Privacy Policy
This Privacy Policy describes how Costa Vida ("we," "us," "our," or "the Company") collects, uses, discloses, and protects your personal information when you visit our website at vidacostas.click, use our online ordering platform, sign up for our loyalty program, or otherwise interact with our food services and digital properties. We are committed to protecting your privacy and handling your personal data with transparency, integrity, and in full compliance with applicable United States privacy laws.
Please read this Privacy Policy carefully. By accessing or using our website or services, you acknowledge that you have read, understood, and agree to the practices described herein. If you do not agree with this policy, please discontinue use of our website and services immediately.
1. Who We Are
Costa Vida is a food service company operating through the website vidacostas.click. We provide fresh Mexican-inspired cuisine, online ordering services, catering options, and loyalty rewards programs to our customers across the United States.
Contact Information:
| Company Name | Costa Vida |
|---|---|
| Website | vidacostas.click |
| [email protected] |
For all privacy-related inquiries, requests, or complaints, you may contact our Privacy Team directly at [email protected].
2. Scope of This Policy
This Privacy Policy applies to:
- All visitors to our website at vidacostas.click
- Registered account holders and loyalty program members
- Customers who place online food orders through our platform
- Individuals who contact us via email, phone, or social media
- Catering inquiry submissions and event service customers
- Participants in surveys, promotions, contests, or marketing communications
This policy does not apply to third-party websites, platforms, or services that may be linked from our website. We encourage you to review the privacy policies of any third-party services you access.
3. Information We Collect
We collect various categories of personal information depending on how you interact with us. Below is a comprehensive breakdown of the data we may collect:
3.1 Personal Identification Information
- Full name – collected when you create an account, place an order, or submit a catering inquiry
- Email address – used for order confirmations, account management, and marketing communications
- Phone number – collected for order updates, delivery coordination, and customer support
- Mailing and billing address – required for delivery orders and payment processing
- Date of birth – collected optionally for loyalty program birthday rewards
- Username and password – for account creation and authentication purposes
3.2 Payment and Financial Information
- Credit card and debit card numbers (last four digits only, after tokenization)
- Billing address associated with payment methods
- Transaction history and purchase records
- Gift card balances and redemption history
3.3 Order and Transaction Data
- Food items ordered, customizations, and special dietary requests
- Order frequency, preferred locations, and ordering habits
- Delivery instructions and preferred pickup times
- Loyalty points earned and redeemed
- Promotional codes and discount usage history
3.4 Usage Data and Technical Information
When you visit our website, we automatically collect certain technical information through cookies and similar tracking technologies, including:
- IP address and approximate geographic location
- Browser type, version, and language settings
- Operating system and device type (desktop, mobile, tablet)
- Referring URLs – websites that directed you to our site
- Pages visited, time spent on pages, and navigation patterns
- Click-through rates and interaction data with menu items and promotions
- Search queries entered within our website
- Session duration and frequency of visits
3.5 Device Information
- Device identifiers (such as advertising IDs on mobile devices)
- Mobile device model and manufacturer
- Screen resolution and display settings
- Network provider and connection type
- App version information (if applicable)
3.6 Communications and Feedback
- Messages sent to us via contact forms or email
- Customer service chat transcripts
- Survey responses and feedback submissions
- Reviews and ratings you submit about our food or service
- Social media posts or mentions that tag or reference Costa Vida
3.7 Information Collected from Third Parties
We may also receive information about you from third-party sources, including:
- Social media platforms (if you connect your account or interact with our social pages)
- Third-party food delivery partners (such as DoorDash, Uber Eats, or Grubhub)
- Analytics providers and data enrichment services
- Advertising networks and marketing partners
4. How We Use Your Information
We use the personal information we collect for the following purposes, each grounded in a legitimate legal basis:
4.1 Providing and Managing Our Services
- Processing and fulfilling your food orders, both in-store and online
- Managing your customer account and loyalty program membership
- Sending order confirmations, receipts, and delivery status updates
- Coordinating catering services and event food orders
- Handling returns, refunds, and complaints effectively
- Providing customer support and responding to your inquiries
4.2 Marketing and Promotional Communications
- Sending newsletters, special offers, seasonal promotions, and new menu announcements
- Personalizing marketing messages based on your order history and food preferences
- Delivering birthday rewards and loyalty program benefits
- Conducting contests, sweepstakes, and promotional campaigns
- Retargeting advertisements on social media and partner websites
You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any of our emails or contacting us at [email protected]. Please note that even if you opt out of marketing emails, we will continue to send you transactional communications related to your orders and account.
4.3 Analytics and Service Improvement
- Analyzing website traffic patterns and customer behavior to improve site usability
- Understanding which menu items are most popular and optimizing our offerings accordingly
- Monitoring and improving the performance and security of our online platform
- Conducting market research and customer satisfaction studies
- Testing new features, website designs, and ordering experiences
4.4 Legal Compliance and Security
- Complying with applicable federal and state laws and regulations
- Detecting, investigating, and preventing fraudulent transactions and abuse
- Enforcing our Terms of Service and other agreements
- Responding to lawful requests from law enforcement and regulatory authorities
- Protecting the rights, property, and safety of Costa Vida, our customers, and the public
5. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site usage, and deliver personalized content and advertisements. Cookies are small text files placed on your device when you visit our website.
5.1 Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Required for the website to function properly; enable shopping cart, login sessions, and order processing | Session / Up to 1 year |
| Performance Cookies | Collect anonymous usage statistics to help us understand how visitors use our site (e.g., Google Analytics) | Up to 2 years |
| Functional Cookies | Remember your preferences such as location, language settings, and saved orders | Up to 1 year |
| Marketing Cookies | Used to display relevant advertisements and measure campaign effectiveness across platforms | Up to 2 years |
You can manage your cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of our website. For more detailed information about the cookies we use, please refer to our Cookie Policy.
6. Sharing Your Information with Third Parties
We do not sell your personal information to third parties for monetary compensation. However, we may share your information in the following circumstances:
6.1 Service Providers and Business Partners
We engage trusted third-party service providers who assist us in operating our business and providing services to you. These providers are contractually obligated to use your information only for the purposes we specify and to maintain appropriate security measures. Categories of service providers include:
- Payment processors – to securely process credit/debit card and digital wallet transactions
- Delivery platform partners – to coordinate and fulfill food delivery orders
- Cloud hosting and IT infrastructure providers for website operation and data storage
- Email marketing platforms for sending newsletters and promotional communications
- Analytics providers such as Google Analytics for website usage insights
- Customer relationship management (CRM) software providers
- Advertising networks for targeted and retargeted advertising campaigns
- Loyalty program technology providers
6.2 Legal Requirements and Law Enforcement
We may disclose your personal information if required to do so by law or in good faith belief that such disclosure is necessary to:
- Comply with a legal obligation, court order, or governmental request
- Enforce our Terms of Service or other contractual agreements
- Protect against fraud, security threats, or technical issues
- Protect the rights, property, or personal safety of Costa Vida, our customers, or the public
6.3 Business Transfers
In the event of a merger, acquisition, corporate restructuring, sale of assets, or bankruptcy, your personal information may be transferred to the successor entity as part of the transaction. We will notify you via email and/or prominent notice on our website if such a transfer occurs and your information becomes subject to a different privacy policy.
6.4 With Your Consent
We may share your information with other third parties when you have given us explicit consent to do so, such as participating in a joint promotion with a partner brand or integrating a third-party service with your Costa Vida account.
7. Data Security
We take the security of your personal information seriously and implement a comprehensive set of administrative, technical, and physical safeguards to protect your data from unauthorized access, disclosure, alteration, or destruction.
7.1 Security Measures We Employ
- SSL/TLS encryption for all data transmitted between your browser and our servers
- PCI-DSS compliance for all payment card data handling and processing
- Data encryption at rest for sensitive personal information stored in our databases
- Access controls and authentication protocols limiting employee access to personal data on a need-to-know basis
- Regular security audits and penetration testing to identify and remediate vulnerabilities
- Multi-factor authentication (MFA) for internal systems containing customer data
- Employee training programs on data privacy and cybersecurity best practices
- Incident response procedures to detect, contain, and respond to data breaches promptly
8. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
| Data Category | Retention Period |
|---|---|
| Account and profile information | Duration of account activity, plus 3 years after account closure |
| Order history and transaction records | 7 years (for tax and accounting compliance) |
| Payment information (tokenized) | Duration of account activity or as required by payment processor |
| Marketing preferences and communication logs | 3 years from last interaction or opt-out |
| Website usage and analytics data | Up to 26 months (per Google Analytics default settings) |
| Customer service communications | 3 years from the date of the interaction |
| Legal compliance and fraud prevention records | As required by applicable law, typically up to 7 years |
After the applicable retention period, we securely delete or anonymize your personal information so that it can no longer be associated with you.
9. Your Privacy Rights
Depending on your state of residence, you may have various rights regarding your personal information. We are committed to honoring these rights in full compliance with applicable United States privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the Federal Trade Commission Act (FTC Act) governing consumer protection and fair business practices.
9.1 Rights Available to All Users
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you, the purposes for which it is used, and the categories of third parties with whom we share it.
- Right to Access: You have the right to obtain a copy of the personal information we hold about you in a portable, commonly used format.
- Right to Correction: You have the right to request that we correct inaccurate or incomplete personal information we hold about you.
- Right to Deletion: You have the right to request that we delete your personal information, subject to certain exceptions required by law (such as maintaining records for legal obligations or completing transactions you have initiated).
- Right to Opt Out of Marketing: You have the right to opt out of receiving marketing and promotional communications from us at any time.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights. Exercising your rights will not result in denied services, different prices, or reduced quality of service.
9.2 Additional Rights for California Residents (CCPA/CPRA)
If you are a resident of California, you have additional rights under the CCPA and CPRA, including:
- Right to Know About Sale or Sharing of Personal Information: California residents have the right to know if their personal information is sold or shared for cross-context behavioral advertising purposes. We do not sell your personal information, but we may share data with advertising partners.
- Right to Opt Out of Sale/Sharing: You have the right to opt out of the sale or sharing of your personal information for targeted advertising purposes by contacting us at [email protected] or using the "Do Not Sell or Share My Personal Information" link on our website.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit the use of your sensitive personal information to only what is necessary to provide you our services.
- Right to Data Portability: You may request a copy of your personal data in a structured, machine-readable format.
9.3 How to Exercise Your Rights
To exercise any of the privacy rights described above, please submit your request by:
- Email: [email protected]
We will verify your identity before processing your request to protect your privacy and security. We will respond to your request within 45 days of receipt. If we need additional time (up to 90 days total), we will notify you of the extension and the reason for it. We will not charge a fee for your first request in a 12-month period; however, we reserve the right to charge a reasonable administrative fee for subsequent or manifestly unfounded requests.
9.4 Authorized Agents
California residents may designate an authorized agent to submit privacy rights requests on their behalf. Authorized agents must provide written authorization signed by the consumer or a power of attorney. We may still require the consumer to verify their identity directly with us.
10. Children's Privacy
Costa Vida is committed to protecting the privacy of minors. Our website, online ordering platform, and loyalty program are not directed at children under the age of 18. We do not knowingly solicit or collect personal information from anyone under 18 years of age.
If you are a parent or legal guardian and believe that your child under the age of 18 has provided us with personal information without your consent, please contact us immediately at [email protected]. Upon verification, we will promptly investigate and take steps to delete the child's information from our systems in compliance with the Children's Online Privacy Protection Act (COPPA).
If we discover that we have inadvertently collected personal information from a child under 13 years of age, we will delete such information immediately and take corrective action to prevent future occurrences.
11. International Data Transfers
Costa Vida is based in the United States and primarily operates within the United States. The personal information we collect is stored and processed on servers located in the United States. If you are accessing our website from outside the United States, please be aware that your information may be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your home country.
By using our website and services, you consent to the transfer of your information to the United States. We take appropriate steps to ensure that any international data transfers are conducted in compliance with applicable legal requirements and that your personal information remains protected at a standard equivalent to the protections offered in your home jurisdiction.
We do not intentionally target users outside the United States. If you are located outside the United States and choose to use our services, you do so voluntarily and acknowledge that your information will be processed in accordance with this Privacy Policy and United States law.
12. Third-Party Links and Integrations
Our website may contain links to third-party websites, social media platforms, food delivery apps, or other external services. These links are provided for your convenience and informational purposes only. Costa Vida has no control over the privacy practices or content of these third-party sites and is not responsible for their privacy policies or data handling practices.
We strongly encourage you to review the privacy policies of any third-party websites you visit through links on our platform. Common third-party services that may collect information when you interact with our website include:
- Google Analytics and Google Ads
- Meta (Facebook) Pixel for advertising
- Instagram and other social media platforms
- Food delivery platforms (e.g., DoorDash, Uber Eats, Grubhub)
- Payment gateways and digital wallet providers
13. Do Not Track Signals
Some web browsers allow users to send "Do Not Track" (DNT) signals to websites they visit. Currently, our website does not respond to DNT signals from browsers, as there is no universally accepted standard for how websites should respond to such signals. However, you can manage your tracking preferences through our cookie consent settings and your browser's built-in privacy controls.
California residents may also exercise their right to opt out of the sharing of personal information for cross-context behavioral advertising by contacting us at [email protected].
14. State-Specific Privacy Disclosures
14.1 California Residents
In addition to the CCPA/CPRA rights described in Section 9.2, California residents are entitled to request a list of the categories of personal information we have disclosed to third parties for their direct marketing purposes in the preceding calendar year (California "Shine the Light" law). To make such a request, please email us at [email protected] with the subject line "California Shine the Light Request."
14.2 Virginia, Colorado, Connecticut, Utah, and Other State Residents
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with enacted consumer privacy laws may have rights similar to those described for California residents, including rights to access, correction, deletion, portability, and opt-out from targeted advertising. We honor these rights upon verified request submitted to [email protected].
15. How to File a Privacy Complaint
We take privacy concerns seriously and are committed to resolving any issues you may have regarding how we handle your personal information. If you believe your privacy rights have been violated, we encourage you to follow these steps:
15.1 Contact Us Directly
As a first step, please contact our Privacy Team at:
- Email: [email protected]
Please describe your concern in detail, including the specific information or practice you believe is in violation of your rights. We will acknowledge receipt of your complaint within 5 business days and work to resolve the matter within 30 to 45 days.
15.2 File a Complaint with Regulatory Authorities
If you are not satisfied with our response, you have the right to file a complaint with the appropriate regulatory authority. In the United States, relevant authorities include:
| Authority | Jurisdiction | Contact |
|---|---|---|
| Federal Trade Commission (FTC) | Federal – Consumer Protection and Data Privacy | ftc.gov/complaint |
| California Privacy Protection Agency (CPPA) | California Residents – CCPA/CPRA Enforcement | cppa.ca.gov |
| State Attorney General | Your state of residence | Visit your state's official government website |
16. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Post a prominent notice on our website homepage or during your next login session
- Send an email notification to registered account holders (where required by law or where the change is material)
Your continued use of our website and services after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. We encourage you to review this page periodically to stay informed about how we protect your information.
17. Contact Us
If you have any questions, concerns, or requests related to this Privacy Policy or our data handling practices, please do not hesitate to contact us:
| Company | Costa Vida |
|---|---|
| Website | vidacostas.click |
| [email protected] | |
| Privacy Inquiries | Subject line: "Privacy Policy Inquiry" to [email protected] |
We are dedicated to being transparent about our data practices and responsive to your privacy needs. Our team strives to respond to all privacy-related inquiries within 5 business days.
This Privacy Policy was last reviewed and updated on March 28, 2026, and is effective as of the same date. Costa Vida is committed to protecting your privacy and complying with all applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), Children's Online Privacy Protection Act (COPPA), and the Federal Trade Commission Act (FTC Act).