Privacy Policy

Effective July 2, 2026

Who we are

Restaurant Agent (“we”, “us”) is a platform that connects the systems a restaurant already runs — accounting, payments, payroll, reservations — to AI agents that staff and guests interact with in plain language. This policy explains what information we collect, how we use it, who we share it with, and the choices you have.

It covers both surfaces of the product: the authenticated staff console used by restaurant owners, managers, hosts, and servers, and the public guest experience used to browse a menu, order, and pay.

Information we collect

Staff account information

When a staff member creates an account we collect their name, email address, and a password. Passwords are stored only as salted hashes — we never store or see the plaintext. Each account is assigned a role (owner, manager, host, or server) and belongs to exactly one restaurant.

Connected-system data

When a restaurant connects a system such as QuickBooks or Stripe, we receive OAuth access credentials for that system and, on your behalf, read the business data your agents ask about — for example profit-and-loss summaries, invoices, payouts, and account balances. We store the credentials encrypted (see “Security” below) and fetch business data on demand rather than warehousing it.

Conversations with agents

We process the messages staff and guests exchange with agents, along with the tool calls and results those conversations produce, in order to generate responses and carry out requested actions.

Guest orders and payments

When a guest places an order or pays through the guest experience, we process the order contents, amounts, and tips. Card payments are processed by Stripe; we never receive or store full card numbers.

Audit and operational records

Every staff action that moves money or changes a schedule is proposed first, confirmed by a staff member, and then recorded in an audit log — who confirmed it, what it did, and when. Guest checkouts and reservations likewise run only after the guest explicitly confirms, and each confirmed transaction is recorded with its details, though not tied to a named individual. We also keep routine operational logs needed to run and secure the service.

How we use information

  • To provide the service: answer questions, prepare proposals, and execute actions you explicitly confirm.
  • To secure the platform: authenticate staff, enforce role-based access, isolate each restaurant's data, and investigate abuse.
  • To keep accurate records: maintain the audit log of confirmed actions that restaurants rely on for accountability.
  • To operate and improve the platform: monitor reliability and diagnose failures using operational logs.

We do not sell personal information, and we do not use your data for advertising.

AI processing

Staff agents are powered by Anthropic’s Claude models. When a staff member converses with an agent, the conversation and any tool results needed to answer are sent to Anthropic’s API for processing under Anthropic’s commercial terms, which do not permit training on customer content. The public guest experience does not send guest messages to an AI provider.

When we share information

We share information only with:

  • Connected systems you authorize (for example Intuit QuickBooks and Stripe), strictly to perform the reads and confirmed actions you request. Each provider handles that data under its own privacy policy.
  • Anthropic, as described under “AI processing” above.
  • Infrastructure providers that host the application and its database, bound by confidentiality and data-protection obligations.
  • Authorities, when required by law or to protect the safety and integrity of the service.

Security

  • Connected-system credentials are encrypted at rest with AES-256-GCM and cryptographically bound to the owning restaurant, so one restaurant's credentials can never be decrypted as another's.
  • The public guest experience and the authenticated staff console are structurally separated — they share no gateway or tool access, so guest interactions can never reach staff systems like payroll or refunds.
  • No agent moves money or changes a schedule on its own: every such action requires explicit human confirmation. Staff confirmations are written to an audit log recording who confirmed what and when; guest confirmations are recorded per transaction.
  • Passwords are stored as salted hashes; sessions are managed with signed tokens; OAuth flows are protected against cross-site forgery.

Data retention and deletion

We keep staff account data and connected-system credentials for as long as the restaurant’s account is active. Audit records are retained to preserve the integrity of the action history. When a restaurant disconnects a system, we stop using its credentials; when an account is closed, we delete or de-identify associated personal information except where we must retain it to meet legal or accounting obligations.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us at the address below. If you are a guest of a restaurant using this platform, we may direct your request to that restaurant where it, rather than we, controls the data.

Children

The service is intended for restaurant operations and general dining audiences. It is not directed at children under 13, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this policy as the platform evolves — for example when new connectors launch. We will post the updated policy on this page and revise the effective date above. Material changes will be communicated to restaurant owners directly.

Contact

Questions or requests about this policy can be sent to [email protected].