Privacy Policy

Effective Date: September 19, 2026

1. Data We Collect

  • Account data — name, email, and restaurant name provided during sign-up.
  • Restaurant operational data — menus, orders, floor plans, inventory, recipes, staff schedules, and sales figures you enter into the platform.
  • Delivery platform data — CSV reports and analytics you upload from DoorDash, Uber Eats, Grubhub, and similar services.
  • Financial account data — if you choose to connect a bank or credit-card account through Stripe Financial Connections via Orion, or another bank provider you enable, we access the account details (name, type, mask, and balance) and transaction history for the accounts you link, so we can build your bookkeeping and cash-flow reporting.
  • Google account data — if you choose to connect your Google Business Profile, you sign in with Google and grant AI-R the “manage your business listings” permission. We use it only to read the listing that belongs to your restaurant (name, category, description, hours, phone, website, rating and reviews) and, when you approve a specific proposal inside AI-R, to write that one change back to the listing. We never post, reply, or edit on your behalf without an approval you have made, we do not use this data for advertising, and we do not sell it or share it with anyone beyond the processors that run AI-R. You can disconnect at any time from Settings → Integrations or from your Google Account permissions page, and we delete the stored access token when you do. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
  • Usage & device data — browser type, device info, and interaction logs collected automatically to improve the product.

2. How We Use Your Data

  • Provide and operate the AI-R platform and its features.
  • Generate AI-powered insights, recommendations, and reports for your restaurant.
  • Process payments via Square or Stripe on your behalf.
  • Import, categorize, and reconcile your financial transactions to produce bookkeeping, expense, budgeting, and cash-flow reporting.
  • Send transactional communications (receipts, alerts, account notices).
  • Improve the platform through aggregated, anonymized analytics.

3. Data Sharing

We do not sell your data. We share information only with:

  • Payment processors (Square, Stripe) to complete transactions.
  • Financial connectivity & accounting providers (Stripe Financial Connections and Orion for the AIR bank feed; Plaid where enabled; Intuit QuickBooks for accounting sync) to deliver the bookkeeping features you enable.
  • Infrastructure providers (hosting, database, authentication) under strict data-processing agreements.
  • Law enforcement if required by valid legal process.

4. Data Retention

We retain your data for as long as your account is active. If you close your account, we delete your restaurant data within 90 days, except where retention is required by law (e.g., tax records).

5. Security

All data is encrypted in transit (TLS) and at rest. Access to production systems is restricted to authorized personnel with multi-factor authentication.

6. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us. California residents have additional rights under the CCPA.

7. Financial Account Connections

AIR uses Stripe Financial Connections through Orion for its bank-transaction feed. When you choose to link an account, Stripe provides the connection and consent flow. Orion processes the authorized account details, balances, transactions, connection identifiers, and permissions, and supplies the data to AIR for your restaurant workspace. AIR and Orion do not receive your bank login password from this flow.

We use this connection on a read-only basis for bookkeeping, cash-flow reporting, categorization, and matching transactions to expenses and invoices. The bank feed does not initiate payments or move money. Separate payment features require their own authorization.

You can disconnect the Stripe bank feed in Settings → Integrations → Bank Transactions. This stops further access through that connection; it does not automatically delete previously imported bookkeeping records or connection audit records. To request deletion, contact us using the address below; applicable retention obligations may still apply.

See the Stripe Privacy Policy and Orion Privacy Policy for their data handling. If you separately enable Plaid or Intuit QuickBooks, those providers process the data needed for that integration. Plaid connections are covered by the Plaid End User Privacy Policy.

8. Contact

Questions about this policy? Reach us at privacy@ai-restaurant.net.