Privacy Policy
Last updated 14 August 2026
The short version
- We store what you type into Restowise so the apps work — staff records, schedules, payroll figures, checklists, inventory and imported order data.
- We do not sell personal information, and we do not use your data to advertise to anyone.
- Your restaurant's data is yours. We hold it on your behalf and hand it back or delete it when you ask.
- Three outside companies hold data for us: Supabase (the database), Vercel (the websites) and Resend (email). They are listed below.
- Email admin@restowise.app to see, correct or delete your data.
1. Who this covers
Restowise is restaurant operations software. Data reaches us in three different ways, and your rights differ depending on which one describes you.
| You are | What that means here |
| An operator |
You signed up and run one or more stores. You are our customer, and this policy is the agreement about your own account data. |
| Staff at a store |
Your employer put you on a schedule, a payroll run or a staff list. You may never have signed up yourself. Your employer decides what is recorded about you; we hold it for them. Requests about your data should go to your manager first, and we will help them answer you. |
| A customer of a restaurant |
You ordered food and your name arrived here inside a delivery-platform export the restaurant imported. We hold it only as part of that record. Contact the restaurant, and we will assist them. |
For staff and customer data we act as a service provider to the restaurant: we process it on their instructions and we do not use it for our own purposes.
2. What we collect
Your account
- Email address, display name, and a password (stored only as a bcrypt hash — nobody at Restowise can read it).
- Your role, which stores you belong to, and which apps you may open.
- The time you were last active, so administrators can see who is still using the account.
- A profile picture, if you have one. Default avatars are generated images from DiceBear referenced by URL — we do not upload a photo of you anywhere.
- Whether two-step email sign-in is switched on.
Data you enter into the apps
- Staff records — names, roles, target hours, availability, days off, scheduling constraints, termination dates, and hourly pay rates.
- Schedules — shifts, hours, notes, catering assignments.
- Time-off and shift-swap requests, including any reason you type.
- Payroll — pay periods, hours, tips, company details, and generated payroll documents.
- Onboarding documents you upload and the signed acknowledgements returned against them, including the typed name and timestamp used as the acknowledgement.
- Delivery receipts — photographs of receipts, order numbers and tip amounts.
- Checklists and HACCP logs — who completed what, when, notes, and any photographs attached as evidence.
- Inventory and dough-prep counts, and cost settings.
- Imported delivery-platform reports (for example DoorDash exports), which include order totals, tips, timings and — in some exports — a customer name.
Records we generate
- An audit log of significant actions: who changed what, when, and in some cases the before-and-after values. This is a security feature and is deliberately hard to erase.
- Standard server logs kept by our hosting providers, which include IP addresses.
What we deliberately do not collect: no advertising or tracking cookies, no analytics pixels, no location tracking, no social-media trackers, and no biometric data. The fingerprint or face unlock on the mobile app is checked by your phone; the result reaches us as a yes or no, and the biometric itself never leaves the device.
3. Why we hold it
| Purpose | Examples |
| Running the service you asked for | Building a schedule, producing payroll, recording a fridge temperature |
| Keeping accounts secure | Sign-in, two-step codes, the audit log, permission checks |
| Supporting you | Answering an email about something that went wrong |
| Legal obligations | Retaining records where the law requires it |
We do not profile you, make automated decisions with legal effects about you, or use your data to train our own models.
4. Who we share it with
These are every outside company that can hold or see your data, and why.
| Provider | What it handles | Where |
| Supabase | The database, accounts, and uploaded files (receipt photos, checklist photos, onboarding documents, generated reports) | United States |
| Vercel | Hosting and delivery of the websites, plus server logs | United States / global edge |
| Resend | Sending email — verification, password resets, two-step codes | United States |
| Apple, Google Play | Distributing the mobile app | United States |
Some pages also load public resources that receive your IP address as a side effect of the request, but are sent no account information: Google Fonts (typefaces), DiceBear (default avatars), Open-Meteo (weather for the week you are scheduling), and Ticketmaster and ESPN (nearby events, so you can staff a busy night).
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We may disclose data if the law compels us, or transfer it if the business is ever sold — in which case this policy travels with it.
5. How long we keep it
- While your account is open: for as long as you keep it there. The apps are a record-keeping tool, so nothing is deleted on a timer.
- Deleted account: the sign-in is destroyed immediately. Records the person entered — schedules, imports, payroll — are transferred to the store owner rather than deleted, because deleting them would destroy the store's own history.
- Audit log: retained for security, with the person's name attached, after their account is gone.
- Backups: may hold deleted data for up to 30 days before rotating out.
6. Your choices
You can, at any time:
- See what we hold about you and get a copy.
- Correct it — most of it you can edit yourself, or a manager can.
- Delete your account. Store owners and administrators can do this from the Admin Panel. If nobody at your store can, email us and we will do it.
- Turn off two-step sign-in, unless your employer requires it.
If you are in California, you also have the right to know what is collected and disclosed, to have it deleted, to correct it, and not to be discriminated against for asking. We do not sell personal information or share it for behavioural advertising, so there is nothing to opt out of. Exercise any of these by emailing admin@restowise.app — we will verify who you are before acting, and we aim to answer within 45 days.
If you are staff at a store, your employer decides what is recorded about you and how long it stays. Ask them first; if you cannot get an answer, write to us and we will help.
7. Security
- Everything travels over HTTPS.
- Passwords are stored only as bcrypt hashes.
- Every table enforces row-level security, so one store cannot read another's data even if the app is wrong.
- Uploaded files sit in private buckets reachable only through short-lived signed links.
- Optional two-step sign-in by emailed code, which an owner can require for everyone.
- The mobile app can be locked with your phone's fingerprint, face or passcode, and stores its session in the device keychain.
No system is perfect. If something goes wrong that affects you, we will tell you.
8. Children
Restowise is workplace software and is not directed at children under 13, and we do not knowingly collect their data. Where a restaurant employs minors under local law, that employment record is entered by their employer, who is responsible for the lawfulness of doing so.
9. Where data is held
Restowise is operated from the United States, and all of the providers above store data in the United States. If you use it from elsewhere, your data is transferred there.
10. Changes
If we change this policy in a way that matters, we will update the date at the top and tell account holders by email. Continuing to use Restowise after a change means you accept it.
11. Contact
Questions, requests, or anything that looks like a security problem: admin@restowise.app.