Privacy Policy
Señor Taco — How We Collect, Use & Protect Your Information
Effective: January 1, 2026 · Last updated: March 2026
1. Overview
Señor Taco ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, online ordering platform, loyalty program, or sign up for promotional communications.
Short version: We only collect what we need to serve you better. We never sell your data. You can opt out or request deletion at any time.
2. Information We Collect
We collect information you provide directly when you create an account, place an order, or sign up for notifications:
- Phone number — used for account verification (one-time code) and SMS notifications
- First and last name — used to personalize your account and communications
- Email address — used for order confirmations and promotional emails (optional)
- Date of birth — used solely to deliver your birthday reward (optional)
- Preferred location — Senoia or Suwanee, used to route your orders and notifications
- Order history — items ordered, totals, timestamps, used for loyalty punch card and order tracking
- Communication preferences — your SMS and email opt-in/opt-out status
We also collect limited technical data automatically:
- Browser type and device type (for compatibility)
- Pages visited and time spent (via Google Analytics, anonymized)
- IP address (used for security and rate limiting only)
3. Payment Information
Señor Taco does not collect, store, or process your payment card information directly. All payments are handled securely by Stripe, a PCI-DSS Level 1 certified payment processor.
Powered by Stripe. When you enter payment details, they go directly to Stripe's secure servers — never to ours. Stripe may retain your payment information in accordance with their own privacy policy at
stripe.com/privacy.
We only receive a payment confirmation token and the last 4 digits of your card for display purposes.
4. How We Use Your Information
Your information is used exclusively by Señor Taco for:
- Processing and confirming your online orders
- Sending order confirmations and receipts via email
- Verifying your identity via SMS one-time code at login
- Operating the loyalty punch card and birthday reward programs
- Sending promotional SMS messages and emails (only if you opt in)
- Notifying you when online ordering launches at your preferred location
- Improving our platform, menu, and service based on usage patterns
- Preventing fraud and abuse via IP-based rate limiting
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
5. Data Sharing & Third Parties
We share your data only with the service providers that directly power our platform, and only to the extent necessary:
- Stripe — payment processing. Your card details go directly to them.
- Twilio — SMS delivery for verification codes and promotional messages.
- Zoho Mail — email delivery for order confirmations and promotional emails.
- Amazon Web Services (AWS) — secure cloud hosting for our platform and database.
- Google Analytics — anonymized website traffic analysis. No personally identifiable information is shared.
All third-party providers are contractually required to protect your data and may only use it to provide services to us — not for their own marketing.
6. SMS & Email Communications
By providing your phone number or email and agreeing to our Terms & Conditions, you consent to receive communications from Señor Taco. These may include:
- Order confirmation and receipt messages (transactional — always sent)
- One-time verification codes at login (transactional — always sent)
- Promotional SMS and email messages (only if opted in)
- Online ordering launch notifications for your preferred location
To opt out of promotional SMS: Reply STOP to any text from us, or turn off "Promotional Texts" in your account settings.
To opt out of promotional emails: Click "Unsubscribe" in any email, or turn off "Promotional Emails" in your account settings.
Note: Opting out of promotional messages does not affect transactional messages like order confirmations and login codes.
Standard message and data rates may apply depending on your mobile carrier.
7. Data Storage & Security
Your data is stored on Amazon Web Services (AWS) infrastructure in the US East region, protected by industry-standard security measures including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Database encryption at rest on AWS RDS
- Phone-based OTP authentication — no passwords stored
- IP-based rate limiting to prevent unauthorized access attempts
- Access restricted to authorized Señor Taco team members only
While we implement strong security measures, no system is 100% secure. We will notify you promptly if a data breach occurs that affects your personal information.
8. Data Retention
We retain your personal information for as long as your account is active or as needed to provide our services. Specifically:
- Account data (name, phone, email) — retained while your account is active
- Order history — retained for 3 years for loyalty program and business records
- Communication preferences — retained until changed or account deleted
- Analytics data — anonymized, retained per Google Analytics default settings
To request deletion of your account and personal data, email us at hello@elsenortaco.com. We will remove your data within 30 days, except where retention is required by law or for completed transaction records.
9. Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correct — update your name, email, or birthday in your account settings at any time
- Delete — request full deletion of your account and associated data
- Opt out — stop receiving promotional SMS or emails at any time
- Portability — request your data in a readable format
To exercise any of these rights, contact us at hello@elsenortaco.com. We will respond within 30 days.
10. Cookies & Local Storage
Our website uses browser local storage (not cookies) to maintain your signed-in session. This stores your first name, phone number, and session timestamp on your device only — it is never transmitted to third parties.
We use Google Analytics, which sets anonymized cookies for traffic analysis. These do not contain personally identifiable information. You can opt out via your browser settings or the Google Analytics Opt-out Add-on.
We do not use advertising cookies, tracking pixels, or retargeting technology.
11. Children's Privacy
Our services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at hello@elsenortaco.com and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we may notify you via SMS or email if you have opted in to communications. Continued use of our platform after any changes constitutes your acceptance of the updated policy.
13. Contact Us
For privacy questions, data requests, or to exercise your rights:
Also see our Terms & Conditions for information on how we use your data for communications and promotions.
© 2026 Señor Taco · Senoia & Suwanee, Georgia · All rights reserved.