Gregorio's Trattoria Logo

Privacy Policy

Effective date: August 20, 2026

Gregorio's Trattoria ("Gregorio's," "we," "us") operates this website, online ordering, and the Gregorio's Rewards program, with technology provided by Tavolit ("our service provider"). This policy describes what information we collect, how we use it, and the choices you have. It replaces our previous privacy policy as of the date above.

Information we collect

Account information. When you create an account: your name, email address, password, and — optionally — your phone number and your birthday (month and day only — we never collect the year). Passwords are handled by our identity provider (Amazon Cognito) and are never visible to us or stored on our systems.

Order information. When you place an order: the items you order, order totals, tip, your contact details, and — for delivery orders — your delivery address. Orders are transmitted to the restaurant's point-of-sale system (Heartland) to be prepared.

Payment information. We never see or store your card number. Card details are entered into fields controlled by our payment processor (Global Payments / Heartland) and are tokenized before our systems are involved; we receive only a one-time token, the card brand, and the last four digits. Gift card numbers you enter are passed directly to the processor for balance checks and redemption and are not stored or logged by us.

Rewards and visit information. If you are a Rewards member, we keep your points balance, points history, coupons, and order history. When you dine in-restaurant and give your phone number or email, the restaurant's point-of-sale system reports the completed ticket to us so points can be credited to the matching account.

In-restaurant tickets without a matching account. If a phone number or email is entered on a restaurant ticket that doesn't match any account, we hold that ticket's details (contact info given, items, subtotal) for up to 30 days so the visit can still be credited if you join or ask staff to attach it — after 30 days unclaimed, it is deleted automatically.

Prior rewards program (Como) records. We imported identifiers (email or phone) and point balances from the restaurant's previous rewards program so returning members keep their points. We did not import names, birthdays, or marketing preferences. A legacy balance is attached to your new account when your verified email or verified phone number matches.

Communications. Messages you send through the contact or catering forms, including your name and contact details.

Technical information. Standard web server logs (IP address, browser type, pages requested) used for security, rate limiting, and abuse prevention. We do not run third-party analytics or advertising trackers.

How we use information

  • To process and fulfill your orders and reservations
  • To operate the Rewards program (earning, coupons, birthday rewards)
  • To send transactional messages: order confirmations, verification codes, coupon and account notices
  • To verify your phone number by SMS, with your consent (see SMS below)
  • To respond to your inquiries
  • To secure the service: fraud prevention, rate limiting, debugging
  • To meet legal, tax, and accounting obligations

We do not sell your personal information, and we do not share it with third parties for their own advertising.

SMS / text messages

If you provide your phone number and consent, we send verification codes by SMS. Message frequency is low (verification and account-related messages only). Message and data rates may apply. Reply STOP to opt out and HELP for help. Opting out of SMS does not affect your account; providing a phone number is optional, though it is how in-restaurant visits are matched for points.

Who we share information with

  • The restaurant's point-of-sale and payment systems (Heartland / Global Payments) — to prepare orders, process payments, and operate gift cards.
  • Our service provider (Tavolit) and its hosting provider (Amazon Web Services) — to run the website, ordering, and rewards infrastructure.
  • Google— location pages embed Google Maps, and we display Google review content; interacting with embedded Google content is subject to Google's own privacy policy.
  • OpenTable— if you book through the reservations widget, your reservation details go to OpenTable under OpenTable's privacy policy.
  • Authorities or advisors when required by law or to protect our legal rights.

Cookies and local storage

We use browser local storage for functional purposes only: keeping you signed in, remembering your cart, and remembering interface choices. We do not use advertising cookies or cross-site trackers.

Data retention

  • Account and rewards records: kept while your account is active.
  • Order and transaction records: retained as business and tax records.
  • Unmatched in-restaurant tickets: deleted after 30 days (see above).
  • Server and application logs: retained for a limited period (up to 90 days) for security and reliability, then deleted.

Your choices and rights

You may:

  • Access or correct your information — most of it directly in your account settings (name, phone, password).
  • Delete your account yourself, at any time, from Account → Settings → “Delete my account” — or by contacting us (below) if you prefer. Either way we anonymize your personal details: your name, email address, phone number and birthday are removed, and any unused rewards are voided. Order and transaction records we must keep for tax and accounting purposes are retained without your identifying information.
  • Opt out of SMS at any time (reply STOP).

Residents of Virginia, Maryland, and other states with consumer privacy laws may have additional rights (such as confirming whether we process your data, or appealing a refused request). We honor the rights above for all customers regardless of residence — contact us and we will respond within 45 days.

Children

Our website and Rewards program are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it.

Security

Information is encrypted in transit (HTTPS everywhere) and at rest. Payment card data is handled exclusively by our PCI-compliant payment processor. Access to systems holding personal information is restricted and logged.

Changes to this policy

We may update this policy; changes will be posted on this page with a new effective date. Material changes will be flagged prominently.

Contact us

Gregorio's Trattoria — admin@gregoriostrattoria.com 240-994-6509
Or through the contact form on this site.

Looking for our refund policy? See our Terms of Service.