Privacy Policy
Last updated: August 31, 2026
Who this covers
This policy applies to personal data processed by the RestroKendra platform: the software used by restaurant owners, managers, and staff to run point-of-sale, ordering, staff, and accounting operations, and by their customers using a restaurant's QR ordering, loyalty, or reservation features.
1. Restaurant owners, managers, and staff accounts
We collect a full name and phone number (your login identifier), an optional email address, and a password stored only as a one-way hash. We also store your role/permissions at each restaurant, and session metadata needed to keep you logged in. If you enable two-factor authentication, we store a TOTP secret and backup codes — the TOTP secret is kept in a readable form, because verifying a live login code requires reading it back; this is a deliberate, disclosed exception, not an oversight.
2. Staff employment and payroll data
For paid staff, a restaurant's owner/manager can record salary configuration, bank account details (if they choose to), payroll payment history, attendance records, leave requests, and holidays. RestroKendra does not initiate bank transfers — this data exists for the restaurant's own record-keeping.
3. Staff attendance photos (“selfie verification”)
- A restaurant can optionally turn on photo-verified clock-in/clock-out. One photo is captured per clock-in and clock-out, from the staff member's own device camera.
- Consent is required before the first photo — a staff member is shown a plain-language notice explaining what's collected, why, who can see it, and how long it's kept, and must actively agree. Every consent version anyone has ever agreed to is kept permanently, never overwritten.
- Photos are stored in private object storage (an S3-compatible bucket), never in the application database, never publicly reachable.
- Photos are only ever viewed through a short-lived, signed URL minted at the moment someone with permission looks at it — no permanent public link exists.
- Who can see a photo: that restaurant's own owner/managers, and RestroKendra platform staff for support or legal purposes if genuinely needed.
- Retention: 90 days by default (configurable per deployment via
ATTENDANCE_PHOTO_RETENTION_DAYS), after which a purge routine deletes the file and clears the database record. That purge does not run on its own schedule — this product has no background job runner, so it only runs when a platform administrator (or an operator's external cron job) triggers it. In a deployment where nobody has wired that up, expired photos are not actually deleted on time — a real gap, stated here plainly. - A staff member can decline consent and still clock in/out without a photo, unless their specific restaurant requires one.
4. Customers
Depending on which features a restaurant uses, a customer may have their phone number, name, optional email/date of birth, order history, loyalty points/tier, visit streaks, and any notes staff add stored against their profile. This is collected by the restaurant operating RestroKendra for its own CRM and loyalty purposes. Each restaurant's customer list is isolated from every other restaurant's on the platform — none of it is sold, rented, or shared across restaurants.
5. Financial records
A restaurant's expenses, purchases, supplier records, ledger/"Account Books" entries, cash-register sessions, and end-of-day closes are stored as that restaurant's own business data, visible only to its own authorized staff by role/permission.
6. AI assistant usage
If a restaurant uses the AI assistant, its questions and the data pulled to answer them are sent to a configured third-party AI provider, scoped strictly to that restaurant's own data. A restaurant-supplied AI provider API key is stored encrypted at rest, not in plain text.
How data is stored and protected
- Every restaurant's data is isolated from every other restaurant's at the application layer.
- Passwords are one-way hashed; attendance selfies live in private object storage behind signed URLs; AI provider keys are encrypted at rest.
- Sensitive actions (payroll changes, refunds, staff management, platform-admin actions) are recorded in an audit log.
- RestroKendra has not undergone an independent third-party security audit or penetration test as of this writing.
Retention and deletion
See the DATA_RETENTION.md document in the project repository for the full per-category breakdown. In short: attendance photos default to a 90-day retention window; everything else (accounts, orders, payroll, ledger, customer records) is kept for as long as a restaurant's account exists. There is currently no self-service "delete my account and all data" feature for owners, staff, or customers — removing data today requires a direct request handled manually by whoever operates the platform. Cancelling or letting a subscription lapse does not delete a restaurant's data.
How to request deletion or export
If you are a restaurant's customer or staff member, ask that restaurant's owner/manager first — they control your data and can action most requests directly. If you are a restaurant owner, or your manager can't resolve the request, contact privacy@restromitra.com (a placeholder address — to be replaced with a real, monitored inbox before commercial launch). Some export already works today as a self-service feature (customers, inventory, ledger, suppliers, staff roster); orders, purchases, attendance, and payroll do not yet have a dedicated export tool.
Children's data
RestroKendra is a business tool, not intended for use by children, and does not knowingly collect data about children beyond what a restaurant might record about its own staff.
Changes to this policy
This page is updated whenever the product's actual data practices change — it is meant to describe reality, not aspirations.
Contact
privacy@restromitra.com (placeholder — set a real, monitored address before commercial launch).
