Weill Café

Loyalty Rewards - Privacy Policy

Last Updated Date: September 29, 2025

Café Name: Weill Café
Location: 154 W57th street New York, NY

This Privacy Policy explains how Weill Café (“we,” “us,” or “our”) collects, uses, shares, and protects your information in connection with our points-based loyalty rewards program powered by Toast, Inc. (“Toast”).

By enrolling in or participating in our Toast Loyalty Rewards Program (“Program”), you agree to the terms of this Privacy Policy.

1. Information We Collect

We collect information that you voluntarily provide to us when you sign up for or participate in the Toast-powered loyalty program.  The information that we collect depends on the context of your interaction with the Toast-powered loyalty program. The information that we collect may include the following:

A. Personal Information
  • Name
  • Email address
  • Phone number
  • Date of birth (optional, e.g., for birthday rewards)
B. Transactional Information
  • Order history and purchase amount
  • Loyalty points earned, redeemed, or expired
  • Rewards claimed or available
  • Payment method (Toast handles this securely; we do not store full credit/debit card details)
C. Technical and Usage Information (when ordering online or using digital receipts)
  • IP address
  • Device and browser type
  • Access time and date

2. How We Use Your Information

We use your information that we collect about you or that you provide to us for the following purposes:

  • To enroll you in the Toast loyalty program
  • To track purchases and calculate loyalty points
  • To issue, manage, and redeem rewards
  • To send you order confirmations, reward notifications, and program updates
  • To personalize offers and promotions (if you opt-in)
  • To improve our services and customer experience
  • To comply with legal and financial recordkeeping requirements

3. Use of Toast Services

Our rewards program is powered by Toast, Inc., which provides restaurant point-of-sale and loyalty software. Toast has its own Privacy Policy that governs how your data is handled by their system.

Toast may collect and process your data in accordance with its privacy practices when you:

  • Sign up for loyalty at the register, via text, or online
  • Make purchases using a Toast-powered checkout system
  • Receive digital receipts or communications

We recommend reviewing Toast’s privacy policy for full details on how they handle your personal data.

4. Marketing Communications

If you opt in, we may use your contact information to send you:

  • Loyalty program updates
  • Exclusive member-only offers or rewards
  • Event invitations or café promotions

 

You may opt out of promotional emails or text messages at any time by:

  • Clicking “Unsubscribe” in an email
  • Replying “STOP” to a promotional SMS
  • Contacting us directly at [email protected]

 

You will still receive essential service-related messages, such as reward confirmations or account notices.

5. Data Sharing and Disclosure

We do not sell your personal information. We may also disclose personal data that we collect or you provide as described in this privacy policy:

  • Toast, Inc.: To operate and manage the loyalty platform
  • Marketing service providers: For sending permitted communications
  • Payment processors: For secure handling of transactions
  • Government authorities or law enforcement: If legally required
  • Successors or assigns: In the event of a business transfer or acquisition
  • Terms of use: To enforce our terms of use and other agreements, including for billing and collection purposes.

All third-party vendors are contractually obligated to safeguard your data and use it only for authorized purposes.

6. Data Security

We and Toast use commercially reasonable administrative, physical, and technical measures designed to protect your personal data from accidental loss or destruction and from unauthorized access, use, alteration, and disclosure, including:

  • Encryption during transmission and storage (as supported by Toast)
  • Access restrictions for sensitive data
  • Regular monitoring of systems for vulnerabilities

However, no website, mobile application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your personal data transmitted to, through, using, or in connection with the Programs. In particular, email, texts, and chats sent to or from the Program may not be secure, and you should carefully decide what information you send to us via such communications channels. Any transmission of personal data is at your own risk. Please notify us immediately if you suspect unauthorized use of your loyalty account.

7. Your Rights and Choices

This section describes mechanisms you can use to control certain uses and disclosures of your information and rights you may have under state law, depending on where you live. Depending on your state of residency, you may have certain rights related to your personal data including

  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your loyalty account and associated data (subject to legal or operational retention requirements)
  • Withdraw consent for marketing communications

 

Important: The exact scope of these rights vary by state. There are also several exceptions where we may not have an obligation to fulfill your request.

To exercise your rights, contact us at:

📧 [email protected]
📞 212-424-2032

📍 Or visit us at 154 W57th Street New York, NY

8. California Residents

California Civil Code Section 1798.83, also known as the “Shine The Light” law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.

If you are under 18 years of age, reside in California, and have a registered account with the Program, you have the right to request removal of unwanted data that you publicly post on the Program. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Program, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g., backups, etc.).

CCPA Privacy Notice

The California Code of Regulations defines a “resident” as:

(1) every individual who is in the State of California for other than a temporary or transitory purpose and

(2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose

All other individuals are defined as “non-residents.”

If this definition of “resident” applies to you, we must adhere to certain rights and obligations regarding your personal information.

What categories of personal information do we collect?

We have collected the following categories of personal information in the past twelve (12) months:

A.         Identifiers

address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name

YES

 

B.          Personal information categories listed in n the California Customer Records statute

Name, contact information, education, employment history and financial information.

YES

 

C.          Protected classification characteristics under California or federal law

Gender and date of birth

YES

D.          Commercial information

Transaction information, purchase history, financial details and payment information

YES

E.           Biometric information

Fingerprints and voiceprints

NO

F.           Internet or other similar network activity

Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems and advertisements

YES

G.          Geolocation data

Device location

YES

H.          Audio, electronic, visual, thermal, olfactory or similar information

Images and audio, video or call recordings created in connection with our business activities

NO

I.            Professional or employment-related information

Business contact details in order to provide you our Services at a business level or job title, work history and professional qualifications if you apply for a job with us

NO

J.            Education information

Student records and directory information

NO

K.          Inferences drawn from other personal information

Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics

NO

L.           Sensitive Personal Information

 

NO

We will use and retain the collected personal information as needed to provide the Program or for:

■ Category A – See Paragraph 11 below

■ Category B – See Paragraph 11 below

■ Category F – See Paragraph 11 below

■ Category G – See Paragraph 11 below

We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:

■ Receiving help through our customer support channels;

■ Participation in customer surveys or contests; and

■ Facilitation in the delivery of the Program and to respond to your inquiries.

We collect and share your personal information through:

■ Your enrollment in the Program

More information about our data collection and sharing practices can be found in this privacy notice. You may contact us by referring to the contact details in Paragraph 7 above in this document or in Paragraph 13 at the bottom of this document.

If you are using an authorized agent to exercise your right to opt out, we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.

Will your information be shared with anyone else?

We may disclose your personal information with our service providers as provided in Paragraph 5 of this document. We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be “selling” of your personal information.  We have not sold or shared any personal information to third parties for a business or commercial purposes in the preceding twelve (12) months.  We have disclosed the following categories of personal information to third parties for a business or commercial purpose in the preceding twelve (12) months:

The categories of third parties to whom we disclosed personal information for a business or commercial purposes can be found in Paragraph 5, “Data Sharing and Disclosure.”

Your rights with respect to your personal data

Right to request deletion of the data – Request to delete

You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities.

Right to be informed – Request to know

Depending on the circumstances, you have a right to know:

■ whether we collect and use your personal information;

■ the categories of personal information that we collect;

■ the purposes for which the collected personal information is used;

■ whether we sell or share personal information to third parties;

■ the categories of personal information that we sold, shared, or disclosed for a business purpose;

■ the categories of third parties to whom the personal information was sold, shared, or disclosed for a business purpose;

■ the business or commercial purpose for collecting, selling, or sharing personal information; and

■ the specific pieces of personal information we collected about you.

In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.

Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights

We will not discriminate against you if you exercise your privacy rights.

Right to Limit Use and Disclosure of Sensitive Personal Information

We do not process consumer’s sensitive personal information.

Verification Process

Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. For instance, depending on the type of request you submit, we may ask you to provide certain information so that we can match the information you provide with the information we already have on file, or we may contact you through a communication method (e.g., phone or email) that you have previously provided to us. We may also use other verification methods as the circumstances dictate. We will only use personal information provided in your request to verify your identity or authority to make the request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.

Other Privacy Rights

■ You may object to the processing of your personal information.

■ You may request correction of your personal data if it is incorrect or no longer relevant, or ask to restrict the processing of the information.

■ You can designate an authorized agent to make a request under the CCPA on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with the CCPA.

■ You may request to opt out from future selling or sharing of your personal information to third parties. Upon receiving an opt-out request, we will act upon the request as soon as feasibly possible, but no later than fifteen (15) days from the date of the request submission.

To exercise these rights, you may contact us by referring to the contact details in Paragraph 7 above in this document or in Paragraph 13 at the bottom of this document.

9. Virginia Residents

Under the Virginia Consumer Data Protection Act (COPA):

“Consumer” means a natural person who is a resident of the Commonwealth acting only in an individual or household context. It does not include a natural person acting in a commercial or employment context.

“Personal data” means any information that is linked or reasonably linkable to an identified or identifiable natural person. “Personal data” does not include de-identified data or publicly available information.

“Sale of personal data” means the exchange of personal data for monetary consideration.

If this definition “consumer” applies to you, we must adhere to certain rights and obligations regarding your personal data.

The information we collect, use, and disclose about you will vary depending on how you interact with us and our Program. To find out more, please review the following paragraphs in this policy:

■ Paragraph 1: Personal data we collect

■ Paragraph 2: How we use your personal data

■ Paragraph 5: When and with whom we share your personal data

Your rights with respect to your personal data

■ Right to be informed whether or not we are processing your personal data

■ Right to access your personal data

■ Right to correct inaccuracies in your personal data

■ Right to request deletion of your personal data

■ Right to obtain a copy of the personal data you previously shared with us

■ Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects (“profiling”)

We have not sold any personal information to third parties for a business or commercial purposes. We will not sell personal data in the future belonging to website visitors, users or other consumers. 

Exercise your rights provided under the Virginia COPA

More information about our data collection and sharing practices can be found in this privacy notice.

You may contact us by referring to the contact details in Paragraph 7 above in this document or in Paragraph 13 at the bottom of this document.

If you are using an authorized agent to exercise your rights, we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.

Verification Process

We may request that you provide additional information reasonably necessary to verify you and your consumer’s request. If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request.

Upon receiving your request, we will respond without undue delay, but in all cases, within forty-five (45) days of receipt. The response period may be extended once by forty-five (45) additional days when reasonably necessary. We will inform you of any such extension within the initial 45-day response period, together with the reason for the extension.

Right to Appeal

If we decline to take action regarding your request, we will inform you of our decision and reasoning behind it. If you wish to appeal our decision, please contact us by referring to the contact details in Paragraph 7 above in this document or in Paragraph 13 at the bottom of this document. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may contact the Attorney. General to submit a complaint.

10. Children's Privacy

Our Toast Loyalty Rewards Program is intended for individuals aged 18 or older. We do not knowingly collect personal information from children under 18 or market to children under 18. By using the Program, you represent that you are at least 18. If we become aware that a child under 18 has enrolled, we will deactivate the account and take reasonable measures to will promptly delete their data from our records.

11. Retention of Data

We retain your personal and loyalty data as long as your account is active or as needed to:

  • Provide rewards and loyalty tracking
  • Comply with legal obligations
  • Resolve disputes and enforce our agreements
  • For safety, security and fraud prevention

 

This means that we consider our legal and business obligations, potential risks of harm, and nature of the information when deciding how long to retain personal data. At the end of the retention period, personal data will be deleted, destroyed, or deidentified.

If you are a California resident, visit California Privacy Notice for more information about the retention periods that apply to the personal data categories we collect.

Inactive accounts may be deleted after 12 months of no activity.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated “Last Updated” date and the updated version will be effective as soon as it is accessible. IF we make material changes to this privacy notice, we may notify you of material changes via email or prominently on our website.

13. Contact Us

For questions about this Privacy Policy or our Toast Loyalty Rewards Program, please contact:

Weill Café
154 W 57th Street New York, NY
[email protected]
212-424-2032

By enrolling in or using the Toast Loyalty Rewards Program at Weill Café, you agree to the practices described in this Privacy Policy.