RatedWithAI

RatedWithAI

Accessibility scanner

Privacy LawSeptember 20, 2026

The Notice Has to Be Given Before the Order. There Is Nowhere on the Kiosk to Put It.

Self-ordering screens, AI drive-thru voice and predictive upsell moved a restaurant into a privacy regime designed for websites — and the two surfaces that collect the most are the two with no room for a disclosure.

The exposure is in the vendor contracts, not the software. A kiosk that collects an order is unremarkable. A kiosk whose vendor is permitted to retain that order data and combine it across its other restaurant customers is not a service provider, which makes the disclosure a sale — and a sale you never disclosed, with no opt-out anywhere on the property.

Why Restaurant Groups Undercount Themselves

Operators tend to test scope against the customer list. The statute tests against something much wider.

The consumer count is per person, not per transaction

The headline threshold counts consumers or households whose personal information you buy, sell, share or otherwise process at the defined volume in a year. A single busy location running a loyalty app, wifi capture and a delivery marketplace integration touches far more identified people than its headcount or footprint suggests.

A device identifier is a consumer

Personal information includes identifiers tied to a device or household, not only names and emails. The app SDK, the wifi portal and the tablet at the counter all generate them, and none of those look like a customer database to the person doing the count.

Revenue alone can put you in scope

A gross revenue test sits alongside the volume test. Multi-unit groups and mid-size franchisees cross it routinely while still thinking of themselves as a restaurant rather than a data business.

Doing business in California is not the same as being in California

Serving California residents can be enough. A ghost kitchen brand, a delivery-only concept or a chain whose app is downloadable statewide is exposed even where the dining rooms sit elsewhere.

Six Collection Surfaces, Six Different Problems

The self-ordering kiosk

What it takes: Order contents, time, payment token, upsell responses, dwell time, sometimes a camera feed used for age or attention estimation.

Where it breaks: The notice at collection has to be given at or before the point of collection. A kiosk screen has no room for a privacy policy and a hungry queue behind it, so the notice becomes a link nobody opens — or it is simply absent, which is the more common finding.

AI voice at the drive-thru

What it takes: An audio recording of a person speaking, plus a transcript, plus whatever the model inferred to route the order.

Where it breaks: Audio is personal information, and a voiceprint used to identify a returning customer moves it into the sensitive category with its own limitation right. California wiretapping rules run in parallel and are not satisfied by a privacy notice.

The loyalty program

What it takes: Identity, contact details, full purchase history, location of visits, and inferences about preference and price sensitivity.

Where it breaks: Loyalty is where a financial incentive notice becomes mandatory, and the notice has to explain the value of the data. It is also the dataset most often shared with advertising partners, which turns it into a sale or share.

Predictive POS and suggested upsell

What it takes: Behavioural inferences drawn from order history and context.

Where it breaks: Inferences drawn to create a profile are personal information in their own right, and they are within reach of access, deletion and correction rights. A model's stored preference vector is not exempt because it is a model artifact.

The ordering website and app

What it takes: Everything above, plus analytics, pixels and SDKs that fire before anyone taps accept.

Where it breaks: This is where the opt-out obligation is visible and where enforcement has concentrated. Advertising and analytics tags that transmit identifiers to third parties for cross-context behavioural advertising are a share, whether or not money moves.

Delivery marketplace integration

What it takes: Customer identity and order data flowing both directions between you and a platform.

Where it breaks: Two businesses, one order. Which one is the business and which is the service provider depends on the contract, and most restaurant groups have never read that clause in a marketplace agreement they did not negotiate.

What Has to Exist Before the Next Lunch Rush

Notice at collection, at the point of collection

Every physical surface needs an offline-appropriate notice: a readable placard at the kiosk and drive-thru, plus a short on-screen line with a QR code to the full notice. It must list the categories collected and the purposes, and state whether anything is sold or shared.

A working opt-out path

If advertising tags on the ordering site transmit identifiers for cross-context advertising, the opt-out link has to exist and actually stop the transmission. Honouring the browser-level global signal is a separate requirement from the link, and it is the one most commonly failed.

Requests received where customers reach you

Deletion and access requests will arrive through the app, the website form, the phone number on the receipt and the person at the counter. Staff at the register need a script and a routing path, because an in-person request is a request.

Vendor contracts that make vendors service providers

POS, kiosk, voice AI, loyalty and analytics vendors are service providers only if the contract restricts them to your purposes and forbids retaining or using the data for their own. Without that clause, sending them data is a sale — and many kiosk and voice vendors want your audio for model training.

Sensitive data handling for voice

If audio is used to identify a speaker rather than merely to take an order, treat it as sensitive personal information: limit use, offer the limitation right, and set a retention period short enough to defend. Training on customer audio needs its own analysis, not a line in the vendor's terms.

Retention stated in advance

Retention periods have to be disclosed per category. Order video, drive-thru audio and kiosk sessions accumulate silently on vendor infrastructure, and nobody can state a period for a dataset they did not know was being kept.

The Franchise Question Nobody Answered in the Agreement

Who is the business?

Usually the franchisee for its own customer transactions, because it decides the purposes and means of processing at its restaurants. The franchisor is frequently a business too, in its own right, for the brand app and loyalty program that it operates across the system.

Where it gets confused

A brand app that takes an order for a franchised location splits the data between two entities that each have their own obligations. Two businesses jointly deciding purposes is not the same as one business with a vendor, and the privacy notice has to name who the consumer is actually dealing with.

The contract usually does not say

Franchise agreements pre-date this and often address data only through a general compliance clause. A short data addendum that allocates roles, request handling, retention and breach duties is cheap now and unobtainable during an enforcement inquiry.

Questions Operators Ask

We are a single restaurant group. Are we really in scope?

More often than operators expect, because the tests do not measure the thing restaurants measure. One threshold is gross revenue, which mid-size multi-unit groups and larger franchisees cross routinely. The other counts consumers, households or devices whose personal information you process in a year — and personal information includes device and household identifiers, not just names. A loyalty app, a wifi captive portal, an ordering site with analytics and a delivery marketplace integration together touch far more identified devices than the number of regulars anyone would name. The practical step is not a legal memo. It is an inventory: list every system that stores something tied to an individual or a device, ask each vendor how many unique identifiers it holds for a year, and add them up. Most groups discover the count sits in the systems nobody thinks of as customer data.

How do you give notice at collection on a kiosk?

With a layered notice, because a kiosk cannot display a privacy policy to someone ordering lunch. The requirement is that the notice be given at or before the point of collection, so the first layer has to be physically present: a short, readable on-screen line naming the categories collected and the purposes, with a clearly signposted way to reach the full notice. A QR code and a printed placard at the kiosk and the drive-thru menu board carry the second layer. Three details get missed. If anything is sold or shared, that has to appear in the first layer rather than three taps away. Retention periods have to be stated, which means someone has to know them. And the same notice has to reach the drive-thru, where there is no screen at all and the placard is the only surface available.

Does AI voice ordering create extra obligations beyond a normal order?

Yes, on two independent tracks. On the privacy track, an audio recording of a customer is personal information, and if a voiceprint is used to recognise a returning customer it becomes sensitive personal information carrying a right to limit its use. That changes what you may do with it and forces a defensible retention period. On the wiretapping track, California law restricts recording confidential communications without the consent of all parties, and a privacy notice is not obviously consent. The mitigations are concrete: an audible notice before the interaction begins, a documented decision about whether audio is retained at all or transcribed and discarded, a contract that forbids the vendor from training on your customers' audio unless you have specifically decided to allow it, and a retention window measured in days rather than indefinitely.

Is our POS vendor a service provider or are we selling data to them?

It depends entirely on the contract, and the default is worse than most operators assume. A vendor is a service provider only where a written agreement limits it to processing for your specified business purposes and prohibits retaining, using or disclosing the data for any other purpose, including combining it with other customers' data. Absent that, disclosing personal information for something of value is a sale, which brings an opt-out obligation and disclosure duties you are almost certainly not meeting. This matters most with the newer AI vendors: kiosk, voice and recommendation providers frequently want order and audio data to improve their models across the whole customer base, which is the clause that breaks service-provider status. Read three things in each agreement — purpose limitation, the no-combining clause, and whether training on your data is permitted.

A customer asked for their data at the counter. Does that count?

Yes. The obligation is to provide methods for submitting requests that reflect how you interact with consumers, and a business that serves people in person needs a path for an in-person or telephone request. The failure mode is not refusal, it is silence — a shift manager who has no idea what was asked, so nothing is logged and the response clock runs out unacknowledged. The fix is operational rather than legal. Give staff a one-line script, a single destination to route to, and permission to take the request without judging whether it qualifies. Log the date it arrived, because the deadline runs from receipt rather than from the moment head office hears about it. Verification comes later and is a separate step; collecting the request is what must not fail at the counter.

In a franchise, who answers a deletion request?

Whoever is the business for the data being asked about, which in a franchise is usually both parties for different slices. The franchisee typically determines purposes and means for its own restaurant transactions. The franchisor typically does so for the brand app, the loyalty program and system-wide analytics. A single deletion request can therefore reach two entities with two systems, and the consumer does not know or care about that split. Two things make it workable. First, a data addendum to the franchise agreement that allocates roles explicitly, names who receives requests, sets turnaround for the other party's portion, and covers retention and breach notification. Second, a privacy notice that tells the consumer which entity holds what, so the request lands correctly the first time. Both are cheap to write before anyone asks and effectively impossible to negotiate during an inquiry.

The Receipt Test

Take a receipt from one of your own locations and try to complete a deletion request using only what is printed on it and what is visible at the counter.

If there is no route from that piece of paper to a person who knows what to do, the gap is not the privacy policy on the website. It is that the request channel the statute assumes exists has never been built on the side of the business where the customers actually are.

Related Reading