Skip to main content

Privacy Policy

Spillover Privacy Policy
Updated: 24 August 2026

Spillover Software Group, LLC ("Spillover," "we," "us" or "our") provides restaurant websites, online ordering, eCommerce, email and text marketing, reputation and social media tools, reservations, loyalty, analytics, automation, artificial-intelligence-enabled tools and related digital marketing services (collectively, the "Platform") to restaurants and other businesses (our "Customers").

This Privacy Policy is our single privacy notice and is intended to cover both: (1) visitors to Spillover.com and people who interact directly with Spillover as prospects, Customers, partners, vendors or business contacts; and (2) restaurant guests, diners, consumers and other individuals ("End Users") who interact with a Customer through a website, online ordering page, reservation tool, form, loyalty program, email, text message, review workflow, social feature or other service powered or supported by Spillover. Customer websites may link directly to this Privacy Policy as the privacy notice for Spillover-powered functionality.

Important: When you interact with a Restaurant or other Customer, that Customer may also have its own privacy practices, legal obligations and notices. Spillover provides technology and services to the Customer and may process information on the Customer's behalf as well as for the purposes described in this Policy.

1. Information We Collect

The information we collect depends on how you interact with Spillover, a Customer and the Platform. It may include:

  • Contact and business information, including name, email address, phone number, company or Restaurant name, job title, sales or support enquiries, account information, billing contacts and correspondence.
  • Device and usage information, including browser and device type, IP address, time zone, cookies, pages viewed, referring pages, search terms, clicks and other interactions with Spillover.com or the Platform.
  • Order and transaction information, including name, billing or delivery address, items ordered, order frequency, Restaurant location, fulfillment details, refunds and other transaction information. Payment card information is generally processed and tokenized by independent payment processors rather than stored by Spillover.
  • End User contact and account information, including email address, mobile number, loyalty or club information, form submissions, reservation details and information provided when interacting with a Customer.
  • Feedback and reputation information, including surveys, ratings, reviews, social interactions and other feedback intended for a Customer or public display.
  • We store only very limited, if any, financial information that we collect. Otherwise, all financial information is stored by our payment processing partner and their privacy policy can be found at  https://jupico.com/privacy-policy/ opens a new site page
  • Location information when you choose to provide it or when reasonably necessary for delivery, store selection or other location-based functionality.
  • Information received through integrations and third-party services, including APIs, Google services, social networks, communications providers, payment processors, reservation systems, delivery providers and other services connected to the Platform.

2. Cookies, Analytics and Advertising Technologies

We and service providers acting on our behalf may use cookies, pixels, web beacons and similar technologies to operate Spillover.com and the Platform, remember preferences, understand usage, improve functionality, measure campaign performance and, where permitted by law, support remarketing, targeted or interest-based advertising. You can control cookies through your browser or device settings and, where available, through applicable cookie controls. Disabling some cookies may affect functionality.

3. How We Use Personal Information

We may use personal information to:

  • Provide, operate, secure, maintain and support Spillover.com, the Platform and the services requested by our Customers and End Users.
  • Respond to demo requests, sales enquiries, support requests, billing matters and other business communications.
  • Process orders, reservations, loyalty activity, customer-service requests and other transactions and communications.
  • Send transactional communications and, where permitted by law, email, text and other marketing communications on behalf of Customers or Spillover.
  • Personalize experiences, analyze usage, campaign performance and engagement, and improve or develop our products, services and artificial-intelligence-enabled tools.
  • Conduct analytics, benchmarking, market intelligence, audience measurement, affiliate, referral, co-marketing, joint-marketing and targeted or interest-based advertising activities where permitted by law and subject to required choices.
  • Protect security and integrity, prevent fraud or misuse, enforce agreements and comply with legal obligations.
  • Create aggregated, anonymized, de-identified, statistical, analytical, benchmarking and other derived information as described below.

4. Customer Data, Spillover Databases and Resultant Data

As between Spillover and a Customer, the Customer retains whatever rights it has under applicable law in identifiable End User Data relating to its End Users. This does not give the Customer or End User any ownership interest in Spillover's Platform, databases, database architecture, database compilations, metadata, system-generated records, analytical outputs or Resultant Data.

Spillover has a worldwide, royalty-free, transferable and sublicensable right to host, copy, store, organize, structure, transmit, process, analyze, combine and otherwise use identifiable data as reasonably necessary to provide, secure, support, maintain, operate, improve and develop the Platform; carry out lawful Customer instructions; prevent fraud and misuse; comply with law; maintain business continuity; create and exploit Resultant Data; and support a Corporate Transaction, subject to applicable law.

"Resultant Data" includes aggregated, anonymized, de-identified, statistical, analytical, benchmarking, inferred, modeled or derived data, metadata, metrics, trends, scores, segments, models, reports, outputs, compilations and insights generated from or relating to the operation or use of Spillover.com, the Platform, Customer data or End User activity, provided that it does not identify an individual End User and, where required by law, does not identify a Customer as its source.

Spillover exclusively owns its Platform, databases, database architecture, database compilations, metadata, system-generated records, analytical outputs and Resultant Data, including the organization, selection, arrangement, methodologies, models, benchmarks and insights embodied in or generated from them. Spillover may retain, reproduce, combine, analyze, commercialize, license, sell, disclose, transfer and otherwise use Resultant Data and related non-identifying information for any lawful business purpose, including analytics, benchmarking, product development, market intelligence, artificial intelligence and machine learning.

Spillover does not sell identifiable End User or business-contact information as a standalone data product unrelated to our services. We may use and disclose identifiable information as described in this Policy. Where applicable law treats targeted advertising, analytics, joint marketing or another disclosure as a "sale" or "sharing," we will provide any notice, opt-out mechanism or other rights required by that law.

5. How We Share Information

We may disclose personal information:

  • To the relevant Customer with whom an End User is interacting, so the Customer can provide products, services, support, marketing and customer service.
  • To service providers and technology partners that help us operate our website, Platform and business, including hosting, communications, messaging, CRM, payment processing, analytics, security, reservation, delivery, advertising and integration providers.
  • To Spillover affiliates where reasonably necessary to operate, improve, market, finance and support our business and Platform.
  • To selected advertising, analytics, referral, co-marketing or joint-marketing partners where permitted by law and subject to any required notice, consent or opt-out rights.
  • Where required by law, legal process or government request, or where reasonably necessary to protect rights, safety, security, prevent fraud or enforce agreements.
  • With your consent or at your direction.
  • In connection with a Corporate Transaction as described below.

Third-party services may also be governed by their own privacy policies and terms.

6. Corporate Transactions and Business Transfers

Personal information, customer relationships, contracts, the Platform, databases, metadata, analytical outputs, End User Data, Resultant Data and related business records may be reviewed, disclosed, assigned, sold or transferred in connection with a financing, investment, merger, acquisition, reorganization, change of control, sale of equity, sale of assets, bankruptcy or similar corporate transaction (a "Corporate Transaction"). Information may be shared with bona fide prospective investors, lenders, purchasers and their professional advisers under appropriate confidentiality arrangements and may be transferred to an affiliate, successor or acquirer, subject to applicable law.

A successor or acquirer may continue to process identifiable personal information for purposes consistent with this Policy, applicable Customer agreements and applicable law. No separate consent is required for a Corporate Transaction unless applicable law requires it. Spillover may retain and transfer Resultant Data, metadata, analytical outputs and other non-identifying information, and a successor or acquirer may own, retain, commercialize, license, sell, transfer and otherwise use those assets to the same extent as Spillover.

7. Online Ordering, Delivery, Reservations and Other Customer Services

Spillover provides its own online ordering technology as part of the Platform. Spillover is not the Restaurant, food provider or delivery company. Restaurants are responsible for the underlying products, menus, pricing, taxes, preparation, fulfillment, refunds and customer service. Delivery, payment processing, mapping, reservations and other connected services may be performed by the Restaurant or independent third parties. Those third parties may process information under their own privacy policies and terms.

8. Email Marketing

Our Platform is designed for permission-based or otherwise lawful email marketing. Customers are responsible for ensuring that they have the rights, permissions or lawful basis required to send marketing communications. Marketing emails sent through the Platform include an unsubscribe mechanism. If you receive unwanted email sent through our Platform, use the unsubscribe link or contact support@spillover.com.

9. Text Messaging

Spillover may provide text messaging functionality through telecommunications and messaging service providers, currently at time of publication Spillover offers our Customers a text messaging service via a 3rd party called iVisionMobile (ivisionmobile.com). Through iVisionMobile we provide a sophisticated software system that allows our Customers to create and manage interactive mobile campaigns. Companies use iVision Mobile to interact with their target audience using mobile phones through text messages, mobile content such as ringtones, wallpapers, video, and more.

This service complies with TCPA regulations. Key to these regulation is that (i) Our Customer (restaurant or small business) must have prior express consent from you (the End User) prior to texting you (ii) they must inform you that your giving permission will allow them to send ongoing messages (although usually there is a limitation stated on the frequency this will happen) and (iii) that your consent (for text messaging) is not required for you to be able to purchase goods or services from them

Customers are responsible for obtaining any consent required by law and carrier rules before sending marketing messages. Message and data rates may apply. Message frequency varies by program. Consent to receive marketing messages is not a condition of purchase where prohibited by law. You may opt out by replying STOP, END, CANCEL, UNSUBSCRIBE or QUIT, or by following other opt-out instructions. For help, reply HELP where supported or contact support@spillover.com or contact iVisionMobile directly at support@ivisionmobile.com opens your email app.  If you are experiencing problems with opting out of a mobile campaign, please email us including your cellphone # to support@spillover.com opens your email app . Include in email title the word “Text Issues” and address it to our Data Protection Officer.

Carriers Supported

The following carriers are currently supported on the iVision Mobile platform: T-Mobile, Sprint, Nextel, Boost, AT&T, Cellular One Dobson, Alltel, Verizon Wireless, Virgin Mobile, Cricket, Cincinnati Bell, and Cellular South. More carriers will be added to this list when they participate with the iVisionMobile programs.

CTIA Compliance

CTIA recommends the following rules be applied for SMS text messaging and Spillover strongly encourages our Customers to follow these rules and supports their application through our Platform;

  • All messages should convey a clear call to action.
  • End Users must understand precisely what they’re signing up to receive.
  • Clearly labeled Terms & Conditions and Privacy Policy links must be displayed in the opt-in message.
  • Once a subscriber their SMS program, our Customer must send them a message that includes the description of the recurring program, the message frequency, a disclaimer that message and data rates may apply for each message, and information about getting help or opting out.
  • Subscribers must be able to opt-out at any time by responding with language like: “stop,” “end,” “cancel,” “unsubscribe,” or “quit.”
  • Subscribers should be able to get help by responding with the message “help,” which should automatically respond with the program name and information on getting help.
  • All outgoing text messages must clearly include our Customers business name.
  • Content such as (but not limited to) hate speech, certain firearms, and violence cannot be promoted via SMS messaging.
  • Programs must display opt-out instructions at regular intervals in SMS messages.
  • Opt-out information must be clearly displayed in the message or within the Terms & Conditions

10. Google User Data

Where the Platform receives information through Google APIs, our use of information received from Google APIs will comply with applicable Google API Services User Data Policy requirements, including any Limited Use requirements that apply. We use Google-provided data to support Platform functionality, provide relevant information to our Customers and improve the End User experience. We do not publicly disclose personally identifiable Google user data except as authorized by the user, required to provide the service, or required by law.

11. Data Retention, De-Identification and Deletion

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including to provide services, maintain business and transaction records, protect security, prevent fraud, resolve disputes, enforce rights, complete Corporate Transactions and comply with legal obligations.

We may anonymize, de-identify, aggregate or derive information from personal information so that it can no longer reasonably be associated with an individual. Once information has been lawfully de-identified or incorporated into Resultant Data, Spillover may retain, own, combine, analyze, commercialize, license, disclose, transfer and otherwise use it indefinitely and is not required to re-identify it in response to an individual access or deletion request.

You may request deletion or other privacy rights by contacting support@spillover.com. We may retain information where necessary to provide a requested service, protect security, comply with law, maintain records, establish or defend legal claims, or for other purposes permitted by law. Where a Customer controls the underlying End User relationship, we may refer or coordinate the request with that Customer.

12. Security

We use reasonable administrative, technical and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Public Authority and Law Enforcement Requests

Spillover reviews legally valid requests for personal information in accordance with applicable law. We may require appropriate legal process, such as a subpoena, court order or warrant, depending on the information requested. Where legally permitted and appropriate, we may notify the affected individual or Customer and seek to disclose only information reasonably necessary to respond to a valid request. Emergency requests involving an immediate risk of death or serious bodily injury may be sent to legal@spillover.com and support@spillover.com.

14. Children

Spillover.com and the Platform are intended for a general audience and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information, contact us so that we can take appropriate action.

15. Your Privacy Rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of certain personal information, or to object to or restrict certain processing. You may also have rights relating to targeted advertising, sale or sharing of personal information, or the use of sensitive personal information where applicable. To exercise a privacy right, contact support@spillover.com. We may need to verify your identity.

16. California Privacy Rights

California residents may have additional rights under California law, including rights to know, access, correct or delete certain personal information and, where applicable, to opt out of sale or sharing of personal information or certain uses of sensitive personal information. We will not discriminate against you for exercising applicable privacy rights. California Civil Code Section 1798.83 may also permit eligible California residents to request certain information regarding disclosures for third parties' direct marketing purposes.

17. Third-Party Links and Services

Spillover.com, Customer websites and the Platform may contain links to or integrations with third-party websites and services. Their privacy practices are governed by their own policies and terms, and Spillover is not responsible for the privacy practices of independent third parties.

18. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted with a revised Updated date. Where required by law, we will provide additional notice of material changes.

19. Contact Information

For privacy questions or requests, contact the Spillover Data Protection Officer at support@spillover.com or write to:

Spillover Software Group, LLC
7600 Burnet Road, Suite 170
Austin, Texas 78757

For End Users: This Privacy Policy is intended to be the privacy notice linked from Spillover-powered Customer websites and other End User-facing Platform services.

Ready to Learn More?

Take advantage of seasonal package pricing
when you Schedule a Demo Today!