Privacy Framework
Privacy Policy
Last Updated: June 17, 2026. This policy outlines how Bitzza collects, processes, and secures your personal and session data.
1. Data We Collect & Classify
To provide a fast, checkout-first dine-in ordering service without forced registrations, we collect and store:
- **Personal Data**: Display name (for order pickup/delivery validation), valid mobile phone number (essential for order identification and cashier lookup), and physical coordinates or table references.
- **Session Credentials**: Cryptographic authentication session tokens generated during login or guest registration.
- **Transaction Logs**: Item selections, custom modifiers, payment states, timestamps, order codes, and Bitzza Coins ledger entries.
- **System Metadata**: IP addresses (for rate-limiting and security audits), browser user-agents (to format responsive views), and route navigation sequences.
2. Operational Purposes of Data Processing
All collected data is processed strictly for the execution of your ordering contract:
- **Kitchen Coordination**: Displaying your ordered items, options, and guest notes on the Kitchen Display Screen (KDS) for chef preparation.
- **Cashier Auditing**: Maintaining exact payment logs and print layouts to help cashiers cross-reference receipts and validate physical payments.
- **Loyalty Operations**: Crediting, spend-deducting, and sweeping expired lots of Bitzza Coins in your wallet.
- **FOG/WAF Security**: Analysing IP metadata and rate-limiting to protect our database against DDoS, spam order submissions, and unauthorized role changes.
3. Cookie Declaration
Our application utilizes cookies and browser local storage. We classify them into two categories:
- **Essential Session Cookies (Better Auth)**: These cryptographically signed cookies are used to authenticate your browser, persist your active login state, maintain your cart items, and grant you access to your order status pages. Without these cookies, digital checkout is disabled.
- **Preference Cookies**: Local storage items used to save your interface styling, UI preferences, and table selections across sessions.
4. Data Hosting, Replication, and Security
We are committed to state-of-the-art security measures to protect your database records:
- **Turso Infrastructure**: Your data is hosted on Turso's managed SQLite/LibSQL database, utilizing replicated databases for high reliability and low connection latencies.
- **Encryption**: All client-to-database and browser-to-server connections are encrypted using industry-standard TLS/SSL protocols.
- **Zero-Sharing Policy**: We maintain an absolute zero-sharing data policy. We do not sell, trade, or share your contact info or transaction history with any third-party marketing, analytics, or advertising platforms.
5. Retention & User Data Erasure Rights
Guest session data and completed transaction logs are archived or pruned regularly to maintain database performance. Under local data regulations, you have rights regarding your information:
- You have the right to request a summary of the personal information stored in your active customer profile.
- You can request the complete erasure of your profile and history from our database by contacting the store administrator.
Please submit privacy requests via email to **support@bitzza.pizza**. The administration will verify your phone ownership before processing any deletion queries.
Contact and Privacy Inquiries
Registered Address: House 21, Lake Drive, Dhanmondi, Dhaka, Dhaka, Bangladesh | Phone: +880 1700-000000 | Official Support Email: support@bitzza.pizza