PRIVACY POLICY

Last updated: 20 June 2026
Effective from: 20 June 2026
Version: 1.0

1. About This Policy

This Privacy Policy explains how Paul Hepple, a sole trader trading as DarkByte Creations handles personal data in connection with NibbleKit.

In this policy, DarkByte, NibbleKit, we, us and our refer to Paul Hepple trading as DarkByte Creations.

This policy applies to NibbleKit services that link to it, including, where applicable:

NibbleKit is a white-label technology platform. A NibbleKit-powered service may display a participating Merchant's brand.

A Merchant may have its own privacy notice covering its independent use of personal data. This policy does not replace that notice.

2. Who We Are

DarkByte's contact details are:

Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com Privacy contact: privacy@darkbyte.uk Telephone: 07549 253991 ICO registration number: not published here; available where legally required

3. Key Terms

In this policy:

4. DarkByte, Merchant and Provider Roles

Privacy roles are determined by the actual decisions each party makes about the purposes and essential means of processing. A contractual label does not by itself determine the role.

DarkByte acts as an independent controller where it decides why and how personal data is used for its own purposes.

A Merchant acts as an independent controller where it decides why and how data is used for its sales, fulfilment, food-safety, customer-service and business purposes.

DarkByte acts as a processor where it stores, transmits or otherwise handles data solely on a Merchant's documented instructions.

A payment provider, app store, bank, delivery provider or other third party may act as a separate controller for its own regulated, contractual, security or commercial processing.

Two parties are not joint controllers merely because they both receive the same data or work together. Joint controllership arises only where they jointly determine the purposes and essential means of a particular processing activity.

5. Processing-Role and Lawful-Basis Matrix

The table below describes the standard NibbleKit platform position.

Optional features apply only where they are enabled in the relevant NibbleKit environment, Merchant configuration or checkout flow.

Processing activityDarkByte's roleMerchant or other party's rolePersonal data and purposeDarkByte lawful basis where DarkByte is controller
Public NibbleKit websites and policy pagesIndependent controllerA Merchant may separately control its own pagesDevice, browser, request, security and communication information used to deliver and protect pagesLegitimate interests under Article 6(1)(f); consent where required for optional storage or access technologies
Customer account registration, authentication and account securityIndependent controller for standard NibbleKit authentication and platform account securityMerchant may be a separate controller for its branded customer relationshipName, email, telephone number, identifiers, authentication state, credentials, preferences and security eventsContract under Article 6(1)(b); legitimate interests under Article 6(1)(f); legal obligation under Article 6(1)(c) where applicable
Merchant User authentication and platform accessIndependent controller for platform identity, role security and auditMerchant is an independent controller for deciding who is authorised and for its staff administrationName, work contact details, Merchant, role, permissions, login and audit informationLegitimate interests under Article 6(1)(f); performance of the Merchant contract where Article 6(1)(b) applies; legal obligation where applicable
Merchant menus, product information and availabilityNormally processor for the Merchant's published business content; controller for platform-security logsMerchant is controller for menu and product information linked to Customers or staffProduct interactions, configuration and limited audit informationMerchant determines the basis for processor activity; DarkByte relies on legitimate interests for its separate security and audit processing
Customer order submission, order management and fulfilmentProcessor for the Merchant's order processing, except for separate DarkByte purposes identified in this tableMerchant is independent controller and sellerCustomer identity, contact details, order contents, address, delivery or collection details, instructions and order statusMerchant determines the basis for processor activity; DarkByte may rely on contract, legitimate interests or legal obligation for limited platform records used for its own account, security, dispute or compliance purposes
Customer order history displayed in an accountProcessor for Merchant order records; controller for account access and securityMerchant is controller for the underlying order and customer relationshipHistoric orders, Merchant, dates, status, totals and related account linkageMerchant determines the basis for order records; DarkByte uses contract and legitimate interests for secure account presentation
Payments, refunds and chargebacksIndependent controller for DarkByte platform payment configuration, security, reconciliation, fee and dispute records; processor where handling Merchant-controlled order payment records on Merchant instructionsMerchant, Stripe/payment provider, bank, card network and wallet provider may have separate rolesAmount, currency, transaction identifiers, Merchant account, status, refund, fraud and dispute informationContract, legitimate interests and legal obligation, depending on the payment, dispute, accounting or security purpose
Transactional order messagesNormally processor where sent for the MerchantMerchant is controller for order communicationsContact details, order reference and statusMerchant determines basis; DarkByte uses contract or legitimate interests for separate platform-delivery and security records
DarkByte account, verification and security messagesIndependent controllerMessaging provider acts as processor unless it has a separate stated roleEmail, telephone number, device token and message-delivery informationContract, legal obligation or legitimate interests
Merchant order support and complaintsProcessor where DarkByte acts only on Merchant instructions; independent controller for DarkByte platform supportMerchant is controller for product, fulfilment, refund and food-safety complaintsContact information, order information, correspondence and evidenceMerchant determines the processor basis; DarkByte uses contract, legal obligation or legitimate interests for its own platform support and claims
Saved allergy or dietary-safety profileIndependent controller for the standard optional profile and warning function as configured for the standard NibbleKit featureMerchant becomes a separate controller only where relevant information is disclosed to it for an orderAllergy selections and other health-related dietary information used to provide optional profile warningsConsent under Article 6(1)(a) and explicit consent under Article 9(2)(a)
Allergy or health information attached to an orderProcessor while transmitting or hosting information for the MerchantMerchant is independent controller for use in preparation, fulfilment and food safetyAllergy selections, order notes and related warningsMerchant determines its Article 6 basis and Article 9 condition; DarkByte has no separate basis as processor
DarkByte use of health information for a safety incident, complaint or legal claimIndependent controller only to the extent necessary for that separate purposeMerchant may separately retain information for its own investigationRelevant order, allergy, complaint and incident evidenceLegitimate interests or legal obligation under Article 6; Article 9(2)(f) where processing is necessary for legal claims, or another documented condition where applicable
Platform security, abuse prevention and fraud investigationIndependent controller for the NibbleKit platformMerchant and payment providers may be separate controllers for their own fraud and security processingAccount, device, IP, log, transaction, behavioural and incident informationLegitimate interests, recognised legitimate interests or legal obligation, as applicable
Diagnostics, reliability and crash investigationIndependent controllerDiagnostic provider acts as processor unless it has a separate disclosed roleDevice, app version, fault, crash and performance informationLegitimate interests; consent or a valid PECR exception where device storage or access is involved
Privacy rights requestsIndependent controller for requests concerning DarkByteMerchant is controller for requests concerning Merchant processing; DarkByte may assist as processorIdentity, contact, authority, request and response recordsLegal obligation under Article 6(1)(c); legitimate interests for administration and legal claims
Data-protection complaintsIndependent controller for complaints about DarkByte processing or conductMerchant is controller for complaints about Merchant processingComplaint, correspondence, evidence, investigation and outcome recordsLegal obligation under Article 6(1)(c); legitimate interests for investigation, improvement and legal claims
DarkByte direct marketingIndependent controllerMerchant is separate controller for Merchant marketingContact details, marketing preferences and interaction recordsConsent under Article 6(1)(a), or legitimate interests where lawful; PECR consent or a valid soft opt-in must also apply to electronic mail
Merchant direct marketingNormally processor only where the Merchant instructs use of a platform messaging toolMerchant is controllerContact details, preferences and campaign recordsMerchant determines the lawful basis and PECR position
App Store and Google Play administrationIndependent controller for data DarkByte receives and uses to administer an appApple or Google acts as an independent controller for its Store processingApp identifiers, Store receipt or purchase data, diagnostic and publication informationContract, legitimate interests or legal obligation
DarkByte business, tax, legal and contract administrationIndependent controllerAdvisers and authorities may be processors or separate controllersMerchant contacts, invoices, correspondence, contracts and legal recordsContract, legal obligation and legitimate interests
Demo or trial administrationIndependent controller for demo access and supportProspective Merchant may be a separate controller for its staffBusiness contact, login, activity and support informationLegitimate interests and steps taken at the person's request before contract
Joint-controller activitiesNo joint-controller activities have been identified in the standard NibbleKit demo/platform serviceNot applicable unless a specific feature notice states otherwiseNot applicable unless a specific feature notice states otherwiseNot applicable unless a specific feature notice states otherwise

Where a feature operates differently from the standard position, an additional notice will identify:

6. Merchant Responsibilities

A Merchant is normally responsible for giving Customers privacy information about the Merchant's use of personal data for:

A Merchant's notice should identify the Merchant's full legal identity and contact details.

Where DarkByte is the Merchant's processor, the Merchant determines:

DarkByte's processing for a Merchant is governed by a written data-processing agreement containing the requirements applicable to processors.

7. Joint Controllers

DarkByte and a Merchant will be treated as joint controllers only for a processing activity where they jointly determine its purposes and essential means.

Where joint controllership applies:

A joint-controller arrangement does not prevent you from contacting DarkByte through the Privacy Rights and Data Protection Complaints page.

8. Personal Data We Collect or Receive

Depending on how you use NibbleKit, we may collect or receive the following categories.

8.1 Identity and contact information

This may include:

8.2 Account and authentication information

This may include:

We do not retain plain-text account passwords.

8.3 Order and fulfilment information

This may include:

This may include:

NibbleKit is designed not to store full card numbers or card security codes on DarkByte systems.

This statement reflects the current NibbleKit payment architecture and must be reviewed before any new live payment integration is enabled.

This may include:

This information may be special-category health data.

8.6 Support and complaint information

This may include:

8.7 Merchant and administration information

This may include:

8.8 Device, application and technical information

This may include:

8.9 Cookies and similar-technology information

This may include data stored or accessed through:

The Cookies and Similar Technologies Policy provides further details.

8.10 Marketing information

This may include:

This may include:

9. Sources of Personal Data

We may obtain personal data:

Where another person provides your information, that person should have proper authority and should provide you with relevant privacy information where required.

10. Required and Optional Information

Some information is required to provide a requested service.

For example:

If required information is not provided, the relevant function may be unavailable.

Optional information includes:

Declining an optional field should not prevent access to unrelated core functions.

11. Lawful Bases

Where DarkByte is a controller, it uses one or more of the following lawful bases.

11.1 Contract

We use personal data where necessary to:

We do not rely on contract merely because processing is mentioned in contractual terms. The processing must be objectively necessary for the relevant contract.

We use personal data where necessary to comply with an obligation imposed by law, including applicable:

11.3 Legitimate interests

We use personal data where necessary for legitimate interests that are not overridden by your interests, rights or freedoms.

Those interests may include:

We assess:

Where appropriate, we document a legitimate-interests assessment.

We rely on consent for a specific optional purpose where consent is appropriate.

Consent must be:

Accepting the Terms, EULA or this Privacy Policy is not treated as consent to an unrelated optional purpose.

11.5 Vital interests

In a genuine emergency, personal data may be used where necessary to protect someone's life or physical safety and another appropriate basis is unavailable.

This basis is not used for routine food-order processing.

Allergy, intolerance and related dietary-safety information may reveal health information and may therefore be special-category data.

Where DarkByte provides the standard optional saved allergy-profile function, DarkByte relies on:

The explicit-consent request will be separate from:

Before giving consent, the user will be told:

The current disclosure from an allergy profile to a Merchant is:

Saved allergy selections and the no-known-allergies flag are stored on the customer profile for warning features. Where relevant to an order, allergy selections, order-specific allergy or dietary notes and warning context may be included in order data visible to authorised Merchant, admin and kitchen users who need it for preparation, handover, support or safety purposes.

Saving an allergy profile is optional.

A Customer can update or remove saved allergy information through:

the onboarding allergy step or the Food allergies section on the user/profile screen

A Customer can withdraw explicit consent through:

the user/profile screen where editable, or the Data Request page at https://nibblekit.com/policies/data-request/

Withdrawal stops future processing based on that consent. It does not make earlier consent-based processing unlawful.

Limited information may still be retained where necessary for:

Where a Merchant receives health information for an order, the Merchant becomes responsible for identifying and communicating its own Article 6 basis and Article 9 condition.

DarkByte does not use saved allergy data for advertising.

DarkByte does not disclose saved allergy data to an artificial-intelligence provider or permit it to be used to train a general-purpose model unless this is separately and prominently disclosed and an appropriate lawful basis and Article 9 condition have been established.

This provider statement must be reviewed before any new payment, app-store, wallet or third-party integration is enabled.

13. Information About Other People

A Customer may place an order for another person.

Where you provide another person's contact, delivery, allergy or dietary information, you must:

You should not save another adult's health information to a reusable profile without their knowledge and appropriate authority.

A parent or person with legal responsibility may provide information for a child where appropriate.

14. Payment Processing

Payments may be processed using:

Stripe Connect for card payments and supported wallet methods, plus any cash or offline payment option expressly enabled by the Merchant.

The standard card-payment architecture uses Stripe Connect direct charges on the Merchant connected account where the current PaymentIntent flow is enabled. Stripe processes the payment, the Merchant connected account is the primary recipient for Merchant food or order funds, and checkout or receipt information should identify the relevant Merchant and payment method. DarkByte does not receive full card details and does not act as your card issuer, acquiring bank or payment account provider.

If a Merchant enables a materially different payment flow, the checkout flow, receipt or Merchant-specific terms should identify the payment recipient, refund controller, statement descriptor and relevant provider role before you place the order.

A payment provider may receive information such as:

DarkByte may receive limited payment metadata needed to:

The payment provider may act:

Its own privacy information applies to independent processing.

Apple Pay, Google Pay, banks, card networks and card issuers may also process payment information independently.

15. App Stores and Operating-System Providers

Where an App is distributed through Apple or Google, the Store provider may independently process:

DarkByte may receive limited information from a Store, such as:

Current digital in-app purchase or subscription processing is:

The standard NibbleKit app is currently a free download and does not receive App Store or Google Play digital purchase data for in-app purchases or subscriptions. App stores may still process download, account, device and diagnostic data under their own terms.

Apple and Google normally act as independent controllers for their Store services.

DarkByte is responsible for keeping its App Store privacy information and Google Play Data Safety disclosures accurate and consistent with:

16. Service Messages and Marketing

16.1 Service messages

Service messages are communications needed to provide, protect or administer a requested service.

They may include:

A service message is not treated as marketing merely because it uses a Merchant's branding.

You may be unable to opt out of a message that is genuinely necessary for an active account, pending order, security issue or legal obligation.

16.2 DarkByte marketing

DarkByte will send direct marketing by email, text, push notification or similar electronic message only where:

Every marketing message will identify the sender and provide a simple way to opt out.

A device permission to receive notifications is not, by itself, consent to receive marketing.

16.3 Merchant marketing

A Merchant is responsible for its own marketing purposes, audience selection, lawful basis and PECR compliance.

Where DarkByte sends a Merchant campaign solely on the Merchant's instructions, DarkByte acts as processor.

Marketing choices for one Merchant will not automatically be treated as consent to marketing from DarkByte or another Merchant.

16.4 Suppression records

Where you opt out, a minimal suppression record may be retained so that the choice can be respected.

A suppression record will not be used to restart marketing.

17. Cookies, App Storage and Similar Technologies

NibbleKit may use technologies that store information on or access information from a device, including:

These rules apply to mobile applications and webviews as well as conventional websites.

The NibbleKit Cookies and Similar Technologies Policy identifies:

Where consent is required under PECR, the technology will not be enabled before valid consent is obtained.

A UK GDPR lawful basis is also required where the technology involves personal data.

18. Platform Security and Fraud Prevention

We may process account, device, request, payment-status and behavioural information to:

Security decisions may result in:

Where an urgent automated security control temporarily restricts access, an appropriate review route will be available where the restriction materially affects the user.

We do not treat ordinary business convenience as sufficient justification for intrusive monitoring.

19. Artificial Intelligence and Automated Processing

NibbleKit may use or integrate automated tools for functions such as:

An enabled AI or automated feature must be identified in this section or in a feature-specific notice.

Current enabled AI or automated integrations are:

FeatureProviderData suppliedPurposeProvider retention or model-training positionDarkByte role
No advertising or cross-service tracking feature in the core NibbleKit demo unless separately enabledNot applicable unless separately enabledNot applicable unless separately enabledNot applicable unless separately enabledas configured for the standard NibbleKit featureNot applicable unless separately enabled

We will not intentionally submit:

to a general-purpose AI service.

An automated allergen warning is a supplementary information function. It does not decide whether food is legally or medically safe and normally does not have a legal or similarly significant effect.

The current position on solely automated significant decisions is:

DarkByte does not currently make a significant decision about an individual based solely on automated processing in the standard NibbleKit demo/platform service. Automated security, payment, delivery-area, allergy-warning, pricing and order-status checks support workflows but are not intended to produce a legal or similarly significant decision without human or Merchant involvement where required.

Where DarkByte makes a significant decision based solely on automated processing, DarkByte will provide the safeguards required by applicable law, including as appropriate:

Special-category data will not be used for a solely automated significant decision unless the processing is legally permitted and the required additional safeguards are in place.

20. Recipients and Service Providers

We disclose personal data only where reasonably necessary for a lawful purpose.

20.1 Merchants

A Merchant may receive information needed to:

The Merchant acts as an independent controller for those purposes unless the specific activity states otherwise.

20.2 Material provider register

The exact provider set may vary by environment, Merchant configuration and enabled features. The current public register for the NibbleKit demo/platform services is:

Provider categoryTypical providerTypical dataPurposeTypical role
Hosting and cloud infrastructureFirebase and Google CloudAccount, order, log and configuration dataHost and operate NibbleKitProcessor and/or infrastructure provider
Database and storageCloud Firestore and Firebase StorageAccount, order, Merchant, support and media dataStore platform dataProcessor and/or infrastructure provider
AuthenticationFirebase Authentication and supported identity providersIdentity, account, token and security dataAuthenticate users and protect accountsProcessor and/or independent provider controller depending on feature
Payment processingStripe Connect and enabled wallet/payment methodsPayment, order, fraud, refund and dispute dataProcess payments, pre-authorisations, refunds and disputesIndependent controller and/or processor depending on provider function
Transactional emailConfigured SMTP/email provider and Firebase email action linksName, email, message and delivery statusSend verification, receipt, support and service messagesProcessor/provider
Push notificationsFirebase Cloud Messaging and device operating-system servicesDevice token, account link and message metadataDeliver service notificationsProcessor/provider; device platform may have independent role
Address, postcode, map and route servicesGoogle Places/Maps and configured postcode/address providersAddress, postcode, place, route and request dataAddress lookup, delivery area and route functionsProcessor or independent provider controller depending on feature
Crash reporting and diagnosticsFirebase, Flutter/device diagnostics and hosting logs where enabledDevice, app, crash, log and diagnostic dataReliability, security and fault investigationProcessor/provider
AI, image or nutrition servicesConfigured AI text, image-processing and nutrition providers where enabledMenu, image, nutrition, prompt and generated-output data submitted to the featureMenu assistance, image tools and nutrition lookupProcessor/provider depending on feature
Customer-support toolingInternal email/support workflow unless another support tool is enabledContact, support, order and evidence dataManage support casesController for DarkByte support; processor where acting for Merchant
Account-deletion and privacy-request toolingNibbleKit public form and internal case workflowRequest, identity, authority and case dataManage rights and complaintsController for DarkByte requests; processor support where Merchant-controlled data is involved

A more detailed material provider or subprocessor list is available from privacy@darkbyte.uk on reasonable request until a public register is published.

We may disclose information to:

where reasonably necessary and lawful.

20.4 Business transfers

If all or part of NibbleKit or DarkByte's business is sold, transferred, reorganised or evaluated for a genuine transaction, relevant information may be disclosed under appropriate confidentiality and data-protection safeguards.

Personal data will not be disclosed merely for speculative sale or unrelated marketing.

21. International Transfers

Some providers may process personal data outside the United Kingdom.

Current material hosting and processing locations are:

Firebase/Google Cloud resources are configured primarily in the project region used for the relevant environment, including europe-west2 for the demo functions, with provider support, security and subprocessor operations potentially outside the UK under appropriate safeguards

Where a restricted transfer occurs, we will use a lawful transfer mechanism, such as:

Where appropriate safeguards are used, we will complete and document the applicable transfer risk assessment or data-protection test and consider whether supplementary measures are needed.

An exceptional transfer derogation will be used only where its legal conditions are met and it is appropriate for the circumstances.

Where the EU GDPR separately applies, an appropriate EU transfer mechanism will also be used.

You may request information about the relevant transfer safeguard through the Privacy Rights and Data Protection Complaints page. Commercially confidential information may be redacted where lawful.

22. Retention and Deletion

We retain personal data only for as long as reasonably necessary for:

Detailed periods are set out in the NibbleKit Data Retention and Deletion Policy.

Standard categories include:

Deleting an account does not necessarily delete:

Saved allergy-profile information is deleted separately from longer-lived financial metadata and is not retained merely because a related order amount must be retained for accounting.

23. Security

We use technical and organisational measures designed to protect personal data against:

Measures may include, where appropriate:

Security measures are reviewed according to risk.

No internet or software service can be guaranteed completely secure. You should protect your credentials and report suspected unauthorised access promptly.

24. Personal-Data Breaches

Where DarkByte becomes aware of a suspected personal-data breach, it will:

Where DarkByte acts as processor, it will notify the relevant Merchant without undue delay and provide reasonable assistance.

Where DarkByte acts as controller, a notifiable breach will be reported to the Information Commissioner's Office without undue delay and, where required, within the applicable 72-hour period.

25. Children and Age Limits

The standard NibbleKit customer-account service is intended for people aged:

the minimum age stated in the relevant app, ordering service or Merchant terms

We do not knowingly permit a person below the stated minimum age to create an account unless:

A child may be the intended recipient of food ordered by an adult without becoming an account holder.

Where an online service is likely to be accessed by children, we will take children's needs and best interests into account when deciding:

A parent, guardian, Merchant or child who believes that personal data has been collected inappropriately should contact us through the privacy complaints route.

We may take reasonable steps to verify age or parental authority where necessary and proportionate.

26. Your Data-Protection Rights

Depending on the circumstances, you may have the right to:

Rights are subject to legal conditions and exemptions.

A deletion request does not automatically require deletion of every record. Where only part must be retained, we will consider deleting or anonymising the remainder.

Withdrawing consent does not affect processing carried out lawfully before withdrawal.

27. How to Exercise a Right

You may exercise a right through the NibbleKit Privacy Rights and Data Protection Complaints page at:

https://nibblekit.com/policies/data-request/

You may also contact:

privacy@darkbyte.uk

You do not have to use a particular form or legal wording.

Please provide enough information for us to:

We will request identity evidence only where reasonably necessary and proportionate.

There is normally no fee.

We will normally respond within one month, subject to:

Where a Merchant is controller, we may securely forward the request, ask the Merchant to respond or assist it as processor. We will explain the routing where reasonably possible.

28. Data-Protection Complaints

A data-protection complaint is separate from a request to exercise a right.

You may make a complaint where you believe that personal data has been handled in a way that breaches data-protection law.

Complaints may be submitted through:

When DarkByte receives a complaint about processing for which it is controller, we will:

The outcome will normally:

Where the complaint concerns Merchant-controlled processing, we may securely forward it to the Merchant or separate the Merchant and DarkByte issues.

You do not have to complete DarkByte's process before contacting the Information Commissioner's Office.

29. Complaints to the Information Commissioner's Office

The Information Commissioner's Office is the United Kingdom's data-protection supervisory authority.

You may complain to the Information Commissioner's Office where you are concerned about how personal data has been handled.

Where another European supervisory authority has jurisdiction, you may also have a right to complain to that authority.

Contacting DarkByte first may allow the matter to be resolved more quickly, but it is not a precondition to making a regulatory complaint.

30. Automated-Decision Review Route

Where you are affected by a significant decision based solely on automated processing and applicable law requires safeguards, you may use the Privacy Rights and Data Protection Complaints page to:

Please identify:

31. Account Deletion

Where a NibbleKit App permits account creation, deletion can be initiated:

Deleting the App from a device does not delete the account.

Account deletion normally:

Some records may remain for lawful reasons described in section 22.

A Merchant may separately retain order records for which it is controller.

32. Changes to This Policy

We may update this policy to reflect changes in:

The current version will show its last-updated date and version number.

Where a material change affects how existing personal data is used, we will assess whether:

is required before the change is applied.

An earlier consent will not be treated as consent to a materially different purpose.

Previous material versions will be available at:

Previous material versions are available on reasonable request from support@nibblekit.com.

This policy should link to:

34. Contact Us

For questions about DarkByte's use of personal data:

Paul Hepple, a sole trader trading as DarkByte Creations 152 Lindhurst Road, Barnsley, S71 3DG Email: support@nibblekit.com Privacy email: privacy@darkbyte.uk Telephone: 07549 253991

For a Merchant's use of order, fulfilment, customer-service, food-safety or marketing information, contact the Merchant identified in the relevant ordering service, checkout or order confirmation.