Home › Legal › Privacy Policy
NDPA Compliant — Nebraska Data Privacy Act

Privacy Policy

Last updated: July 7, 2026 · Abraham Oviedo Services, LLC DBA Big Asere

Table of Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Third-Party Service Providers
  5. Your Rights Under the NDPA
  6. Data Retention
  7. Data Security
  8. Children's Privacy
  9. SMS Communications
  10. International Data
  11. Changes to This Policy
  12. Contact & Privacy Requests
  13. Resumen en Español (NDPA)

1. Introduction

Abraham Oviedo Services, LLC ("we," "us," or "our"), doing business as Big Asere, operates the food delivery platform accessible at our website and any associated digital properties. We are committed to protecting your personal information and your privacy.

This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and what rights you have under the Nebraska Data Privacy Act (NDPA) — effective January 1, 2025 — and applicable federal laws including the Federal Trade Commission Act (FTC Act) and the Electronic Communications Privacy Act (ECPA).

Data Controller: Abraham Oviedo Services, LLC DBA Big Asere
Contact: support@bigasere.com

By using Big Asere, you acknowledge that you have read and understood this Privacy Policy. If you disagree with any part of this policy, please refrain from using our services.

2. Information We Collect

We collect only the information necessary to fulfill your order and improve our service.

Identity Information (you provide directly)

  • Full name
  • Phone number

Location Information

  • Delivery address you provide at checkout
  • We do not access your device's GPS location

Order Data

  • Items ordered and quantities
  • Order total, delivery fee, and tip amounts
  • Order timestamps (placed, confirmed, delivered)
  • Order history and status
  • Special instructions you provide

Device / Technical Information (via Cloudflare)

  • IP address (processed by Cloudflare for security; we do not permanently store it)
  • Browser type and version
  • Device type (mobile or desktop)

Payment Information

  • Payment is processed exclusively by Stripe — we do not store card numbers, CVVs, or full financial account details
  • We retain only payment method type (e.g., "Visa ending in ••••") for order records

We Do NOT Collect

  • Social Security numbers or government ID numbers
  • Full financial account numbers or card numbers
  • Biometric data (fingerprints, facial recognition, etc.)
  • Precise GPS or real-time location from your device
  • Sensitive personal information beyond what is listed above

3. How We Use Your Information

We use your personal information for the following lawful purposes:

  • Order fulfillment: Processing your order, coordinating with the restaurant, and dispatching a driver to your delivery address.
  • SMS/email updates: Sending transactional SMS messages via Twilio about your order status (confirmed, being prepared, out for delivery, delivered).
  • Customer support: Responding to your questions, resolving issues, and processing refund requests.
  • Service improvement: Analyzing aggregate, anonymized order data to improve our platform and restaurant partnerships.
  • Fraud prevention and security: Detecting and preventing fraudulent orders, abuse, and unauthorized access.
  • Legal compliance: Meeting obligations under applicable local, state, and federal laws.

We do NOT use your data for behavioral advertising, profiling, or sell it to any third parties.

4. Third-Party Service Providers

We share your data only with service providers necessary to operate our platform. All providers are obligated to protect your information and may not use it for their own purposes.

Supabase — Database Hosting (AWS us-east-1)

Stores your order records, contact information, and delivery history. Data is stored in encrypted databases on AWS us-east-1 (USA). Supabase Privacy Policy →

Stripe — Payment Processing

Processes your credit and debit card payments. We never store your full card number or CVV. Stripe is PCI-DSS Level 1 certified. Stripe Privacy Policy →

Twilio — SMS Delivery

Used to send transactional SMS messages about your order status. Your phone number is shared with Twilio solely for this purpose. Twilio Privacy Policy →

Shipday — Driver Dispatch (if applicable)

Used to dispatch and track delivery drivers for Platform Model orders. Your delivery address and name are shared with Shipday to enable driver routing. Shipday Privacy Policy →

Cloudflare — Security & CDN

Protects our platform against bots, DDoS attacks, and unauthorized access via Cloudflare Turnstile and edge security. Cloudflare processes request metadata (including IP) for security functions. TLS 1.3 encryption is applied to all traffic. Cloudflare Privacy Policy →

Google Maps JS API — Address Validation & Routing

Used for address autocomplete and delivery zone calculation. Google may process address queries per their privacy policy. Google Privacy Policy →

Square — External POS Integration (if applicable)

Used for restaurants operating under the External POS Model. Order data is synchronized directly from the restaurant's Square system. Applicable only when the restaurant uses an external POS system.

We do not share your personal information with advertisers, data brokers, analytics platforms, or marketing companies.

5. Your Rights Under the NDPA

As a Nebraska resident, the Nebraska Data Privacy Act (Neb. Rev. Stat. § 87-97 et seq.), effective January 1, 2025, grants you the following rights regarding your personal data:

Right to Know / Access

Request a copy of the personal data we hold about you.

Right to Correct

Request correction of inaccurate personal data we hold about you.

Right to Delete

Request deletion of your personal data, subject to limited legal exceptions.

Right to Opt Out

Opt out of targeted advertising. Note: We do not conduct targeted advertising — this right is automatically satisfied.

How to Exercise Your Rights

Email support@bigasere.com with subject: "NDPA Request – [Your Full Name]"

Include your name and phone number so we can verify your identity. We will respond within 45 days as required by the NDPA.

If you believe your privacy rights have been violated, you may file a complaint with the Nebraska Attorney General's Office.

6. Data Retention

We retain your order history and associated personal data for 2 years from the date of your most recent order. This retention period supports tax and business record-keeping requirements and dispute resolution.

You may request deletion of your personal data at any time by contacting support@bigasere.com. Deletion requests will be processed within 30 days, subject to any legal holds that require us to retain certain records.

When data is deleted, it is permanently purged from our active systems and queued for deletion from backup systems within 90 days.

7. Data Security

We implement industry-standard technical and organizational measures to protect your personal information:

  • Supabase Row Level Security (RLS): Database-level access controls ensure only authorized operations can read or write your data.
  • Stripe PCI-DSS Level 1: All payment data is handled by Stripe — we never see or store your full card details.
  • Cloudflare TLS 1.3: All data transmitted between your browser and our servers is encrypted in transit.
  • Encryption at rest: Data stored in Supabase is encrypted at rest using AES-256.
  • Access controls: Access to personal data is restricted to personnel who require it to operate the service.

Breach Notification: In the event of a security breach that materially affects your personal data, we will notify you within 72 hours of becoming aware of the breach, in accordance with applicable law and industry best practices.

8. Children's Privacy

Big Asere is not directed to children under the age of 13. We do not knowingly collect, use, or disclose personal information from children under 13. Our practices comply with the Children's Online Privacy Protection Act (COPPA).

If we become aware that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will take steps to delete that information promptly. If you believe we have collected data from a child under 13, please contact us at support@bigasere.com.

9. SMS Communications

By providing your phone number when placing an order, you expressly consent to receive transactional SMS messages from Big Asere regarding your order status.

Message frequency is typically 2–4 messages per order. Message and data rates may apply. To opt out, reply STOP to any message. Reply HELP for assistance.

Mobile information (including your phone number and SMS consent) will not be shared with or sold to any third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. We share your phone number only with Twilio, our SMS service provider, solely to deliver the transactional messages you have requested.

For full details on our SMS program, including carrier information and opt-out procedures, see our SMS Notifications Policy.

10. International Data

All personal data collected by Big Asere is stored exclusively on servers located in the United States of America (AWS us-east-1 via Supabase). We do not transfer personal data to servers outside the United States.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make changes, we will update the "Last updated" date at the top of this page.

For material changes that significantly affect your rights or how we handle your data, we will provide notice via email at least 30 days prior to the change taking effect. Your continued use of Big Asere after any changes constitutes your acceptance of the updated Privacy Policy.

12. Contact & Privacy Requests

For privacy requests, data access, correction, deletion requests, or any questions about this Privacy Policy:

Email: support@bigasere.com

Subject line for NDPA requests: "NDPA Request – [Your Full Name]"

Response time: 45 days (as required by NDPA)

Business: Abraham Oviedo Services, LLC DBA Big Asere

Location: North Platte, NE

Versión en Español

Resumen en Español — Ley de Privacidad de Datos de Nebraska (NDPA)

Este resumen es informativo. La versión oficial y legalmente vinculante es el texto en inglés que aparece arriba.

¿Quiénes somos?

Somos Abraham Oviedo Services, LLC, que opera bajo el nombre comercial Big Asere. Somos una plataforma de entrega de comida en North Platte, Nebraska. Puedes contactarnos en support@bigasere.com.

¿Qué información recopilamos?

Recopilamos tu nombre, número de teléfono, dirección de entrega y los detalles de tu pedido. No recopilamos números de Seguro Social, números de tarjeta completos, datos biométricos ni tu ubicación GPS. Los pagos los maneja Stripe de forma segura.

¿Para qué usamos tu información?

Usamos tu información únicamente para procesar y entregar tu pedido, enviarte actualizaciones por SMS, brindarte soporte al cliente, prevenir fraudes y cumplir con la ley. No vendemos ni compartimos tu información con anunciantes o terceros con fines publicitarios.

Tus derechos bajo la Ley NDPA

  • Acceso: Solicitar una copia de los datos que tenemos sobre ti.
  • Corrección: Solicitar que corrijamos datos incorrectos.
  • Eliminación: Solicitar que borremos tus datos personales.
  • Opt-Out: No realizamos publicidad dirigida — este derecho ya está garantizado.

¿Cómo ejercer tus derechos?

Envía un correo a support@bigasere.com con el asunto "NDPA Request – [Tu Nombre Completo]". Responderemos en un máximo de 45 días, según lo exige la ley NDPA.

Mensajes de texto (SMS)

Al proporcionar tu número de teléfono, aceptas recibir mensajes SMS sobre el estado de tu pedido. Puedes cancelar respondiendo STOP a cualquier mensaje nuestro.

Seguridad de tus datos

Utilizamos cifrado TLS 1.3 en tránsito, cifrado AES-256 en reposo, y Stripe PCI-DSS para pagos. Todos los datos se almacenan en servidores en EE. UU. En caso de una violación de datos, te notificaremos dentro de 72 horas.