Here is a question most restaurant owners cannot answer: of every guest who walked in, ordered delivery, or visited your website last month, how many can you actually email today? For the typical restaurant the honest answer is close to zero. The guests came, they ate, they left, and the only record is a ticket in a POS the restaurant cannot easily mine and a stack of delivery orders the apps will not hand over.
That is the gap. Not a lack of customers, a lack of any owned record of them. And it is the gap that quietly forces restaurants to keep paying platforms to reach people they already served. Closing it is mostly mechanics, and the mechanics are not hard. Getting the review piece wrong, though, can cost you the profile itself, so I want to be precise about that section before anything else.
The principle: capture at the moments you already have them
You do not need to invent new customer touchpoints. A restaurant already has several moments where a guest is engaged and a capture is natural. The job is to put a low-friction opt-in at each one and route everything to a list you own.
The menu is never the toll booth. The opt-in lives next to the menu, never in front of it. Gate the menu and you lose the guest. Offer the opt-in alongside it and a healthy share will say yes.
The table: a QR menu that does triple duty
The single best capture mechanism for a restaurant is the one that also fixes the menu problem. One mobile-first landing page replaces the stack of PDF menus: it loads fast, reads well on a phone, and is easy to update. QR codes on the table tents point to it. On that page:
- The current menu, the daily specials, and the drink list, so guests do not have to flag someone down to ask.
- A soft email opt-in alongside the menu, never blocking it.
- An optional reason to opt in: early access to a new dish, a standing perk, a small voucher. Whatever fits the brand. The incentive lifts the opt-in rate without cheapening anything.
Every signup flows into your customer database, tagged by source. One page does three jobs at once: it serves the menu, it markets the specials, and it builds your owned list, from people who are literally sitting in your dining room.
One detail worth getting right up front: that email checkbox captures consent for email only. If you also want to text this list, treat it as a separate ask, for reasons the review section below will make concrete.
The website: stop letting visitors leave anonymous
Covered in depth elsewhere, but it belongs in the capture system: a real email signup on the site and a post-visit email trigger, so the people your website attracts become contacts instead of anonymous bounces. The website and the table opt-in feed the same list.
The POS: recover the customers the delivery apps "own"
This is the move most restaurants do not realize is available, though how available it is depends on which POS you run. It is worth naming the differences rather than treating "the POS" as one system:
- Square makes this genuinely self-serve. A restaurant can generate its own API access token from the Square Developer Dashboard with no partner approval and no waiting.
- Toast also offers a self-serve path, called Standard API access, created from Toast Web itself rather than through the partner program. The catch is that it requires a subscription of Restaurant Management Suite Essentials or higher and the Manage Integrations permission, so check your plan tier before assuming it is available (Toast's own developer documentation lays out the exact requirements).
- Clover and most of the smaller or older platforms generally route this through their app marketplace or a developer partnership rather than a plain toggle in the owner's dashboard, which means a short setup call or a marketplace app is more realistic than a five-minute self-serve connection.
Whichever system you run, the mechanics once connected are the same:
- You generate read-only credentials in the POS dashboard (or, for the platforms above, work with someone who can) and connect them once.
- Every takeout and delivery order creates or updates a contact: name, email, phone, order history.
On backfill: do not assume a new connection instantly hands you months of history. How far back the order history goes, and how much of it the API actually exposes, varies by system and by plan. Some retain a rolling window of a few months, some retain years, and a few only expose data going forward from the day you connect. Ask the specific question of your specific POS before you promise yourself a clean history, and treat every new order from the connection date forward as the guaranteed part.
A note on scope: dine-in guests usually are not exposed through the POS API, which is exactly why the table QR capture matters. The POS handles takeout and delivery, the table tent handles the room. Together they cover everyone.
Reviews: ask everyone, gate nothing
This is the section I want to be direct about, because the common advice here is not just aggressive, it is a policy violation waiting to be enforced.
The pattern you will see recommended elsewhere is a post-visit prompt that asks the guest how their experience was, then routes happy answers to a public review link and unhappy answers to a private message, quietly, before Google ever sees them. It sounds like good triage. It is review gating, and Google's Business Profile content policy prohibits it directly: a profile may not "discourage or prohibit negative reviews, or selectively solicit positive reviews from customers" (Google, Prohibited and restricted content). A profile that trips this can have content removed or, for repeated or clear violations, be suspended. That is not a hypothetical risk for a restaurant that depends on its map pack listing to be found at all.
Set the policy risk aside for a second, because the practice is bad on its own terms too. If you only let happy guests reach the public review link, you have not improved your restaurant. You have hidden the feedback that would have told you the ticket times slipped on Friday or the new server needs coaching. Gating does not fix problems, it hides them from you along with everyone else, and the rating you end up with reflects a curated slice of reality rather than the real one.
The correct pattern, and the one I set up for every restaurant client:
- Ask every guest the same way, every time. One post-order or post-visit message, the same for everyone, that asks for a public review and links directly to your Google review page.
- Offer a private feedback channel to everyone, not as a filter. A second line in the same message, something like "if anything was off, tell us here first," with its own link, available to every guest regardless of how their visit went. The difference between this and gating is entirely in the sequencing: nothing routes a guest away from the public review based on their answer. Both paths sit next to each other, and the guest picks.
- Do not ask the "how was it" screening question at all. That question is the mechanism that makes gating gating. Removing it is what makes the rest of this compliant.
What you get from doing it this way is what you were actually after: a review count and rating that reflect the real experience, a private inbox that still catches the guest who wants to vent before they post, and a profile that Google has no reason to touch.
Texting the list: a separate consent, not an upgrade
Once a list exists, the instinct is to text it, because open rates on text beat email and it feels like the natural next step. Legally it is not a next step, it is a new opt-in. The Telephone Consumer Protection Act requires prior express written consent, a signed or clearly affirmative agreement specific to receiving marketing texts or calls sent through an automated system, before you can send them (47 CFR 64.1200(a)(2) and (f)(9)). A guest who checked a box for email specials on your QR menu has not agreed to anything about text messages. The two consents are separate under the rule, and there is no version of "well, they gave us their number for the order" that substitutes for it.
In practice this means a distinct SMS opt-in, its own checkbox or its own text-to-join step, clearly labeled as texts, kept separately in your database from the email consent. It is one extra field to build. Skipping it is the kind of thing that looks fine for months and then becomes a real problem the day someone complains.
What you do with the list once it exists
Collecting the data is only valuable because of what becomes possible once you have it. With a real owned list in place, tagged by source and visit behavior, the moves that were impossible become routine:
- Win-back. Email (or text, to the guests who opted into texts specifically) the people who have not been in for sixty days. The cheapest revenue a restaurant has, and impossible without a list.
- Launch advantage. When you open a second concept, the warm list from the first gets first-look invites. You launch to an audience instead of to strangers.
- Segmented promotion. The slow Tuesday, the new menu, the catering push, all addressable to the people most likely to care, without renting access from a platform.
Why this is the asset that compounds
Owned customer data is one of the few restaurant assets that appreciates with time. Every month of capture grows the list and sharpens the segmentation, and every campaign you can run to your own list is a campaign you did not have to pay a platform to deliver. The restaurant that started capturing a year ago has an audience, the one that starts today begins building one, the one that never starts keeps paying to re-acquire customers it already fed.
Where to start
The build is incremental and does not disrupt service:
- Stand up the QR table menu with a soft email opt-in. It fixes the menu and starts the list at the same time.
- Add website email capture.
- Connect the POS, named accurately for your system, so takeout and delivery customers flow in going forward.
- Turn on win-back messaging and the compliant review ask (public link and private-feedback link side by side, no screening question) once data is moving.
- If you plan to text, add a separate, clearly labeled SMS opt-in before you send a single marketing text.
The goal is simple to state: for every customer a platform keeps, you keep one too. That single shift, from collecting nothing to collecting everything, without gating a thing, is what turns a restaurant from a renter of its own customers into an owner.
If you want a map of where your restaurant could be capturing data and is not, a complimentary audit will walk through the moments you are letting walk out the door.
