Privacy Policy

Last Updated: June 2026

1. Introduction

248.AI ("we," "our," or "us") provides Ora, a restaurant data and sales intelligence platform for go-to-market teams. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our website, API, database, enrichment services, exports, checkout pages, and related services (collectively, the "Services").

2. Information We Collect

2.1 Account and Contact Information

When you contact us, request access, create an account, purchase Ora tokens or subscriptions, or use our Services, we may collect:

  • Name, work email address, company name, job title, and contact details
  • Login credentials, authentication data, workspace information, and API keys
  • Billing, checkout, invoice, and payment status information handled through our payment providers
  • Support requests, demo requests, messages, and other information you choose to provide

2.2 Business Data You Provide

When you use Ora, you may provide business data for enrichment, matching, refresh, or export, including:

  • Restaurant names, addresses, domains, location identifiers, and CRM or warehouse rows
  • Requested enrichment fields, filters, webhook URLs, export destinations, and source metadata
  • Lead lists, territory files, account lists, and related sales workflow data

2.3 Publicly Available Business Data

Ora collects and organizes publicly available information about restaurants, bars, operators, and related businesses, including:

  • Official websites, menus, PDFs, online ordering, reservations, catering, loyalty, gift card, and mobile app signals
  • Maps, business profile information, reviews, photos, hours, location status, and category information
  • Delivery, pickup, POS, reservation, payment, and other vendor surfaces
  • Public records, licensing information, filings, local news, social pages, and visible expansion signals

We use this data to create restaurant intelligence records, refresh customer data, and help sales teams prioritize and personalize outreach.

2.4 Usage, Device, and Technical Data

We automatically collect certain information when you use our Services, such as IP address, browser type, device information, pages visited, API requests, request IDs, logs, performance data, error reports, and feature usage.

3. How We Use Information

We use information to:

  • Provide, operate, secure, and maintain Ora
  • Match, enrich, refresh, and export restaurant data requested by customers
  • Run API, database, webhook, checkout, billing, support, and onboarding workflows
  • Improve data quality, coverage, reliability, and product performance
  • Respond to inquiries, provide customer support, and communicate about the Services
  • Detect, prevent, and address fraud, abuse, technical issues, and security vulnerabilities
  • Comply with legal obligations and enforce our agreements

4. Data Sharing and Disclosure

We do not sell personal information. We may share information only in the following circumstances:

  • Service providers: With vendors that help us host, operate, secure, analyze, support, bill for, and deliver the Services.
  • Customer-directed workflows: With destinations you configure, such as webhooks, exports, warehouses, or CRM systems.
  • Legal requirements: When required by law, court order, subpoena, governmental authority, or similar legal process.
  • Business transfers: In connection with a merger, acquisition, financing, reorganization, or sale of assets.
  • Protection of rights: To protect our rights, property, safety, users, customers, or the public.

5. Third-Party Services

Ora may rely on third-party services for hosting, storage, database infrastructure, payment processing, analytics, email delivery, security, support, and public-source data collection. These third parties process information according to their own terms and privacy policies.

6. Data Storage, Security, and Retention

We use technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. These safeguards include access controls, encrypted transport, operational monitoring, and limited access to production systems.

We retain information only as long as needed to provide the Services, meet contractual or legal obligations, resolve disputes, maintain security, and improve data quality. When information is no longer needed, we delete, aggregate, or anonymize it where appropriate.

No method of transmission or storage is completely secure. While we work to protect information, we cannot guarantee absolute security.

7. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.

To exercise these rights, contact us using the information below. We may need to verify your request before responding.

8. Cookies and Website Analytics

Our website may use cookies, local storage, and similar technologies to keep the site working, understand usage, remember preferences, and improve performance. You can control cookies through your browser settings, though disabling cookies may affect parts of the Services.

9. Children's Privacy

The Services are not intended for children under 13, or under 16 in the European Economic Area. We do not knowingly collect personal information from children. If you believe a child provided personal information to us, please contact us.

10. International Data Transfers

Information may be transferred to and processed in countries other than your country of residence. We use safeguards designed to protect information in accordance with this Privacy Policy and applicable law.

11. California Privacy Rights

California residents may have rights to know, access, correct, delete, and opt out of certain uses of personal information. We do not sell personal information.

12. European Privacy Rights

If you are located in the European Economic Area, United Kingdom, or Switzerland, our legal bases for processing may include contract performance, legitimate interests, consent, and legal obligations.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last Updated" date. Your continued use of the Services after changes are posted means you accept the updated policy.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

248.AI

Email: uzair.qarni@248.ai

Address: 151 10th Street, San Francisco, California, United States

We will respond to your inquiry within 30 days.