Privacy policy
Last updated: 4 October 2026
This policy explains how Innolink Capital VBA, trading as Innolink ("Innolink", "we"), Oranjestad, Aruba handles personal data in the Innolink platform and on this website.
Who is responsible
For the data a restaurant or shop puts into the platform (its customers, staff and orders), that business is responsible and we process the data on its behalf. For our own website, our sign-in accounts and our billing, we are responsible.
What we collect
- Account details: name, email address, phone number, role, and sign-in security data such as passkeys and two-step codes.
- Business data: stores, menus, orders, payments, refunds, stock, staff schedules and hours, as entered or created by the business.
- Customer data, when a business uses online ordering, kiosks or loyalty: name, email, phone, delivery address, order history and loyalty points.
- Technical data: device and browser information, IP address and logs, used for security and to keep the service working.
- Data from connected services, such as QuickBooks Online: the company name, the list of accounts, products and suppliers, and the identifiers of the documents we create. We read only what is needed to let the business choose where its sales go, and we write only the sales receipts, refund receipts and bills it has set up to send.
How we use it
To provide and secure the service, process orders and payments, send the emails the service needs (such as order confirmations and sign-in codes), provide support, and bill our customers. We do not sell personal data, and we do not use it for advertising.
Who we share it with
Only with services needed to run the platform, each under its own obligations: hosting, email delivery, error monitoring, and the payment, delivery and accounting services a business chooses to connect (for example CyberSource, Sentoo, Pay.aw, Deliverect and QuickBooks Online). We disclose data to authorities only when the law requires it.
How long we keep it
For as long as the business uses the service. After a business stops, its data is kept for up to 12 months so it can still download it, then deleted, with at least 30 days' notice to the owner. Payment card numbers are never stored by us: card details go directly to the payment provider.
Security
Data is encrypted in transit, sensitive keys are stored encrypted, every account uses two-step sign-in, and access is logged.
Your rights
You can ask to see, correct or delete your personal data. If your data was entered by a restaurant or shop, contact that business first; we will help them. Contact us at privacy@innolinkholdings.com.
Changes
We will post changes here and update the date above. Material changes are also emailed to account owners.