Privacy Policy

This Privacy Policy describes how Costa Vida ("we," "us," "our," or the "Company") collects, uses, discloses, and protects your personal information when you visit our website at eat-costavida.click (the "Website"), use our online ordering services, interact with our digital platforms, or otherwise engage with our business. We are committed to protecting your privacy and handling your personal data in a transparent, responsible, and lawful manner in accordance with applicable United States federal and state privacy laws.

Please read this Privacy Policy carefully before using our Website or providing us with any personal information. By accessing or using our Website, you acknowledge that you have read, understood, and agree to the practices described in this policy. If you do not agree with any part of this Privacy Policy, please discontinue your use of our Website and services immediately.

We reserve the right to update or modify this Privacy Policy at any time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this page and, where appropriate, by sending you an email notification or displaying a prominent notice on our Website. Your continued use of the Website following any changes constitutes your acceptance of the revised Privacy Policy.


1. Who We Are and How to Contact Us

Costa Vida is a food service business operating in the United States. We are committed to protecting your personal information and your right to privacy. If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the details below:

Business Name Costa Vida
Website eat-costavida.click
Email Address [email protected]

Our privacy team is available to respond to your inquiries within a reasonable timeframe. For rights-related requests (such as access, deletion, or correction of your personal data), please allow up to 45 days for a response as permitted under applicable law.


2. Scope and Applicability

This Privacy Policy applies to:

  • All visitors to our Website at eat-costavida.click
  • Customers who place online orders through our Website or affiliated platforms
  • Individuals who sign up for our loyalty program, newsletters, or promotional communications
  • Users who interact with us through social media, customer service channels, or any other digital touchpoint
  • Job applicants who submit personal information through our Website or via email

This Privacy Policy does not apply to third-party websites, applications, or services that may be linked to or from our Website. We encourage you to review the privacy policies of any third-party platforms you visit.


3. Information We Collect

We collect several types of information from and about users of our Website and services. The categories of personal information we collect include:

3.1 Personal Identification Information

When you register an account, place an order, sign up for promotions, or contact us directly, we may collect the following personally identifiable information:

  • Full name
  • Email address
  • Phone number
  • Mailing or delivery address
  • Date of birth (for age verification and birthday promotions)
  • Account username and password (stored in encrypted form)
  • Dietary preferences and food allergy information (when voluntarily provided)

3.2 Payment and Transaction Information

When you make a purchase through our Website, we collect transaction-related information, including:

  • Order history and item selections
  • Billing address
  • Payment method type (credit card, debit card, digital wallet)
  • Transaction amount and date

Please note that complete payment card details (such as full card numbers and CVV codes) are processed by our PCI-DSS compliant third-party payment processors and are not stored on our systems.

3.3 Usage Data and Online Activity

We automatically collect certain information when you visit and interact with our Website, including:

  • IP address and approximate geographic location derived from your IP address
  • Browser type and version
  • Operating system and device type
  • Pages visited, links clicked, and time spent on each page
  • Referring website URLs (the website that brought you to ours)
  • Search queries entered on our Website
  • Time and date of visits
  • Error logs and crash reports

3.4 Device Information

We may collect information about the device you use to access our Website, including:

  • Device identifiers (such as mobile device ID or advertising ID)
  • Hardware model
  • Operating system and version
  • Mobile network information
  • Screen resolution and browser settings

3.5 Location Information

With your permission, we may collect precise geolocation data from your mobile device or browser to help you find the nearest Costa Vida location, provide delivery services, or offer location-relevant promotions. You may disable location sharing in your device or browser settings at any time.

3.6 Communications Data

When you contact us by email, phone, or through our online contact forms, we retain records of those communications, including the content of messages and any information you voluntarily provide.

3.7 Information from Third Parties

We may receive information about you from third-party sources, such as:

  • Social media platforms (if you choose to connect your account or interact with us on social media)
  • Third-party delivery service partners
  • Marketing and analytics service providers
  • Online review platforms

3.8 Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies to collect information about your browsing behavior and preferences. For a full description of the cookies we use and how to manage them, please refer to Section 10 (Cookie Usage) of this Privacy Policy.


4. How We Use Your Information

We use the personal information we collect for a variety of legitimate business purposes, including:

4.1 Providing and Improving Our Services

  • Processing and fulfilling your food orders
  • Managing your account and loyalty program membership
  • Facilitating delivery or pick-up services
  • Responding to your customer service inquiries and complaints
  • Personalizing your experience on our Website and in-store
  • Improving the functionality, design, and content of our Website
  • Conducting research and development to enhance our menu and services

4.2 Marketing and Communications

  • Sending you promotional emails, newsletters, and special offers (with your consent where required)
  • Notifying you about new menu items, seasonal offerings, and upcoming events
  • Displaying personalized advertisements on our Website and third-party platforms
  • Conducting surveys and collecting feedback to improve our offerings
  • Managing our social media engagement and online community

You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at [email protected].

4.3 Analytics and Business Intelligence

  • Analyzing website traffic patterns and user behavior to optimize our digital presence
  • Measuring the effectiveness of our marketing campaigns
  • Understanding customer preferences and purchasing trends
  • Generating internal reports and business analytics

4.4 Legal Compliance and Safety

  • Complying with applicable federal and state laws and regulations
  • Responding to lawful requests from government authorities or law enforcement
  • Enforcing our Terms of Service and other agreements
  • Detecting, preventing, and investigating fraud, security breaches, and other illegal activity
  • Protecting the rights, property, and safety of Costa Vida, our customers, and the public

4.5 Legal Basis for Processing

We process your personal information based on the following legal grounds:

  • Contractual necessity: To perform the contract between you and us (e.g., processing your order)
  • Legitimate interests: For fraud prevention, network security, analytics, and improving our services
  • Consent: For optional marketing communications and non-essential cookies
  • Legal obligation: To comply with applicable laws and regulatory requirements

5. Sharing Your Information with Third Parties

We do not sell your personal information to third parties for monetary compensation. However, we may share your information in the following circumstances:

5.1 Service Providers and Business Partners

We work with trusted third-party service providers who assist us in operating our business and Website. These providers may access your personal information only to the extent necessary to perform their services and are contractually obligated to protect it. Our service providers include:

  • Payment processing companies (for secure transaction handling)
  • Cloud hosting and data storage providers
  • Email marketing and communication platforms
  • Analytics and website performance tools (e.g., Google Analytics)
  • Customer relationship management (CRM) software providers
  • Third-party food delivery platforms
  • Loyalty program technology providers
  • Cybersecurity and fraud prevention services

5.2 Legal Requirements

We may disclose your personal information if we believe in good faith that such disclosure is necessary to:

  • Comply with a legal obligation, court order, subpoena, or governmental request
  • Enforce our Terms of Service or other agreements
  • Protect the rights, property, or safety of Costa Vida, our customers, or the public
  • Detect, prevent, or address fraud, security breaches, or technical issues

5.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred to the acquiring party. We will notify you by email or through a prominent notice on our Website before your personal information becomes subject to a different privacy policy.

5.4 With Your Consent

We may share your information with other third parties when you provide your explicit consent to do so.

5.5 Aggregated and Anonymized Data

We may share aggregated, de-identified, or anonymized information that cannot reasonably be used to identify you with third parties for marketing, advertising, research, or other lawful purposes.


6. Your Privacy Rights

Depending on your state of residence, you may have certain rights regarding your personal information. We are committed to honoring these rights in compliance with applicable United States privacy laws.

6.1 California Residents โ€” CCPA/CPRA Rights

If you are a resident of California, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with the following rights:

  • Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell about you over the past 12 months.
  • Right to Delete: You have the right to request the deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to Correct: You have the right to request that we correct inaccurate personal information we maintain about you.
  • Right to Opt-Out of Sale/Sharing: We do not sell personal information. However, if this practice ever changes, you will have the right to opt out.
  • Right to Limit Use of Sensitive Personal Information: You may have the right to limit how we use and disclose sensitive personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
  • Right to Data Portability: You may request a copy of your personal information in a portable and usable format.

To exercise your California privacy rights, please submit a verifiable consumer request to [email protected]. We will respond within 45 days of receiving your verifiable request, with a possible extension of an additional 45 days when reasonably necessary.

6.2 Rights Available to All U.S. Residents

Regardless of your state of residence, you may have the following rights:

  • Right to Access: Request a copy of the personal information we hold about you.
  • Right to Correction: Request that we correct or update inaccurate or incomplete personal information.
  • Right to Deletion: Request the deletion of your personal information, subject to applicable legal exceptions.
  • Right to Opt-Out of Marketing: Unsubscribe from promotional communications at any time.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of prior processing.

6.3 How to Submit a Privacy Rights Request

To exercise any of the rights described above, please contact us by:

We may need to verify your identity before processing your request. Verification may require you to provide certain identifying information consistent with what we have on file. We will not use any information provided for verification for any purpose other than verifying your identity.


7. Data Security

We take the security of your personal information seriously and implement a range of technical, administrative, and physical security measures designed to protect your data from unauthorized access, disclosure, alteration, or destruction. Our security measures include:

7.1 Technical Safeguards

  • SSL/TLS encryption for all data transmitted between your browser and our Website (HTTPS)
  • Encryption of sensitive data stored in our databases
  • Secure password hashing using industry-standard algorithms
  • Firewalls and intrusion detection systems
  • Regular security vulnerability assessments and penetration testing
  • Two-factor authentication for administrative access to sensitive systems

7.2 Administrative Safeguards

  • Employee training on data privacy and security best practices
  • Role-based access controls limiting employee access to personal data on a need-to-know basis
  • Confidentiality agreements with employees and contractors
  • Documented incident response procedures for data breach situations

7.3 Payment Security

All payment transactions are processed through PCI DSS-compliant third-party payment processors. We do not store complete credit card or debit card numbers on our servers.

7.4 Limitations

While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security. In the event of a data breach affecting your rights and freedoms, we will notify you and relevant authorities as required by applicable law.


8. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Our general data retention guidelines are as follows:

Data Category Retention Period
Account information Duration of account plus 3 years after account closure
Order and transaction history 7 years (for tax and legal compliance purposes)
Marketing preferences and consent records Until consent is withdrawn plus 3 years
Customer service communications 3 years from the date of last interaction
Website usage and analytics data Up to 26 months (Google Analytics default)
Cookie data Varies by cookie type (see Section 10)
Legal claims and compliance records Duration of applicable statute of limitations

When your personal information is no longer needed for the purposes for which it was collected, we will securely delete, anonymize, or aggregate it in accordance with our data retention schedules and applicable legal requirements.


9. Children's Privacy

Our Website, online ordering platform, and digital services are not directed toward individuals under the age of 18. We do not knowingly collect, use, or disclose personal information from children under 13 years of age. If you are under 18, please do not use our Website or provide any personal information to us without the supervision and consent of a parent or legal guardian.

In compliance with the Children's Online Privacy Protection Act (COPPA), if we discover that we have inadvertently collected personal information from a child under 13, we will promptly take steps to delete that information from our records. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at [email protected].


10. Cookie Usage

We use cookies and similar tracking technologies (such as web beacons, pixels, and local storage) to enhance your experience on our Website, analyze usage patterns, and deliver relevant content and advertisements.

10.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the operation of our Website. These cannot be disabled without affecting core functionality (e.g., shopping cart, login sessions).
  • Performance and Analytics Cookies: Help us understand how visitors interact with our Website by collecting anonymous usage data (e.g., Google Analytics).
  • Functionality Cookies: Remember your preferences and settings (e.g., language, location, saved items).
  • Targeting and Advertising Cookies: Used to deliver relevant advertisements and track the effectiveness of our marketing campaigns.

10.2 Managing Your Cookie Preferences

You can manage or disable cookies through your browser settings. Most browsers allow you to refuse or delete cookies. However, please note that disabling certain cookies may affect the functionality and user experience of our Website. Instructions for managing cookies in popular browsers can be found at:

You may also opt out of interest-based advertising by visiting the Network Advertising Initiative (NAI) opt-out page or the Digital Advertising Alliance (DAA) opt-out portal.


11. International Data Transfers

Costa Vida is based in the United States, and your personal information is primarily collected, processed, and stored in the United States. Our Website is intended for use by residents of the United States, and we do not specifically target users in other countries.

If you are accessing our Website from outside the United States, please be aware that your personal information will be transferred to and processed in the United States, where data protection laws may differ from those in your country of residence. By using our Website from outside the United States, you consent to the transfer of your information to the United States and its processing in accordance with this Privacy Policy.

We implement appropriate safeguards, including contractual clauses and data processing agreements with our service providers, to ensure that any international data transfers are conducted in compliance with applicable legal requirements and that your personal information remains adequately protected.


12. Applicable Laws and Regulatory Framework

Our privacy practices are guided by and comply with applicable United States federal and state privacy and consumer protection laws, including:

  • Federal Trade Commission Act (FTC Act), 15 U.S.C. ยง 45: We follow the FTC's guidance on unfair or deceptive practices in connection with privacy and data security.
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA): We honor the privacy rights of California residents as described in Section 6.1 of this Privacy Policy.
  • Children's Online Privacy Protection Act (COPPA): We do not knowingly collect personal information from children under 13 years of age.
  • CAN-SPAM Act: We comply with the CAN-SPAM Act in all commercial email communications.
  • Electronic Communications Privacy Act (ECPA): We protect electronic communications in accordance with federal law.
  • State Privacy Laws: Where applicable, we also comply with privacy laws enacted in other U.S. states, including the Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and other emerging state privacy frameworks.

13. Third-Party Links and External Websites

Our Website may contain links to third-party websites, social media platforms, delivery applications, or other external services. These links are provided for your convenience and information only. We have no control over the content, privacy practices, or data handling of these third-party sites, and this Privacy Policy does not apply to them.

We strongly encourage you to review the privacy policies of any third-party websites you visit before providing any personal information. Costa Vida is not responsible for the privacy practices or content of external websites linked from our site.


14. Do Not Track Signals

Some browsers offer a "Do Not Track" (DNT) feature that signals to websites that you do not want your online activities tracked. At this time, our Website does not respond to "Do Not Track" browser signals because a universal technical standard for DNT compliance has not yet been established. We continue to monitor developments in this area and may update our practices as standards evolve.

However, you may opt out of certain types of tracking and data collection by managing your cookie preferences as described in Section 10 of this Privacy Policy.


15. How to File a Complaint

We take all privacy concerns seriously and are committed to resolving any issues promptly and fairly. If you believe that we have violated your privacy rights or failed to handle your personal information in accordance with this Privacy Policy or applicable law, we encourage you to contact us first so that we may address your concerns directly.

15.1 Contact Us First

Please submit your complaint or concern to:

We will acknowledge receipt of your complaint within 5 business days and aim to resolve it within 30 days. If we require additional time, we will notify you of the expected resolution timeframe.

15.2 Federal Trade Commission (FTC)

If you believe your privacy rights have been violated and you have been unable to resolve the issue directly with us, you may file a complaint with the Federal Trade Commission (FTC), which enforces consumer protection and privacy laws at the federal level in the United States:

  • FTC Online Complaint Assistant: reportfraud.ftc.gov
  • FTC Mailing Address: Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, DC 20580
  • FTC Phone: 1-877-FTC-HELP (1-877-382-4357)

15.3 California Residents

California residents may also file complaints with the California Privacy Protection Agency (CPPA):

  • Website: cppa.ca.gov
  • Address: California Privacy Protection Agency, 2101 Arena Blvd., Sacramento, CA 95834

15.4 State Attorneys General

Residents of other states may contact their respective State Attorney General's Office for guidance on consumer privacy rights and how to file complaints under applicable state law.


16. Automated Decision-Making

We may use automated processes and algorithms to personalize your experience on our Website, including product recommendations, promotional offers, and content tailored to your preferences. We do not use fully automated decision-making processes that produce legal or similarly significant effects on individuals without human oversight.

If you have questions about how automated systems affect your interaction with our Website, please contact us at [email protected].


17. Sensitive Personal Information

In the course of providing our food services, we may collect certain categories of sensitive personal information, such as food allergy information or dietary restrictions that you voluntarily provide when placing an order. This information is used solely for the purpose of fulfilling your order safely and is treated with the highest level of confidentiality. We do not use sensitive personal information for profiling or marketing purposes without your explicit consent.


18. Updates to This Privacy Policy

We review and update this Privacy Policy periodically to reflect changes in our business practices, applicable laws, or technological developments. When we make material changes, we will:

  • Update the "Effective Date" and "Last Updated" date at the top of this page
  • Post a prominent notice on our Website homepage
  • Send an email notification to registered users, where appropriate

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal information. Your continued use of our Website and services following the posting of changes constitutes your acceptance of those changes.


19. Consent

By using our Website at eat-costavida.click and providing us with your personal information, you signify your consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy. Where we rely on consent as a legal basis for processing your data, you may withdraw your consent at any time by contacting us at [email protected]. Withdrawing your consent will not affect the lawfulness of any processing that occurred prior to withdrawal.


20. Contact Information for Privacy Inquiries

For any questions, concerns, or requests related to this Privacy Policy or our data practices, please do not hesitate to reach out to us. Our privacy team is dedicated to addressing your concerns in a timely, transparent, and professional manner.

This Privacy Policy was last reviewed and updated on May 17, 2026. All rights reserved. Costa Vida โ€” eat-costavida.click