1. Introduction
This Privacy Policy explains how [LEGAL ENTITY] (“Palate,” “we,” “us”) collects, uses, and shares personal information in connection with the Palate restaurant management platform (the “Service”). This Policy applies to our operations in the United States.
Palate plays two different roles:
- As a business/controller: for information about restaurant accounts and their administrators, billing, and our direct relationship with our restaurant customers.
- As a service provider/processor: for information about diners and restaurant employees that we process on behalf of a restaurant. In those cases, the restaurant directs the processing and its own privacy notice governs. This Policy describes our practices for transparency, but data subjects should also consult the relevant restaurant’s privacy notice.
[Counsel: confirm this dual-role framing and whether a single national notice with a California section is clearer than a unified multistate notice.]
2. Information We Collect
2.1 Information you provide
| Category | Examples | Whose data | Our role |
|---|---|---|---|
| Restaurant account | Business name, owner name, email, phone, password | Restaurant administrators | Business/Controller |
| Billing | Payout account details (via Stripe), billing contact | Restaurant | Business/Controller |
| Employee data | Names, contact info, schedules, time cards, tip allocations, payroll inputs | Restaurant employees | Service provider/Processor |
| Diner data | Names, emails, phone numbers, order history, reservation details, dietary preferences | Diners | Service provider/Processor |
| Support communications | Messages to support, recovery requests | Various | Business/Controller |
2.2 Information collected automatically
- Device and usage data (browser type, operating system, app version)
- IP addresses and approximate location (for security and fraud prevention)
- Cookies and similar technologies (see the Cookie Policy)
- Authentication and security events (login times, device fingerprints, security log entries)
2.3 Payment information
Payment card data is collected and processed by Stripe, not stored by Palate. Palate retains transaction metadata (amounts, timestamps, references) but not full card numbers.
3. How We Use Information
As a business/controller, we use information to:
- Provide, operate, and secure the Service
- Authenticate users and protect accounts (including multi-factor authentication and fraud prevention)
- Process payments and payouts via Stripe
- Communicate about the Service, including security notifications and transactional emails
- Provide customer support
- Comply with legal obligations
- Improve the Service, including with de-identified, aggregated data [LD-14]
- Send marketing communications where permitted, subject to opt-out for email and prior express written consent for SMS [LD-8]
As a service provider/processor, we process diner and employee data only on the relevant restaurant’s documented instructions and as described in our Data Processing Addendum. We do not use that data for our own purposes except as permitted for a service provider under applicable law (e.g., to provide and improve the Service, detect security incidents, and comply with law).
4. How We Share Information
We share information with:
- Sub-processors / service providers who help us operate the Service (see Section 8). They are bound by contracts restricting use of the data to providing services to us.
- Stripe, for payment processing.
- The relevant restaurant, for data we process on its behalf.
- Legal and safety: when required by law, to protect rights and safety, or in connection with legal proceedings.
- Business transfers: in a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal information for money. [LD-8: confirm “sale”/”share” status under CCPA/CPRA and other state laws, including whether any analytics or advertising could constitute a “sale” or “share” requiring an opt-out.]
5. Data Retention
We retain personal information for as long as needed to provide the Service and for legitimate business and legal purposes. Specific retention periods:
| Data category | Retention | Source |
|---|---|---|
| Security audit logs | 13 months, then archived/purged | Auth-hardening spec |
| Account data | Duration of relationship + [period] after termination | [LD-7] |
| Diner data (as processor) | Per restaurant’s instructions and the DPA | DPA |
| Employee data (as processor) | Per restaurant’s instructions and applicable employment/payroll law | DPA |
| Backups | [period] | Backups & DR spec (pending) |
[LD-7: Counsel and founder to finalize all retention periods.]
6. Your Privacy Rights
Depending on your state of residence, you may have rights to know/access, correct, delete, and obtain a portable copy of your personal information, and to opt out of the sale or sharing of your personal information and of targeted advertising.
- For data where Palate is the business/controller: contact us at [PRIVACY EMAIL].
- For data where Palate is a service provider/processor (diner/employee data): contact the relevant restaurant, which directs the processing. We will assist the restaurant in fulfilling your request.
We will not discriminate against you for exercising your rights.
6.1 California (CCPA/CPRA)
[Counsel to insert: the specific consumer rights, categories of personal information collected/disclosed in the prior 12 months, the “Do Not Sell or Share My Personal Information” mechanism, sensitive personal information handling and limitation rights, the authorized agent process, and the non-discrimination statement.]
6.2 Other US states
[Counsel to insert rights and request mechanisms for Virginia, Colorado, Connecticut, Utah, Texas, and other states whose laws apply based on thresholds, including any appeal process required (e.g., Colorado, Virginia).]
6.3 How to exercise your rights
[Counsel to specify the request channels (web form, email, toll-free number if required by California for certain businesses), identity verification process, and response timelines (generally 45 days, extendable).]
7. Security
We implement technical and organizational measures to protect personal information, including encryption in transit, encryption of sensitive secrets at rest, access controls, multi-factor authentication for privileged accounts, audit logging, and continuous monitoring. No system is perfectly secure; we maintain an incident response process and will notify affected parties and regulators as required by applicable US state breach notification laws in the event of a breach.
(See the security and breach response documentation for our internal controls.)
8. Sub-Processors
We use the following categories of sub-processors. A current list is maintained at [SUB-PROCESSOR PAGE URL].
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | US |
| Cloudflare | Hosting, CDN, storage, security | Global |
| SendGrid / Twilio | Email and SMS | US |
| Sentry | Monitoring and logging | US |
| PagerDuty | Incident alerting | US |
| hCaptcha | Bot prevention | US |
| Instatus | Status page | EU |
| Vanta | Compliance automation | US |
[LD-11: Specify how we notify customers of sub-processor changes.]
9. Children’s Privacy
The Service is not directed to children. We do not knowingly collect personal information from children under 13 (COPPA). If we learn we have collected such information, we will delete it. [Counsel to confirm handling and any state-specific minors’ provisions, e.g., California.]
10. Cookies
We use cookies and similar technologies as described in our Cookie Policy.
11. Changes to This Policy
We may update this Policy. We will post the updated version with a new effective date and, where required, provide additional notice.
12. Contact
Questions about this Policy or our data practices:
- Email: privacy@palate.pro