We keep an enquiry for 18 months and your cookie choice for six.
This is what happens to the details you give us when you ask about office coffee service in Austin, a breakroom micromarket, office lunch delivery or running your staff canteen. It is short where it can be. The notes in the margin carry the dates and the clocks.
01Who runs this site
The site is operated by Continentalserves, trading at continentalserves.net as Continental Serves. We are a workplace food-service operator: coffee points, micromarkets, daily lunch delivery and cafeteria operation for Austin offices. For the purposes of privacy law we are the business that decides what is collected here and why, which the European rules call the controller.
Our postal address is 46 Market Street, Suite 4, Austin, Texas 59966, United States. The same building holds the office and the commissary kitchen, so a letter lands on a desk that someone actually sits at from 06:30 on weekdays.
02What an office coffee or lunch enquiry sends us
The inquiry form posts to our own server. When you press send it writes these fields: your name, phone, email, the office address, the kind of enquiry you picked, your message, any specification you added (headcount, floor, hours, dietary counts) and the consent tick.
With it, automatically, the server records your IP address, your browser's user-agent string, the referring URL, the moment the form was rendered and the moment it was sent. The two timestamps are there because a form filled in under two seconds was not filled in by a person.
The support chat keeps the conversation on our server and a token in your browser, so you can close the tab and come back to the same thread. If you give a name, phone or email in the chat, those are stored with the conversation.
Cookies and similar browser storage hold your consent choice under site_consent_v2. Once you allow storage, the Google, Microsoft and Meta tags can set their own identifiers. When you arrive from an ad, the landing URL carries a click identifier: gclid, msclkid or fbclid. We read it from the address bar. It is a random string tied to the ad click, not your name.
03What each piece is used for
The form fields go to one place: someone here reads them and calls or writes back. The address tells us which route your office sits on and whether the 11:40 crates can reach you by 12:00. Headcount decides whether a micromarket makes sense or whether a coffee point comes first.
IP address, user-agent and the two timestamps are used to stop spam and abuse and to trace a fault if the form breaks. The referring URL and any click identifier tell us which ad or page brought you, so we can see which campaigns produce real enquiries and stop paying for the ones that do not.
The chat transcript is used to answer you and to pick up the thread later. We do not use enquiries for newsletters. We do not sell lists. If you never become a client, we do not keep writing to you.
04The legal basis for each purpose
Where the GDPR applies, every use needs a basis. Ours are set out below. US state law does not use the same labels, but the same limits hold for everyone.
| Purpose | Data | Basis |
|---|---|---|
| Answering your enquiry and preparing a site survey | Form fields, chat transcript | Steps before a contract, at your request, and your consent tick |
| Spam and abuse protection, fault tracing | IP, user-agent, timestamps, server logs | Legitimate interest in keeping the form working |
| Ad measurement and conversion matching | Click identifiers, advertising cookies | Consent, given in the cookie banner |
| Site statistics | Analytics cookies | Consent, given in the cookie banner |
| Remembering your cookie choice | site_consent_v2 | Legal obligation to record consent, and legitimate interest |
| Running the service once you are a client | Contact and site details | Contract |
05The ad platforms that send people here
We pay for clicks. Google Ads and Microsoft Advertising send traffic to this site today, and Meta Ads does where we run a campaign there. Someone searching for office lunch delivery in Austin sees an ad, clicks it, and lands here with a click identifier in the link.
- Google Ads attaches
gclid. - Microsoft Advertising attaches
msclkid. - Meta Ads attaches
fbclid.
If you have allowed storage, the identifier is kept so that, when you later send an enquiry, the platform can count that a click turned into a real conversation. If you have not allowed storage, the identifier stays in the address bar and goes nowhere. These platforms send us clicks; none of them has reviewed or vouched for this site, and we do not suggest otherwise.
06Consent Mode v2, held at denied
We use Google's Consent Mode v2. Before the page does anything else, four signals are set to denied: ad_storage, ad_user_data, ad_personalization and analytics_storage. They stay denied until you press Allow in the banner.
Press Allow and they switch to granted. Press Decline, or withdraw later from Cookie settings, and they go back to denied the same moment. With the signals denied, the tags may send cookieless pings that carry no identifier from your browser; they do not write advertising or analytics cookies.
07Who else receives the data
A short list, named one by one:
- Google Ireland Ltd and Google LLC, for Google Ads. It attaches
gclidto a click and receives the consent signals. - Microsoft Ireland Operations Ltd, for Microsoft Advertising. It attaches
msclkid. Its own handling is covered by the Microsoft privacy statement at privacy.microsoft.com. - Meta Platforms Ireland Ltd, for Meta Ads, which attaches
fbclid, where a campaign runs there. - Our hosting provider, which serves this site and stores the enquiry database and chat transcripts.
- Our mail provider, which carries the notification of a new enquiry to our inbox.
Nobody else. We do not hand enquiries to brokers, food suppliers or other caterers. If a coffee machine supplier needs your floor plan for an install, we ask you first.
08Data that crosses a border
We collect in the United States and keep enquiries here. If you reach us from Europe, your data travels to the US to be read. The ad platforms move data between their Irish entities and their US parents.
Those transfers rest on the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards that apply to a given transfer.
09How long each thing is kept
Real periods, not "as long as needed":
| Record | Kept for |
|---|---|
| Enquiries and their email copies | 18 months |
| Chat transcripts | 18 months |
| Server and access logs | 90 days |
| Record of a consent choice | 6 months |
Eighteen months covers the usual gap between a first call and a signed service: offices plan a move, a lease runs out, a budget waits for the next year. After that the record is deleted. If you become a client, the contract has its own record-keeping, set out in the terms.
10How the data is protected
Every page and every form post travels over HTTPS. The enquiry store sits outside the public web folder and is reached only through a password-protected panel used by our own staff. Honeypot fields and the render-time check keep most bots out before anything is written.
Access is limited to the people who answer enquiries and plan routes. Route drivers do not see enquiry data. No system is perfect; if we find a breach that puts you at risk, we tell you and, where the law requires it, the regulator.
11Your rights under the GDPR
If you reach this site from Europe, the GDPR gives you these rights, and we honour them without asking why:
- Access: a copy of what we hold on you.
- Rectification: fix what is wrong, such as a misspelled name or an old address.
- Erasure: delete it before the retention clock runs out.
- Restriction: we keep it but stop using it while a dispute is settled.
- Portability: your form data in a machine-readable file.
- Objection: to anything we do on legitimate interest.
- Withdrawing consent: at any time, for the future, from the Cookie settings button.
12Rights under US state law
US state privacy law applies here. In California, the CCPA as amended by the CPRA gives you the right to know what we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information. Other states with laws in force, Texas among them, give similar rights.
We do not sell personal information for money. Letting an ad platform count a click can count as sharing for cross-context advertising under the CCPA, so we treat it that way: Decline in the banner, or a Global Privacy Control signal, is your opt-out. We do not treat you differently for using any of these rights. The price basis we quote for a coffee point is the same either way.
13Global Privacy Control
If your browser sends the Global Privacy Control signal, the Sec-GPC header, we treat it as an opt-out of sale and sharing and as a refusal of advertising storage. The four Consent Mode signals stay denied and the banner does not ask you again. You can still allow storage yourself from Cookie settings if you want to.
14Children
This site is for office managers, facilities teams and the people who sign food-service contracts. It is not meant for children and we do not knowingly collect data from anyone under 16. If a child has written to us, tell us and we delete it.
15Complaining to a regulator
Write to us first if you can; most things are fixed in a phone call. You do not have to. You may complain to your state Attorney General, and in California to the California Privacy Protection Agency. From Europe, you may complain to the data protection authority in the country where you live or work.
16Making a data request
Email [email protected] with "Data request" in the subject, or write to 46 Market Street, Suite 4, Austin, Texas 59966, United States. Say what you want: a copy, a correction, deletion, or an opt-out. Send it from the email address you used in the form, or give us the phone number you used, so we can match the record.
We answer within 5 days. Most requests are done in that time; if a request needs longer, the answer tells you why and when. There is no charge.
A request is not a complaint and you do not need a reason. The most common one we get is "delete my enquiry, we signed with someone else." That is fine. It is gone the same week.
17Accessibility
We build the site to WCAG 2.2 level AA as the target. Every page works with a keyboard alone. The skip link jumps past the header. The menu overlay traps focus while open and closes on Escape. Body text on the dark ground is set in warm paper colours chosen for contrast, and every tap target is at least 44 pixels.
If your system asks for reduced motion, the scroll animations stop and the day-route diagram on the home page shows fully drawn, with every stop listed as plain text beside it. Photographs carry descriptions. Forms say what is wrong in words, not only in colour.
Known gaps: the support chat panel has not been tested with every screen reader, and a very long message can scroll inside the panel instead of the page. If something blocks you, call +1 (393) 555-3266 or email [email protected]. We will take the enquiry by phone and fix the page.
18When this policy changes
A change goes up on this page with a new "last updated" date at the top. If it changes what we collect or who receives it, the cookie banner appears again so you can make a fresh choice, and clients with a live service hear about it by email. Old versions are available on request.
19A person to ask
Privacy questions go to the same inbox as everything else, and a person reads it on weekdays.
Email: [email protected]
Phone: +1 (393) 555-3266
Post: Continentalserves, 46 Market Street, Suite 4, Austin, Texas 59966, United States
For the cookies themselves, read the cookie ledger. For how the service works, the services page. To ask about your office, the contact page.