1. Scope and accountability
This policy applies to personal information under MKTrio's control when you visit mktrio.ca, contact us, administer an MKTrio service, use an MKTrio point-of-sale or online-ordering product, or interact with an optional delivery integration configured for a business customer.
When we process information for a restaurant or another business customer, that business may make the primary decisions about the information and may have its own privacy notice. MKTrio remains responsible for protecting the information in our custody and for requiring appropriate protection from service providers acting for us.
2. Information we collect
The information we handle depends on the service and may include:
- business and account information, such as names, business contact details, roles, locations, and authentication records;
- store, menu, order, transaction, tax, tip, discount, payment-status, fulfillment, and refund records;
- delivery information, such as pickup and drop-off names, telephone numbers, addresses, instructions, order references, courier status, and proof-of-delivery events;
- support messages and other communications you send to MKTrio;
- technical and security information, such as IP address, browser or device details, request timestamps, diagnostic logs, and webhook or integration events.
Payment cards are processed by the applicable payment provider or terminal provider. MKTrio services may retain transaction identifiers, amounts, status, and reconciliation records, but our integrations are not designed to store full card numbers or card security codes.
3. How we use information
We use information for identified business purposes, including to:
- operate, authenticate, support, and secure our website and services;
- receive, create, route, fulfill, update, reconcile, cancel, and refund orders and deliveries;
- show accurate App Orders, kitchen, courier, payment, and delivery status information;
- maintain financial and operational records, investigate exceptions, prevent fraud, and meet legal obligations;
- monitor reliability, troubleshoot incidents, and improve services using aggregated or de-identified information where practical.
We limit collection, use, and disclosure to purposes a reasonable person would consider appropriate in the circumstances.
4. Uber Eats and Uber Direct
If a business customer activates an Uber Eats Marketplace integration, Uber may provide MKTrio and the applicable restaurant with store, menu, order, item, modifier, pricing, tax, tip, discount, customer instruction, and fulfillment information. We would use it to create and manage the corresponding restaurant order and to send authorized fulfillment updates back to Uber.
If a business customer activates Uber Direct, MKTrio may send Uber the information needed to quote and perform a delivery, including pickup and drop-off contacts, telephone numbers, addresses, delivery instructions, order references, and package details. Uber may then send delivery, courier, cancellation, and refund-related events to our secured integration endpoint.
Uber handles information under its own privacy notices and terms. Restaurants and other MKTrio customers must only submit information they are authorized to use for the requested order or delivery.
6. Appointment text messages
When you book an appointment, we collect the mobile number you provide, your SMS consent choice, and records needed to deliver and support appointment messages. If you separately and optionally opt in, MKTrio and the business where you booked may send transactional texts about that appointment, including confirmations, reminders, schedule changes, and cancellations. A verification code is sent only when you request one by selecting Send Code and is not treated as consent to recurring appointment texts.
Twilio acts as our communications processor to transmit verification and appointment messages. Consent to appointment texts is optional and is not a condition of purchase. Message frequency varies and message and data rates may apply. Reply STOP to opt out or HELP for help. See our SMS Terms for program details.
We retain the mobile number, consent record, delivery events, and related appointment records only as long as reasonably needed to operate the booking service, document consent and opt-out status, resolve delivery or support issues, meet contractual commitments, and satisfy legal requirements. Mobile information, opt-in data, and consent are not sold or shared with third parties or affiliates for marketing or promotional purposes.
7. Retention and disposal
We keep information only as long as reasonably necessary for the identified purpose, contractual commitments, financial reconciliation, security, dispute resolution, and legal or regulatory requirements. Retention periods vary by record type and customer configuration. When information is no longer required, we delete it, anonymize it, or securely isolate it for deletion through controlled backup cycles.
8. Safeguards
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information. These include access controls, encrypted network transport, protected credential storage, signed webhook validation, tenant routing controls, audit records, monitoring, backups, and incident-response procedures. No system is completely secure, and we continuously review safeguards as our services evolve.
9. Consent, choices, and access
Where consent is the appropriate basis, you may withdraw it subject to legal and contractual restrictions and reasonable notice. Withdrawal may prevent us or the applicable business from providing an order, delivery, or other requested service.
You may ask to access or correct personal information under MKTrio's control, or raise a privacy concern, by contacting us. We may need to verify your identity and may direct requests about a restaurant-controlled record to that restaurant. Applicable law may permit or require limits on access, correction, or deletion.
10. Contact us
Contact MKTrio's privacy team at info@mktrio.ca. Please describe the service, business, and transaction involved without emailing passwords, full payment-card details, or other unnecessary sensitive information.
You may also learn about Canadian private-sector privacy rights from the Office of the Privacy Commissioner of Canada.
11. Updates to this policy
We may update this policy when our services, providers, or legal obligations change. We will post the revised version here and change the effective date. We will provide additional notice when a material change requires it.