Privacy Policy
Last updated: June 19, 2026
This Privacy Policy describes how Restaurant SaaS ("we", "us") collects, uses, and protects your personal information when you use our platform.
1. Information we collect
- Account information: name, email, phone, restaurant name, country, locale.
- Operational data: menu items, orders, customers (entered by you or your team).
- Usage data: pages visited, features used, timestamps.
- Payment data: handled entirely by our PCI DSS-compliant payment processor. We never store card numbers.
2. How we use your information
We use your data to:
- Provide, maintain, and improve the Service.
- Send transactional emails (signup, verification, billing).
- Provide support and respond to your requests.
- Detect fraud, abuse, and security incidents.
- Comply with legal obligations.
3. Multi-tenant data isolation
Each restaurant's data is logically isolated by a tenant identifier. Our automated test suite verifies that no tenant can ever read another tenant's data.
4. Sub-processors
We share data with the following sub-processors:
- Email delivery: SendGrid / SES / Postmark
- Payment processing: Stripe / Tap / HyperPay / Checkout.com (gateway-agnostic)
- Hosting: AWS / GCP / Azure (configurable)
- Observability: Grafana Cloud / self-hosted Loki/Tempo
5. Your rights
You may at any time:
- Access and export your data (Settings → Data → Export).
- Correct inaccurate data.
- Delete your account and all associated data.
- Opt out of marketing communications.
6. Data retention
Operational data is retained for the life of your account, plus 30 days after cancellation for recovery. Audit logs are retained for 7 years for compliance.
7. Security
We follow OWASP ASVS Level 2+, encrypt data in transit (TLS 1.2+) and at rest (AES-256), perform daily backups, and run annual third-party penetration tests.
8. International transfers
We use Standard Contractual Clauses for international data transfers. Enterprise customers can opt in to data-residency controls (EU-only, US-only, etc.).
9. Changes
Material changes will be communicated by email at least 30 days in advance.
10. Contact
Email privacy@resturant-saas.local. For EU residents, our Data Protection Officer can be reached at dpo@resturant-saas.local.
This is a template — please review with a lawyer before production launch.