Privacy Policy
This Privacy Policy describes how Costa Vida ("we," "us," "our," or "the Company") collects, uses, discloses, and protects the personal information of individuals ("you," "your," or "user") who visit our website at foodcostavida.click, place orders, interact with our services, or otherwise engage with us. We are committed to protecting your privacy and handling your personal information in a transparent, lawful, and responsible manner.
Please read this Privacy Policy carefully before using our website or providing any personal information to us. By accessing or using our website, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree with the terms described herein, please discontinue use of our website and services immediately.
This Privacy Policy applies to all personal information collected through our website (foodcostavida.click), mobile applications, in-store interactions, online ordering platforms, loyalty programs, marketing communications, and any other touchpoints where you interact with Costa Vida.
1. About Us
Costa Vida is a food service business operating in the United States. We are dedicated to providing fresh, high-quality food experiences to our customers. For all privacy-related inquiries, you may contact us using the information below:
- Company Name: Costa Vida
- Email: [email protected]
- Website: foodcostavida.click
2. Scope and Applicable Law
Costa Vida operates in the United States and complies with all applicable federal and state privacy laws, including but not limited to:
- The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) — applicable to California residents.
- The Federal Trade Commission Act (FTC Act) — governing unfair or deceptive practices in commerce, including data privacy and security.
- The Children's Online Privacy Protection Act (COPPA) — governing the collection of personal information from children under 13 years of age.
- CAN-SPAM Act — governing commercial email communications.
- Other applicable state privacy laws, including but not limited to those in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Texas (TDPSA), where applicable.
To the extent that our services are accessed by individuals in other states or jurisdictions, we endeavor to comply with all applicable local privacy requirements.
3. Information We Collect
We collect various categories of personal information depending on how you interact with Costa Vida. The categories below describe the types of information we may collect from you directly, automatically, or from third parties.
3.1 Personal Information You Provide to Us
When you interact with our website, create an account, place an order, join our loyalty program, or contact us, you may voluntarily provide the following personal information:
| Category | Examples |
|---|---|
| Identifiers | Full name, username, email address, phone number, postal address, date of birth |
| Account Information | Login credentials, loyalty program membership details, account preferences |
| Payment Information | Credit/debit card details (processed securely through third-party processors), billing address |
| Order Information | Food order history, dietary preferences, special instructions, delivery addresses |
| Communications | Messages, feedback, reviews, customer support inquiries, survey responses |
| Marketing Preferences | Email subscription status, promotional preferences, opt-in/opt-out choices |
3.2 Information Collected Automatically
When you visit our website or use our digital platforms, we and our third-party service providers may automatically collect certain technical and usage data, including:
- Device Information: Device type, operating system, browser type and version, screen resolution, device identifiers, and mobile network information.
- Log Data: IP address, access times and dates, pages viewed, referring URLs, and error logs.
- Usage Data: Clickstream data, navigation patterns, time spent on pages, search queries, and interactions with website elements.
- Location Data: General geographic location derived from your IP address; precise location data only if you grant explicit permission through your device settings.
- Cookie and Tracking Data: Data collected through cookies, web beacons, pixel tags, local storage, and similar technologies. See Section 8 for more information.
3.3 Information from Third Parties
We may receive personal information about you from third parties, including:
- Social Media Platforms: If you choose to log in or interact with us through social media platforms such as Facebook, Instagram, or Google, we may receive certain profile information as permitted by your privacy settings on those platforms.
- Delivery Partners: Third-party delivery services (such as DoorDash, Uber Eats, or Grubhub) may share order and contact information with us to facilitate your food delivery.
- Analytics Providers: Third-party analytics tools provide aggregated and anonymized insights about website usage and user demographics.
- Marketing Partners: Advertising networks and marketing partners may provide data to help us reach relevant audiences.
- Payment Processors: Payment processors may share transaction confirmation data with us to verify and fulfill your orders.
4. How We Use Your Information
Costa Vida uses the personal information we collect for a variety of lawful business purposes. The primary purposes for which we process your data include:
4.1 Service Provision and Order Fulfillment
- Processing and fulfilling your food orders, whether placed online, through our app, or in-store.
- Creating and managing your account and loyalty program membership.
- Processing payments and preventing fraudulent transactions.
- Arranging delivery or facilitating pick-up of your orders.
- Providing customer support and responding to your inquiries or complaints.
- Sending you order confirmations, receipts, and transactional communications.
4.2 Website Operations and Improvements
- Operating, maintaining, and improving our website and digital platforms.
- Monitoring and analyzing website traffic, usage patterns, and performance metrics.
- Troubleshooting technical issues and ensuring the security of our systems.
- Personalizing your website experience based on your preferences and order history.
- Testing new features, products, and menu offerings.
4.3 Marketing and Communications
- Sending you promotional emails, newsletters, special offers, and information about new menu items — where you have opted in or where permitted by law.
- Displaying targeted advertisements on our website and third-party platforms based on your interests and browsing behavior.
- Conducting loyalty program promotions, contests, and sweepstakes.
- Requesting reviews, ratings, and feedback about your experience.
- Sending SMS or push notifications about orders and promotions (where you have consented).
4.4 Analytics and Research
- Conducting market research, customer satisfaction surveys, and business analytics.
- Analyzing purchasing patterns to improve our menu, pricing, and service offerings.
- Creating aggregated, anonymized reports for business intelligence purposes.
4.5 Legal and Compliance Purposes
- Complying with applicable federal, state, and local laws and regulations.
- Responding to legal processes, court orders, government requests, or regulatory inquiries.
- Enforcing our Terms of Service and other legal agreements.
- Protecting the rights, property, and safety of Costa Vida, our customers, and the public.
- Preventing, detecting, and investigating fraud, security breaches, and other prohibited activities.
5. How We Share Your Information
Costa Vida does not sell your personal information to third parties for monetary compensation. However, we may share your personal information in the following circumstances:
5.1 Service Providers
We engage trusted third-party service providers who process personal information on our behalf to help us operate our business. These providers are contractually obligated to use your information only for the purposes we specify and to maintain appropriate security measures. Service providers include:
- Payment Processors: Companies that securely process credit/debit card transactions and other payments.
- Delivery Partners: Third-party delivery services that fulfill delivery orders on our behalf.
- IT and Cloud Services: Hosting providers, database management companies, and cybersecurity firms.
- Email and Communication Platforms: Email service providers used for transactional and marketing communications.
- Analytics Providers: Tools such as Google Analytics that help us understand website usage.
- Marketing and Advertising Platforms: Services that help us deliver targeted advertisements and promotional campaigns.
- Customer Support Tools: Platforms that help us manage customer inquiries and support tickets.
- Loyalty Program Administrators: Providers that manage our rewards and loyalty programs.
5.2 Business Transfers
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal information may be transferred to the acquiring entity as part of the business transaction. We will notify you via email or prominent notice on our website if such a transfer occurs and will inform you of any changes to this Privacy Policy that may result from the transaction.
5.3 Legal Requirements and Law Enforcement
We may disclose your personal information to governmental authorities, law enforcement agencies, or other parties when we believe in good faith that such disclosure is required or permitted by law, including to:
- Comply with a legal obligation, subpoena, court order, or other legal process.
- Protect and defend the rights or property of Costa Vida.
- Prevent or investigate possible wrongdoing in connection with our services.
- Protect the personal safety of users of our services or the public.
5.4 With Your Consent
We may share your personal information with third parties for purposes not described in this Privacy Policy when we have obtained your explicit consent to do so.
5.5 Aggregated and Anonymized Data
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you with third parties for research, analytics, marketing, and other lawful purposes.
6. Data Security
Costa Vida takes the security of your personal information seriously. We implement a comprehensive set of technical, administrative, and physical safeguards designed to protect your information from unauthorized access, disclosure, alteration, destruction, or misuse.
6.1 Security Measures We Employ
- Encryption: We use Secure Socket Layer (SSL)/Transport Layer Security (TLS) encryption for data transmitted between your browser and our servers. Sensitive payment information is encrypted using industry-standard protocols.
- Access Controls: Access to personal information is restricted to authorized personnel on a need-to-know basis. All employees with access to personal data are required to maintain its confidentiality.
- Secure Password Storage: User passwords are hashed using strong cryptographic algorithms and are never stored in plaintext.
- Regular Security Audits: We conduct periodic security assessments, vulnerability scans, and penetration testing to identify and address potential risks.
- Payment Card Industry (PCI DSS) Compliance: Our payment processing systems adhere to PCI DSS standards to protect your financial information.
- Incident Response Plan: We maintain a documented data breach response plan to ensure prompt action in the event of a security incident.
- Employee Training: Our staff receives regular training on data privacy and cybersecurity best practices.
6.2 Limitations of Security
While we make every reasonable effort to protect your personal information, no method of transmission over the Internet or electronic storage is completely secure. Therefore, we cannot guarantee absolute security. If you become aware of any unauthorized use of your account or any security vulnerability, please contact us immediately at [email protected].
7. Your Privacy Rights
Depending on your state of residence within the United States, you may have certain rights with respect to your personal information. Costa Vida is committed to honoring these rights to the fullest extent required by law.
7.1 Rights for California Residents (CCPA/CPRA)
If you are a resident of California, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You have the right to request that we delete the personal information we have collected from you, subject to certain exceptions permitted by law (e.g., completing transactions, security purposes).
- Right to Correct: You have the right to request correction of inaccurate personal information that we maintain about you.
- Right to Opt-Out of Sale/Sharing: You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising purposes. To exercise this right, contact us at [email protected].
- Right to Limit Use of Sensitive Personal Information: You have the right to limit our use and disclosure of sensitive personal information to what is necessary to perform the services you request.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA/CPRA rights. We will not deny you goods or services, charge you different prices, or provide a different quality of service solely because you exercised your privacy rights.
7.2 Rights Under Other State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Texas, and other states with applicable privacy laws may also have rights including:
- Right of Access: The right to confirm whether we process your personal data and to access that data.
- Right to Correction: The right to request correction of inaccurate personal data.
- Right to Deletion: The right to request deletion of personal data provided by or obtained about you.
- Right to Data Portability: The right to receive a copy of your personal data in a portable, machine-readable format.
- Right to Opt-Out: The right to opt out of the processing of personal data for purposes of targeted advertising, the sale of personal data, or profiling for decisions with significant effects.
- Right to Appeal: If we deny your privacy request, you have the right to appeal our decision. We will review your appeal and provide a written response within the timeframe required by applicable law.
7.3 How to Exercise Your Rights
To exercise any of your privacy rights, please submit a verifiable request to us through one of the following methods:
- Email: [email protected]
- Website: foodcostavida.click
To process your request, we may need to verify your identity to ensure that we are disclosing or deleting the information of the correct individual. We may ask you to provide information such as your name, email address, and other details associated with your account. We will respond to verifiable consumer requests within 45 days of receipt, with the possibility of a 45-day extension where reasonably necessary, as permitted by applicable law.
You may designate an authorized agent to submit requests on your behalf. If you choose to use an authorized agent, we may require written proof of the agent's authority to act on your behalf and verification of your own identity.
8. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and deliver personalized content and advertisements. This section provides a summary of our cookie practices.
8.1 Types of Cookies We Use
| Cookie Type | Purpose |
|---|---|
| Strictly Necessary | Essential for the operation of our website, including enabling you to log in, add items to your cart, and place orders. |
| Performance/Analytics | Collect information about how visitors use our website (e.g., pages visited, errors encountered) to help us improve performance. |
| Functionality | Remember your preferences and choices (e.g., language, location, dietary preferences) to provide a more personalized experience. |
| Targeting/Advertising | Track your browsing habits to deliver relevant advertisements both on and off our website. |
| Social Media | Enable sharing of our content on social media platforms and allow us to understand social media-driven traffic. |
8.2 Managing Cookie Preferences
You can manage or disable cookies through your browser settings. Most web browsers allow you to refuse cookies, delete existing cookies, or receive notifications when a cookie is set. Please note that disabling certain cookies may affect the functionality of our website and your ability to use certain features.
You may also opt out of interest-based advertising by visiting:
- Digital Advertising Alliance (DAA) Opt-Out
- Network Advertising Initiative (NAI) Opt-Out
- Google Ads Settings
For more detailed information about the cookies we use and your choices, please refer to our full Cookie Policy available on our website at foodcostavida.click.
9. Data Retention
Costa Vida retains your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, enforce our agreements, and support our legitimate business operations.
9.1 General Retention Periods
| Data Category | Retention Period |
|---|---|
| Account Information | Duration of account existence, plus up to 3 years after account closure |
| Order and Transaction Records | Up to 7 years for financial and tax compliance purposes |
| Marketing Communication Records | Up to 3 years from last interaction or opt-out date |
| Customer Support Communications | Up to 3 years from date of resolution |
| Website Usage and Analytics Data | Up to 2 years (typically anonymized or aggregated after 13 months) |
| Cookie Data | Varies by cookie type (session cookies expire when browser is closed; persistent cookies may last from 30 days to 2 years) |
| Legal and Compliance Records | As required by applicable law, typically 5–10 years |
When personal information is no longer required, we will securely delete, destroy, or anonymize it in accordance with our data retention and disposal policies. If you submit a deletion request, we will delete your information within the timeframes specified by applicable law, subject to any legal retention requirements.
10. Children's Privacy
Costa Vida complies with the Children's Online Privacy Protection Act (COPPA). If you are under 13 years of age, please do not use our website, create an account, or submit any personal information to us. If you are a parent or guardian and believe that your child under the age of 13 has provided personal information to us without your consent, please contact us immediately at [email protected]. We will take prompt steps to delete such information from our records.
Individuals between the ages of 13 and 17 may use our website only under the supervision of a parent or legal guardian who agrees to be bound by this Privacy Policy. The parent or guardian accepts responsibility for ensuring that the minor's use of our services complies with this policy.
We do not knowingly sell, share, or disclose the personal information of consumers under 16 years of age without affirmative authorization as required by California law and other applicable state laws governing minors' privacy rights.
11. International Data Transfers
Costa Vida is headquartered in the United States, and your personal information is primarily stored and processed in the United States. If you are accessing our services from outside the United States, please be aware that your personal information will be transferred to, processed, and stored in the United States, where data protection laws may differ from those in your home country.
By using our services and providing your personal information, you acknowledge and consent to the transfer of your information to the United States. We take steps to ensure that any international transfers of personal data are conducted in accordance with applicable law and that appropriate safeguards are in place to protect your information, including:
- Contractual protections (standard contractual clauses or data processing agreements) with third-party service providers located outside the United States.
- Ensuring that any international service providers maintain security standards equivalent to or exceeding those described in this Privacy Policy.
- Implementing technical measures to secure data during transmission.
If you have questions about international data transfers or the safeguards we have in place, please contact us at [email protected].
12. Third-Party Links and Platforms
Our website may contain links to third-party websites, applications, or services that are not owned or controlled by Costa Vida, including social media platforms, delivery partner websites, and payment gateway portals. This Privacy Policy applies solely to information collected by Costa Vida through our own website and services.
We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any third-party websites or services before providing them with your personal information. The inclusion of a link to a third-party website does not constitute our endorsement of that website or its privacy practices.
13. Do Not Track Signals
Some web browsers include a "Do Not Track" (DNT) feature that sends a signal to websites requesting that your browsing not be tracked. Currently, there is no universally agreed-upon standard for how websites should respond to DNT signals. Our website does not currently respond to DNT browser signals. However, you may manage your tracking preferences through your browser settings and by using the opt-out mechanisms described in the Cookie section of this Privacy Policy.
California residents may be entitled to know whether we honor DNT signals. In compliance with California's "Shine the Light" law (California Civil Code Section 1798.83), we disclose that we do not currently modify our data collection practices in response to DNT signals but provide alternative means of managing your privacy preferences as outlined in this policy.
14. How to File a Privacy Complaint
If you have concerns about how Costa Vida handles your personal information or if you believe that your privacy rights have been violated, we encourage you to contact us first so that we may attempt to resolve your concern.
14.1 Internal Complaint Process
- Submit your complaint in writing to: [email protected]
- Include your name, contact information, and a detailed description of your concern.
- We will acknowledge receipt of your complaint within 5 business days and will provide a substantive response within 30 days of receipt.
- If we are unable to resolve your concern to your satisfaction within 45 days, you will receive a written explanation of our decision and information on your right to escalate the complaint.
14.2 Complaints to Regulatory Authorities
You also have the right to file a complaint with applicable regulatory authorities. The relevant authorities depending on your state of residence include:
| State / Federal Authority | Contact Information |
|---|---|
| Federal Trade Commission (FTC) | reportfraud.ftc.gov | 1-877-382-4357 |
| California Privacy Protection Agency (CPPA) | cppa.ca.gov |
| California Attorney General | oag.ca.gov/privacy |
| Virginia Attorney General | oag.state.va.us |
| Colorado Attorney General | coag.gov |
We strongly encourage you to contact us directly first. However, you are always free to contact your state's Attorney General or any relevant federal or state data protection authority at any time.
15. Changes to This Privacy Policy
Costa Vida reserves the right to update or modify this Privacy Policy at any time to reflect changes in our business practices, applicable laws, or technology. When we make material changes, we will:
- Post the updated Privacy Policy on our website at foodcostavida.click with a new "Last Updated" date.
- Notify you via email (if you have provided your email address) or through a prominent notice on our website prior to the changes taking effect, where required by law.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our website and services after any changes to this Privacy Policy constitutes your acceptance of those changes.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please do not hesitate to contact us:
Costa Vida — Privacy Inquiries
- Email: [email protected]
- Website: foodcostavida.click
- Effective Date: June 4, 2026
We are committed to working with you to resolve any privacy concerns you may have. Our team will make every effort to respond to your inquiries promptly and to handle your personal information with the utmost care and respect.