+1 801-566-1437 | [email protected]
7101 Bingham Jct Blvd, Midvale, UT 84047, USA

Privacy Policy

At Costa Vida, we are deeply committed to protecting your privacy and safeguarding the personal information you share with us. This Privacy Policy explains in detail how we collect, use, disclose, retain, and protect your personal data when you visit our website at costavidacafe.click, use our online ordering platform, subscribe to our communications, or otherwise interact with our services. Please read this document carefully to understand our practices and your rights regarding your personal information.

By accessing or using our website or services, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree with the practices described herein, please discontinue use of our website and services immediately.


1. About Costa Vida

Costa Vida is a food and dining establishment operating in the United States. We provide fresh, high-quality food services to our customers through our physical locations and digital platforms. Our digital presence is maintained through our official website at costavidacafe.click.

1.1 Contact Information

Company Name Costa Vida
Website costavidacafe.click
Email [email protected]

For all privacy-related inquiries, requests, or concerns, please contact us using the email address listed above. We are committed to responding to all privacy inquiries in a timely and professional manner.


2. Scope of This Privacy Policy

This Privacy Policy applies to all individuals who interact with Costa Vida's digital services, including but not limited to:

  • Visitors to our website at costavidacafe.click
  • Customers who place online orders through our platform
  • Individuals who subscribe to our email newsletter or promotional communications
  • Users who create accounts on our platform
  • Individuals who contact us through our website contact forms or email
  • Users who interact with our social media pages and digital advertisements

This policy does not apply to third-party websites, applications, or services that may be linked from our website. We encourage you to review the privacy policies of any third-party platforms you visit through links on our website.


3. Information We Collect

We collect various categories of personal information to provide our services, improve your experience, and comply with applicable legal obligations. Below is a comprehensive description of the types of information we collect.

3.1 Personal Identification Information

When you create an account, place an order, or contact us, we may collect the following personal identification information:

  • Full name — to identify you and personalize your experience
  • Email address — for account management, order confirmations, and communications
  • Phone number — for order updates, customer service, and verification purposes
  • Mailing and delivery address — for processing and delivering your orders
  • Date of birth — where provided, for age verification and promotional purposes
  • Username and password — for account security and authentication

3.2 Payment and Financial Information

When you make a purchase through our website, we collect payment-related information necessary to process your transaction. This may include:

  • Credit card or debit card number (last four digits only, as full card numbers are processed by our secure payment processor)
  • Billing address associated with your payment method
  • Transaction history and order amounts
  • Payment method type (e.g., Visa, Mastercard, American Express)

3.3 Usage and Behavioral Data

We automatically collect information about how you interact with our website and services. This includes:

  • Pages visited and time spent on each page
  • Clickstream data and navigation patterns
  • Search queries submitted on our platform
  • Products or menu items viewed, added to cart, or purchased
  • Features used and interactions with our digital tools
  • Referral URLs (the website that directed you to ours)
  • Session duration and frequency of visits

3.4 Device and Technical Information

We collect technical information about the device and software you use to access our website, including:

  • IP address and approximate geographic location derived from your IP address
  • Browser type and version
  • Operating system and device type (mobile, tablet, desktop)
  • Screen resolution and display settings
  • Time zone settings
  • Language preferences
  • Cookie identifiers and similar tracking technologies
  • Internet service provider (ISP) information

3.5 Communications and Feedback

When you communicate with us directly, we collect the information contained in those communications, which may include:

  • Content of emails or messages sent to our customer service team
  • Feedback, reviews, and ratings you provide about our food or services
  • Survey responses and opinions expressed through research activities
  • Social media interactions and messages

3.6 Information From Third Parties

We may receive information about you from third-party sources, including:

  • Social media platforms (if you log in using social media credentials or interact with our social pages)
  • Marketing partners and data analytics providers
  • Delivery service partners who facilitate order fulfillment
  • Review platforms that aggregate customer feedback

4. How We Use Your Information

We use the personal information we collect for a variety of legitimate business purposes. The legal bases for processing your data under applicable U.S. law and industry standards include fulfilling contractual obligations, legitimate business interests, compliance with legal requirements, and with your consent where required.

4.1 Service Provision and Order Fulfillment

  • Processing and fulfilling your food orders, whether for pickup or delivery
  • Creating and managing your customer account
  • Sending order confirmations, receipts, and delivery updates
  • Facilitating payment processing and refunds
  • Providing customer support and resolving complaints
  • Personalizing your menu experience based on past orders and preferences

4.2 Analytics and Service Improvement

  • Analyzing website traffic, user behavior, and usage patterns to improve our platform
  • Conducting internal research and development to enhance our menu offerings
  • Measuring the effectiveness of our website features and user interface
  • Identifying and resolving technical issues, bugs, and security vulnerabilities
  • Monitoring and improving website performance and load times

4.3 Marketing and Promotional Communications

  • Sending you promotional emails, newsletters, and special offers (where you have opted in)
  • Delivering personalized marketing messages based on your preferences and order history
  • Running loyalty programs and rewarding repeat customers
  • Displaying targeted advertisements on third-party platforms (subject to your preferences)
  • Conducting promotional campaigns, contests, and giveaways

You have the right to opt out of marketing communications at any time. Each promotional email we send will include an unsubscribe link. You may also opt out by contacting us at [email protected].

4.4 Legal Compliance and Safety

  • Complying with applicable federal, state, and local laws and regulations
  • Responding to lawful requests from government authorities or law enforcement
  • Enforcing our Terms of Service and other legal agreements
  • Protecting the rights, property, and safety of Costa Vida, our customers, and the public
  • Detecting, preventing, and addressing fraud, unauthorized transactions, and other illegal activities

5. Sharing of Your Information With Third Parties

Costa Vida values your privacy and does not sell your personal information to third parties for monetary compensation. However, we may share your information in the following circumstances:

5.1 Service Providers and Business Partners

We engage trusted third-party service providers who assist us in operating our business and delivering services to you. These providers are contractually obligated to protect your information and use it only for the purposes we specify. Categories of service providers include:

  • Payment processors — to securely handle credit card and payment transactions
  • Delivery and logistics partners — to facilitate food delivery to your location
  • Email and communication platforms — to send transactional and marketing communications
  • Cloud hosting and IT infrastructure providers — to store and manage our website and data
  • Analytics providers — to analyze website performance and user behavior (e.g., Google Analytics)
  • Marketing and advertising platforms — to deliver targeted advertisements and measure campaign effectiveness
  • Customer relationship management (CRM) systems — to manage customer interactions and service requests

5.2 Legal Requirements and Law Enforcement

We may disclose your personal information when required to do so by law or in good-faith belief that such disclosure is necessary to:

  • Comply with a legal obligation, subpoena, court order, or regulatory requirement
  • Respond to requests from law enforcement or government agencies
  • Protect and defend the legal rights of Costa Vida
  • Investigate potential violations of our Terms of Service
  • Protect the safety of our customers, employees, or the general public

5.3 Business Transfers

In the event of a merger, acquisition, corporate restructuring, sale of assets, or bankruptcy proceeding involving Costa Vida, your personal information may be transferred to the acquiring entity as part of the transaction. We will notify you of any such change in ownership or control of your personal data in accordance with applicable law.

5.4 With Your Consent

We may share your information with third parties in other circumstances with your explicit prior consent. You may withdraw such consent at any time by contacting us at [email protected].


6. Cookie Policy and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, and deliver personalized content and advertisements. This section provides a summary of our cookie practices.

6.1 What Are Cookies?

Cookies are small text files placed on your device by websites you visit. They are widely used to make websites function efficiently and to provide information to website owners. Cookies can be "session cookies" (deleted when you close your browser) or "persistent cookies" (remaining on your device for a set period).

6.2 Types of Cookies We Use

Cookie Type Purpose Duration
Strictly Necessary Required for core website functionality (e.g., shopping cart, login sessions) Session
Performance & Analytics Collect anonymous data about website usage to improve performance Up to 2 years
Functionality Remember your preferences (e.g., language, location) Up to 1 year
Targeting & Advertising Deliver personalized ads and measure marketing campaign effectiveness Up to 2 years

6.3 Managing Cookie Preferences

You can manage or disable cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or be notified when a cookie is being set. Please note that disabling certain cookies may affect the functionality of our website and your ability to use certain features, including online ordering.

Additionally, you may opt out of interest-based advertising through industry tools such as the Digital Advertising Alliance's opt-out page at optout.aboutads.info or the Network Advertising Initiative's opt-out page at optout.networkadvertising.org.


7. Data Security Measures

Costa Vida takes the security of your personal information seriously and implements a range of technical, administrative, and physical safeguards to protect your data against unauthorized access, disclosure, alteration, or destruction.

7.1 Technical Safeguards

  • SSL/TLS Encryption: All data transmitted between your browser and our website is encrypted using industry-standard Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocols.
  • Data Encryption at Rest: Sensitive data stored on our servers is encrypted using AES-256 encryption or equivalent standards.
  • Firewalls and Intrusion Detection: We deploy firewalls, intrusion detection systems, and security monitoring tools to protect our network infrastructure.
  • Access Controls: Access to personal data is restricted to authorized personnel on a need-to-know basis, and all access is logged and monitored.
  • Secure Payment Processing: Payment data is handled by PCI-DSS Level 1 compliant payment processors to ensure the highest standards of financial data security.

7.2 Administrative Safeguards

  • Regular employee training on data privacy and security best practices
  • Data privacy impact assessments for new projects and technologies involving personal data
  • Vendor due diligence to ensure third-party service providers meet our security standards
  • Documented incident response procedures for handling data breaches

7.3 Limitations of Security

While we strive to use commercially reasonable means to protect your personal information, no method of data transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data. In the event of a data breach that affects your rights and freedoms, we will notify you and relevant authorities as required by applicable law, including state data breach notification laws applicable in your state of residence.


8. Your Privacy Rights

Depending on your state of residence within the United States, you may have various rights regarding your personal information. Costa Vida is committed to honoring these rights and provides mechanisms for you to exercise them.

8.1 Rights Under the California Consumer Privacy Act (CCPA/CPRA)

If you are a resident of California, you have the following rights under the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA):

  • Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you, the sources from which we collected it, the purposes for which we use it, and the third parties with whom we share it.
  • Right to Delete: You have the right to request the deletion of your personal information that we have collected, subject to certain exceptions provided by law.
  • Right to Correct: You have the right to request that we correct inaccurate personal information we maintain about you.
  • Right to Opt Out of Sale or Sharing: You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising purposes. To exercise this right, please contact us at [email protected].
  • Right to Limit Sensitive Personal Information Use: You have the right to limit our use of sensitive personal information to necessary purposes.
  • Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA/CPRA privacy rights. We will not deny you services, charge you different prices, or provide a different level of service based on your exercise of these rights.

8.2 General Privacy Rights for All U.S. Customers

Regardless of your state of residence, Costa Vida extends the following rights to all customers to the extent practicable:

  • Right of Access: You may request a copy of the personal information we hold about you.
  • Right to Correction: If your personal information is inaccurate or incomplete, you may request that we update it.
  • Right to Deletion: You may request that we delete your personal data, subject to certain legal retention requirements.
  • Right to Data Portability: Where technically feasible, you may request that we provide your personal information in a structured, commonly used, machine-readable format.
  • Right to Withdraw Consent: Where we rely on your consent to process your data, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to Opt Out of Marketing: You may opt out of receiving marketing communications from us at any time.

8.3 How to Exercise Your Rights

To submit a privacy request or exercise any of the rights described above, please contact us using the following method:

We will verify your identity before processing your request to ensure the security of your personal information. We will respond to verified requests within 45 days of receipt. If we require additional time, we will notify you of the extension and the reasons for it. In some cases, we may not be able to fulfill your request if doing so would conflict with applicable legal obligations or legitimate business interests; in such cases, we will explain the basis for our decision.


9. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. The specific retention periods we apply depend on the type of information and the purpose for which it was collected.

Data Category Retention Period Basis for Retention
Account information Duration of account + 3 years after closure Contractual obligation, legal compliance
Order history and transaction records 7 years Tax and accounting obligations (IRS requirements)
Payment information (tokenized) Duration of account or last transaction + 1 year Fraud prevention, chargeback handling
Marketing communications preferences Until opt-out + 1 year Compliance with anti-spam laws
Website analytics and usage data Up to 26 months Legitimate business interest
Customer service communications 3 years from last interaction Dispute resolution, quality assurance
Security and fraud prevention logs 2 years Security monitoring and incident response

When your personal information is no longer needed for these purposes, we will securely delete, anonymize, or aggregate it in accordance with our internal data retention and disposal procedures.


10. Children's Privacy

Costa Vida's website and online services are intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from children under the age of 13, in compliance with the Children's Online Privacy Protection Act (COPPA), or from individuals under the age of 18 without verifiable parental consent.

If you are under 18 years of age, please do not use our website, create an account, or submit any personal information to us. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at [email protected]. Upon verification, we will promptly delete such information from our records and terminate any associated account.

We do not knowingly direct targeted advertising at children and do not include children in our intended audience for marketing purposes.


11. International Data Transfers

Costa Vida operates primarily within the United States, and your personal information is collected, processed, and stored on servers located within the United States. However, some of our third-party service providers, including cloud hosting services, analytics providers, and communication platforms, may process data on servers located outside of the United States.

When we transfer your personal information internationally, we take appropriate steps to ensure that your data receives an adequate level of protection, consistent with the requirements of applicable United States privacy laws and industry best practices. These measures may include:

  • Entering into data processing agreements with international service providers that include appropriate contractual data protection clauses
  • Ensuring that international providers maintain equivalent data security standards
  • Conducting due diligence on international service providers' privacy and security practices

By using our services, you acknowledge that your information may be transferred to and processed in countries outside of your country of residence, which may have different data protection laws than those applicable in your jurisdiction.


12. Legal Basis for Processing Under U.S. Law

In the United States, our data processing activities are governed by applicable federal and state privacy laws, including:

  • The Federal Trade Commission Act (FTC Act) — which prohibits unfair or deceptive business practices, including in relation to privacy and data security
  • The California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) — governing the privacy rights of California residents
  • The Children's Online Privacy Protection Act (COPPA) — governing the collection of data from children under 13
  • The CAN-SPAM Act — governing commercial email communications
  • The Electronic Communications Privacy Act (ECPA) — governing the interception of electronic communications
  • Applicable state-specific data breach notification laws
  • Other applicable federal and state consumer protection laws

We process your personal information in accordance with these legal frameworks and maintain internal compliance programs to ensure ongoing adherence to applicable law.


13. Third-Party Links and External Websites

Our website may contain links to third-party websites, social media platforms, and partner services that are not operated by Costa Vida. When you click on these links, you will be directed away from our website and subject to the privacy practices of those third-party platforms.

We have no control over the content, privacy policies, or data practices of third-party websites. We are not responsible for the privacy practices or the content of any third-party sites. We encourage you to review the privacy policies of every website you visit. The inclusion of a link on our website does not imply our endorsement of the linked website or its privacy practices.


14. Do Not Track Signals

Some web browsers and mobile devices offer a "Do Not Track" (DNT) feature that sends a signal to websites requesting that they do not track your browsing activities. Currently, there is no universally accepted standard for how websites should respond to DNT signals. As a result, our website does not currently respond to DNT browser signals in a uniform manner. However, you may use the cookie management tools described in Section 6 of this policy to control tracking technologies on our website.

We will continue to monitor developments regarding DNT standards and will update our practices accordingly as industry norms evolve.


15. How to File a Complaint

If you believe that Costa Vida has violated your privacy rights or failed to comply with applicable privacy laws, we encourage you to first contact us directly so that we may attempt to resolve your concern:

We take all privacy complaints seriously and will acknowledge receipt of your complaint within 10 business days and aim to resolve the matter within 45 days.

15.1 Filing a Complaint With Regulatory Authorities

If you are not satisfied with our response to your privacy complaint, you have the right to escalate your complaint to applicable regulatory authorities:

  • California Residents: The California Privacy Protection Agency (CPPA) oversees enforcement of the CCPA/CPRA. You may file a complaint at: cppa.ca.gov. Additionally, the California Attorney General's office handles CCPA enforcement matters.
  • Federal Level: The Federal Trade Commission (FTC) handles complaints related to deceptive or unfair trade practices, including privacy violations. Complaints may be filed at: reportfraud.ftc.gov or ftc.gov/complaint.
  • All U.S. Residents: If you believe your privacy rights have been violated, you may also contact your state Attorney General's office for assistance or to file a formal complaint under your state's consumer protection laws.

16. Changes to This Privacy Policy

Costa Vida reserves the right to update, modify, or revise this Privacy Policy at any time to reflect changes in our business practices, legal requirements, or technological developments. When we make material changes to this policy, we will take reasonable steps to notify you, which may include:

  • Posting a prominent notice on our website homepage
  • Sending an email notification to registered users
  • Updating the "Last Updated" date at the top of this policy

Your continued use of our website or services following the posting of any updated Privacy Policy constitutes your acceptance of the revised terms. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information. If you do not agree with the updated policy, you should discontinue use of our services and may request deletion of your personal information as described in Section 8.


17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to reach out to us. Our team is dedicated to addressing your privacy concerns promptly and transparently.

Company Costa Vida
Website costavidacafe.click
Privacy Email [email protected]

This Privacy Policy was last updated on June 29, 2026, and is effective as of the same date. All previous versions of this Privacy Policy are superseded by this document.