Privacy Policy
How we handle your information when you use the El Mexicano Grille rewards app.
Last updated: August 28, 2026
Who we are
This rewards app is operated by Mexicano Grille Software LLC, a Texas limited liability company. We refer to ourselves as “we,” “us,” or “the operator” below.
What we collect
- Your phone number. We use it as your account identifier so you don't have to remember a password or email. You provide it when you sign up at /signup.
- Language preference (English or Spanish) and a marketing-opt-in flag, both of which you can change later.
- Transactions you claim from your receipt. When you scan the QR sign at a location and type your check number and total, we record the location, the amount, the time, and the points you earned. If you use the camera scan option, we also record the line items, server name, subtotal, tax, and tip we read off the receipt photo, so you can see a digital receipt in your history later. The restaurant uses those dish lines two ways. Most of it is menu planning in aggregate — which items sell, and which sell together — and those totals carry no name or phone number. But the owner of the restaurant can also open your individual account and see the dish you've ordered most often and your average ticket, alongside your visit history. That per-customer view is visible only to the restaurant's owner account: never to other customers, never to counter staff, and never to anyone outside the business. We never see card numbers. We ask you to enter the pre-tip total; if you include a tip in what you typed, we'll credit points on whatever you entered, but we have no way to separate tip from food.
- Redemptions. When you use points for a free item, we record which reward, when, where, and how many points you spent.
- Push notifications, if you turn them on. If you allow notifications, your browser gives us an address for your device and two keys that let us encrypt messages to it. We store those with your account so we can send you an earn or redemption confirmation. When push is switched on for a device, your loyalty confirmations arrive there instead of by text, not in addition to it. You can turn this off in the app's settings or in your browser, and we delete the device's registration when your browser tells us it is no longer valid.
- Limited technical data. Your IP address and browser user-agent are visible to the vendors below as part of normal request handling and error reporting (Sentry, PostHog, Twilio metadata, Vercel logs, Supabase gateway logs, Google Maps when you load the locations page). Cookies set by the app are functional only: your signed-in session, your language choice, a note that you dismissed a prompt, the staff-device binding for a restaurant's register, and — during signup only — the marketing box you ticked and the number you are verifying. Those last two are readable only by our server, are scoped to the signup page, and are dropped as soon as signup finishes or twenty minutes pass. No advertising or tracking cookies.
We do not collect: your card number, your home address, your email (unless you send us one), your social media identity, or anything from third-party trackers.
About location. On the locations screen you can tap “use my location” to find the nearest restaurant. Your browser asks your permission first, and if you agree the coordinates stay on your device — they are held in your browser's session storage to sort the list and are never sent to us or to Google. What we do save is the restaurant you end up choosing, as your home location, so the app can open on the right menu next time. You can change it any time by picking a different one.
Who processes it for us
We rely on these vendors to run the app. Each gets only what it needs:
- Supabase — our database (hosted on AWS, US region). Stores your phone, transactions, redemptions, and language preference.
- Twilio — sends the one-time signup code and the earn/redeem confirmation texts. Twilio gets your phone number and the message body for each text we send.
- Vercel — hosts the website. Receives standard request logs (IP, user-agent, URL).
- Sentry — captures crashes so we can fix them. Records a masked replay of the page on errors (we configure it to hide all text and inputs by default so phone numbers and codes stay private). Receives the IP, user-agent, and request URL of the erroring session, plus the technical detail of the error itself — which, for a crash on our server, can include the values the code was working with at that moment. Because your phone number is one of those values, we run every report through a filter that strips phone-number patterns before it leaves our server, and we identify you in Sentry by a salted one-way hash rather than your number.
- PostHog — counts events like signups and redemptions so we can see which parts of the app are working. We never send your phone number in plaintext — we send a salted one-way hash so identical visits group together without exposing the number. PostHog also receives your IP and user-agent on each captured event as part of standard analytics traffic.
PostHog also records a masked replay of how the app is used — which screens you open and where you tap — so we can find the places people get stuck. Typed input and sensitive on-screen text are hidden before the recording leaves your device, including your phone number, your account number, and any reward code. Recording is switched off entirely on the sign-in screen, the screen showing a reward code, and your wallet card. We do not record your camera, and receipt photos are never part of a replay. - Google Maps — renders the map on the locations page. When that page loads, Google receives the IP and page URL of your device. Google does not receive your GPS coordinates from us — see the note on location above.
- Anthropic — reads your receipt photo when you choose the camera option on the scan screen. The image is sent to Anthropic's Claude API, which returns the check number, total, and line items as structured fields; the image is discarded as soon as those values come back. We save those fields on our own server at that moment, before you confirm, so that a phone which loses its place — a reload, a switched app, a browser that clears storage — doesn't cost you the receipt. If you never finish the claim, that scan is deleted within about a day. We don't save the photo, we don't store the transcript, and we send no other context (not your phone number or account). We send it to Anthropic's paid developer API — not a consumer chatbot — under the commercial terms that cover business use, and we grant no permission for your receipt to be used to train anyone's model. If you'd rather not use the camera, the typed-entry option is right below it and works without any photo upload.
We do not sell your information. We do not share it with marketers.
SMS and TCPA
By providing your phone number at signup, you consent to receive transactional text messages from us: the one-time signup code, an earn confirmation when you scan a receipt, and a redemption confirmation when you spend points. (If you have turned on push notifications, the earn and redemption confirmations go to your device as a notification instead of a text — you get one or the other, never both. The one-time signup code is always a text.) Message frequency varies (these texts are triggered by what you do — a signup, an earn, a redemption). Reply STOP to any of these to opt out of all texts, or HELP for help. Standard message and data rates from your carrier may apply. We do not send marketing texts unless you check the marketing opt-in at signup; that's a separate consent and you can also opt out of marketing texts by replying STOP.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging opt-in data and consent are never shared with anyone. We do not sell, rent, or trade your phone number. The only companies that touch it are the service providers who operate the app on our behalf — our SMS carrier and our database host — and they may use it only to deliver the service, never for their own marketing. Our payment processor never receives it at all: it bills the restaurants for using this app, and customers never pay us anything. Full program details live on the SMS Program page.
How long we keep it
We keep your account and history for as long as it's active, so your point balance and redemption history stay accurate. There is no automatic expiry — we don't delete dormant accounts and we don't expire points.
If you ask us to delete your account, we remove the whole customer record: your phone number, name, birthday, language preference and marketing flag, along with your saved devices, notes, and the record of the texts we sent you. Your past receipts and redemptions are kept, but the phone number on them is erased, so the restaurant's sales history stays correct while the rows no longer point at a person. This is a manual step we do when you email us, so please allow a few business days — we are not able to do it instantly.
Two things age out on their own. Records of the texts we send you are kept about 90 days and then deleted. A camera scan you start but never finish is deleted within a day or two — those are held only long enough to let you pick the claim back up.
Cross-location visibility
El Mexicano Grille is a family of restaurants run by separate Texas LLCs operating under the same brand. Your account, balance, and history are one record across every Mexicano Grille location participating in this app — so you can earn at one location and redeem at another. Each location sees its own activity with you; the platform operator (Mexicano Grille Software LLC) sees activity across the chain so the loyalty program works as one program rather than separate ones.
Your rights
- See what we have. Sign in at /me to see your balance, history, and language setting.
- Correct it. If a detail is wrong, email us (below) and we'll fix it.
- Delete it. Email us and we'll close your account.
- Stop the texts. Reply STOP to any text. (Stopping texts does not by itself delete your account.)
Children
The app is not intended for anyone under 13. If you're under 13, please don't sign up; if a child under 13 has signed up, contact us and we'll delete the account.
Texas note
We're a Texas operation. We respect Texas consumer rights, and if Texas (or federal) law gives you specific data rights — like the right to know what's collected about you or to ask us to delete it — you can exercise them by emailing the address below.
Changes
If we change this policy in a material way, we'll update the “last updated” date at the top and, where it makes sense, text affected customers.
Contact
Email support@elmexicanogrille.com with privacy or data questions.
See also our Terms of Service.