1. Scope and our role
This Privacy Policy applies to the Coorder application for Apple devices, its supporting cloud services, and the Coorder integration available through the Clover App Market (collectively, the “Service”). Coorder is provided by DomePath (“DomePath,” “we,” “us,” or “our”).
For information received from Clover on behalf of a restaurant or other business using Coorder (a “Merchant”), the Merchant determines why that information is processed and DomePath generally acts as a service provider or data processor. This policy does not replace the privacy notice that a Merchant may need to provide to its customers or personnel.
2. Information we process
Coorder account information
Coorder uses Sign in with Apple and Firebase Authentication. Depending on what you choose to share through Apple, we may receive and process your Apple account identifier, name, email address or Apple private relay email address, and a Firebase user identifier. We do not receive your Apple password.
Merchant and Clover connection information
When a Merchant authorizes Coorder, we process the Clover Merchant ID, merchant name, selected Clover environment, authorization status, connection and verification timestamps, and OAuth access and refresh tokens. One-time connection codes are validated in the secure backend and are not stored in the Coorder app on the Apple device.
Order and menu information
To provide order synchronization, Coorder processes operational order information made available by Clover, including:
- Clover order, line-item, item, and order-type identifiers;
- order creation and modification times, order title or reference, order type, and cancellation state;
- item names, alternate names, quantities, modifiers, item notes, and order-level special instructions; and
- menu or inventory item identifiers and names needed to connect Clover items with Coorder inventory.
Coorder does not request or store payment card numbers, bank account information, payment totals, taxes, tips, or Clover employee records through this integration.
Information created in Coorder
We process content that authorized users create or configure in Coorder, such as orders entered in the app, preparation status, inventory records, categories, modifiers, work areas, order types, board settings, display preferences, and a custom restaurant logo.
Technical and support information
Our service providers may automatically process limited technical information required to operate and secure the Service, such as IP address, request timestamps, authentication events, device or operating-system information, diagnostic logs, and error details. If you contact us, we process the information included in your support request.
3. Sources of information
We receive information directly from authorized Coorder users, from Apple when a user chooses Sign in with Apple, from Clover after the Merchant installs and authorizes Coorder, and automatically from the systems used to provide and secure the Service.
4. How we use information
We process information only as reasonably necessary to:
- authenticate users and maintain Coorder accounts;
- authorize, verify, maintain, and disconnect Clover integrations;
- receive Clover order events and synchronize order and menu information into the correct Merchant’s Coorder workspace;
- display, organize, update, and recover restaurant order workflows;
- provide inventory mapping and other features requested by the Merchant;
- protect the Service, prevent unauthorized connections, troubleshoot failures, and enforce our terms;
- provide support and communicate material service or security information; and
- comply with applicable law and lawful requests.
We do not use Clover Merchant Data for third-party advertising or to build advertising profiles.
6. Security
We use reasonable administrative and technical safeguards designed to protect information. Clover tokens, connection challenges, and private integration events are kept in the backend rather than stored in the Coorder app on the Apple device. Access to Merchant data is tied to authenticated accounts, and sensitive requests are sent over encrypted network connections.
No method of storage or transmission is completely secure. We therefore cannot guarantee absolute security.
7. Retention, disconnection, and deletion
We retain account and Merchant information for as long as reasonably necessary to provide the Service, maintain the Clover integration, resolve synchronization failures, protect the Service, comply with legal obligations, resolve disputes, and enforce agreements.
A Merchant can disconnect its Clover merchant from the Coorder settings. The Merchant can also revoke Coorder’s Clover authorization through Clover. Revoking authorization in Clover is the most direct way to invalidate Clover access tokens. Users can initiate Coorder account deletion from the app. To request deletion or confirm removal of backend Clover integration records, contact us at leonardo.arias@domepath.com.
Information may remain for a limited period in backups, security logs, fraud-prevention records, or records that we must retain by law. We delete or de-identify information when it is no longer reasonably needed.
8. Privacy rights and choices
Depending on location and subject to legal exceptions, individuals may have rights to request access, correction, deletion, restriction, objection, or portability of personal information. Customers or personnel of a Merchant should normally direct requests to that Merchant because the Merchant controls the applicable relationship and can identify the relevant order or account. We will reasonably assist Merchants with valid requests.
Merchants and Coorder account holders may send a request to leonardo.arias@domepath.com. We may need to verify the requester’s identity and authority before acting. We will not discriminate against anyone for exercising an applicable privacy right.
9. United States and California disclosures
During the preceding 12 months, Coorder may have processed the following categories of personal information for the business purposes described above:
| Category | Examples in Coorder | Business-purpose recipients |
|---|---|---|
| Identifiers | Account identifier, email or private relay email, Merchant ID, order and item identifiers | Merchant, Apple, Clover, Firebase/Google Cloud |
| Commercial information | Products ordered, quantities, modifiers, order type, notes, and order status | Merchant, Clover, Firebase/Google Cloud |
| Internet or network activity | Authentication events, service requests, IP address, timestamps, and operational logs | Firebase/Google Cloud and security or support providers |
Coorder does not sell these categories and does not share them for cross-context behavioral advertising. We do not knowingly use or disclose sensitive personal information for purposes that require a right to limit under California law.
10. International processing
Coorder’s cloud infrastructure may process information in the United States or other countries where our providers operate. Where required, DomePath will use an approved transfer mechanism and reasonable safeguards for cross-border transfers. Merchants remain responsible for providing notices and establishing a lawful basis for information they direct Coorder to process.
11. Children and tracking
Coorder is a business service and is not directed to children. We do not knowingly collect personal information directly from children through Coorder accounts.
The Coorder app does not engage in cross-app behavioral advertising. Because the Service does not track users across third-party websites for advertising, it does not respond differently to browser “Do Not Track” signals.
12. Changes to this policy
We may update this Privacy Policy to reflect changes to Coorder, our Clover integration, legal requirements, or our practices. We will update the date at the top of this page and provide additional notice when required by law.
