Privacy Policy

Last updated: September 3, 2026

1. What we collect

Restaurant owners and staff: your name, email address, password (stored only as a secure hash), restaurant name, slug, opening hours, printing details, tax and delivery settings, onboarding survey answers and billing status. Staff QR codes store only the display name you give them (e.g. "Waiter Ahmed") — no personal data beyond that label.

Your menu content: menu photos and PDFs you upload, plus the items, prices, descriptions, tags, allergens and images extracted from them.

Guests: guests order without an account. When placing an order they provide a name, phone number and optional instructions, which are stored with the order so the restaurant can serve them. For delivery orders they also provide a delivery address; for orders a staff member enters on a guest's behalf, only the table and order details are recorded, along with the staff member's name for the restaurant's own audit trail.

Order records: each order stores its items, totals, any tax and delivery fee amounts shown on bills, and — for cash payments — the amount tendered and change returned, so the restaurant can reconcile its drawers. This is the restaurant's business record; the restaurant is the controller of its guest data (see section 7).

Usage and technical data: standard logs and error reports needed to run and improve the service.

2. How we use it

To provide the service: show your menu to guests, deliver orders to your dashboard, cashier portal and kitchen, print receipts, apply the tax and delivery settings you configure, record cash tendered by your staff, and manage your subscription.

To improve the product: onboarding answers and aggregate usage help us decide what to build next. We never sell your data or your guests' data, and we never use it for advertising.

To communicate with you: essential account and billing emails only. No marketing lists.

3. Third-party processors

We use a small set of providers, each limited to what it needs:

Supabase — database, authentication and realtime. Safepay — processes all billing: your PlateDash subscription (paid by you) and, when you enable online guest payments, your guests' card payments into your own Safepay account; card details go directly to Safepay and never touch our servers. Google Gemini — reads your uploaded menu files for AI extraction. Cloudflare R2 — stores item images. Upstash — rate limiting. Sentry — error monitoring, with personal data collection disabled.

Financial details of guest payments (card numbers, wallet data) never reach our servers. We only see order totals and payment status so your boards and reports work.

4. Cookies

We use only the cookies required for sign-in sessions and security. There are no advertising or tracking cookies on PlateDash.

5. Retention and deletion

Your data stays while your account is active. If your subscription lapses, we keep your data so you can come back. Deleting your account is a manual process: to permanently delete your restaurant and all its data, email support@platedash.pro from your account owner address — we verify the request and remove everything within a reasonable period. Deletion is permanent and cannot be undone, so print or export anything you need first.

6. Security

Access is enforced at the database level (row-level security): each restaurant can only see its own data, guests can only place orders and read published menus, and billing details are server-only. Cash tender records and paid-status changes are restricted to the owner and cashier accounts you create; kitchen accounts cannot touch them. Staff ordering codes are secret URLs — treat printed staff QR cards like passwords and remove codes when staff leave. All traffic is encrypted in transit. If you connect online payments, your Safepay keys are stored encrypted with AES-256-GCM, are never displayed after saving, and are never shared with anyone.

7. Your rights

You can request a copy, correction or deletion of your personal data at any time by emailing us. Guests who want their order data removed should contact the restaurant they ordered from — the restaurant controls guest order data.

8. Children

PlateDash is a business product for restaurant owners and is not directed at children. We do not knowingly collect data from children.

9. Changes and contact

We will update the date above when this policy changes and email account owners about material changes. Questions: support@platedash.pro