171 S Rio Grande St, Salt Lake City, UT

Privacy Policy

This Privacy Policy describes how Costa Vida ("we," "us," "our," or the "Company") collects, uses, discloses, and protects your personal information when you visit our website at costavida-eat.click, place orders, participate in loyalty programs, or otherwise interact with our services. Please read this policy carefully. By accessing or using our website and services, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy.

We are committed to protecting your privacy and handling your personal information in an open and transparent manner. This policy has been prepared in compliance with applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Federal Trade Commission Act (FTC Act), the CAN-SPAM Act, and other relevant regulations governing the collection and use of personal data.


1. Who We Are

Costa Vida is a food service business operating in the United States. We provide customers with a high-quality dining experience through our website, online ordering platform, and other digital services.

Company Name Costa Vida
Website costavida-eat.click
Email Address [email protected]

For all privacy-related questions, requests, or concerns, please contact us using the information above or refer to Section 14 of this policy.


2. Information We Collect

We collect several types of information from and about users of our website and services, including information by which you may be personally identified. The categories of personal information we collect include:

2.1 Personal Identification Information

When you create an account, place an order, sign up for our newsletter, join our loyalty program, or contact us, we may collect:

  • Full name
  • Email address
  • Mailing address and delivery address
  • Telephone number
  • Date of birth (for verification and promotional purposes)
  • Username and password (for account creation)
  • Payment information, including credit card numbers, billing address, and related financial data (processed securely via third-party payment processors)
  • Dietary preferences or food restrictions, if voluntarily provided

2.2 Order and Transaction Information

When you make a purchase through our website or app, we collect:

  • Order history and purchase details
  • Items ordered, customizations, and special requests
  • Payment method type and last four digits of card
  • Order confirmation numbers and timestamps
  • Delivery and pickup preferences

2.3 Usage Data and Technical Information

When you visit our website, we automatically collect certain technical information about your visit, including:

  • IP address and approximate geographic location
  • Browser type, version, and language settings
  • Operating system and device type
  • Pages visited, time spent on each page, and navigation paths
  • Referring URLs (the web page from which you arrived at our site)
  • Search queries entered on our website
  • Date and time of access
  • Error logs and crash reports

2.4 Cookie and Tracking Data

We use cookies, web beacons, pixel tags, and similar tracking technologies to collect information about your browsing behavior on our website. This includes session cookies, persistent cookies, and third-party cookies placed by analytics and advertising partners. For more details, please see Section 9 of this policy.

2.5 Communications Data

If you contact us via email, phone, chat, or social media, we may retain:

  • The content of your messages and correspondence
  • Contact details you provide when reaching out
  • Records of your requests, complaints, or feedback

2.6 Social Media and Third-Party Login Data

If you choose to log in or register using a third-party service (such as Google, Apple, or Facebook), we may receive information from those platforms in accordance with their privacy policies, including your name, email address, and profile picture.

2.7 Information You Provide Voluntarily

From time to time, we may conduct surveys, promotions, or contests. If you participate, we collect the information you provide, such as your opinions, preferences, and any other information you voluntarily submit.


3. How We Use Your Information

We use the personal information we collect for a variety of business and operational purposes, including:

3.1 Providing and Managing Our Services

  • Processing and fulfilling your food orders and transactions
  • Managing your user account and loyalty program membership
  • Communicating order confirmations, updates, and delivery notifications
  • Facilitating payment processing through secure third-party processors
  • Providing customer support and responding to your inquiries
  • Personalizing your dining experience based on past orders and preferences

3.2 Analytics and Website Improvement

  • Analyzing website traffic patterns, user behavior, and performance metrics
  • Understanding which menu items, promotions, and features are most popular
  • Identifying and fixing technical issues, bugs, or security vulnerabilities
  • Testing new features and improving the overall functionality of our website
  • Conducting internal research to better understand our customer base

3.3 Marketing and Promotional Communications

  • Sending promotional emails, newsletters, and special offers (with your consent or as permitted by law)
  • Notifying you about new menu items, seasonal promotions, and events
  • Displaying personalized advertisements on our website and third-party platforms
  • Running targeted advertising campaigns based on your browsing history and preferences
  • Administering contests, sweepstakes, or loyalty reward programs

3.4 Legal Compliance and Safety

  • Complying with applicable federal, state, and local laws and regulations
  • Responding to lawful requests from government authorities or law enforcement
  • Protecting against fraud, unauthorized transactions, and misuse of our services
  • Enforcing our Terms of Service and other agreements
  • Protecting the rights, property, and safety of Costa Vida, our customers, and the public

4. Legal Basis for Processing Personal Information

As a business operating in the United States, we process your personal data based on the following grounds:

  • Contractual Necessity: Processing is necessary to fulfill your orders and provide the services you requested.
  • Legitimate Interests: We process data to operate, improve, and grow our business, provided such interests are not overridden by your rights.
  • Consent: Where required by law, we obtain your explicit consent before processing your data, particularly for marketing communications.
  • Legal Obligation: Processing may be required to comply with applicable federal or state legal requirements.

5. Sharing Your Information with Third Parties

We value your privacy and do not sell your personal information to third parties for their own marketing purposes. However, we may share your information in the following circumstances:

5.1 Service Providers and Business Partners

We work with trusted third-party vendors and service providers who assist us in operating our website and delivering services. These may include:

  • Payment Processors: Secure payment gateways (e.g., Stripe, Square, PayPal) that handle financial transactions on our behalf
  • Delivery Platforms: Third-party delivery services that facilitate order fulfillment
  • Analytics Providers: Services such as Google Analytics that help us understand website usage
  • Email and Marketing Platforms: Services used to send newsletters and promotional emails
  • Cloud Hosting Providers: Companies that store and manage our website data and databases
  • Customer Support Tools: Platforms used to manage customer inquiries and support tickets

All service providers are contractually required to protect your personal information and may only use it for the specific purposes for which it was shared.

5.2 Legal Requirements and Law Enforcement

We may disclose your personal information if required to do so by law, court order, or government regulation, or if we believe in good faith that such disclosure is necessary to:

  • Comply with a legal obligation under applicable federal or state law
  • Respond to a valid subpoena, court order, or government request
  • Investigate or prevent fraudulent, harmful, or illegal activity
  • Protect the vital interests of an individual

5.3 Business Transfers

In the event that Costa Vida undergoes a merger, acquisition, reorganization, asset sale, or bankruptcy proceeding, your personal information may be transferred to the successor entity. We will notify you via email or a prominent notice on our website before your information is transferred and becomes subject to a different privacy policy.

5.4 Aggregated and De-Identified Data

We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you personally with third parties for research, analytics, or promotional purposes.


6. Data Security

We take the security of your personal information seriously and implement a range of technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. Our security practices include:

6.1 Technical Safeguards

  • Encryption: All data transmitted between your browser and our website is encrypted using Secure Socket Layer (SSL) / Transport Layer Security (TLS) technology.
  • Secure Payment Processing: We do not store full payment card details on our servers. Payment data is processed by PCI DSS-compliant third-party processors.
  • Firewalls and Intrusion Detection: Our servers are protected by firewalls, intrusion detection systems, and regular security monitoring.
  • Access Controls: Access to your personal information is restricted to employees and contractors who need it to perform their job functions.
  • Data Minimization: We only collect and retain the minimum amount of data necessary for the purposes described in this policy.

6.2 Organizational Safeguards

  • Regular employee training on data privacy and security best practices
  • Internal data protection policies and procedures
  • Vendor due diligence and data processing agreements with all third-party service providers
  • Periodic security audits and vulnerability assessments

Despite these measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, and you provide personal information at your own risk. If you suspect your account has been compromised, please contact us immediately at [email protected].


7. Your Privacy Rights

Depending on your location and applicable law, you may have various rights regarding the personal information we hold about you.

7.1 General Rights (All Users)

  • Right to Access: You may request a copy of the personal information we hold about you.
  • Right to Correction: You may request that we correct inaccurate or incomplete personal information.
  • Right to Deletion: You may request that we delete your personal information, subject to certain exceptions required by law.
  • Right to Opt-Out of Marketing: You may unsubscribe from marketing emails at any time by clicking the "unsubscribe" link in any email or by contacting us directly.
  • Right to Data Portability: Where technically feasible, you may request a copy of your data in a structured, commonly used, and machine-readable format.

7.2 How to Exercise Your Rights

To exercise any of the rights listed above, please submit a request using one of the following methods:

We will respond to your request within 45 days of receipt. If we need additional time to respond (up to 90 days total), we will notify you in writing within the initial 45-day period. We may need to verify your identity before processing your request.

7.3 Non-Discrimination

We will not discriminate against you for exercising your privacy rights. We will not deny you goods or services, charge you different prices, provide a different quality of service, or suggest that you will receive worse service for exercising your rights under applicable privacy law.


8. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by applicable law. Our general retention periods are as follows:

Category of Data Retention Period
Account and profile information Until account deletion plus 2 years
Order and transaction history 7 years (for tax and legal compliance)
Payment records 7 years (as required by financial regulations)
Marketing and communication preferences Until opt-out plus 3 years
Website usage and analytics data 26 months (or as configured with analytics provider)
Customer support communications 3 years from last interaction
Cookie and tracking data Session cookies: until browser closes; Persistent cookies: up to 2 years
Legal and compliance records As required by applicable law (typically 5–10 years)

When personal information is no longer needed, we will securely delete, anonymize, or destroy it in accordance with our data disposal procedures.


9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze usage, and deliver relevant advertising. Cookies are small text files placed on your device when you visit a website.

9.1 Types of Cookies We Use

  • Essential Cookies: Necessary for the website to function properly. They enable core functions such as security, account login, and order processing. These cannot be disabled.
  • Analytics Cookies: Used to collect information about how visitors use our website, such as pages visited and time spent. We use tools like Google Analytics for this purpose.
  • Functional Cookies: Allow the website to remember your preferences (such as language, location, and cart contents) to improve your experience.
  • Marketing and Advertising Cookies: Used to track your activity across websites to deliver personalized advertisements. These may be set by us or by third-party advertising partners.

9.2 Managing Your Cookie Preferences

You can control or disable cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our website. Most browsers allow you to:

  • View and delete cookies stored on your device
  • Block cookies from specific websites or all websites
  • Configure alerts when cookies are set

For more detailed information about our use of cookies and how to manage your preferences, please refer to our Cookie Policy.


10. Children's Privacy

Our website and services are intended for users who are 18 years of age or older. We do not knowingly collect, use, or disclose personal information from individuals under the age of 18.

If you are a parent or guardian and believe that your child under the age of 18 has provided us with personal information without your consent, please contact us immediately at [email protected]. Upon confirmation, we will take prompt steps to delete the child's information from our records.

Our practices are consistent with the Children's Online Privacy Protection Act (COPPA), which prohibits the collection of personal information from children under 13 years of age without verifiable parental consent. We extend this protection to all minors under the age of 18.


11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), effective January 1, 2023.

11.1 Your California Rights

  • Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you in the past 12 months, the sources of collection, the business purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You have the right to request deletion of your personal information that we have collected, subject to certain exceptions.
  • Right to Correct: You have the right to request that we correct inaccurate personal information we maintain about you.
  • Right to Opt-Out of Sale or Sharing: You have the right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of sensitive personal information to specific permitted purposes.
  • Right to Non-Discrimination: You have the right not to be discriminated against for exercising your privacy rights.

11.2 Categories of Personal Information Collected (Last 12 Months)

Category Collected Purpose
Identifiers (name, email, IP address) Yes Service provision, account management
Commercial information (order history) Yes Order fulfillment, loyalty program
Internet/network activity (browsing data) Yes Analytics, website improvement
Geolocation data (approximate) Yes Delivery, location-based promotions
Inferences (preferences, interests) Yes Personalization, targeted marketing

11.3 How to Submit a California Privacy Request

California residents may submit privacy requests by emailing us at [email protected] with the subject line "California Privacy Request." We will verify your identity before processing your request and respond within 45 days.


12. International Data Transfers

Costa Vida is based in the United States, and all data processing activities primarily take place within the United States. However, some of our third-party service providers may be located in or process data in other countries. By using our services, you acknowledge that your personal information may be transferred to and processed in countries other than your country of residence, which may have different data protection standards.

Whenever we transfer personal information internationally, we take appropriate measures to ensure that such transfers comply with applicable laws and that your data is afforded an adequate level of protection. These measures may include data transfer agreements incorporating standard contractual clauses or other legally recognized mechanisms.

Our primary operations are domestic, and we follow all applicable U.S. federal and state privacy laws, including the FTC Act provisions governing unfair or deceptive privacy practices.


13. Third-Party Links and Services

Our website may contain links to third-party websites, social media platforms, delivery partners, or other external services. This Privacy Policy applies only to information collected by Costa Vida through our website and services. We are not responsible for the privacy practices of third-party websites, and we encourage you to review their privacy policies before providing any personal information.

Third-party services that may be integrated into our website include, but are not limited to:

  • Social media platforms (Facebook, Instagram, Twitter/X)
  • Delivery platforms (DoorDash, Uber Eats, Grubhub)
  • Payment processors (Stripe, PayPal, Square)
  • Analytics tools (Google Analytics, Meta Pixel)

14. How to File a Privacy Complaint

If you believe we have not handled your personal information in accordance with this Privacy Policy or applicable law, you have the right to file a complaint.

14.1 Contact Us First

We encourage you to contact us directly so that we can address your concerns promptly:

We will acknowledge your complaint within 5 business days and endeavor to resolve the matter within 30 business days.

14.2 Regulatory Complaints

If you are not satisfied with our response, or if you believe we are processing your personal information in violation of applicable law, you may file a complaint with the relevant authorities:

  • Federal Trade Commission (FTC): The FTC enforces federal consumer privacy laws and can be reached at:
    Website: ftc.gov/complaint
    Phone: 1-877-382-4357
  • California Attorney General (for California Residents): The California Attorney General enforces the CCPA/CPRA:
    Website: oag.ca.gov/privacy/ccpa
  • California Privacy Protection Agency (CPPA): The dedicated California agency for privacy enforcement:
    Website: cppa.ca.gov
  • State Attorney General: Residents of other states may also contact their state's Attorney General's office regarding potential privacy law violations.

15. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Post a prominent notice on our website homepage
  • Send an email notification to registered users (where required by law)

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our website and services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.


16. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to contact us:

Costa Vida — Privacy Inquiries

We are committed to working with you to achieve a fair resolution of any complaint or concern about your privacy. Our privacy team will review your request and respond in a timely and professional manner.


This Privacy Policy was last reviewed and updated on May 20, 2026. © 2026 Costa Vida. All rights reserved.