Privacy & Security

We take our responsibility to protect the privacy and confidentiality of your data very seriously. You can trust that we take every precaution to provide a service with high grade security.

  • Encryption

    All sensitive information is encrypted in transit and at rest. Our TLS certificate uses a 2048-bit RSA key with a SHA256WITHRSA algorithm to ensure all your data is served over a secured connection.

  • Safeguards

    Bento adheres to a strict set of safeguards around ePHI (Electronic Protected Health Information) and PHI (Protected Health Information). These include technical, physical and administrative safeguards to ensure your data remains protected at all times.

  • Compliance

    Bento is HIPAA (Health Insurance Portability and Accountability Act of 1996) compliant. We undergo annual internal and third-party audits to ensure we remain in compliance. All employees are required to undergo background checks and annual security awareness training.

Privacy Policy

Last Updated 01/18/24

This Privacy Policy describes the data practices of Bento. It applies to information that we collect, use, and disclose about you when you access or use our websites (including https://www.gobento.com) that link to this Privacy Policy, engage with our services including through text message communications, or otherwise interact with us online or offline. We refer to our website and other ways of interacting with you collectively as the “Services.”

If you or your health plan, clinic, or other organization has an individual agreement with us, that agreement may have privacy terms that also apply to the information provided to us under that agreement.  In such circumstances, you should also ask your organization about additional ways in which your information is processed in connection with the Services.

Please read this privacy policy carefully to understand how we handle your information. If you do not agree to this privacy policy, please do not use the Services.

The Information We Collect

We obtain information about you through the means discussed below when we provide the Services.

1. Information You Provide to Us

We collect a variety of information that you provide directly to us. For example, we collect information from you through:

  • Signing up to use our Services 

  • Signing up to be a partner or customer of the Services

  • Requests or questions you submit to us via online forms, text message, email, or otherwise, including when you sign up to receive our newsletters or other information, as relevant

  • When you engage with our Services, including when you select or otherwise interact with any meal programs and order flows

  • Your participation in surveys, focus groups, sweepstakes, contests, or events

Information About You

The types of data we may collect directly from may include:

  • First and last name 

  • Title, role, and company or organization name

  • Email address 

  • Information about your dietary preferences/needs and related health information 

  • Physical address 

  • Mobile phone number 

  • Commercial information, including any products or services you purchase through our Services

  • Any other information you choose to directly provide to us in connection with your use of the Services, such as information you submit through an order

2. Information We Collect through Automated Means

When you use our websites, we and our service providers use cookies, pixels, web beacons, and similar technologies to automatically collect certain information to analyze your use of our websites. Such information includes browser type, browser language, operating system, software and hardware attributes platform type, the number of clicks, pages viewed and the order of those pages, the date and time you used the websites, error logs, and other similar information. We also collect your IP address for purposes of understanding the city and state in which our website visitors are located. 

We may also allow third-party partners, such as Squarespace and Plausible, to place cookies and similar technologies on the Services to collect information about how visitors use our Services for the purposes of analytics. These third parties may use cookies, pixel tags (also called web beacons or clear gifs), and/or other technologies to collect such usage information for such purposes. Pixel tags enable us and our third-party partners to recognize a browser’s cookie when a browser visits the site on which the pixel tag is located in order to learn which advertisement or website brings a user to a given site.

Please note that you can change your settings to notify you when a cookie is being set or updated, or to block cookies altogether. Please consult the “Help” section of your browser for more information (e.g., Internet Explorer, Google Chrome, Mozilla Firefox, or Apple Safari).  Please note that by blocking any or all cookies, you may not have access to certain features or offerings of the Services.  If you use multiple browsers on your device, you will need to instruct each browser separately. Your ability to limit cookies is subject to your browser settings and limitations. 

3. Information We Collect from Others

We may receive information about you required to use the Services from individuals who submit it on your behalf, such as your medical provider.  We may also collect certain information, including demographic and statistical information from third parties, such as partners, researchers, analysts, and others. Additionally, if you interact with us on third-party platforms, such as via email or social email, we may collect information we receive from such third-party platforms as well.

We use this information to supplement the information we collect directly from you for purposes of providing our Services.

How We Use Your Information

We may use your information for various purposes depending on the types of information we have collected from and about you, to:

  • Provide our Services

  • Respond to your requests for information and provide you with more effective and efficient customer service

  • Contact you by email, postal mail, or phone (including SMS) regarding Bento and our Services, as well as third-party organizations, surveys, research studies, projects, and other subjects that we think may be of interest to you

  • Conduct sweepstakes, contests, and referral programs

  • Help us better understand your interests, and improve and customize our Services

  • Secure our Services and resolve technical issues being reported

  • Engage in research and analytics regarding the use of our Services

  • Comply with any procedures, laws, and regulations which apply to us where it is necessary for our legitimate interests or the legitimate interests of others

  • Establish, exercise, or defend our legal rights where it is necessary for our legitimate interests or the legitimate interests of others

Additionally, we may combine any of the information that we collect from and about you (including information from third parties) and use such combined information in accordance with this Policy. We may aggregate, de-identify and/or anonymize any information collected through the Services so that such information is no longer linked to you. We may use aggregated and/or anonymized information for any purpose, including for research and marketing purposes, and we may also disclose such information to third parties, at our discretion.  

How We Disclose Your Information

Bento may disclose your information in the following ways:

  • Service Providers: We provide access to or disclose your information to select third parties who perform services on our behalf. They may provide a variety of services to us, including food ordering platforms and grocery services, billing and payment services, transaction processing, data storage, marketing, communications services, security, fraud prevention, and legal services.

  • Affiliates: We disclose information to affiliated entities that assist us in managing and providing our Services.

  • Your Organization, Health Plan, or Clinic: If you use the Services as a benefit provided by your employer, we may provide limited information about your use of the Services with your employer in connection with receiving that benefit.

  • Business Transactions: We may disclose information in connection with a proposed or actual merger, acquisition or transfer of all or a portion of Bento.

  • Protection of Bento and Others: By using our Services, you acknowledge and agree that we may access, retain, and disclose the information we collect and maintain about you if required to do so by law or in a good faith belief that such access, retention or disclosure is reasonably necessary to: (a) comply with legal process (e.g. a subpoena or court order); (b) enforce any contracts with you, if relevant; (c) respond to claims that any content violates the rights of third parties; (d) respond to your requests for customer service; and/or (e) protect the rights, property or personal safety of Bento, its agents and affiliates, its users and/or the public.

  • Consent: We may disclose your information in other ways if you have asked us to do so or have given consent. For example, with your consent, we may post user testimonials that may identify you.

Your Rights and Your Choices

In accordance with applicable laws, you may have certain rights with respect to your information as further described in this section.

1. Your Legal Rights

If you would like further information in relation to your legal rights under applicable law or would like to exercise any of them, please contact us using the information in the “Contact Information” section below at any time. Your local laws may permit you to request that we:

  • Provide access to and/or a copy of certain information we hold about you

  • Update information which is out of date or incorrect

  • Delete certain information which we are holding about you

  • Restrict the way that we process and disclose certain of your information

  • Revoke your consent for the processing of your information

We will consider all requests and provide our response within the time period stated by applicable law and as otherwise required by applicable law. Please note, however, that certain information may be exempt from such requests in some circumstances, which may include if we need to keep processing your information for our legitimate interests or to comply with a legal obligation. We may request you provide us with information necessary to confirm your identity before responding to your request.

2. Marketing Communications

In accordance with applicable law, we may send you marketing communications regarding our Services or the services of third parties that we believe will be interesting to you. You can ask us to stop sending such communications at any time through the opt-out instructions provided in the communication or by contacting us using the information in the “Contact Information” section below.   

Please note that, regardless of your request, we may still use and disclose certain information as permitted by this Privacy Policy or as required by applicable law. For example, you may not opt out of certain administrative or transactional emails from us, such as those confirming your requests or providing you with updates regarding our Privacy Policy or other terms. 

Third Party Links and Features

Our Services may contain links to third-party websites and features. If you choose to use these sites, please note that we are not responsible for their content or privacy practices. The collection, use, and disclosure of your information will be subject to the privacy policies of the third-party websites, and not this Privacy Policy. We urge you to read the privacy policies of these third parties.

How We Protect Your Information

Bento takes a variety of technical and organizational security measures to protect the information provided to us from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no Internet or email transmission is ever fully secure or error free. Please keep this in mind when disclosing any information to us online.

Retention of Your Information

We keep your information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws.

Children

Our Services are intended for general audiences and are not directed at children. If we become aware that we have collected data without legally valid parental consent from children under an age where such consent is required, we will take reasonable steps to delete it as soon as possible.

Changes to Our Privacy Policy

We reserve the right to amend this Privacy Policy at any time to reflect changes in the law, our data collection and use practices, or advances in technology. We will make the revised Privacy Policy accessible on our Services, so you should review the Privacy Policy periodically. You can know if the Privacy Policy has changed since the last time you reviewed it by checking the “Last Updated” date included at the beginning of the document. If we make a material change to the Policy, you will be provided with appropriate notice in accordance with applicable legal requirements. By continuing to use the Services, you are confirming that you have read and understood the latest version of this Privacy Policy.

Contact Information

Please feel free to email us at legal@gobento.com if you have any questions about Bento’s Privacy Policy or our information processing practices.