RSRestaurant SaaS

Privacy Policy

Last updated: June 19, 2026

This Privacy Policy describes how Restaurant SaaS ("we", "us") collects, uses, and protects your personal information when you use our platform.

1. Information we collect

2. How we use your information

We use your data to:

3. Multi-tenant data isolation

Each restaurant's data is logically isolated by a tenant identifier. Our automated test suite verifies that no tenant can ever read another tenant's data.

4. Sub-processors

We share data with the following sub-processors:

5. Your rights

You may at any time:

6. Data retention

Operational data is retained for the life of your account, plus 30 days after cancellation for recovery. Audit logs are retained for 7 years for compliance.

7. Security

We follow OWASP ASVS Level 2+, encrypt data in transit (TLS 1.2+) and at rest (AES-256), perform daily backups, and run annual third-party penetration tests.

8. International transfers

We use Standard Contractual Clauses for international data transfers. Enterprise customers can opt in to data-residency controls (EU-only, US-only, etc.).

9. Changes

Material changes will be communicated by email at least 30 days in advance.

10. Contact

Email privacy@resturant-saas.local. For EU residents, our Data Protection Officer can be reached at dpo@resturant-saas.local.

This is a template — please review with a lawyer before production launch.