Roots Bread

Privacy Policy

Last updated: February 24, 2026

1. Introduction

ROOTS Bread Bakery ("ROOTS," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our website and services.

2. Information We Collect

We collect the following types of personal information:

  • Contact Information: Phone number, email address, name
  • Delivery Information: Address, delivery instructions
  • Account Information: Login credentials, preferences, order history
  • Payment Information: Processed securely through third-party payment providers
  • Loyalty Program Data: Stars balance, tier status, rewards history

3. How We Use Your Information

We use your personal data to:

  • Process and fulfill your orders
  • Send order confirmations and delivery updates
  • Verify your identity through SMS one-time passwords (OTP)
  • Manage your loyalty rewards account
  • Respond to your inquiries and provide customer support
  • Improve our products and services

4. SMS & Phone Communications

We use Twilio, a trusted third-party service, to send SMS messages to your phone number for:

  • Authentication: One-time passwords (OTP) for secure login
  • Order Updates: Confirmation and delivery notifications

We do NOT use your phone number for marketing or promotional SMS without your explicit consent.

Message and data rates may apply. You can opt out of non-essential SMS at any time by contacting us or replying STOP to any message.

5. No Spam Policy

We are committed to a strict no-spam policy. We will never sell, rent, or share your contact information with third parties for marketing purposes. You will only receive communications directly related to your orders and account, unless you explicitly opt-in to receive promotional content.

6. Third-Party Services

We use the following third-party services to operate our platform:

  • Supabase: Secure database and authentication
  • Twilio: SMS delivery for authentication codes
  • Google: OAuth sign-in (optional)
  • Vercel: Website hosting

These services have their own privacy policies and handle data according to their respective terms of service.

7. Data Security

We implement industry-standard security measures to protect your personal information, including encrypted connections (HTTPS), secure password hashing, and access controls. However, no method of transmission over the internet is 100% secure.

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time by contacting us.

9. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Withdraw consent for marketing communications
  • Export your data in a portable format

10. Cookies

We use essential cookies to maintain your session and shopping cart. We do not use tracking cookies or third-party advertising cookies without your consent.

11. Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal information from children under 16.

12. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any significant changes by posting the new policy on this page with an updated date.

13. Contact Us

If you have questions about this privacy policy or wish to exercise your rights, please contact us:

ROOTS Bread Bakery

Bishkek, Kyrgyzstan

Email: hello@rootsbread.com

Phone: +996 555 123 456