Privacy Policy

Effective Date: July 24, 2026  |  Last Updated: July 24, 2026

This Privacy Policy describes how Chopt ("we," "us," "our," or "the Company") collects, uses, discloses, and protects the personal information of visitors and customers who access or use our website at fresh-chopt.rest (the "Website") and our food-related services (collectively, the "Services"). We are committed to protecting your privacy and ensuring that your personal information is handled responsibly, transparently, and in accordance with applicable United States federal and state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the Federal Trade Commission Act (FTC Act).

Please read this Privacy Policy carefully. By accessing or using our Website or Services, you acknowledge that you have read, understood, and agree to the practices described herein. If you do not agree with any part of this Privacy Policy, please discontinue your use of our Website and Services immediately.


1. About Us and How to Contact Us

Chopt operates a food service business dedicated to providing fresh, high-quality food products and dining experiences to our valued customers. Our contact details for privacy-related inquiries are as follows:

Company Name Chopt
Website fresh-chopt.rest
Email Address [email protected]
Business Type Food Service / Restaurant
Operating Location United States

For all privacy-related questions, requests, or concerns, you may contact us directly at [email protected]. We will endeavor to respond to all legitimate inquiries within thirty (30) calendar days of receipt.


2. Scope and Applicability

This Privacy Policy applies to all individuals who:

  • Visit or browse our Website at fresh-chopt.rest;
  • Create an account or register on our platform;
  • Place orders for food products or services through our Website;
  • Subscribe to our newsletters, promotional emails, or loyalty programs;
  • Contact us via email, contact forms, or any other communication channel;
  • Interact with our online advertisements or marketing materials;
  • Participate in surveys, contests, or promotional campaigns we conduct.

This policy does not apply to third-party websites, applications, or services that may be linked from our Website. We encourage you to review the privacy policies of any third-party platforms you visit, as we have no control over their data practices.


3. Information We Collect

We collect various categories of personal information depending on how you interact with our Website and Services. The types of information we collect include:

3.1 Personal Identification Information

When you create an account, place an order, make a reservation, or contact us, we may collect the following identifying information:

  • Full name — first and last name as provided by you;
  • Email address — used for account creation, order confirmations, and marketing communications;
  • Phone number — used for order updates and customer service;
  • Mailing or delivery address — used for delivery orders or account preferences;
  • Date of birth — when required for age verification purposes;
  • Username and password — for account authentication and security.

3.2 Payment and Financial Information

When you place an order or make a purchase through our Website, we may collect payment-related information. Please note that all financial transactions are processed through secure, PCI-DSS-compliant third-party payment processors. We do not store full credit card numbers or sensitive banking details on our own servers. We may, however, retain:

  • Partial payment card information (e.g., last four digits);
  • Billing address associated with your payment method;
  • Transaction history, order amounts, and purchase records;
  • Preferred payment methods and stored payment tokens.

3.3 Order and Transaction Information

Every time you place an order or request a service through our Website, we collect:

  • Items ordered, including customizations and dietary preferences;
  • Order history and frequency;
  • Delivery instructions and special requests;
  • Promotional codes or discounts applied;
  • Timestamps and order confirmation numbers.

3.4 Usage and Behavioral Data

We automatically collect certain information about how you use our Website, including:

  • Pages visited, time spent on each page, and navigation paths;
  • Search queries entered on our Website;
  • Links and buttons clicked;
  • Products or menu items viewed, added to cart, or purchased;
  • Referral URLs (the page that directed you to our Website);
  • Frequency and duration of visits.

3.5 Device and Technical Information

When you access our Website, we may automatically collect technical information about your device and browser, including:

  • IP address and approximate geographic location derived from IP;
  • Browser type and version (e.g., Chrome, Firefox, Safari);
  • Operating system and device type (desktop, mobile, tablet);
  • Device identifiers and unique hardware identifiers;
  • Screen resolution and display preferences;
  • Time zone settings and language preferences;
  • Internet service provider (ISP) information.

3.6 Cookies and Tracking Technologies

We use cookies, web beacons, pixel tags, and similar tracking technologies to enhance your experience on our Website. Please refer to Section 9 (Cookie Usage) of this Privacy Policy for detailed information about the types of cookies we use and how to manage your preferences. By continuing to use our Website, you consent to our use of cookies as described herein.

3.7 Communications and Feedback

When you communicate with us — whether through our contact form, email, live chat, or customer service — we retain records of those communications, including:

  • The content of your messages and inquiries;
  • Your contact information as provided in the communication;
  • Our responses and any follow-up correspondence;
  • Customer reviews and feedback submitted through our platform.

3.8 Information from Third Parties

We may receive information about you from third-party sources, such as:

  • Social media platforms, if you choose to log in or share our content;
  • Marketing partners and data analytics providers;
  • Delivery platform integrations (e.g., third-party food delivery apps);
  • Payment processors and fraud detection services;
  • Public databases and commercially available data sources.

4. How We Use Your Information

We use the personal information we collect for a variety of legitimate business purposes. We will only process your data when we have a lawful basis for doing so, which may include your consent, the performance of a contract, compliance with a legal obligation, or our legitimate business interests.

4.1 Service Provision and Order Fulfillment

The primary reason we collect your information is to deliver the food services you request, including:

  • Processing and fulfilling food orders placed through our Website;
  • Managing your account and preferences;
  • Sending order confirmations, receipts, and delivery notifications;
  • Providing customer support and resolving complaints;
  • Facilitating payment processing and fraud prevention.

4.2 Website Performance and Analytics

We use usage and technical data to improve our Website's performance and user experience:

  • Analyzing traffic patterns and user behavior to enhance website design;
  • Identifying and fixing technical errors, bugs, and performance issues;
  • Testing new features, layouts, and menu presentations;
  • Measuring the effectiveness of our content and promotional campaigns;
  • Generating aggregated, anonymized statistical reports.

4.3 Marketing and Promotional Communications

With your consent, or where permitted by applicable law, we may use your information for marketing purposes:

  • Sending promotional emails, newsletters, and special offers;
  • Personalizing recommendations based on your order history;
  • Delivering targeted advertisements on our Website and third-party platforms;
  • Notifying you about new menu items, seasonal specials, and events;
  • Managing loyalty programs, rewards, and referral schemes.

You may opt out of receiving marketing communications at any time by clicking the "unsubscribe" link in any email we send, or by contacting us at [email protected]. Please note that opting out of marketing emails does not affect transactional or service-related communications.

4.4 Legal Compliance and Safety

We may use your information to comply with applicable laws, regulations, and legal processes:

  • Meeting tax, accounting, and financial reporting obligations;
  • Responding to lawful requests from government authorities and law enforcement;
  • Detecting, investigating, and preventing fraudulent transactions;
  • Enforcing our Terms of Service and other legal agreements;
  • Protecting the rights, safety, and property of our customers, employees, and the public.

5. Sharing Your Information with Third Parties

We respect the confidentiality of your personal information and do not sell, rent, or trade your personal data to third parties for their own independent marketing purposes. However, we may share your information in the following circumstances:

5.1 Service Providers and Business Partners

We engage carefully vetted third-party service providers who assist us in operating our business and delivering our Services. These providers access your data only to the extent necessary to perform their contracted services and are bound by strict confidentiality and data protection obligations. Categories of service providers include:

  • Payment processors — to securely handle payment transactions;
  • Delivery and logistics partners — to coordinate and fulfill delivery orders;
  • Cloud hosting and infrastructure providers — to store and process data securely;
  • Email and communication service providers — to send transactional and marketing emails;
  • Analytics providers — to analyze Website usage and improve our Services;
  • Customer support platforms — to manage customer inquiries and complaints;
  • Marketing and advertising technology providers — to display relevant advertisements.

5.2 Legal Requirements and Law Enforcement

We may disclose your personal information to government authorities, regulators, or law enforcement agencies if we believe in good faith that such disclosure is necessary to:

  • Comply with a legal obligation, court order, or governmental directive;
  • Respond to lawful requests from regulatory authorities;
  • Investigate or prevent suspected fraud, security breaches, or illegal activity;
  • Protect the safety and well-being of our customers, employees, or the public;
  • Establish, exercise, or defend legal claims against or involving the Company.

5.3 Business Transfers

In the event that Chopt undergoes a merger, acquisition, restructuring, sale of assets, or insolvency proceeding, your personal information may be transferred to the acquiring entity or successor as part of the business transaction. We will notify you via email or a prominent notice on our Website before your data is transferred and becomes subject to a different privacy policy.

5.4 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data — which cannot reasonably be used to identify any individual — with business partners, researchers, or the public for analytical, statistical, or business development purposes. Such disclosures do not constitute sharing of personal information.


6. Data Security Measures

The security of your personal information is a top priority for Chopt. We implement a comprehensive range of administrative, technical, and physical security measures designed to protect your data from unauthorized access, alteration, disclosure, or destruction. Our security measures include:

6.1 Technical Safeguards

  • SSL/TLS Encryption: All data transmitted between your browser and our Website is encrypted using industry-standard Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocols;
  • Data Encryption at Rest: Sensitive personal data stored on our servers is encrypted using AES-256 or equivalent encryption standards;
  • Firewalls and Intrusion Detection: We deploy firewalls and intrusion detection systems to monitor and protect our network infrastructure;
  • Access Controls: We restrict access to personal data on a strict need-to-know basis, using role-based access controls and multi-factor authentication;
  • Regular Security Audits: We conduct periodic vulnerability assessments and penetration testing to identify and address security risks.

6.2 Organizational Safeguards

  • Regular privacy and data security training for all staff members who handle personal information;
  • Comprehensive data protection policies and internal procedures;
  • Vendor due diligence and contractual data protection obligations for all third-party processors;
  • An established incident response plan in the event of a data breach.
Please Note: While we take every reasonable precaution to safeguard your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data, and you transmit information to us at your own risk. We encourage you to use strong, unique passwords and to keep your login credentials confidential.

6.3 Data Breach Notification

In the event of a data breach that affects your personal information and creates a risk of harm, we will notify affected individuals and, where required, relevant regulatory authorities, in compliance with applicable United States federal and state breach notification laws, including state-specific data breach notification statutes applicable to our operations.


7. Your Privacy Rights

Depending on your state of residence within the United States, you may have certain rights regarding your personal information. We are committed to honoring these rights in accordance with applicable law, including but not limited to the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) for California residents.

7.1 Right to Know and Access

You have the right to request information about the personal data we have collected about you, including the categories of data collected, the sources from which it was collected, the purposes for which it is used, and the categories of third parties with whom it has been shared. You may also request a copy of the specific personal information we hold about you.

7.2 Right to Correction

If any personal information we hold about you is inaccurate, incomplete, or outdated, you have the right to request that we correct or update it. You may also update certain information directly through your account settings on our Website.

7.3 Right to Deletion

You have the right to request that we delete your personal information, subject to certain exceptions. We may retain your data where retention is necessary to: complete a transaction, comply with a legal obligation, detect or prevent security incidents, exercise free speech rights, enable solely internal uses consistent with your expectations, or comply with other legal requirements.

7.4 Right to Opt Out of Sale or Sharing

Under the CCPA/CPRA, California residents have the right to opt out of the sale or sharing of their personal information for cross-context behavioral advertising purposes. To exercise this right, please contact us at [email protected]. We will process your request within fifteen (15) business days.

7.5 Right to Data Portability

You have the right to request a copy of your personal information in a structured, commonly used, machine-readable format so that you can transfer it to another service provider, where technically feasible.

7.6 Right to Limit Use of Sensitive Personal Information

Where applicable under CPRA, you have the right to direct us to limit our use and disclosure of sensitive personal information to only what is necessary to perform our services or comply with legal obligations.

7.7 Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights. This means we will not deny you goods or services, charge you different prices, provide a different level of service quality, or suggest that you will receive different treatment for exercising your rights under applicable privacy law.

7.8 How to Submit a Privacy Rights Request

To exercise any of your privacy rights, please submit a verifiable consumer request to us by:

To process your request, we may need to verify your identity. We will ask you to provide certain information that allows us to confirm that you are the person whose data you are requesting access to or deletion of. We will not use the information provided for verification purposes for any other purpose.

We will respond to verifiable consumer requests within forty-five (45) calendar days of receipt, with a possible extension of an additional forty-five (45) days where reasonably necessary, with prior notice.


8. Data Retention Periods

We retain your personal information only for as long as is necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, resolve disputes, and enforce our agreements. The specific retention periods depend on the category of data and the purpose for which it is held:

Category of Data Retention Period Reason
Account Information Duration of account + 3 years Service provision and legal compliance
Order and Transaction Records 7 years Tax, accounting, and legal compliance
Payment Information Duration of relationship + 5 years Fraud prevention and legal compliance
Marketing Preferences Until opt-out + 1 year Compliance with communication preferences
Website Usage and Analytics Data 26 months Analytics and website improvement
Customer Support Records 3 years from last contact Service improvement and dispute resolution
Cookie and Tracking Data As specified in Cookie Policy Website functionality and analytics

After the applicable retention period has expired, we will securely delete, anonymize, or de-identify your personal information in accordance with our internal data destruction procedures.


9. Cookie Usage

Our Website uses cookies and similar tracking technologies to enhance your browsing experience, analyze Website traffic, and deliver personalized content and advertisements. Cookies are small text files that are stored on your device when you visit our Website.

9.1 Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for the Website to function properly. These cookies enable core features such as security, network management, account authentication, and shopping cart functionality. These cannot be disabled without impairing your use of the Website.
  • Performance and Analytics Cookies: These cookies collect anonymized information about how visitors use our Website, including which pages are visited most often, error messages encountered, and navigation patterns. This data helps us improve Website performance.
  • Functionality Cookies: These cookies allow the Website to remember choices you make (such as your preferred language or region, saved orders, and login status) to provide a more personalized experience.
  • Marketing and Advertising Cookies: These cookies track your browsing activity to deliver targeted advertisements relevant to your interests, both on our Website and on third-party platforms. They may be set by our advertising partners.

9.2 Managing Cookie Preferences

You can manage your cookie preferences at any time through your browser settings. Most browsers allow you to refuse all or certain cookies, delete existing cookies, and receive alerts when new cookies are set. Please note that disabling certain cookies may affect the functionality and performance of our Website.

For more detailed information about the cookies we use, the specific data they collect, and how to manage your preferences, please refer to our Cookie Policy available on our Website at fresh-chopt.rest.


10. Children's Privacy

Age Restriction: Our Website and Services are intended exclusively for individuals who are 18 years of age or older. We do not knowingly collect, solicit, or process personal information from children under the age of 18.

We do not knowingly collect personal information from minors under the age of 18. If you are under 18 years of age, please do not use our Website or submit any personal information to us. If you are a parent or legal guardian and you believe that your child under 18 has provided us with personal information without your consent, please contact us immediately at [email protected].

Upon receiving notification and verifying the claim, we will take immediate steps to delete such information from our records. We comply fully with the Children's Online Privacy Protection Act (COPPA) as administered by the Federal Trade Commission, which restricts the online collection of information from children under the age of 13, and we maintain our age restriction at 18 as an additional protective measure.


11. International Data Transfers

Chopt is based in the United States and operates primarily within the United States. However, some of the third-party service providers and partners we use to operate our Website and deliver our Services may be located in other countries or may process your data on servers located outside the United States.

If your personal information is transferred to or processed in countries outside the United States, we take steps to ensure that appropriate safeguards are in place to protect your information and that such transfers comply with applicable United States law. These safeguards may include:

  • Standard contractual clauses or data processing agreements that impose data protection obligations on the receiving party;
  • Ensuring that service providers located in other countries adhere to recognized data protection standards;
  • Implementing additional technical and organizational measures to protect data in transit and at rest.

By using our Services, you acknowledge and consent to the possible transfer of your personal information to countries outside the United States. If you have questions about international data transfers, please contact us at [email protected].


12. California Privacy Rights (CCPA/CPRA)

If you are a resident of the State of California, you have specific privacy rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), which became fully effective January 1, 2023. In addition to the rights described in Section 7, California residents have the following rights:

12.1 Categories of Personal Information Collected

In the preceding twelve (12) months, we have collected the following categories of personal information as defined by the CCPA:

  • Identifiers (name, email address, IP address, account username);
  • Commercial information (purchase history, order records);
  • Internet or other electronic network activity (browsing history, interactions with our Website);
  • Geolocation data (approximate location derived from IP address or delivery address);
  • Inferences drawn from other personal information to create a profile about preferences and characteristics.

12.2 Do Not Sell or Share My Personal Information

California residents have the right to opt out of the "sale" or "sharing" of their personal information as defined under CCPA/CPRA. To submit such a request, please email us at [email protected] with the subject line "Do Not Sell or Share My Personal Information."

12.3 Shine the Light Law

Under California's "Shine the Light" law (California Civil Code Section 1798.83), California residents may request information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please contact us at [email protected].


13. Third-Party Links and External Websites

Our Website may contain links to third-party websites, social media platforms, delivery partner portals, or other online services that are not owned or operated by Chopt. These links are provided for your convenience and informational purposes only. We have no control over the content, privacy practices, or data collection activities of these third-party websites.

We strongly encourage you to review the privacy policies of any third-party website you visit before submitting personal information or making a transaction. Chopt is not responsible for the privacy practices, content, or security of external websites, and your use of such websites is at your own risk.


14. How to File a Complaint

If you have a concern about how we handle your personal information and you are not satisfied with our response, you have the right to file a complaint with the appropriate regulatory authority.

14.1 Contacting Us First

Before filing a formal complaint, we encourage you to contact us directly to allow us the opportunity to resolve your concerns:

14.2 Federal Trade Commission (FTC)

The Federal Trade Commission (FTC) is the primary federal consumer protection agency in the United States with authority over unfair or deceptive trade practices, including violations of consumer privacy. You may file a complaint with the FTC at:

  • Website: www.ftc.gov/complaint
  • Phone: 1-877-382-4357
  • FTC Consumer Response Center: 600 Pennsylvania Avenue NW, Washington, D.C. 20580

14.3 California Privacy Protection Agency (CPPA)

California residents may submit privacy-related complaints to the California Privacy Protection Agency (CPPA), the agency responsible for enforcing the CCPA/CPRA:

  • Website: cppa.ca.gov
  • Address: 2101 Arena Blvd, Sacramento, CA 95834

14.4 State Attorney General Offices

Depending on your state of residence, you may also file a complaint with your state's Attorney General's office, which may have authority to investigate privacy violations under state consumer protection and data privacy laws. We encourage you to consult your state's official government website for the appropriate contact information.


15. Changes to This Privacy Policy

We reserve the right to update, modify, or revise this Privacy Policy at any time to reflect changes in our business practices, legal requirements, or the ways in which we collect and use personal information. When we make material changes to this Privacy Policy, we will:

  • Update the "Last Updated" date at the top of this page;
  • Post a prominent notice on our Website notifying you of the changes;
  • Where required by law or where changes are material, send you an email notification if we have your email address on file.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our Website or Services after the effective date of any revised Privacy Policy constitutes your acknowledgment and acceptance of the updated terms.


16. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the United States, including applicable federal statutes such as the Federal Trade Commission Act (15 U.S.C. § 45), the Children's Online Privacy Protection Act (15 U.S.C. §§ 6501–6506), the CAN-SPAM Act (15 U.S.C. §§ 7701–7713), and the Electronic Communications Privacy Act (18 U.S.C. §§ 2510–2523). For California residents, this policy is additionally subject to the California Consumer Privacy Act (Cal. Civ. Code §§ 1798.100–1798.199) as amended by the California Privacy Rights Act.

Any disputes arising under this Privacy Policy shall be subject to the exclusive jurisdiction of the applicable courts in the United States.


17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your personal information, or our data practices, please do not hesitate to contact our Privacy Team:

Chopt — Privacy Inquiries

We are committed to working with you to resolve any privacy-related concerns in a timely and transparent manner. We will respond to all verifiable privacy requests within the timeframes required under applicable law, and no later than forty-five (45) calendar days from the date of receipt.

This Privacy Policy was last reviewed and updated on July 24, 2026. If you have accessed this policy after this date, please verify whether a newer version is available on our Website at fresh-chopt.rest.