Privacy Policy

Effective Date: June 24, 2026  |  Last Updated: June 24, 2026

This Privacy Policy describes how Costa Vida ("we," "us," or "our") collects, uses, shares, and protects information obtained from individuals ("you" or "user") who visit our website at costavidagrill.rest, use our online ordering services, sign up for our loyalty programs, or otherwise interact with us. We are committed to protecting your personal information and your right to privacy. Please read this policy carefully to understand our practices regarding your personal data and how we will treat it.

By accessing or using our website or services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please discontinue use of our website and services immediately.

This Privacy Policy is governed by applicable United States federal and state privacy laws, including but not limited to the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Children's Online Privacy Protection Act (COPPA), and the Federal Trade Commission Act (FTC Act). We comply with all applicable regulations to ensure your personal data is handled responsibly and transparently.


1. About Costa Vida

Costa Vida is a food service business operating in the United States. We are dedicated to delivering fresh, high-quality food experiences to our valued customers. Our digital presence includes our website and online ordering platform, through which we collect certain personal information as described in this Privacy Policy.

Business Name Costa Vida
Website costavidagrill.rest
Email Address [email protected]
Country of Operation United States

2. Information We Collect

We collect various types of information in connection with the services we provide. The categories of information we collect include personal information you provide directly, information we collect automatically, and information we obtain from third parties.

2.1 Personal Information You Provide Directly

When you interact with us — whether by placing an order, creating an account, signing up for our newsletter, participating in a promotion, or contacting our customer support team — you may provide us with the following types of personal information:

  • Contact Information: Your full name, email address, mailing address, and telephone number.
  • Account Credentials: Your username and password when you create an account on our platform.
  • Payment Information: Credit card numbers, debit card information, billing addresses, and other financial details necessary to process your transactions. Note that full payment card data is processed by our PCI-DSS compliant payment processors and is not stored on our servers.
  • Order Information: Details about the food items you order, your preferences, dietary restrictions or allergies you voluntarily share, delivery addresses, and special instructions.
  • Loyalty Program Data: Information provided when you enroll in our rewards or loyalty program, including your preferences and purchase history.
  • Communications: The content of messages you send us via email, contact forms, or customer support channels, including feedback, reviews, and complaints.
  • Survey Responses: Any information you voluntarily provide when participating in surveys, contests, or promotional activities.
  • Marketing Preferences: Your preferences regarding receiving marketing communications from us.

2.2 Information We Collect Automatically

When you visit our website at costavidagrill.rest, we automatically collect certain technical information about your device and how you interact with our platform. This information is collected through cookies, web beacons, pixels, and similar tracking technologies:

  • Device Information: Your device type, operating system, browser type and version, screen resolution, and language settings.
  • Log Data: Your IP address, access times, pages viewed, referring URLs, and the links you click on within our website.
  • Usage Data: Information about how you interact with our website, including the features you use, the pages you visit, how long you spend on each page, and the search queries you enter.
  • Location Data: Approximate geographic location based on your IP address. If you grant permission, we may also collect more precise location data to facilitate services such as finding the nearest restaurant location.
  • Cookie Data: Data collected through cookies and similar technologies as described in Section 7 of this Privacy Policy.
  • Transaction Metadata: Information about the timing, frequency, and nature of your purchases and interactions with our online ordering system.

2.3 Information We Obtain from Third Parties

We may also receive information about you from third-party sources, which we may combine with information we collect directly. These sources include:

  • Social Media Platforms: If you log in to our platform using a social media account (such as Facebook or Google), we may receive basic profile information such as your name, email address, and profile picture from that platform.
  • Analytics Providers: Third-party analytics services that provide us with aggregated and anonymized data about website traffic and user behavior.
  • Marketing Partners: Business partners who may share data about individuals who have expressed interest in food delivery or restaurant services.
  • Payment Processors: Confirmation of transaction status and fraud prevention signals from payment processing partners.
  • Review Platforms: Publicly available reviews and feedback about our services posted on third-party review websites.

3. How We Use Your Information

We use the personal information we collect for a variety of legitimate business purposes. Each purpose for which we process your data is described below:

3.1 Providing and Managing Our Services

  • Processing and fulfilling your food orders, including coordinating delivery or pickup.
  • Creating and managing your customer account.
  • Processing payments and sending transaction confirmations and receipts.
  • Administering our loyalty and rewards programs.
  • Responding to your inquiries, complaints, and customer support requests.
  • Sending you order status updates, delivery notifications, and other service-related communications.

3.2 Improving and Personalizing Our Services

  • Analyzing usage patterns to understand how customers interact with our website and services.
  • Personalizing your experience by remembering your preferences and past orders.
  • Developing new features, products, and services based on user feedback and behavior.
  • Conducting internal research and quality assurance testing.
  • Improving our menu offerings, pricing strategies, and overall customer experience.

3.3 Marketing and Communications

  • Sending you promotional emails, newsletters, and special offers about our products and services, subject to your marketing preferences.
  • Conducting targeted advertising campaigns on social media and other digital platforms.
  • Inviting you to participate in surveys, contests, and promotional events.
  • Informing you about new menu items, seasonal specials, and restaurant news.

You have the right to opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at [email protected].

3.4 Legal and Compliance Purposes

  • Complying with applicable federal, state, and local laws and regulations, including tax reporting requirements.
  • Enforcing our Terms of Service and other legal agreements.
  • Preventing fraud, unauthorized access, and other illegal activities.
  • Protecting the rights, property, and safety of Costa Vida, our customers, and the public.
  • Responding to legal requests, court orders, or government inquiries.

3.5 Business Operations

  • Conducting internal business analytics and reporting.
  • Managing our supplier and partner relationships.
  • Assessing and improving our security infrastructure.
  • Facilitating business transactions such as mergers, acquisitions, or asset sales.

4. Sharing Your Information with Third Parties

We do not sell your personal information to third parties for monetary compensation. However, we may share your information in the following circumstances:

4.1 Service Providers

We engage trusted third-party companies and individuals to perform services on our behalf. These service providers are authorized to use your personal information only as necessary to provide services to us and are contractually obligated to protect your data. Categories of service providers include:

  • Payment Processors: Companies that securely handle payment card transactions on our behalf.
  • Delivery Partners: Third-party delivery platforms and courier services that fulfill your food orders.
  • Cloud Hosting Providers: Companies that host our website, databases, and application infrastructure.
  • Email and Communication Services: Platforms used to send transactional and marketing emails.
  • Analytics Services: Companies such as Google Analytics that help us understand website usage patterns.
  • Customer Support Tools: Software providers that support our customer service operations.
  • Marketing and Advertising Platforms: Digital advertising networks used for targeted marketing campaigns.

4.2 Legal Requirements and Law Enforcement

We may disclose your personal information if we believe in good faith that such disclosure is necessary to:

  • Comply with a legal obligation, court order, subpoena, or other legal process.
  • Protect and defend the rights or property of Costa Vida.
  • Prevent or investigate possible wrongdoing in connection with our services.
  • Protect the personal safety of users of our services or the public.
  • Cooperate with law enforcement, regulatory agencies, or governmental authorities.

4.3 Business Transfers

In the event that Costa Vida is involved in a merger, acquisition, sale of all or a portion of its assets, bankruptcy, or other corporate transaction, your personal information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website of any change in ownership or uses of your personal information.

4.4 With Your Consent

We may share your information with third parties when you have given us explicit consent to do so, such as when you choose to integrate third-party services with your account or participate in co-branded promotions.

4.5 Aggregated and De-identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for industry analysis, demographic profiling, marketing, and other business purposes.


5. Data Security

Costa Vida takes the security of your personal information seriously and implements a variety of technical, administrative, and physical security measures designed to protect your data from unauthorized access, disclosure, alteration, and destruction.

5.1 Security Measures We Employ

  • Encryption: We use industry-standard SSL/TLS encryption to protect data transmitted between your browser and our servers.
  • Access Controls: Access to personal information is restricted to authorized personnel who need it to perform their job functions. All employees are subject to confidentiality obligations.
  • Payment Security: Payment card data is processed through PCI-DSS compliant payment processors. We do not store full payment card numbers on our servers.
  • Secure Infrastructure: Our website and databases are hosted on secure, regularly audited cloud infrastructure.
  • Regular Security Assessments: We conduct regular security reviews and vulnerability assessments of our systems.
  • Incident Response: We maintain an incident response plan to promptly address potential security breaches.

5.2 Limitations

While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the confidentiality of your account credentials and for restricting access to your devices.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected individuals and relevant authorities in accordance with applicable law, including any applicable state breach notification laws.


6. Your Rights and Choices

Depending on your state of residence, you may have certain rights regarding your personal information. We respect and support these rights and provide mechanisms for you to exercise them.

6.1 Rights for California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

Right Description
Right to Know You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for which it is used, and the categories of third parties with whom we share it.
Right to Delete You have the right to request that we delete personal information we have collected from you, subject to certain exceptions permitted by law.
Right to Correct You have the right to request correction of inaccurate personal information we maintain about you.
Right to Opt-Out of Sale/Sharing You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising purposes.
Right to Limit Use of Sensitive Information You have the right to limit our use of your sensitive personal information to what is necessary to provide you with services.
Right to Non-Discrimination We will not discriminate against you for exercising any of your CCPA/CPRA rights.
Right to Data Portability You have the right to receive your personal information in a portable, machine-readable format.

6.2 General Rights for All Users

Regardless of your state of residence, we offer the following rights to all users:

  • Access and Review: You may request access to the personal information we hold about you by contacting us at [email protected].
  • Correction: You may update or correct inaccurate personal information through your account settings or by contacting us directly.
  • Deletion: You may request deletion of your account and associated personal information, subject to our legal obligations to retain certain records.
  • Opt-Out of Marketing: You may opt out of receiving promotional communications from us at any time.
  • Data Portability: You may request a copy of your personal data in a structured, commonly used, and machine-readable format.

6.3 How to Exercise Your Rights

To exercise any of the rights described above, please submit a request to us using one of the following methods:

We will verify your identity before processing your request to protect the security of your information. We aim to respond to all verifiable consumer requests within 45 days of receipt. If we require additional time, we will inform you of the reason and the extension period.

You may designate an authorized agent to submit requests on your behalf. If you use an authorized agent, we may require written permission and may directly verify your identity.


7. Cookie Policy and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your experience, analyze traffic, and support our marketing activities.

7.1 Types of Cookies We Use

  • Strictly Necessary Cookies: These cookies are essential for the website to function properly. They enable core functionalities such as account login, shopping cart operations, and security features. These cookies cannot be disabled.
  • Performance and Analytics Cookies: These cookies collect information about how visitors use our website, such as which pages are visited most often and whether users receive error messages. This data helps us improve our website. We use tools such as Google Analytics for this purpose.
  • Functional Cookies: These cookies allow our website to remember your preferences and choices (such as your language, location, or saved order preferences) to provide enhanced, personalized features.
  • Targeting and Advertising Cookies: These cookies are used to deliver advertising that is relevant to your interests. They also limit the number of times you see an advertisement and help us measure the effectiveness of our marketing campaigns.
  • Social Media Cookies: These cookies are set by social media services when you interact with social sharing buttons on our website.

7.2 Managing Your Cookie Preferences

Most web browsers allow you to control cookie settings through their settings preferences. You may be able to:

  • Delete all cookies stored on your device.
  • Block cookies from being placed on your device.
  • Set your browser to notify you when cookies are being placed.

Please note that disabling certain cookies may impact the functionality of our website and your ability to use certain features of our online ordering system. For a more detailed description of our cookie practices, please refer to our full Cookie Policy available on our website at costavidagrill.rest.

7.3 Do Not Track Signals

Some browsers may transmit "Do Not Track" signals to websites. Currently, there is no universal standard for how websites should respond to such signals. We will continue to monitor developments in this area and update our practices accordingly.


8. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.

8.1 Retention Periods

Category of Data Retention Period
Account Information For the duration of your account plus 3 years after account closure
Order History and Transaction Records 7 years (for tax and accounting purposes)
Customer Support Communications 3 years from the date of the last interaction
Marketing Preferences and Consent Records 5 years from the date of last consent or opt-out
Website Usage and Analytics Data 26 months (in line with Google Analytics default settings)
Cookies (Session) Deleted when you close your browser
Cookies (Persistent) Up to 2 years, depending on cookie type
Legal and Compliance Records As required by applicable law, typically 7-10 years

When personal data is no longer needed, we will securely delete or anonymize it. If deletion is not immediately possible (for example, because data has been stored in backup archives), we will securely store the data and isolate it from further processing until deletion is possible.


9. Children's Privacy

Important Notice: Our website and services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from children under the age of 18.

Costa Vida does not direct its products, services, or website content toward individuals under the age of 18. We do not knowingly collect, use, or disclose personal information from minors. Our online ordering system, loyalty programs, and account registration features are designed for adult users only.

If you are a parent or guardian and believe that your child under the age of 18 has provided us with personal information without your consent, please contact us immediately at [email protected]. Upon verification, we will promptly delete such information from our records.

We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under the age of 13. If we become aware that we have inadvertently collected information from a child under 13, we will take immediate steps to delete that information.


10. International Data Transfers

Costa Vida is based in the United States and operates primarily within the United States. The personal information we collect is stored and processed on servers located within the United States. If you are accessing our services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence.

By using our website and services from outside the United States, you consent to the transfer of your information to the United States and the processing of your data in accordance with this Privacy Policy and applicable U.S. laws.

If we transfer personal data internationally, we take appropriate measures to ensure that such transfers comply with applicable data protection laws and that your personal information remains protected to the standard described in this Privacy Policy. These measures may include:

  • Transferring data only to countries that have been deemed to provide an adequate level of data protection.
  • Entering into data transfer agreements with third parties that include standard contractual clauses or other appropriate safeguards.
  • Obtaining your explicit consent to the transfer where required by law.

11. Third-Party Links and Services

Our website may contain links to third-party websites, applications, or services that are not operated by Costa Vida. When you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. This Privacy Policy applies solely to information collected by Costa Vida through the costavidagrill.rest website and our associated services.


12. California Privacy Rights — Additional Disclosures

In addition to the rights described in Section 6 of this Privacy Policy, California residents are entitled to additional disclosures under the CCPA/CPRA.

12.1 Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information as defined under the CCPA:

  • Identifiers (name, email address, IP address, account credentials)
  • Commercial information (purchase history, order records, loyalty program data)
  • Internet or other electronic network activity information (browsing history on our site, search queries)
  • Geolocation data (approximate location based on IP address)
  • Inferences drawn from personal information to create a profile about consumer preferences
  • Financial information (payment card details processed by third-party processors)

12.2 Shine the Light Law

California Civil Code Section 1798.83 permits California residents to request certain information regarding our disclosure of personal information to third parties for direct marketing purposes. If you are a California resident and wish to make such a request, please contact us at [email protected].

12.3 Do Not Sell or Share My Personal Information

Under the CCPA/CPRA, California residents have the right to opt out of the sale or sharing of their personal information. To exercise this right, please contact us at [email protected] with the subject line "Do Not Sell or Share My Personal Information."


13. How to File a Complaint

If you have concerns about how we handle your personal information and we have not satisfactorily addressed those concerns, you have the right to file a complaint with the appropriate regulatory authority.

13.1 California Residents

California residents may file a complaint with the California Privacy Protection Agency (CPPA) or the California Attorney General's Office:

California Privacy Protection Agency
Website: cppa.ca.gov
Email: [email protected]

California Attorney General
Website: oag.ca.gov/privacy
Phone: 1-800-952-5225

13.2 Federal Complaints

For concerns related to unfair or deceptive business practices under the FTC Act, you may file a complaint with the Federal Trade Commission (FTC):

Federal Trade Commission
Website: ftc.gov
Complaint Center: reportfraud.ftc.gov
Phone: 1-877-382-4357

13.3 Other State Residents

Residents of other states with applicable privacy laws may file complaints with their respective state attorney general's office or designated data protection authority. We encourage you to consult your state's official government website for relevant contact information.

Before filing a formal complaint with any regulatory authority, we encourage you to contact us directly so we may have the opportunity to resolve your concerns promptly and satisfactorily.


14. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time and for any reason. When we make changes, we will revise the "Last Updated" date at the top of this policy. If we make material changes to how we collect, use, or share your personal information, we will notify you by:

  • Posting the updated Privacy Policy on our website at costavidagrill.rest with the new effective date.
  • Sending an email notification to the email address associated with your account (where applicable).
  • Displaying a prominent notice on our website homepage.

We encourage you to review this Privacy Policy periodically to stay informed about our data practices. Your continued use of our website and services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.


15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us. We are committed to addressing your inquiries promptly and transparently.

Privacy Inquiries — Costa Vida

Business Name: Costa Vida

Website: costavidagrill.rest

Email: [email protected]

Subject Line: Please use "Privacy Policy Inquiry" or "Data Rights Request" as your email subject line so we can route your request to the appropriate team member as quickly as possible.

We aim to acknowledge receipt of all privacy-related inquiries within 5 business days and to provide a substantive response within 45 days, or as required by applicable law.

Your Privacy Matters to Us. At Costa Vida, we are committed to being transparent about how we collect and use your information. We believe that trust is the foundation of a great customer relationship, and we take our responsibility to protect your data seriously. Thank you for trusting us with your information.

This Privacy Policy was last updated on June 24, 2026, and is effective as of that date. All previous versions of this Privacy Policy are superseded by this document.