1. Introduction
Allen Halal Meat (“we,” “us,” “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains what information we collect, how we use it, with whom we share it, and what rights you have regarding your data when you use our website and online ordering platform (the “Service”).
By using the Service, you consent to the practices described in this policy. If you do not agree, please do not use the Service.
2. Information We Collect
Information you provide directly:
- Full name, email address, and phone number (at checkout or account registration)
- Delivery address and any delivery instructions
- Payment information (card number, expiration, CVC — processed and tokenised by Stripe; never stored on our servers)
- Order preferences, special requests, and dietary notes
- Communications you send us (support requests, feedback)
Information collected automatically:
- Device type, operating system, browser type and version
- IP address and approximate geolocation (city/region level)
- Pages visited, time spent, click patterns, and referral sources
- Cookies and similar tracking technologies (see Section 7)
3. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract performance: To process and deliver your orders, manage your account, and administer loyalty points
- Legitimate interest: To improve our Service, prevent fraud, enforce our terms, and conduct analytics
- Consent: To send marketing communications (you may withdraw consent at any time)
- Legal obligation: To comply with tax, accounting, and regulatory requirements
4. How We Use Your Information
- Process, fulfil, and deliver your orders
- Send transactional communications (order confirmations, status updates, receipts, delivery notifications)
- Provide customer support and resolve disputes
- Administer loyalty points, promotional offers, and gift cards
- Detect and prevent fraudulent activity and security threats
- Improve our platform, personalise your experience, and analyse usage patterns
- Send marketing communications (only with your opt-in consent)
- Comply with applicable legal and regulatory obligations
5. Information Sharing & Disclosure
We do not sell, rent, or trade your personal information. We share data only in the following circumstances:
- Payment processing: Stripe (PCI DSS Level 1 compliant) to authorise and process transactions
- Delivery partners: DoorDash Drive and/or Uber Direct — limited to name, phone, and delivery address necessary to complete delivery
- Communication services: Email (Nodemailer/SES) and SMS (Twilio) providers to send order updates
- Analytics: Google Analytics, Umami, or similar tools (data anonymised or pseudonymised where possible)
- Legal requirements: When required by law, subpoena, court order, or to protect our rights, property, or safety
- Business transfers: In connection with a merger, acquisition, or sale of assets (you will be notified of any change in ownership)
6. Data Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
- TLS/HTTPS encryption for all data in transit
- Encryption at rest for sensitive data stores
- PCI DSS-compliant payment processing (we never store full card numbers)
- Role-based access controls and audit logging
- Regular security assessments and monitoring
Despite these measures, no system is completely secure. We cannot guarantee absolute security of your data, and you use the Service at your own risk.
7. Cookies & Tracking Technologies
- Essential cookies: Required for authentication, session management, cart persistence, and security. Cannot be disabled without breaking core functionality.
- Analytics cookies: Help us understand how visitors interact with the platform. Data is aggregated and does not personally identify you.
- Marketing cookies: Used only with your consent to measure ad effectiveness (e.g., Facebook Pixel, Google Ads).
You can manage cookie preferences through your browser settings. Disabling essential cookies may impair the functionality of the Service.
8. Data Retention
- Active accounts: Data retained for the duration of your account plus 30 days after deletion request
- Order records: Retained for 7 years to comply with tax and accounting requirements
- Marketing data: Deleted within 30 days of unsubscribing
- Analytics data: Anonymised after 26 months
- Guest checkout data: Retained for order fulfilment and support purposes for 12 months
9. Your Rights
Depending on your jurisdiction, you may have the following rights under applicable data protection laws (including GDPR, CCPA/CPRA, and similar regulations):
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your data (“right to be forgotten”), subject to legal retention requirements
- Restriction: Request that we limit processing of your data in certain circumstances
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interest or for direct marketing
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing
- Non-discrimination: We will not discriminate against you for exercising your privacy rights (CCPA)
To exercise any of these rights, contact us at the details below. We will respond within 30 days (or as required by applicable law). We may request identity verification before processing your request.
10. International Data Transfers
Your data may be processed in countries other than your country of residence, including the United States. Where transfers occur outside your jurisdiction, we ensure appropriate safeguards are in place, including Standard Contractual Clauses or reliance on the recipient's certification under applicable frameworks.
11. Children's Privacy
The Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, please contact us immediately.
12. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those third parties. We encourage you to review their privacy policies before providing any personal information.
13. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email (if you have an account) or a prominent notice on the Service. The “Effective date” at the top indicates the latest revision. Continued use after changes are posted constitutes acceptance.
14. Governing Law
This Privacy Policy is governed by the laws of the State of TX. For EU/EEA residents, the General Data Protection Regulation (GDPR) applies. For California residents, the California Consumer Privacy Act (CCPA/CPRA) applies.
15. Contact & Data Protection Officer
For privacy inquiries, data access requests, or complaints, please contact:
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.