourage you to review the privacy policies of any third-party services you access through our website before providing them with your personal information. The inclusion of a link on our website does not imply our endorsement of the linked site or its privacy practices.

14. California-Specific Disclosures

In addition to the rights described in Section 7.2, California residents are entitled to the following additional disclosures under the CCPA/CPRA:

14.1 Categories of Personal Information Collected in the Past 12 Months

Category Examples Collected
Identifiers Name, email, IP address, account ID Yes
Commercial Information Purchase history, ordering preferences Yes
Internet Activity Browsing history, search queries on our site Yes
Geolocation Data Approximate location for delivery purposes Yes
Financial Information Payment card type, last four digits Yes
Inferences Preferences and behavioral profiles for marketing Yes
Sensitive Personal Information Account login credentials, precise location (if applicable) Limited

14.2 Do Not Sell or Share My Personal Information

Costa Vida does not sell your personal information for monetary consideration. However, we may share certain data with advertising partners for purposes that may constitute "sharing" under the CPRA (i.e., cross-context behavioral advertising). California residents may opt out of such sharing by contacting us at [email protected] with the subject line "Do Not Sell or Share My Personal Information."

15. How to File a Complaint

If you believe that Costa Vida has violated your privacy rights or has not adequately addressed your privacy concerns, you have the right to file a complaint with the appropriate authority.

15.1 Contact Us First

We encourage you to contact us directly before filing a formal complaint so that we have the opportunity to address your concerns:

15.2 Regulatory Authorities

If you are not satisfied with our response, you may file a complaint with the following regulatory bodies depending on your state of residence:

  • California Residents: California Privacy Protection Agency (CPPA) — cppa.ca.gov
  • All U.S. Residents: Federal Trade Commission (FTC) — www.ftc.gov
  • For online fraud or cybercrime: Internet Crime Complaint Center (IC3) — www.ic3.gov

You may also contact your state's Attorney General office for consumer protection matters related to data privacy.

16. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our business practices, legal requirements, or data processing activities. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this Privacy Policy
  • Post a prominent notice on our website notifying users of the changes
  • Send an email notification to registered users where required or appropriate

Your continued use of our Services following the posting of any changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this page periodically to stay informed about how we protect your information.

17. Consent and Withdrawal of Consent

Where we rely on your consent to process your personal information (for example, for marketing communications), you have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of any processing that occurred prior to your withdrawal.

To withdraw your consent, please contact us at [email protected] or use the opt-out mechanism provided in any marketing email we send you. Please allow up to 10 business days for your request to be processed.

18. Contact Us

If you have any questions, concerns, or requests related to this Privacy Policy or the way we handle your personal information, please do not hesitate to reach out to us. We are committed to addressing your concerns in a timely and transparent manner.

Business Name Costa Vida
Email [email protected]
Website costavida-cafe.click
Country United States

We will make every effort to respond to your inquiry within 30 days of receipt. For requests related to your privacy rights under CCPA/CPRA or other applicable laws, we will respond within the timeframes prescribed by law.