Two numbers
Across the sites we scanned between January and August 2026, restaurants averaged 9.8 out of 100 on privacy across 10,653 sites. Independent ecommerce averaged 22.8 across 2,466. The whole-sample mean, across all 18,524 scored sites, was 13.8.
So restaurants score less than half what ecommerce scores, and they sit below the average of a sample they make up most of.
The lazy reading, and why we are refusing it
The obvious story is that one industry cares less. It writes itself, it flatters the reader if the reader is not a restaurant, and it is both insulting and wrong.
It is wrong because it does not survive contact with how these businesses are actually built. Restaurant operators are not less diligent than ecommerce operators. In several respects they are under more scrutiny, because they handle food safety, licensing, accessibility and payment security under regimes that inspect them in person. The idea that this is the one group that shrugs at a compliance obligation does not hold up.
Refusing the lazy reading is what earns the right to offer a better one. Here is the better one, and it is a hypothesis rather than a finding. We measured the gap. We did not measure why it exists, and the index does not prove the explanation below. It is the best available reading of a real difference, offered as that and nothing more.
Count the domains, not the pages
Map a restaurant customer journey the way a browser sees it, which means counting registrable domains rather than pages or screens.
The marketing site is one domain. Online ordering is very often a hosted platform on the vendor's domain, or on a subdomain of it wearing the brand's colours. Loyalty is frequently a second vendor. Reservations a third. Delivery marketplaces a fourth, and there are usually several of those. Gift cards a fifth, on a processor's infrastructure. Catering enquiries sometimes a sixth.
A single guest going from a homepage to a completed order can cross three or four separate origins without noticing, because every one of them is styled to look like the same company.
We wrote about what that sprawl does to tracking and attribution in Your Restaurant Website Is Not One Website. This is the privacy companion to it, and the mechanism is the same one seen from a different angle.
Consent does not travel across that boundary
The mechanic is short and we are not going to re-derive it here. Consent captured on brand.com is stored against brand.com. A page served from brand.vendor.com cannot read it. The browser is not being awkward; that separation is the whole point of the origin model and it is what stops any site reading any other site's storage.
The full version, including why the domain boundary does not decide who is responsible, is in Your Checkout Is on a Different Domain. Your Consent Record Did Not Follow It..
The consequence for a restaurant brand is direct. A banner on the marketing site governs the marketing site. It does not govern the ordering flow, and the ordering flow is where the customer types a name, a phone number, a delivery address and a card.
The surface you control is the least important one
This is the part that makes the gap structural rather than cultural.
The domain a restaurant brand fully controls is the marketing site. It carries the menu, the locations, the hours and the story. It collects very little, it transacts nothing, and it is the easiest place in the estate to deploy a tag manager and a consent platform. So that is where the consent work gets done, because that is where there is access.
The domains carrying the payment details and the contact data are the ones nobody at the brand can deploy anything to. There is no tag manager container to open. There is a vendor, a support queue, a contract, and a configuration screen that may or may not include a consent setting.
Effort and access have come apart. The brand can work as hard as it likes on the surface that matters least.
The ecommerce contrast, which is mostly an accident
Independent ecommerce faces the same obligations with a friendlier topology. Checkout usually runs on the brand's own domain, or on a platform subdomain the brand can configure, because that is simply how ecommerce platforms are built. Payment is often iframed in from a processor, but the surrounding page, the cart, the account and the analytics all sit inside one consent scope.
One banner therefore reaches the transaction. Not because anyone made a wiser decision, but because the stack they bought happened to put the sensitive part inside the boundary they control.
Worth being fair here: the ecommerce number is 22.8 out of 100. That is better, and it is not good. Both groups have a long way to go, and the gap between them is a difference in difficulty rather than a difference in virtue.
Why the diagnosis changes the remedy
This is the practical part, and it is the reason the gap is worth understanding rather than just observing.
Two brands can have the same low score for opposite reasons.
- Low because nobody got to it. The estate is mostly on domains the brand controls, and the work simply has not been scheduled. The remedy is to schedule it. A consent platform, a tag audit, a proper gating configuration, and the number moves.
- Low because half the funnel is on vendor domains. The remedy above will not move the number, because the number is not being driven by the surface it improves. You can do a flawless job on the marketing site and the score barely shifts, because the exposure was never there.
Most brands buy the first remedy for the second problem. It is an expensive mistake and a demoralising one, because the work is real, it is done competently, and it does not appear to accomplish anything. Then the conclusion drawn is that privacy work does not help, which is the worst possible lesson to take from it.
The second problem needs different tools: a vendor inventory, a written request to each platform for its cookie table and stated basis, contract language at renewal, and ongoing monitoring of domains you cannot deploy to. That is a procurement and governance exercise as much as a technical one.
The three-step audit
You can do the first pass yourself in an afternoon, and you should do it before anyone quotes you for anything.
- List every domain between your homepage and a completed order. Actually walk it. Order something. Write down the address bar at every step, including the redirects that flash past. Then do it again for loyalty signup, for a reservation, and for a gift card purchase. You are looking for registrable domains, so brand.com and shop.brand.com count as one, and brand.vendor.com counts as its own.
- Load each one in a fresh private window and watch what fires before any consent interface appears. Network tab open first. You are not judging anything yet, just recording what leaves the browser before the visitor is asked.
- Look for a privacy preferences link in each footer. On each domain, not just the marketing site. This is the one that surprises people, because the vendor-hosted pages very often have no route to a preference at all, and that is the page holding the card details.
At the end you have a table: domain, who controls it, what fires before consent, whether a preference is reachable. That table is the diagnosis. Everything after it is a decision about what to do, and most of those decisions are commercial rather than technical.
Whose problem is it
The uncomfortable answer is that it is the brand's, and that being unable to deploy to a domain does not transfer the exposure to whoever can.
The customer typed their details into a page that said the restaurant's name at the top. They did not evaluate a vendor, they did not read a subprocessor list, and from where they are standing there was never more than one company involved. That perception is not naive. It is the entire reason the ordering page is styled to look like the brand.
So the question is not whether the vendor is doing a good job. It is whether anyone at the brand has ever looked, and whether the answer would be written down anywhere if they had.
What the numbers do and do not say
Every figure here is from the Website Privacy Index: 18,613 sites scanned, 18,524 scored, crawled between January and August 2026, covering restaurant, hospitality and independent ecommerce sites. Restaurants 9.8 across 10,653. Ecommerce 22.8 across 2,466. Hospitality 19.4 across 499.
These are detections, not legal conclusions. We loaded public pages and recorded what happened. No site and no vertical is described here as non-compliant, unlawful or in breach, and a low score is not an allegation. Equally, a high score is not a clean bill of health, because an absence of findings is not a finding.
And the causal argument in this piece remains a hypothesis. The gap is measured. The explanation is reasoning about how these businesses are assembled, and it should be treated as reasoning.
If your funnel crosses domains you do not own, a one-off audit of your own site structurally cannot cover it. That is the gap Managed Privacy is built for. Or start with the free scan and the published data on the Website Privacy Index.
Rawsoft provides technical implementation and analysis, not legal advice. Please confirm any regulatory interpretation with your counsel.