Scope and our approach
This Privacy Policy explains how H&A Deli handles information through hadeliroc.com, its direct order-submission flow, and its authorized staff order system. It does not govern DoorDash, Uber Eats, Grubhub, Google Maps, or another service you choose to visit.
H&A uses personal information to run the deli, handle orders, protect the website, and keep necessary business records. H&A does not sell personal information or use the website for targeted advertising.
Information we collect
Information you provide
- Your name, phone number, and optional email address.
- Pickup or delivery selection; delivery address, apartment or unit, and delivery instructions when delivery is selected.
- Food items, sizes, quantities, toppings, sauces, modifiers, special instructions, and voluntary allergy or safety notes.
- Order number, status, prices, tax, delivery fee, timestamps, and the history of staff actions on the order.
Please do not enter a payment-card number, password, Social Security number, or other unrelated sensitive information in an instruction or notes field.
Website, device, and security information
When a browser requests the website, H&A's hosting and security providers may process ordinary request information such as IP address, browser or device type, operating system, requested page, referrer, approximate location, timestamps, and network or security signals. The order application converts IP and phone information into coded, keyed identifiers for rate limiting. Raw IP addresses are not stored in the customer order record by H&A's order application.
Vercel Web Analytics records aggregate page-use information such as page URL, referrer, approximate location, browser, operating system, device type, and timestamp. H&A does not configure custom analytics events to send order-form values. Vercel BotID uses a browser challenge on the order endpoint to help identify automated or abusive submissions.
Authorized staff information
For staff who use the private dashboard, H&A and Supabase process account email, display name, role, active status, authentication and multi-factor authentication information, session information, password-reset activity, staff actions, internal notes, and security or audit events. Failed-login security records use coded email and IP identifiers.
Cookies and browser storage
The public ordering interface uses local storage to keep cart items, quantities, customizations, and pickup or delivery choice in your browser. After a successful submission, session storage temporarily holds the order number, status, total, time, customer name, and fulfillment type so the confirmation page can display them. You can clear these records through your browser; session storage normally ends when the browser session ends.
Vercel Web Analytics is designed to operate without third-party analytics cookies. The site does not contain Google Analytics, Google Ads, Meta Pixel, TikTok Pixel, or another advertising pixel. Authorized staff authentication uses necessary Supabase session cookies, and the staff dashboard can save a sound preference in local storage.
The embedded Google map loads only when it nears the visible page. When it loads, your browser connects to Google, which may receive technical information and use cookies under Google's own policies.
How we use information
- Receive, price, confirm, prepare, fulfill, deliver, update, or cancel submitted orders.
- Call or otherwise contact customers about their order and provide customer service.
- Handle allergy or safety notes and other instructions supplied for an order.
- Prevent spam, fake orders, fraud, abuse, security incidents, and technical errors.
- Run staff accounts, role-based access, availability controls, audit records, and store reporting.
- Understand aggregate website use and improve reliability and usability.
- Maintain records, resolve disputes, enforce terms, and meet legal or business obligations.
Payment-card information
H&A does not currently collect or process payment-card numbers through hadeliroc.com. Website submission does not charge you. After phone confirmation, staff manually enters the confirmed order into H&A's Clover point-of-sale workflow, and payment occurs through H&A's normal in-person or delivery process.
Do not put card information in special instructions, delivery instructions, allergy notes, or any other website text field.
Allergy and safety notes
Allergy and safety information is optional and is used to handle the order, alert authorized staff, and document related actions. It may reveal health-related information, so provide only what H&A needs for the order.
Customers with severe food allergies should also tell H&A Deli staff by phone when confirming the order. H&A Deli cannot guarantee an allergen-free or cross-contact-free preparation environment.
This notice does not reduce H&A's food-safety responsibilities. Ask staff when you are uncertain about ingredients or preparation.
Third-party ordering and links
The website links to DoorDash, Uber Eats, Grubhub, Google Maps, and other external services. A link does not send H&A's direct order form to that service, but the external company may collect information after you open its site or app. Its own privacy policy, terms, prices, fees, and security practices apply.
How long information is kept
H&A keeps information for as long as reasonably necessary for order operations, store records, security and audit needs, dispute resolution, and legal or business requirements. The current order system does not have a fixed automatic deletion period. Completed and canceled orders can remain in order history, and security audit records are designed to be append-only.
Browser-stored cart and confirmation information follows the browser behavior described above. Service providers may keep logs and service records under their own retention practices. H&A will review a deletion request against operational, security, recordkeeping, and legal needs.
Security
H&A uses safeguards appropriate to this service, including HTTPS in production, authenticated individual staff accounts, authenticator-app MFA, role-based access, Supabase Row Level Security, restricted server credentials, append-only audit records, rate limiting, bot protection, and server-side price validation.
No website or storage system can be guaranteed completely secure. If H&A learns of a security incident, it will evaluate and respond to it under applicable law.
Children and minors
This is a general-audience restaurant website and is not primarily directed to children or designed for children under 13. H&A does not ask users to provide their age and does not use known minors' personal data for targeted advertising, marketing profiling, or sale.
If H&A learns that a website user is under 18, it will limit processing to what is reasonably necessary to provide the requested order or service, operate the business, prevent fraud or security incidents, comply with law, or protect a person's safety, unless another lawful basis and any required consent apply. A parent or guardian with a concern may call H&A.
Your choices and requests
- Email is optional for direct website orders.
- You can clear local or session storage using your browser settings.
- You can avoid loading the embedded map by not scrolling to it and can choose not to open external links.
- You may call to ask about, correct, or request deletion of information associated with an order. H&A may need to verify the request and may retain information when reasonably necessary or legally required.
The website currently has no marketing-email list, targeted advertising, or sale of personal information to opt out of.
Changes and contact
H&A may update this policy when the website, vendors, or legal requirements change. A revised version will be posted here with a new effective date. Material changes will not be applied misleadingly to earlier activity.
H&A Deli1042 Dewey Avenue
Rochester, NY 14613
585-647-2319
