Effective Date
This Privacy Policy is effective as of March 28, 2026.
1. About This App
Tacos Pasiados is a mobile loyalty and ordering app for Tacos Pasiados restaurant customers. It allows customers to earn points, redeem rewards, browse the menu, and receive order status updates via push notifications.
This app is operated by Tacos Pasiados. If you have questions about this policy, contact us at [email protected].
2. Information We Collect
We collect only the information necessary to provide the app's core features:
- Email address — collected when you sign up or sign in with email/password or Google Sign-In, via Firebase Authentication.
- Phone number — collected if you choose to sign in using SMS verification, via Firebase Authentication.
- Device token (FCM token) — a unique identifier provided by your device's operating system to deliver push notifications. This token does not identify you personally.
- Order history and loyalty points balance — records of the orders you have placed and the points you have earned or redeemed, stored in our database (Firebase Firestore).
- QR code identifier — a unique identifier linked to your account used for in-store loyalty scanning.
3. Information We Do NOT Collect
- No location or GPS data
- No camera or microphone access from customers
- No advertising identifiers
- No analytics or crash reporting data
- No third-party advertising or tracking SDKs
- No biometric data
4. How We Use Your Information
- Authentication: Your email or phone number is used to identify your account and allow secure sign-in.
- Loyalty program: Your order history and points balance are used to track and display your earned rewards.
- Push notifications: Your FCM token is used to send you order status updates (e.g., "Your order is ready"). You can disable notifications at any time in your device settings.
- In-store scanning: Your QR code identifier is used by restaurant staff to look up your account during in-store visits.
5. Third-Party Services
This app uses Firebase, a platform provided by Google LLC, for the following services:
- Firebase Authentication — manages sign-in with email/password, Google, Apple, and phone number.
- Cloud Firestore — stores your order history, points balance, and QR code identifier.
- Firebase Storage — stores menu item photos uploaded by restaurant staff. Customers do not upload content.
- Firebase Cloud Messaging (FCM) — delivers push notifications to your device.
Firebase is governed by Google's Privacy Policy: https://policies.google.com/privacy
We do not use any other third-party analytics, advertising, or data-sharing services.
6. Data Security
All data transmitted between the app and Firebase is encrypted in transit using TLS (Transport Layer Security). Firebase provides server-side encryption at rest. We use Firebase Security Rules to enforce that users can only access their own data.
7. Data Retention and Deletion
Your account data is retained for as long as your account is active. You may delete your account at any time using the in-app account deletion feature (accessible from your profile settings). Upon deletion, your authentication record, order history, points balance, QR code identifier, and device tokens are removed from our systems.
8. Children's Privacy
This app is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us at [email protected] and we will delete it promptly.
9. Your Rights
Depending on your location, you may have rights under applicable privacy laws, including the right to access, correct, or delete your personal information. To exercise these rights, contact us at [email protected].
You can also revoke notification permissions at any time through your device's system settings.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the Effective Date at the top of this page. Continued use of the app after any changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us at:
- Email: [email protected]