Privacy Policy

Last updated: August 6, 2026

1. What we collect

Restaurant owners: your name, email address, password (stored only as a secure hash), restaurant name, slug, opening hours, printing details, onboarding survey answers and billing status.

Your menu content: menu photos and PDFs you upload, plus the items, prices, descriptions, tags, allergens and images extracted from them.

Guests: guests order without an account. When placing an order they provide a name, phone number and optional instructions, which are stored with the order so the restaurant can serve them.

Usage and technical data: standard logs and error reports needed to run and improve the service.

2. How we use it

To provide the service: show your menu to guests, deliver orders to your dashboard and kitchen, print receipts, and manage your subscription.

To improve the product: onboarding answers and aggregate usage help us decide what to build next. We never sell your data or your guests' data, and we never use it for advertising.

To communicate with you: essential account and billing emails only. No marketing lists.

3. Third-party processors

We use a small set of providers, each limited to what it needs:

Supabase — database, authentication and realtime. Lemon Squeezy — payments; card details go directly to them and never touch our servers. Google Gemini — reads your uploaded menu files for AI extraction. Cloudflare R2 — stores item images. Upstash — rate limiting. Sentry — error monitoring, with personal data collection disabled.

4. Cookies

We use only the cookies required for sign-in sessions and security. There are no advertising or tracking cookies on PlateDash.

5. Retention and deletion

Your data stays while your account is active. If your subscription lapses, we keep your data so you can come back. To permanently delete your restaurant and all its data, email us — we will remove it within a reasonable period.

6. Security

Access is enforced at the database level (row-level security): each restaurant can only see its own data, guests can only place orders and read published menus, and billing details are server-only. All traffic is encrypted in transit. If you connect online payments, your Stripe restricted key is stored encrypted with AES-256-GCM, is never displayed after saving, and is never shared with anyone.

7. Your rights

You can request a copy, correction or deletion of your personal data at any time by emailing us. Guests who want their order data removed should contact the restaurant they ordered from — the restaurant controls guest order data.

8. Children

PlateDash is a business product for restaurant owners and is not directed at children. We do not knowingly collect data from children.

9. Changes and contact

We will update the date above when this policy changes and email account owners about material changes. Questions: support@platedash.com