Privacy Policy

Effective Date: July 20, 2026  |  Last Updated: July 20, 2026

This Privacy Policy explains how Guzman y Gomez ("we", "us", "our", or "the Company") collects, uses, discloses, stores, and protects your personal information when you visit our website at guzmansigomez.com, use our mobile application, place orders online or in-store, participate in loyalty programs, or interact with us in any other way. We are committed to protecting your privacy and handling your personal information in an open and transparent manner in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.

Please read this Privacy Policy carefully. By accessing or using our website, placing an order, or otherwise engaging with us, you acknowledge that you have read, understood, and agree to the practices described in this policy. If you do not agree with this policy, please discontinue your use of our services immediately.


1. About Us

Guzman y Gomez is an Australian food and restaurant business specialising in fresh, high-quality Mexican-inspired food. We operate restaurants, a website, a mobile application, and various online ordering platforms across Australia and internationally.

Company Name Guzman y Gomez
Website guzmansigomez.com
Email Address [email protected]
Governing Law Privacy Act 1988 (Cth), Australian Privacy Principles (APPs)

If you have any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal information, please contact us using the details provided in Section 14 of this policy.


2. What Personal Information We Collect

We collect personal information that is reasonably necessary for us to carry out our business functions and activities. The types of personal information we may collect include the following:

2.1 Personal Identification Information

  • Full name
  • Date of birth (where required for age verification or loyalty programs)
  • Gender (optional, where provided voluntarily)
  • Photograph or profile image (where voluntarily uploaded to an account)
  • Nationality or country of residence (where relevant to international operations)

2.2 Contact Information

  • Email address
  • Phone number (mobile or landline)
  • Residential or delivery address
  • Postcode and suburb

2.3 Account and Order Information

  • Username and password (stored in encrypted form)
  • Order history, including items ordered, quantities, customisations, and order frequency
  • Saved preferences and dietary requirements
  • Loyalty program membership details, points balance, and redemption history
  • Feedback, reviews, and ratings submitted through our platforms
  • Customer service correspondence and complaint records

2.4 Payment and Financial Information

  • Payment method type (credit card, debit card, digital wallet, etc.)
  • Billing name and address
  • Transaction identifiers and order reference numbers
Important: We do not store full credit or debit card numbers on our systems. All payment card data is processed through PCI-DSS compliant third-party payment processors. We retain only tokenised references necessary for processing refunds or resolving disputes.

2.5 Usage and Behavioural Data

  • Pages and screens visited on our website or app
  • Search queries entered on our platforms
  • Time and duration of visits
  • Links and buttons clicked
  • Referring URLs (the website you visited before arriving at ours)
  • Drop-off points and abandonment data (e.g., abandoned cart information)
  • Interaction with promotional emails and push notifications

2.6 Device and Technical Information

  • IP address
  • Browser type and version
  • Operating system and device type (desktop, mobile, tablet)
  • Device identifiers (e.g., IDFA, GAID for mobile devices)
  • Screen resolution and language preferences
  • Mobile network and connection type

2.7 Location Information

  • Approximate location derived from IP address
  • Precise GPS location (only when you expressly grant permission through your device settings for delivery or "find a restaurant" features)
  • Delivery address provided at checkout

2.8 Cookie and Tracking Data

We use cookies, web beacons, pixel tags, and similar technologies to collect information about your interactions with our digital platforms. Please refer to Section 9 of this policy for detailed information about our cookie practices.

2.9 Information from Third Parties

  • Social media profile information when you log in using a social media account (e.g., Facebook, Google, Apple)
  • Information from delivery platform partners (e.g., Uber Eats, DoorDash, Menulog) where you have consented to data sharing under their respective policies
  • Publicly available information used for fraud prevention and identity verification
  • Information from analytics and advertising partners

2.10 Sensitive Information

Under the Privacy Act 1988 (Cth), certain categories of information are classified as "sensitive information" and are afforded a higher level of protection. We do not intentionally collect sensitive information such as health information, racial or ethnic origin, religious beliefs, or political opinions. However, if you voluntarily disclose dietary requirements or allergen information (e.g., gluten intolerance, nut allergy), we may collect and use this information solely for the purpose of processing your food order safely. We will always seek your consent before collecting sensitive information in any other context.


3. How We Collect Personal Information

We collect personal information through the following means:

3.1 Directly From You

  • When you create an account on our website or mobile application
  • When you place an order online, via our app, or in-store
  • When you sign up for our loyalty program or promotional offers
  • When you contact our customer service team by phone, email, or web form
  • When you complete a survey, competition, or feedback form
  • When you interact with us on social media
  • When you visit one of our restaurant locations and use our in-store kiosks or Wi-Fi services

3.2 Automatically

  • Through cookies and tracking technologies placed on our website and app
  • Through server logs that record details of visits to our digital platforms
  • Through mobile application analytics tools embedded in our app

3.3 From Third Parties

  • From social media platforms when you authenticate using a social login
  • From delivery partner platforms where you order Guzman y Gomez products
  • From advertising and marketing partners who help us reach relevant audiences
  • From fraud detection and identity verification service providers

4. How We Use Your Personal Information

We use the personal information we collect for the following purposes, all of which are reasonably necessary for our business functions and for providing you with our products and services:

4.1 Providing and Managing Our Services

  • Processing and fulfilling your food orders, whether placed online, in-app, in-store, or via third-party delivery platforms
  • Managing your account, including login credentials and saved preferences
  • Administering our loyalty program and tracking reward points
  • Processing payments and handling refunds, chargebacks, and disputes
  • Coordinating delivery and communicating estimated delivery times
  • Sending transactional communications such as order confirmations, receipts, and delivery notifications

4.2 Customer Support

  • Responding to your enquiries, feedback, and complaints
  • Investigating and resolving disputes relating to orders or billing
  • Maintaining records of customer service interactions for quality assurance

4.3 Marketing and Promotions

  • Sending you promotional emails, push notifications, and SMS messages about new menu items, special offers, and events (where you have provided your consent or where permitted under the Spam Act 2003 (Cth))
  • Personalising the content and offers you see on our website, app, and marketing communications based on your order history and preferences
  • Administering competitions, giveaways, and promotional campaigns
  • Conducting targeted advertising through social media platforms and digital advertising networks using interest-based targeting and custom audience features
You may opt out of receiving marketing communications at any time by clicking the "Unsubscribe" link in any marketing email, adjusting your notification preferences in the app, or contacting us directly at [email protected].

4.4 Analytics and Service Improvement

  • Analysing usage patterns, order trends, and customer behaviour to improve our menu, website, and app
  • Conducting internal research and business planning
  • Measuring the effectiveness of our marketing campaigns
  • Identifying and fixing technical issues on our digital platforms
  • Developing new products, features, and services

4.5 Legal, Security, and Compliance Purposes

  • Complying with applicable Australian laws, including the Privacy Act 1988 (Cth), the Australian Consumer Law (ACL) under the Competition and Consumer Act 2010 (Cth), the Food Standards Australia New Zealand Act 1991, and other applicable regulations
  • Detecting, preventing, and investigating fraud, identity theft, and other illegal or unauthorised activities
  • Enforcing our Terms of Service and other legal agreements
  • Responding to lawful requests from law enforcement agencies, government bodies, and courts
  • Protecting the rights, property, and safety of Guzman y Gomez, our customers, employees, and the public

5. Disclosure of Personal Information to Third Parties

We do not sell your personal information to third parties. However, we may share your personal information with the following categories of recipients in the circumstances described below:

5.1 Service Providers and Business Partners

We engage third-party service providers who perform functions on our behalf, including but not limited to:

  • Payment processors: To securely process your payment transactions (e.g., Stripe, Braintree, PayPal)
  • Delivery partners: To fulfil delivery orders placed through our platforms (e.g., Uber Eats, DoorDash, Menulog, and direct courier services)
  • Cloud hosting providers: To host our website, app, databases, and systems (e.g., Amazon Web Services, Microsoft Azure, Google Cloud)
  • Email and SMS marketing platforms: To send marketing and transactional communications on our behalf
  • Analytics providers: To analyse usage data and improve our services (e.g., Google Analytics, Mixpanel)
  • Customer relationship management (CRM) platforms: To manage customer records and loyalty programs
  • Advertising technology partners: To deliver targeted advertising and measure campaign performance
  • Fraud detection and identity verification services: To protect against fraudulent transactions and account takeovers
  • Legal, accounting, and professional advisors: Who are bound by confidentiality obligations

All third-party service providers are required to handle your personal information in accordance with our instructions, this Privacy Policy, and applicable Australian privacy laws. We use contractual arrangements to ensure appropriate data protection standards are maintained.

5.2 Franchise Partners and Related Entities

Where Guzman y Gomez restaurants are operated by franchisees, we may share relevant customer and order information with those franchisees to the extent necessary to fulfil your order, manage your loyalty account, or provide customer support. All franchisees are bound by privacy obligations consistent with this policy.

5.3 Legal and Regulatory Disclosures

We may disclose your personal information where we are required or permitted to do so by law, including:

  • In response to a valid court order, subpoena, or other legal process
  • To comply with a request from a law enforcement or regulatory authority (e.g., the Australian Federal Police, the Australian Competition and Consumer Commission, the Office of the Australian Information Commissioner)
  • To protect against fraud, threat to safety, or breach of our legal rights

5.4 Business Transfers

In the event of a merger, acquisition, sale of business assets, restructuring, or other corporate transaction, your personal information may be disclosed to the relevant parties as part of that transaction. We will notify you of any such change in the ownership or use of your personal information and will provide you with choices where required by law.


6. International Transfers of Personal Information

Guzman y Gomez operates primarily in Australia; however, some of our third-party service providers, cloud hosting infrastructure, and technology platforms may be located overseas, including but not limited to the United States of America, the United Kingdom, Ireland, Singapore, and other countries.

When we transfer personal information overseas, we take steps to ensure that it receives an adequate level of protection. This may include:

  • Entering into contractual arrangements with overseas recipients that require them to handle your information in accordance with the Australian Privacy Principles
  • Assessing whether the overseas country has privacy laws that are substantially similar to those in Australia
  • Obtaining your consent where required

Please be aware that under Australian Privacy Principle 8 (APP 8), where we disclose personal information to an overseas recipient, we remain accountable for ensuring that the recipient does not breach the APPs in relation to your information, unless an exception applies. By using our services, you acknowledge that your information may be transferred and stored outside of Australia in the circumstances described in this section.


7. Data Security

We take the security of your personal information seriously and implement a range of technical, administrative, and physical security measures to protect it from unauthorised access, disclosure, alteration, misuse, and loss.

7.1 Technical Safeguards

  • SSL/TLS encryption for all data transmitted between your browser or app and our servers
  • Encryption of sensitive data at rest using industry-standard encryption protocols
  • Secure password hashing using bcrypt or equivalent algorithms
  • Multi-factor authentication options for user accounts
  • Regular automated vulnerability scanning and penetration testing
  • Firewalls, intrusion detection systems, and network monitoring
  • PCI-DSS compliance for all payment processing systems

7.2 Administrative Safeguards

  • Access to personal information is restricted to employees and contractors who have a legitimate need to access it for their job functions
  • All staff receive training on data privacy and security obligations
  • Confidentiality agreements are in place with employees and third-party service providers
  • Regular audits of data access logs and internal security policies

7.3 Physical Safeguards

  • Secure access controls to our offices and data centres
  • Secure disposal of physical records containing personal information
Data Breach Notification: In the event of a data breach that is likely to result in serious harm to affected individuals, we will comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). This means we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.

Despite our best efforts, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security. You also play a role in keeping your account secure — please use a strong password, keep your login credentials confidential, and notify us immediately if you suspect any unauthorised access to your account.


8. Your Privacy Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the following rights in relation to your personal information:

8.1 Right to Access

You have the right to request access to the personal information we hold about you. We will provide you with access within 30 days of receiving your request, unless an exception under the Privacy Act applies. We may charge a reasonable fee to cover the administrative costs of providing access in complex cases, and we will inform you of any applicable fee before proceeding.

8.2 Right to Correction

If you believe that the personal information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you have the right to request that we correct it. We will correct the information free of charge as soon as reasonably practicable. If we disagree that a correction is warranted, we will explain our reasons and inform you of your right to complain to the OAIC.

8.3 Right to Deletion (Erasure)

In certain circumstances, you may request that we delete or de-identify personal information we hold about you. We will consider such requests and comply where we are not required by law or legitimate business need to retain the information. Please note that deletion of your account and associated data may affect your ability to use certain features of our services, including loyalty reward balances.

8.4 Right to Data Portability

Where technically feasible and appropriate, you may request that we provide your personal information in a structured, commonly used, and machine-readable format so that you can transfer it to another service provider. We will consider such requests in good faith and respond within a reasonable timeframe.

8.5 Right to Withdraw Consent

Where we rely on your consent as the basis for processing your personal information (e.g., for marketing communications or location tracking), you may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to your withdrawal.

8.6 Right to Opt Out of Marketing

You may opt out of receiving direct marketing communications from us at any time by:

  • Clicking the "Unsubscribe" link at the bottom of any marketing email
  • Adjusting your notification preferences in your account settings on our website or app
  • Replying "STOP" to any marketing SMS
  • Contacting us at [email protected]

Please note that even if you opt out of marketing communications, we will continue to send you transactional communications that are necessary for the provision of our services (e.g., order confirmations and receipts).

8.7 How to Exercise Your Rights

To exercise any of the rights described above, please contact our Privacy Officer using the details in Section 14 of this policy. We may need to verify your identity before processing your request. We will respond to your request within 30 days, or notify you if we require additional time.


9. Cookies and Tracking Technologies

We use cookies, web beacons, pixel tags, local storage, and similar tracking technologies on our website and mobile application to enhance your experience, analyse usage, and deliver targeted advertising.

9.1 Types of Cookies We Use

Cookie Type Purpose
Strictly Necessary Cookies Required for the website to function (e.g., session management, shopping cart, login authentication). Cannot be disabled.
Performance and Analytics Cookies Collect anonymous data about how visitors use our website to help us improve performance (e.g., Google Analytics).
Functionality Cookies Remember your preferences and settings (e.g., language, location, saved items) to provide a personalised experience.
Targeting and Advertising Cookies Used to deliver relevant advertisements and measure their effectiveness across our platforms and third-party sites (e.g., Meta Pixel, Google Ads).

9.2 Managing Cookies

You can manage your cookie preferences through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or be notified when a new cookie is set. Please note that disabling certain cookies may affect the functionality of our website and services.

For more detailed information about our use of cookies and how to manage your preferences, please refer to our Cookie Policy.


10. Data Retention

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law. The following general retention periods apply:

Category of Information Retention Period
Account information and profile data For the duration of your account plus 7 years after account closure
Order history and transaction records 7 years (as required by Australian tax and financial record-keeping obligations)
Customer service correspondence 3 years from the date of the last interaction
Marketing preferences and consent records For the duration of the marketing relationship plus 3 years
Website usage and analytics data Up to 26 months in identifiable form, then aggregated and anonymised
Payment and fraud prevention records 7 years from the date of the transaction
Legal dispute and complaint records 7 years from the resolution of the matter
Loyalty program data For the duration of your membership plus 3 years

When personal information is no longer required, we take reasonable steps to destroy or de-identify it in a secure manner.


11. Children's Privacy

Our website, mobile application, and loyalty programs are intended for use by individuals who are 18 years of age or older. We do not knowingly collect personal information from children under the age of 18 without verified parental or guardian consent.

If you are under the age of 18, please do not use our online services, create an account, or submit personal information to us without the knowledge and consent of a parent or legal guardian. Orders placed in-store may be made by individuals under 18 in the ordinary course of purchasing food products, and in such cases only minimal transaction data necessary to process the order is collected.

If we become aware that we have inadvertently collected personal information from a child under the age of 18 without appropriate consent, we will take prompt steps to delete that information from our records. If you believe that we may have collected information from or about a child under 18, please contact us at [email protected] and we will investigate promptly.


12. Direct Marketing and Your Choices

We may use your personal information to send you direct marketing communications, including promotional offers, new menu announcements, loyalty program updates, competitions, and event invitations. We do this in compliance with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth), which means we will only contact you via email or SMS where you have provided your consent (express or inferred) and we will always include a clear and functional opt-out mechanism in every marketing message.

We may also engage in targeted advertising through digital advertising platforms such as Google, Meta (Facebook and Instagram), and other networks. This may involve the use of your data to identify you as part of a custom audience or to find similar audiences. You can typically opt out of interest-based advertising through the settings of those platforms or by visiting the Network Advertising Initiative opt-out page.

You may opt out of all direct marketing from us at any time using the methods described in Section 8.6 above. We will process your opt-out request as soon as practicable and within 5 business days for electronic communications as required by the Spam Act 2003 (Cth).


13. Links to Third-Party Websites and Platforms

Our website and app may contain links to third-party websites, social media platforms, delivery partners, and other external services. This Privacy Policy applies only to Guzman y Gomez's own platforms and does not cover the privacy practices of any third-party website or service. We encourage you to read the privacy policies of any third-party platforms you visit, as we have no control over and accept no responsibility for their content, privacy practices, or policies.

Third-party platforms that may be relevant to your interactions with us include:

  • Uber Eats, DoorDash, Menulog (food delivery platforms)
  • Google, Meta/Facebook, Instagram, TikTok (advertising and social media)
  • PayPal, Afterpay, and other payment service providers
  • Apple App Store and Google Play Store

14. Contact Us — Privacy Enquiries

If you have any questions, concerns, or requests relating to this Privacy Policy or the way in which we handle your personal information, please contact our Privacy Officer using the details below:

Privacy Officer Guzman y Gomez — Privacy Team
Email [email protected]
Website guzmansigomez.com

We will acknowledge your enquiry within 5 business days and aim to provide a full response within 30 days. If your enquiry is complex, we will notify you of the expected timeframe for a complete response.


15. How to Make a Complaint

If you believe that we have breached the Australian Privacy Principles or handled your personal information in a way that is not in accordance with this Privacy Policy, you have the right to make a formal complaint.

15.1 Internal Complaints Process

We encourage you to first raise your complaint directly with us by contacting our Privacy Officer using the details in Section 14. We take all privacy complaints seriously and will investigate your complaint thoroughly and in good faith. We will respond to your complaint within 30 days. If we need additional time to investigate, we will keep you informed of our progress.

15.2 External Complaints — Office of the Australian Information Commissioner (OAIC)

If you are not satisfied with our response, or if we fail to respond to your complaint within a reasonable timeframe, you have the right to escalate your complaint to the Office of the Australian Information Commissioner (OAIC), which is the independent regulator responsible for overseeing compliance with the Privacy Act 1988 (Cth).

Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992 (within Australia)
GPO Box 5218, Sydney NSW 2001
Online Complaint Form: www.oaic.gov.au/privacy/privacy-complaints

The OAIC can investigate complaints, make determinations, and, in some cases, award compensation. There is no cost to you for making a complaint to the OAIC.

You may also contact the relevant state or territory privacy regulator if your complaint relates to a state or territory government agency, although Guzman y Gomez as a private sector entity is primarily regulated by the Commonwealth Privacy Act 1988 (Cth) and the OAIC.


16. Changes to This Privacy Policy

We may update or revise this Privacy Policy from time to time to reflect changes in our business practices, technology, legal requirements, or regulatory guidance. When we make material changes to this policy, we will:

  • Post the updated Privacy Policy on our website at guzmansigomez.com with a revised "Last Updated" date
  • Notify you via email (where we hold your email address) or via a prominent notice on our website or app, where the changes are significant

Your continued use of our website, app, or services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we are protecting your information.


17. Applicable Law and Jurisdiction

This Privacy Policy is governed by the laws of Australia. Your use of our services and the collection, use, and disclosure of your personal information are subject to the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth), the Competition and Consumer Act 2010 (Cth) (including the Australian Consumer Law), and other applicable Australian federal and state legislation.

Any disputes relating to privacy matters that cannot be resolved through our internal complaints process or the OAIC will be subject to the exclusive jurisdiction of the courts of Australia.


Guzman y Gomez

Email: [email protected]

Website: guzmansigomez.com

This Privacy Policy was last updated on July 20, 2026.