Reggie Ray's Privacy Notice

Effective: September 27, 2026 · Last updated: September 27, 2026

This notice explains how Reggie Ray's Family Restaurants Incorporated, an Ohio nonprofit corporation ("we," "us"), 1888 State Rt. 59, Kent, OH 44240, collects, uses and shares personal information through our website and ordering site at reggierayskent.com (the "Site"; registered in our name through Cloudflare Registrar), our restaurant, our Dining Plan, and our Community Tiers.

"Reggie Ray's" is used under license from Mitchell & Mitchell Holdings Company. Mitchell & Mitchell Holdings Company is a separate company. It doesn't operate this Site or the Kent restaurant and doesn't receive our customers' personal information (see §6.3).

1. Information we collect

Category Examples Source Why
Account and login Name, email, phone, password (stored only as a salted hash), account ID. You can enroll online on the Site or in person at the restaurant You Create and secure your account
Plan membership Plan tier, start date, billing date, renewal status, your auto-renewal consent record (date, time, the terms shown, and how you consented), cancellation requests You; our systems Run your Dining Plan (Terms §§3, 7)
Meal and credit tracking Meals used per week or month, Dining Credit balance, redemption date, time and item, dine-in, takeout or delivery Our POS and Site Apply Meal Limits, credits and the Member Discount (Terms §§5–6)
Orders Items, allergy or dietary notes you enter, delivery address, receipts You; our systems Fill orders; food safety
Payment Square's payment token, card brand, last 4 digits, expiry, billing ZIP, transaction amount and status. We never receive or store full card numbers or security codes. Square holds that data. You, through Square Take payment; refunds
Community Tier eligibility Only: the eligibility status (approved / not approved / expired), which option (e.g., Children's free, Adult), which eligibility path was used (SNAP, school meals, agency referral, other government food assistance, government medical assistance such as Medicaid, or affidavit of indigency), the approval date, the next re-check date (eligibility is re-checked every six months), and which staff member approved it. For the Children's Tier: the parent's account and the child's first name, last initial, and school grade band (K–5 / 6–8 / 9–12) Staff Confirm eligibility (Terms §4)
Communications Marketing opt-ins and opt-outs (with date and time), messages you send us You Consent records; support
Device and usage IP address, browser type, pages viewed, and strictly necessary cookies (§8) Automatically Security; keep the Site working

Community Tier proof isn't stored on the Site. Proof of eligibility (a SNAP/EBT card or benefits notice, a school-meal approval letter, a partner agency referral, a WIC or other food-assistance card or notice, a Medicaid card or approval notice, or, for the affidavit-of-indigency path, proof of income such as a pay stub or benefits letter) is looked at in person by authorized staff and handed back. We don't scan, photograph, upload or keep copies. If you use the affidavit-of-indigency path, you fill out and sign a short affidavit in person (name, household size, monthly household income, and the types of proof shown). There's no fixed income limit; staff decide need from your household size and proof of income. Staff review it with your proof and hand it back, and we don't record your income amount. We don't collect Social Security numbers, immigration status, or health information for eligibility. (If you show a Medicaid card, staff only note that the "government medical assistance" path was used. We don't record your Medicaid number or any health details.)

Alcohol age checks (Premium Tier, Terms §3.8; online Soulrita orders, Terms §9.5): staff or our delivery driver look at your ID in person, at the table, at pickup or at the door. We don't scan, copy or store it. We may record "21+ verified," the date and the staff member or driver.

2. How we use information

To create and manage accounts; run the Dining Plan (billing, renewals, cancellations, meal and credit tracking); fill orders; confirm Community Tier eligibility; food and allergen safety; customer support; send transactional messages (receipts, renewal and price-change notices under Terms §§7 and 11, cancellation confirmations, and six-month eligibility re-check reminders); marketing email and texts only if you opt in, sent through Square's marketing services (§4); detect fraud and misuse (Terms §13); security; meet legal, tax and accounting duties (e.g., Ohio sales tax records); and report aggregate, de-identified figures such as "meals served" to our board, grant funders and regulators. Nobody is identified in funder reports.

We don't use your information for automated decisions that have legal or similarly significant effects. Eligibility decisions are made by staff.

3. Payments through Square

Payments are processed by Block, Inc. (Square) under our own Square merchant account. Card data is entered into Square's secure payment form and goes directly to Square. We receive only a token and limited details (card brand, last 4 digits, expiry, status) to show receipts, run recurring plan charges you authorized (Terms §§7.2, 8.2), and issue refunds. Square handles card data under the Payment Card Industry Data Security Standard (PCI DSS) and its own privacy notice (squareup.com/us/en/legal/general/privacy). Square may use some data for its own purposes, such as fraud prevention, as its notice describes.

4. Email and text messages

Transactional messages (receipts, plan renewal, price or term changes, cancellation confirmations, and Community Tier eligibility re-check reminders, sent about every six months) are part of the service, and you can't opt out of them while you have an active plan.

Our marketing providers. Square (Block, Inc.) provides our email and text-message marketing services: Square Marketing for email and Square Text Marketing for texts. Square handles your email address, phone number and opt-in or opt-out status on our behalf to send these messages.

Marketing email: sent only if you opt in (a box that isn't pre-checked). Every marketing email identifies us, includes our postal address, and has a working unsubscribe link. We honor opt-outs within 10 business days (CAN-SPAM Act, 15 U.S.C. §7704; 16 CFR Part 316).

Marketing texts (SMS): sent only with your prior express written consent, given by a separate, unchecked box or keyword opt-in that says you agree to receive recurring automated marketing texts from Reggie Ray's at the number provided. Consent isn't a condition of buying anything. Message frequency varies. Message and data rates may apply. Reply STOP to opt out (or HELP for help), or tell us any other reasonable way. We'll honor it within 10 business days (TCPA, 47 U.S.C. §227; 47 CFR 64.1200(a)(2), (a)(10)). Texts are sent only between 8 AM and 9 PM your local time. We don't share or sell phone numbers or SMS opt-in data to third parties for their marketing. Community Tier participants are never enrolled in marketing automatically.

5. Children

The Site isn't directed to children and doesn't let anyone under 13 create an account. We don't knowingly collect personal information online from children under 13.

Children's Community Tier: a parent or legal guardian enrolls the child through the parent's own account or in person (Terms §§2.2, 4.2). We collect only what we need from the parent: the child's first name and last initial, grade band, eligibility status and approving staff member, and the parent's contact details. Children aren't asked to give personal information to the Site, can't log in, and don't receive marketing. At pickup, staff confirm the child against the parent's enrollment. A parent can review, correct or delete the child's information at any time (§9).

If we learn we've collected personal information online from a child under 13 without verifiable parental consent, we'll delete it.

6. How we share information

6.1 We don't sell your personal information, and we don't share it for cross-context behavioral (targeted) advertising. We don't rent or trade customer lists.

6.2 Service providers only. We share personal information only with providers who handle it for us under contracts that limit its use to serving us and require reasonable security:

  • Square (Block, Inc.): payments and POS
  • Render Services, Inc.: website and ordering-site hosting; data stored in the United States (Ohio)
  • Email service provider: Square Marketing (Square Plus); SMS provider: Square Text Marketing (Square Plus)
  • Cloudflare, Inc.: domain registration, DNS, email forwarding (Cloudflare Email Routing), and cookieless website analytics (Cloudflare Web Analytics)
  • Accountants, auditors and lawyers, under confidentiality duties

We may also disclose information: when the law requires it (e.g., a subpoena or court order); to protect safety or prevent fraud; to a successor charitable organization that takes over the restaurant (with notice to you, consistent with Terms §17); or with your consent. Community Tier status is never shared except with your consent, with the partner agency that referred you (limited to confirming enrollment), or as the law requires (Terms §12.2).

6.3 Mitchell & Mitchell Holdings Company. Mitchell & Mitchell Holdings Company ("M&M"), which licenses us the "Reggie Ray's" name, doesn't receive customer, member, Community Tier, order or payment information from us. We share only aggregate, non-identifying sales figures if the trademark license requires them for royalty reporting or quality control. We don't share our Square account, POS, customer lists, gift-card program or marketing lists with M&M or its other Reggie Ray's locations. Before that could change, we would update this notice, explain why, and ask for consent where required.

7. Retention

We keep information only as long as needed:

Data Retention
Active account and plan data While the account is active
Closed accounts Deleted or de-identified 24 months after closure, except the records below
Transaction and sales-tax records 4 years (Ohio sales-tax records: R.C. 5739.11 / OAC 5703-9-02)
Auto-renewal consent and cancellation records 3 years after the plan ends (Terms §7.2)
Marketing opt-in and opt-out records 5 years after the last message (TCPA's 4-year limitation period plus a buffer)
Community Tier eligibility status and approver Until the next six-month re-check plus 12 months, then deleted (for example, a status confirmed on Jan 15 is re-checked by Jul 15 and, if not renewed, deleted by the following Jul 15). Aggregate counts kept
Order allergy notes Kept with the order record for 90 days, unless you save them to your profile
Server and security logs 90 days

8. Cookies and analytics

We use strictly necessary cookies and similar storage (e.g., browser localStorage for your cart, login session, and security tokens). Analytics: we use Cloudflare Web Analytics, a privacy-focused service from Cloudflare, Inc. that doesn't use cookies or local storage and doesn't track you across sites. It uses a small script to count page views and measure page load times in aggregate (for example, the page visited, the referring site, browser and device type, and approximate country). It doesn't build a profile of you or use your information for advertising. We don't use advertising or cross-site tracking cookies, or social media pixels. Your browser settings let you block cookies, but the cart and login may not work. We don't currently respond to "Do Not Track" signals, and our cookieless analytics doesn't track individuals across sites.

9. Your choices and rights

Any customer (not only residents of states with privacy laws) can ask to:

  • access a copy of their personal information;
  • correct it;
  • delete it (we may keep what the law requires, e.g., tax records, or what's needed to finish an active plan charge or resolve a dispute);
  • opt out of marketing email or texts at any time (§4); and
  • for parents, review or delete a child's information (§5).

How: email [email protected], call (234) 226-0561, or ask at the restaurant. We'll verify your identity (e.g., by confirming account details) and respond within 30 days. We won't treat you differently for using these rights.

10. Security and breach notification

We use administrative, technical and physical safeguards: HTTPS; hashed passwords; multi-factor authentication for staff and admin access; staff access based on role (Community Tier status visible only to manager-level staff); tokenized payments through Square; vendor contracts; and staff training. No system is perfectly secure.

Breach notice. If a security breach exposes personal information as defined in Ohio R.C. 1349.19 (name plus Social Security number, driver's license or state ID number, or a financial account or card number with the code or password needed to use it, when not encrypted or redacted), in a way that causes or reasonably is believed to cause a material risk of identity theft or fraud, we'll notify affected Ohio residents as fast as possible and no later than 45 days after discovering it. The deadline can be delayed for law enforcement needs or to determine the scope and restore the system (R.C. 1349.19(B)(2), (D)). Notice may be written, electronic, by phone, or by substitute notice as the statute allows. If more than 1,000 Ohio residents are affected in one breach, we'll also notify the nationwide consumer reporting agencies (R.C. 1349.19(G)). Our service providers must tell us promptly about any breach of data they hold for us (R.C. 1349.19(C)). We'll also follow card-network and Square breach procedures.

11. Changes to this notice

We'll post updates here with a new "Last updated" date. For material changes, e.g., a new kind of sharing, we'll notify account holders by email at least 30 days in advance and ask for consent where required. We won't use previously collected data in a materially different way without consent.

12. Contact

Privacy contact: Regina Barkley, Chief Financial Officer, Reggie Ray's Family Restaurants Incorporated, 1888 State Rt. 59, Kent, OH 44240 · [email protected] · (234) 226-0561.