Privacy Policy

Effective Date: June 9, 2026  |  Last Updated: June 9, 2026

This Privacy Policy describes how Costa Vida ("we," "us," "our," or the "Company") collects, uses, discloses, and protects your personal information when you visit our website at cosvida.click, use our online ordering services, participate in our loyalty programs, or otherwise interact with us. Please read this policy carefully to understand our practices regarding your personal data and how we will treat it.

By accessing or using our website, placing an order, or engaging with our services in any way, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with this policy, please discontinue your use of our website and services immediately.

We are committed to protecting your privacy and handling your personal information with transparency, integrity, and respect. This Privacy Policy complies with applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and the Federal Trade Commission (FTC) Act governing unfair or deceptive trade practices.


1. About Us

Costa Vida is a food and restaurant business operating within the United States. We are dedicated to providing fresh, flavorful, and high-quality food experiences to our customers. Our contact information is as follows:

Company Name Costa Vida
Website cosvida.click
Email Address [email protected]

For any questions, concerns, or requests related to your privacy or this Privacy Policy, you may contact us at any time using the information provided above.


2. Information We Collect

We collect various types of information in connection with the services we provide. The categories of personal information we may collect are described below.

2.1 Personal Information You Provide Directly

When you interact with us voluntarily — such as creating an account, placing an order, signing up for our newsletter, or contacting customer support — you may provide us with the following types of personal information:

  • Identification Information: Your full name, username, and similar identifiers.
  • Contact Information: Email address, mailing address, telephone number, and billing address.
  • Account Credentials: Password or other authentication information when you create an account on our website.
  • Payment Information: Credit or debit card numbers, bank account details, billing address, and other financial information necessary to process transactions. Note that payment card data is processed through secure third-party payment processors and is not stored directly on our servers.
  • Order History and Preferences: Information about the food items you order, your dietary preferences, customizations, and order history.
  • Loyalty Program Data: If you participate in our rewards or loyalty program, we collect your enrollment information, points balance, redemption history, and related data.
  • Communications: Any messages, feedback, reviews, or other content you send to us via email, contact forms, social media, or other channels.
  • Survey Responses: Information you provide when participating in surveys or promotional campaigns.

2.2 Information Collected Automatically

When you visit our website at cosvida.click, we automatically collect certain technical and usage data through cookies, web beacons, log files, and similar tracking technologies. This information may include:

  • Device Information: Device type, operating system, browser type and version, screen resolution, device identifiers, and hardware settings.
  • Log Data: Internet Protocol (IP) address, browser activity, referring URLs, pages visited, time and date of visits, time spent on pages, and other diagnostic data.
  • Usage Data: Information about how you navigate and interact with our website, including clicks, links followed, search queries entered, and features used.
  • Location Data: General geographic location inferred from your IP address, and precise geolocation if you grant permission through your browser or device settings.
  • Cookie and Tracking Data: Information collected through cookies, pixel tags, web beacons, and similar technologies as further described in Section 8 of this policy.

2.3 Information Collected from Third Parties

We may receive information about you from third-party sources, including:

  • Social Media Platforms: If you connect your social media account (such as Facebook, Google, or Instagram) to our services or log in using social sign-in features, we may receive certain profile information from those platforms.
  • Delivery Partners: When you order through third-party food delivery platforms that partner with us, we may receive order and contact information necessary to fulfill your request.
  • Analytics Providers: We work with analytics services that provide aggregated data about website traffic and user behavior.
  • Marketing Partners: We may receive information from advertising networks or marketing partners to improve the relevance of our promotions.
  • Publicly Available Sources: Information available in public records or publicly accessible databases.

3. How We Use Your Information

We use the personal information we collect for the following purposes:

3.1 Providing and Improving Our Services

  • Processing and fulfilling your food orders, including online orders and in-store transactions.
  • Managing your account, including account creation, authentication, and profile management.
  • Administering and operating our loyalty and rewards program.
  • Processing payments and preventing fraudulent transactions.
  • Providing customer support, responding to inquiries, and resolving disputes.
  • Personalizing your experience by remembering your preferences and order history.
  • Improving the functionality, performance, and user experience of our website and services.
  • Conducting internal research and development to enhance our food offerings and services.

3.2 Communications and Marketing

  • Sending you order confirmations, receipts, and transactional communications.
  • Delivering promotional offers, discounts, newsletters, and updates about new menu items or restaurant locations, where you have provided consent or where permitted by applicable law.
  • Sending you reminders, surveys, or feedback requests related to your experience with us.
  • Personalizing advertisements and marketing messages based on your preferences and interactions.

3.3 Analytics and Research

  • Analyzing usage patterns and trends to understand how customers engage with our website and services.
  • Measuring the effectiveness of our marketing campaigns and promotional efforts.
  • Conducting market research and customer satisfaction surveys.
  • Generating aggregated, anonymized statistical data about our customer base and service performance.

3.4 Legal and Compliance Purposes

  • Complying with applicable federal and state laws, regulations, and legal processes.
  • Enforcing our Terms of Service and other applicable agreements.
  • Detecting, investigating, and preventing fraud, security breaches, and other harmful or unlawful activities.
  • Protecting the rights, property, and safety of Costa Vida, our customers, and the public.
  • Responding to lawful requests from public authorities, including law enforcement agencies.

3.5 Legal Basis for Processing

We process your personal information on the following legal grounds:

  • Contractual Necessity: Processing is necessary to perform a contract with you (e.g., fulfilling your food orders).
  • Legitimate Interests: Processing is necessary for our legitimate business interests, such as improving our services, preventing fraud, and marketing our products, provided those interests are not overridden by your rights.
  • Consent: Where you have given us explicit consent to process your data for a specific purpose, such as receiving marketing communications.
  • Legal Obligation: Processing is necessary to comply with a legal obligation applicable to us under United States federal or state law.

4. Sharing Your Information with Third Parties

We do not sell your personal information to third parties. However, we may share your information with the following categories of recipients under specific circumstances:

4.1 Service Providers and Business Partners

We share personal information with third-party service providers who assist us in operating our business and delivering our services. These providers are contractually bound to use your information only for the purposes we specify and to implement appropriate security measures. Categories of service providers include:

  • Payment processors and financial institutions that handle transaction processing.
  • Food delivery and logistics partners that fulfill delivery orders.
  • Cloud hosting, data storage, and IT infrastructure providers.
  • Customer relationship management (CRM) software providers.
  • Email marketing and communications platform providers.
  • Analytics and website performance monitoring services.
  • Advertising networks and digital marketing partners.
  • Fraud detection and security service providers.
  • Legal, accounting, and professional advisory firms.

4.2 Legal Requirements and Law Enforcement

We may disclose your personal information if required to do so by law or in response to valid legal processes, including:

  • Complying with a court order, subpoena, or other legal obligation.
  • Responding to lawful requests from government authorities or law enforcement agencies.
  • Protecting against fraud, cybersecurity threats, or illegal activity.
  • Defending or asserting our legal rights in litigation or regulatory proceedings.

4.3 Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal information may be transferred to a successor entity. We will notify you of any such transfer and any changes to this Privacy Policy that may result from it.

4.4 With Your Consent

We may share your personal information with other third parties when you have given us your explicit consent to do so.

4.5 Aggregated or De-Identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for marketing, research, analytics, or other business purposes.


5. Data Security

We take the security of your personal information seriously and implement a range of technical, administrative, and physical safeguards designed to protect your data from unauthorized access, disclosure, alteration, and destruction. Our security measures include, but are not limited to:

  • Encryption: We use industry-standard Secure Socket Layer (SSL) / Transport Layer Security (TLS) encryption to protect data transmitted between your browser and our website. Sensitive data, including payment information, is encrypted both in transit and at rest.
  • Access Controls: Access to personal information is restricted to authorized personnel who need it to perform their job functions. We implement role-based access controls and require strong authentication for system access.
  • Secure Payment Processing: We use PCI DSS-compliant third-party payment processors and do not store complete credit or debit card numbers on our servers.
  • Regular Security Assessments: We conduct periodic security audits, vulnerability assessments, and penetration testing to identify and address potential security risks.
  • Employee Training: Our employees receive regular training on data protection best practices and our internal security policies.
  • Incident Response: We have established procedures for detecting, reporting, and responding to data breaches and security incidents in compliance with applicable state breach notification laws.
  • Data Minimization: We collect only the personal information that is necessary for the purposes described in this policy.
Important Notice: While we implement robust security measures, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your personal information. You are responsible for maintaining the confidentiality of your account credentials and for any activities that occur under your account.

6. Your Privacy Rights

Depending on your state of residence, you may have certain rights with respect to your personal information. We are committed to honoring these rights in accordance with applicable United States law.

6.1 Rights Under the California Consumer Privacy Act (CCPA/CPRA)

If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:

  • Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business purposes for which it was collected, and the categories of third parties with whom it was shared.
  • Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions permitted by law.
  • Right to Correct: You have the right to request correction of inaccurate personal information that we maintain about you.
  • Right to Opt-Out of Sale or Sharing: You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising. Note that we do not sell your personal information in the traditional sense; however, certain advertising practices may constitute "sharing" under the CPRA.
  • Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of sensitive personal information to purposes necessary to provide the services you request.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights. We will not deny you services, charge different prices, or provide a different quality of service based on your exercise of these rights.

6.2 General Privacy Rights (All U.S. Residents)

Regardless of your state of residence, we offer the following rights to all users:

  • Right to Access: You may request a copy of the personal information we hold about you.
  • Right to Correction: You may request that we correct inaccurate or incomplete personal information.
  • Right to Deletion: You may request that we delete your personal information, subject to certain legal exceptions.
  • Right to Data Portability: You may request that we provide your personal information in a structured, commonly used, and machine-readable format.
  • Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing prior to such withdrawal.
  • Right to Opt Out of Marketing: You may opt out of receiving promotional communications from us at any time by clicking the "unsubscribe" link in our emails or by contacting us directly.

6.3 How to Exercise Your Rights

To exercise any of your privacy rights, please contact us using the following methods:

We will verify your identity before fulfilling your request to protect your security. We will respond to your request within 45 days of receipt. If we require additional time (up to 90 days in total), we will notify you of the extension and the reason for it. We will not charge a fee for processing your request unless it is excessive, repetitive, or manifestly unfounded.


7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, regulatory, or reporting requirements. The criteria we use to determine retention periods include:

Category of Data Retention Period
Account and registration information Duration of account plus 3 years after account closure
Order history and transaction records 7 years for financial and tax compliance purposes
Customer service communications 3 years from the date of last communication
Marketing preferences and consent records Until consent is withdrawn, plus 3 years
Website usage and analytics data Up to 26 months (Google Analytics default) or as required by tool
Cookie and tracking data As specified in our Cookie Policy (typically 30 days to 2 years)
Loyalty program data Duration of program membership plus 2 years after termination
Legal and compliance records As required by applicable law, typically 7 years or more

When personal information is no longer required, we securely delete or anonymize it in accordance with our data destruction procedures. Where anonymization is not possible, we store the data in a secure manner and ensure it is isolated from further processing.


8. Cookie Policy Summary

Our website at cosvida.click uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and deliver personalized content and advertisements. Cookies are small text files stored on your device when you visit our website.

8.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the operation of our website, including session management, security, and enabling core features such as online ordering and account login. These cookies cannot be disabled.
  • Functional Cookies: Allow us to remember your preferences and settings, such as language selection, location preferences, and previously viewed items.
  • Analytics Cookies: Help us understand how visitors interact with our website by collecting information about page views, traffic sources, and user behavior. We use services such as Google Analytics for this purpose.
  • Marketing and Advertising Cookies: Used to track your browsing activity across websites to deliver targeted advertisements relevant to your interests. These may be set by third-party advertising partners.

8.2 Managing Cookie Preferences

You can manage your cookie preferences through your browser settings or through our cookie consent management tool, which appears when you first visit our website. Most web browsers allow you to refuse cookies, delete cookies, or receive a warning before a cookie is stored. Please note that disabling certain cookies may affect the functionality of our website and your ability to use certain features.

For more detailed information about how we use cookies, including a complete list of cookies used and instructions on how to manage your preferences, please refer to our full Cookie Policy available on our website at cosvida.click.


9. Children's Privacy

Age Restriction: Our website and services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from children under the age of 18.

Costa Vida's website and online ordering services are not directed to children under the age of 18. We do not knowingly solicit or collect personal information from minors. If you are under 18 years of age, please do not use our website, create an account, or provide any personal information to us.

If we become aware that we have inadvertently collected personal information from a child under the age of 18 without parental consent, we will take immediate steps to delete that information from our records. If you are a parent or guardian and believe that your child has provided personal information to us without your knowledge or consent, please contact us immediately at [email protected] so that we can promptly investigate and remove such information.

This commitment is consistent with the Children's Online Privacy Protection Act (COPPA), which prohibits the collection of personal information from children under 13 without verifiable parental consent. We extend this protection to users under 18 years of age.


10. International Data Transfers

Costa Vida is based in the United States and processes personal information primarily within the United States. Our servers, data storage facilities, and primary business operations are located in the United States. If you access our website from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your home country.

If you are located outside the United States and choose to provide personal information to us, you understand and consent to the transfer and processing of your information in the United States. We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy regardless of where it is processed.

In situations where we transfer personal data internationally to service providers or partners, we implement appropriate contractual mechanisms and safeguards, such as Standard Contractual Clauses or other legally recognized transfer mechanisms, to ensure that your personal information is protected to a standard consistent with applicable data protection laws.


11. Third-Party Links and Services

Our website may contain links to third-party websites, applications, and services, including social media platforms, delivery apps, and partner websites. This Privacy Policy does not apply to any third-party websites or services. We are not responsible for the privacy practices, content, or security of third-party sites.

We encourage you to review the privacy policies of any third-party websites you visit. The inclusion of a link on our website does not imply our endorsement of that third party's privacy practices or policies.

When you use third-party food delivery platforms (such as DoorDash, Uber Eats, or Grubhub) to order our food, your information is subject to those platforms' privacy policies. We receive only the order information necessary to prepare and fulfill your delivery.


12. Your Marketing Preferences

We respect your right to control how we communicate with you for marketing purposes. You may opt out of receiving promotional communications from us at any time:

  • Email Marketing: Click the "unsubscribe" or "manage preferences" link included in the footer of any marketing email we send you. You will be removed from our marketing list within 10 business days.
  • SMS/Text Messages: Reply "STOP" to any marketing text message we send you to unsubscribe from future messages.
  • Account Settings: Log in to your account on our website and update your communication preferences in your profile settings.
  • Direct Contact: Email us at [email protected] with your opt-out request, and we will honor your preference promptly.

Please note that even if you opt out of marketing communications, we may still send you transactional and administrative messages related to your account or orders, as these are not marketing communications and are necessary to provide you with our services.


13. California Privacy Rights — Additional Disclosures

In addition to the rights described in Section 6, California residents are entitled to the following additional disclosures under the CCPA/CPRA:

13.1 Categories of Personal Information Collected in the Past 12 Months

  • Identifiers (name, email address, IP address, account username)
  • Commercial information (purchase history, preferences, loyalty program data)
  • Internet or other electronic network activity information (browsing history, interaction with our website)
  • Geolocation data (general location based on IP address or precise location with consent)
  • Inferences drawn from other personal information to create a profile about you
  • Financial information (payment card data processed through secure third-party processors)

13.2 Shine the Light Law

California Civil Code Section 1798.83 permits California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. If you are a California resident and would like to make such a request, please contact us at [email protected].

13.3 Do Not Track Signals

Our website currently does not respond to "Do Not Track" (DNT) signals from web browsers. As the online industry has not yet established a uniform standard for responding to DNT signals, we have not yet implemented such functionality. We continue to monitor developments in this area and will update our practices accordingly.


14. How to File a Complaint

If you believe your privacy rights have been violated or you have concerns about our data handling practices, we encourage you to first contact us directly so that we can address your concerns:

We will acknowledge your complaint within 5 business days and work to resolve your concern within 30 days of receipt. If we require more time, we will notify you of the expected resolution timeline.

14.1 Filing a Complaint with a Regulatory Authority

If you are not satisfied with our response or believe we have not adequately addressed your concern, you may file a complaint with the relevant data protection or consumer protection authority:

Authority Jurisdiction Contact
Federal Trade Commission (FTC) Federal (all U.S. residents) ftc.gov/complaint | 1-877-382-4357
California Privacy Protection Agency (CPPA) California residents cppa.ca.gov
State Attorney General Your state of residence Contact your state's Attorney General office

15. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our business practices, legal requirements, or the services we offer. When we make material changes to this policy, we will:

  • Update the "Last Updated" date at the top of this page.
  • Post the revised policy on our website at cosvida.click.
  • Send an email notification to registered users if the changes are significant.
  • Display a prominent notice on our website homepage, if required by law.

Your continued use of our website and services after the effective date of any revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.


16. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please do not hesitate to reach out to us. We are committed to addressing your inquiries promptly and transparently.

Company Name Costa Vida
Email Address [email protected]
Website cosvida.click
Location United States

We will make every reasonable effort to respond to all privacy-related inquiries within 45 days of receipt. For California residents exercising rights under the CCPA/CPRA, we will respond within the timeframes required by law.

Effective Date: June 9, 2026. This Privacy Policy was last reviewed and updated on June 9, 2026. All previous versions of this Privacy Policy are superseded by this document.