In certain instances, Toast will be able to assist you with various aspects of your California Consumer Privacy Act of 2018 (including as amended by the California Privacy Rights Act of 2020, or “CPRA”) (CCPA) compliance efforts in relation to the fulfillment of individual rights. If you need to learn more about the CCPA - a California data privacy law - check out our article California Consumer Privacy Act Overview.
Please note that Toast can only support customers with individual rights requests for personal information that is collected by Toast’s products and services. If you use other service and technology providers to store customer or employee personal information, you'll need to reach out to them separately. |
Individual Rights Request - First Steps
After you've received an individual rights request, before reaching out to Toast, you need to:
Confirm receipt and verify the identity of the individual making the request;
Confirm whether the request itself is a valid individual rights request (e.g. not subject to an exemption) under the CCPA;
Determine the appropriate scope of the request; and
Confirm that the request itself is relevant to Toast and that Toast collects, maintains, or uses the information forming part of the request.
Submit a Request to Toast
Once those elements are confirmed, requests can be submitted to Toast’s Privacy Office via a form within a privacy compliance dashboard located in Toast Web. For instructions on how to access and submit these requests via the privacy dashboard, please review this Support Center article, Manage Your Privacy Compliance Obligations. Alternatively, please contact us at privacy@toasttab.com. Your message should include:
The nature of the request (e.g., access, deletion, opt-out of sale, etc.) in the subject line of the email; and
The name, email, phone number, and other relevant details of the requestor (as applicable) to enable us to search our records and support the fulfillment of the request.
Toast Support
Once we receive your message, Toast will provide the following support in addition to verification support or to confirm what data is being processed by Toast:
For access requests, Toast will scan our systems to determine if we hold information about the individual. Please provide the name, email, phone number, and other relevant details of the request (as applicable) to enable us to perform the search. To the extent any information is found within Toast or within any service provider systems, Toast or the relevant service provider will provide you with the requested information in a reasonable and timely manner.
For deletion requests, Toast will support the fulfillment of the deletion request by removing the relevant personal information held by Toast as part of the request. To the extent applicable, Toast may also notify other third-party service providers that support Toast with the processing activities. Once the above activities are completed, Toast will respond to you and verify that the requested information has been deleted and that the appropriate third parties have been notified.
For right to opt out of sale requests, where a sale has occurred, Toast will ensure that any further sale of the requestor’s personal information is restricted. Toast, where applicable, will also notify any third parties that process the information on Toast’s behalf of the same. Once Toast has fulfilled the request, Toast will respond to you to verify that the individual has been opted out of further sales (as to information Toast holds).
Please note that it is your responsibility to verify the appropriateness of the individual rights request and to determine the applicable scope. Please review the CCPA for additional information on the applicable requirements or consult your independent legal counsel for additional guidance generally or in relation to the fulfillment of any individual rights.
Toast’s support will only cover instances where Toast processes personal information relevant to the request. If for any reason Toast is unable to provide support or fulfill aspects of the individual rights requests above, we will
communicate that to you along with our rationale for why the request cannot be fulfilled from the Toast side.