Privacy Policy

Effective Date: July 2, 2026  |  Last Updated: July 2, 2026

1. Introduction and Who We Are

Welcome to Costa Vida. We are a food service business operating in the United States, committed to providing our customers with high-quality food products and an exceptional dining experience. We deeply respect your privacy and are dedicated to protecting the personal information you share with us.

This Privacy Policy applies to all personal information collected through our website costavidago.click, our online ordering systems, in-store interactions, mobile platforms, marketing communications, and any other services we provide (collectively referred to as our "Services").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to the collection and use of your information as described in this Privacy Policy. If you do not agree with the terms outlined here, please discontinue use of our Services immediately.

Contact Information:

2. Scope and Applicability

This Privacy Policy governs our data collection and processing activities in accordance with applicable United States federal and state privacy laws, including but not limited to:

  • The Federal Trade Commission Act (FTC Act) – governing unfair or deceptive practices related to consumer data
  • The California Consumer Privacy Act (CCPA) and its amendment, the California Privacy Rights Act (CPRA), for California residents
  • The Children's Online Privacy Protection Act (COPPA)
  • The CAN-SPAM Act for email marketing communications
  • The Electronic Communications Privacy Act (ECPA)
  • Other applicable state and federal consumer protection laws

If you are a resident of California, please pay particular attention to Section 12 of this policy, which contains specific disclosures and rights afforded to you under the CCPA/CPRA.

3. Information We Collect

We collect various types of information in connection with our Services. The categories of information we may collect include the following:

3.1 Personal Identification Information

When you create an account, place an order, sign up for our loyalty program, or contact us, we may collect:

  • Full name
  • Email address
  • Phone number
  • Mailing or delivery address
  • Date of birth (for birthday rewards and age verification)
  • Username and password for account access
  • Profile photo or avatar (if provided)

3.2 Payment and Financial Information

When you make a purchase through our Services, we collect payment-related information. Note that we do not store full credit card numbers or sensitive payment data directly. Transactions are processed through secure, PCI-DSS compliant third-party payment processors. We may collect:

  • Last four digits of credit or debit card numbers
  • Billing address
  • Transaction ID and order history
  • Gift card or voucher information

3.3 Order and Transaction Data

In connection with your food orders and purchases, we collect:

  • Items ordered, customizations, and dietary preferences
  • Order date, time, and location
  • Order frequency and purchase history
  • Delivery instructions and special requests
  • Feedback and ratings submitted after an order

3.4 Usage and Behavioral Data

When you interact with our website or digital platforms, we automatically collect:

  • Pages visited, time spent on each page, and navigation paths
  • Search queries made on our website
  • Links clicked and buttons interacted with
  • Referral URLs (the website you came from before visiting ours)
  • Frequency and duration of visits
  • Abandonment data (e.g., items added to cart but not purchased)

3.5 Device and Technical Information

We automatically collect technical data about the devices you use to access our Services, including:

  • IP address
  • Browser type and version
  • Operating system and device type
  • Screen resolution and display settings
  • Device identifiers and advertising IDs
  • Time zone and language settings
  • Mobile network information

3.6 Location Information

With your permission, we may collect precise geolocation data to help you find the nearest Costa Vida location, facilitate delivery services, or offer location-specific promotions. You can disable location tracking in your device settings at any time.

3.7 Communications and Customer Support Data

When you contact us for customer support, provide feedback, or communicate with us through any channel, we collect:

  • The content of your messages, emails, or chat conversations
  • Support ticket details and resolution history
  • Survey responses and reviews
  • Social media interactions if you contact us through social platforms

3.8 Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your online behavior. For a detailed explanation of our cookie practices, please refer to Section 10 of this policy.

3.9 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Social media platforms if you connect your account or interact with our social media pages
  • Third-party delivery platforms (such as DoorDash, Uber Eats, or Grubhub)
  • Marketing and analytics partners
  • Publicly available sources

4. How We Use Your Information

We use the personal information we collect for the following purposes:

4.1 Providing and Managing Our Services

  • Processing and fulfilling your food orders and transactions
  • Creating and managing your customer account
  • Facilitating delivery or in-store pickup orders
  • Administering our loyalty rewards program
  • Responding to customer service inquiries and resolving disputes
  • Sending order confirmations, receipts, and status updates

4.2 Analytics and Service Improvement

  • Analyzing usage patterns to improve website functionality and user experience
  • Conducting internal research and business analytics
  • Identifying popular menu items and optimizing our food offerings
  • Testing new features and website improvements
  • Generating aggregated and anonymized statistical reports

4.3 Marketing and Promotional Communications

  • Sending promotional emails, newsletters, and special offers (with your consent where required)
  • Delivering targeted advertisements based on your preferences and browsing behavior
  • Notifying you about new menu items, seasonal promotions, and events
  • Personalizing your experience with tailored content and recommendations
  • Administering contests, sweepstakes, and promotional campaigns

You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at [email protected].

4.4 Legal Compliance and Security

  • Complying with applicable laws, regulations, and legal obligations
  • Detecting, preventing, and investigating fraud, unauthorized access, and other illegal activities
  • Enforcing our Terms of Service and other policies
  • Protecting the rights, property, and safety of Costa Vida, our customers, and the public
  • Responding to lawful requests from government authorities or law enforcement

4.5 Business Operations

  • Managing and improving our internal operations
  • Evaluating and executing business transactions such as mergers or acquisitions
  • Training staff and improving customer service standards
  • Auditing and verifying our business activities

5. How We Share Your Information

We do not sell your personal information to third parties for monetary compensation. However, we may share your information in the following circumstances:

5.1 Service Providers and Business Partners

We work with trusted third-party service providers who assist us in operating our business and delivering our Services. These providers may have access to your personal information only to the extent necessary to perform their functions and are contractually obligated to maintain confidentiality. Categories of service providers include:

  • Payment processors – to securely handle financial transactions
  • Delivery and logistics partners – to fulfill your food delivery orders
  • Email and SMS marketing platforms – to send promotional communications
  • Analytics providers – to help us understand how customers use our Services
  • Cloud hosting and IT infrastructure providers – to store and manage our data securely
  • Customer support platforms – to manage service inquiries
  • Loyalty program administrators – to manage rewards and incentives

5.2 Legal Requirements and Law Enforcement

We may disclose your personal information if required to do so by law or in response to valid legal process, including:

  • Compliance with court orders, subpoenas, or legal proceedings
  • Requests from law enforcement or government agencies
  • Situations where disclosure is necessary to prevent harm, fraud, or illegal activity
  • Enforcement of our legal rights and agreements

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website if such a transfer occurs and your data will be subject to any commitments made in this Privacy Policy.

5.4 With Your Consent

We may share your information with third parties when you have provided explicit consent for us to do so, such as when you participate in co-branded promotions or partner programs.

5.5 Aggregated or Anonymized Data

We may share aggregated or anonymized data that does not identify you personally with third parties for industry research, marketing analysis, and similar purposes.

6. Data Security

We take the security of your personal information seriously and have implemented a range of technical, administrative, and physical safeguards designed to protect your data from unauthorized access, disclosure, alteration, or destruction.

6.1 Security Measures We Employ

  • SSL/TLS Encryption: All data transmitted between your browser and our website is encrypted using Secure Socket Layer (SSL) or Transport Layer Security (TLS) protocols.
  • Access Controls: We restrict access to personal information to authorized employees and contractors who need it to perform their job functions.
  • Secure Data Storage: Personal data is stored on secure servers with appropriate access controls and firewalls.
  • PCI-DSS Compliance: Our payment processing systems comply with Payment Card Industry Data Security Standards.
  • Regular Security Audits: We conduct regular assessments of our security practices and vulnerability testing.
  • Employee Training: Our staff receives training on data privacy and security best practices.
  • Incident Response Plan: We maintain a documented data breach response plan to address security incidents promptly.

6.2 Your Responsibility

While we strive to protect your personal information, no method of data transmission or storage over the internet is completely secure. You are responsible for maintaining the confidentiality of your account credentials and for any activities that occur under your account. Please notify us immediately at [email protected] if you suspect any unauthorized use of your account.

7. Your Privacy Rights

Depending on your location and applicable laws, you may have the following rights regarding your personal information:

7.1 Right to Access

You have the right to request a copy of the personal information we hold about you, including information about how we use and share it. We will provide this information free of charge within 45 days of a verifiable request.

7.2 Right to Correction

You have the right to request that we correct any inaccurate or incomplete personal information we maintain about you. You may also update your information directly through your account settings on our website.

7.3 Right to Deletion

You have the right to request that we delete your personal information, subject to certain exceptions permitted by law. We may retain certain information as required by legal obligations, to complete transactions you have initiated, or to prevent fraud.

7.4 Right to Data Portability

You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format, and to have that data transmitted to another party where technically feasible.

7.5 Right to Opt Out of Marketing

You have the right to opt out of receiving marketing communications from us at any time. You can do this by:

  • Clicking the "unsubscribe" or "opt-out" link in any marketing email
  • Texting "STOP" in response to marketing SMS messages
  • Contacting us directly at [email protected]
  • Updating your communication preferences in your account settings

7.6 Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights. You will not receive different levels of service, be charged different prices, or be denied goods or services as a result of exercising your privacy rights.

7.7 How to Submit a Privacy Request

To exercise any of your privacy rights, you may contact us by:

We will verify your identity before processing your request to protect the security of your personal information. We aim to respond to all verifiable requests within 45 days. In some cases, we may need an additional 45 days to respond, in which case we will notify you of the extension.

8. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Our general retention guidelines are as follows:

Type of Data Retention Period
Account and profile information Duration of account plus 3 years after account closure
Order and transaction history 7 years (for tax and legal compliance purposes)
Payment processing records 7 years (as required by financial regulations)
Marketing preferences and communications 3 years from last interaction or opt-out
Customer support records 3 years from resolution of inquiry
Website analytics and usage data 26 months from collection
Cookie data As specified in our Cookie Policy (typically 13 months)
Legal compliance and fraud prevention data As required by applicable law or regulatory guidance

When your personal information is no longer needed for the purposes described, we will securely delete, anonymize, or aggregate it in accordance with our data retention procedures.

9. Children's Privacy

In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under the age of 13 without verifiable parental consent. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at [email protected].

Upon receiving notice that a child under 13 has submitted personal information to us without proper parental consent, we will promptly delete such information from our records. We encourage parents and guardians to actively supervise their children's online activities and to use parental control tools available through internet service providers.

If you are between the ages of 13 and 17, please obtain permission from your parent or legal guardian before using our Services and before submitting any personal information to us.

10. Cookie Policy Overview

We use cookies and similar tracking technologies on our website to enhance your browsing experience, analyze website traffic, and deliver personalized content and advertising. This section provides a brief overview of our cookie practices.

10.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the operation of our website, including enabling you to navigate the site and use features like the shopping cart. These cannot be disabled.
  • Performance and Analytics Cookies: Help us understand how visitors interact with our website by collecting and reporting information anonymously (e.g., Google Analytics).
  • Functionality Cookies: Allow our website to remember your preferences (such as language settings and saved addresses) to provide enhanced features.
  • Targeting and Advertising Cookies: Used to deliver advertisements relevant to you and your interests, and to measure the effectiveness of our advertising campaigns.

10.2 Managing Your Cookie Preferences

You can control and manage cookies through your browser settings. Most browsers allow you to refuse or accept cookies, delete existing cookies, and set preferences for certain websites. Please note that disabling certain cookies may impact the functionality of our website.

You may also opt out of interest-based advertising by visiting:

For more detailed information about the cookies we use, please contact us at [email protected].

11. International Data Transfers

Costa Vida is based in the United States, and your personal information will primarily be collected, stored, and processed within the United States. Our third-party service providers may also process your data in other countries.

If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored in, and processed in the United States or other countries where data protection laws may differ from those in your home country. By using our Services, you consent to the transfer of your information to the United States and to other countries as described in this Privacy Policy.

We take appropriate steps to ensure that any international transfers of personal information are conducted in compliance with applicable data protection laws and that appropriate safeguards are in place to protect your data.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), which became effective January 1, 2023.

12.1 Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information from California consumers:

  • Identifiers (name, email address, IP address, account username)
  • Commercial information (purchase history, order records)
  • Internet or electronic network activity information (browsing history, search history on our site)
  • Geolocation data (with your permission)
  • Inferences drawn from personal information (preferences, characteristics, behavior)
  • Sensitive personal information (financial account information, precise geolocation when enabled)

12.2 California Consumer Rights

As a California resident, you have the following rights:

  • Right to Know: The right to know what personal information we collect, use, disclose, and sell about you
  • Right to Delete: The right to request deletion of your personal information, subject to certain exceptions
  • Right to Correct: The right to request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: The right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: The right to limit our use and disclosure of sensitive personal information to specific purposes
  • Right to Non-Discrimination: The right not to be discriminated against for exercising your CCPA/CPRA rights

12.3 Submitting California Privacy Requests

California residents may submit privacy requests by contacting us at:

We will respond to verifiable consumer requests within 45 calendar days. You may designate an authorized agent to make requests on your behalf, provided they submit written proof of authorization.

13. Do Not Track Signals

Some web browsers offer a "Do Not Track" (DNT) feature that sends a signal to websites requesting that your browsing activity not be tracked. Currently, there is no universally accepted standard for how websites should respond to DNT signals. Our website does not currently respond to DNT signals, but we honor opt-out preferences as described in the cookie management and opt-out sections above.

14. Third-Party Links and Services

Our website may contain links to third-party websites, applications, or services that are not operated by Costa Vida. When you click on such links, you will be directed to those third-party sites. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

We encourage you to review the privacy policies of every website you visit. The inclusion of a link on our website does not imply our endorsement of the linked site or its privacy practices.

This applies to third-party food delivery platforms (such as DoorDash, Uber Eats, and Grubhub), social media platforms, and payment processors. These services have their own privacy policies, and your interactions with them are governed by those policies.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by:

  • Posting the updated Privacy Policy on our website at costavidago.click with a new effective date
  • Sending an email notification to the address associated with your account (for significant changes)
  • Displaying a prominent notice on our website homepage

Your continued use of our Services after the effective date of any updated Privacy Policy constitutes your acceptance of the revised policy. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

16. How to File a Complaint

If you have concerns about our privacy practices or believe that we have not handled your personal information in accordance with applicable law, you have the right to file a complaint with relevant authorities.

16.1 Contacting Us First

We encourage you to contact us first so we can address your concerns directly:

We will investigate your complaint and respond within a reasonable timeframe.

16.2 Filing a Complaint with Regulatory Authorities

If you are not satisfied with our response, you may file a complaint with the following authorities:

  • Federal Trade Commission (FTC): The FTC enforces federal consumer protection and privacy laws in the United States.
    Website: reportfraud.ftc.gov
    Phone: 1-877-382-4357
  • California Privacy Protection Agency (CPPA): For California residents, the CPPA enforces the CCPA/CPRA.
    Website: cppa.ca.gov
  • Your State Attorney General: Most U.S. states have an Attorney General's office that handles consumer privacy complaints. You may locate your state's Attorney General through the National Association of Attorneys General (NAAG).

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please do not hesitate to contact us:

Privacy Inquiries – Costa Vida

Company: Costa Vida
Email: [email protected]
Website: costavidago.click

We are committed to responding to all privacy-related inquiries within 30 business days. For urgent matters related to data security or suspected unauthorized access, please mark your email as "URGENT – Privacy Matter" for expedited handling.