TagPipes Companion for Chrome Add to Chrome →

Privacy Research

Why Restaurant Websites Score Worst On Privacy, And It Is Not Carelessness

Two numbers

Across the sites we scanned between January and October 2026, restaurants averaged 9.9 out of 100 on privacy across 31,167 sites. Independent ecommerce averaged 24.0 across 8,386. The whole-sample mean, across all 47,420 scored sites, was 13.5.

So restaurants score less than half what ecommerce scores, and they sit below the average of a sample they make up most of.

Where restaurant sites actually land

The average hides the shape. Here is how the 31,167 restaurant sites split across the four tiers, which describe the mechanism the scan observed rather than the company:

  • Gated: 132 (0.4%). A consent platform, a working Consent Mode v2 signal, and no tracking seen before consent or after a refusal. That is about one restaurant site in 236.
  • Partial: 685 (2.2%). A consent platform was detected, with a gap behind it.
  • Exposed: 4,662 (15.0%). A privacy or cookie preferences link, but no consent platform detected.
  • Unprotected: 25,688 (82.4%). No consent platform and no privacy preferences link detected.

Hospitality, in the same scan and measured the same way, gates at 5.1% (36 of 704), roughly twelve times the restaurant rate. Same method, same window, so the gap is in practice rather than in measurement. Hospitality's sample is much smaller, though, so read its percentage as indicative. Full breakdowns: restaurants and hospitality.

The lazy reading, and why we are refusing it

The obvious story is that one industry cares less. It writes itself, it flatters the reader if the reader is not a restaurant, and it is both insulting and wrong.

It is wrong because it does not survive contact with how these businesses are actually built. Restaurant operators are not less diligent than ecommerce operators. In several respects they are under more scrutiny, because they handle food safety, licensing, accessibility and payment security under regimes that inspect them in person. The idea that this is the one group that shrugs at a compliance obligation does not hold up.

Refusing the lazy reading is what earns the right to offer a better one. Here is the better one, and it is a hypothesis rather than a finding. We measured the gap. We did not measure why it exists, and the index does not prove the explanation below. It is the best available reading of a real difference, offered as that and nothing more.

Count the domains, not the pages

Map a restaurant customer journey the way a browser sees it, which means counting registrable domains rather than pages or screens.

The marketing site is one domain. Online ordering is very often a hosted platform on the vendor's domain, or on a subdomain of it wearing the brand's colors. Loyalty is frequently a second vendor. Reservations a third. Delivery marketplaces a fourth, and there are usually several of those. Gift cards a fifth, on a processor's infrastructure. Catering enquiries sometimes a sixth.

A single guest going from a homepage to a completed order can cross three or four separate origins without noticing, because every one of them is styled to look like the same company.

We wrote about what that sprawl does to tracking and attribution in Your Restaurant Website Is Not One Website. This is the privacy companion to it, and the mechanism is the same one seen from a different angle.

The mechanic is short and we are not going to re-derive it here. Consent captured on brand.com is stored against brand.com. A page served from brand.vendor.com cannot read it. The browser is not being awkward; that separation is the whole point of the origin model and it is what stops any site reading any other site's storage.

The full version, including why the domain boundary does not decide who is responsible, is in Your Checkout Is on a Different Domain. Your Consent Record Did Not Follow It..

The consequence for a restaurant brand is direct. A banner on the marketing site governs the marketing site. It does not govern the ordering flow, and the ordering flow is where the customer types a name, a phone number, a delivery address and a card.

The surface you control is the least important one

This is the part that makes the gap structural rather than cultural.

The domain a restaurant brand fully controls is the marketing site. It carries the menu, the locations, the hours and the story. It collects very little, it transacts nothing, and it is the easiest place in the estate to deploy a tag manager and a consent platform. So that is where the consent work gets done, because that is where there is access.

The domains carrying the payment details and the contact data are the ones nobody at the brand can deploy anything to. There is no tag manager container to open. There is a vendor, a support queue, a contract, and a configuration screen that may or may not include a consent setting.

Effort and access have come apart. The brand can work as hard as it likes on the surface that matters least.

The ecommerce contrast, which is mostly an accident

Independent ecommerce faces the same obligations with a friendlier topology. Checkout usually runs on the brand's own domain, or on a platform subdomain the brand can configure, because that is simply how ecommerce platforms are built. Payment is often iframed in from a processor, but the surrounding page, the cart, the account and the analytics all sit inside one consent scope.

One banner therefore reaches the transaction. Not because anyone made a wiser decision, but because the stack they bought happened to put the sensitive part inside the boundary they control.

Worth being fair here: the ecommerce number is 24.0 out of 100. That is better, and it is not good. Both groups have a long way to go, and the gap between them is a difference in difficulty rather than a difference in virtue.

Why the diagnosis changes the remedy

This is the practical part, and it is the reason the gap is worth understanding rather than just observing.

Two brands can have the same low score for opposite reasons.

  • Low because nobody got to it. The estate is mostly on domains the brand controls, and the work simply has not been scheduled. The remedy is to schedule it. A consent platform, a tag audit, a proper gating configuration, and the number moves.
  • Low because half the funnel is on vendor domains. The remedy above will not move the number, because the number is not being driven by the surface it improves. You can do a flawless job on the marketing site and the score barely shifts, because the exposure was never there.

Most brands buy the first remedy for the second problem. It is an expensive mistake and a demoralizing one, because the work is real, it is done competently, and it does not appear to accomplish anything. Then the conclusion drawn is that privacy work does not help, which is the worst possible lesson to take from it.

The second problem needs different tools: a vendor inventory, a written request to each platform for its cookie table and stated basis, contract language at renewal, and ongoing monitoring of domains you cannot deploy to. That is a procurement and governance exercise as much as a technical one.

The three-step audit

You can do the first pass yourself in an afternoon, and you should do it before anyone quotes you for anything.

  1. List every domain between your homepage and a completed order. Actually walk it. Order something. Write down the address bar at every step, including the redirects that flash past. Then do it again for loyalty signup, for a reservation, and for a gift card purchase. You are looking for registrable domains, so brand.com and shop.brand.com count as one, and brand.vendor.com counts as its own.
  2. Load each one in a fresh private window and watch what fires before any consent interface appears. Network tab open first. Start with the homepage and the page behind the order button, before touching anything on a banner. You are not judging anything yet, just recording what leaves the browser before the visitor is asked.
  3. Look for a privacy preferences link in each footer. On each domain, not just the marketing site. This is the one that surprises people, because the vendor-hosted pages very often have no route to a preference at all, and that is the page holding the card details.

At the end you have a table: domain, who controls it, what fires before consent, whether a preference is reachable. That table is the diagnosis. Everything after it is a decision about what to do, and most of those decisions are commercial rather than technical.

Whose problem is it

The uncomfortable answer is that it is the brand's, and that being unable to deploy to a domain does not transfer the exposure to whoever can.

The customer typed their details into a page that said the restaurant's name at the top. They did not evaluate a vendor, they did not read a subprocessor list, and from where they are standing there was never more than one company involved. That perception is not naive. It is the entire reason the ordering page is styled to look like the brand.

So the question is not whether the vendor is doing a good job. It is whether anyone at the brand has ever looked, and whether the answer would be written down anywhere if they had.

Most restaurant brands can name who owns how the site looks. Far fewer can name who owns what fires on it. Those are different jobs, and the second one is usually nobody's.

What the numbers do and do not say

Every figure here is from the Website Privacy Index: 47,506 sites scanned, 47,420 scored, crawled between January and October 2026, covering restaurant, hospitality and independent ecommerce sites. Restaurants 9.9 across 31,167. Ecommerce 24.0 across 8,386. Hospitality 18.6 across 704.

These are detections, not legal conclusions. We loaded public pages and recorded what happened. No site and no vertical is described here as non-compliant, unlawful or in breach, and a low score is not an allegation. Equally, a high score is not a clean bill of health, because an absence of findings is not a finding.

And the causal argument in this piece remains a hypothesis. The gap is measured. The explanation is reasoning about how these businesses are assembled, and it should be treated as reasoning.

If your funnel crosses domains you do not own, a one-off audit of your own site structurally cannot cover it. That is the gap Managed Privacy is built for. Or start with the free scan and the published data on the Website Privacy Index.

More from the Website Privacy Index: Consent platform market share · Restaurant privacy index · Ecommerce privacy index

Rawsoft provides technical implementation and analysis, not legal advice. Please confirm any regulatory interpretation with your counsel.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy and consent management, and media tracking for enterprise brands.

Add Rawsoft as a preferred source on Google

More from the blog

Analytics

Your Restaurant Website Is Not One Website

A typical restaurant chain site hands visitors to an ordering platform, a loyalty program, a gift card processor and a catering system, each on different code and different domains. Here is what that sprawl does to tracking, attribution and privacy compliance.

August 2026Read

Privacy Research

More Than Four In Ten Cookie Banners Do Not Block Anything

Of 47,419 sites we scored, 1,475 showed a cookie banner and 620 of those tracked the visitor anyway. The problem is not the sites with no consent tooling. It is the ones that bought it and are protected by none of it.

August 2026Read