Legal

Privacy Policy

Last updated: June 2025

1. Introduction

ProfitPlate ("we", "us", "our") provides a restaurant profit intelligence platform that helps restaurant operators track food costs, margins, overhead, and branch profitability ("the Service"). This Privacy Policy explains how we collect, use, store, and protect information when you use ProfitPlate.

By using ProfitPlate, you agree to the practices described in this policy.

2. Information We Collect

2.1 Account & Business Information

When you register or are onboarded as a client, we collect:

• Business name, owner name, email address, and phone number

• Country and business type

• Branch details (names, locations, number of branches)

• Subscription plan and billing details

2.2 Operational Data

To provide the Service, we collect and store data you enter, including:

• Ingredient names, units, categories, and prices

• Recipes and kitchen section configurations

• Resource and overhead data (labour, utilities, rent, packaging, etc.)

• Menu items, pricing, and sales data

• Deal, event, and delivery configurations

• Daily sales entries and reports

2.3 Account Security Data

• Encrypted email addresses (using industry-standard encryption)

• Hashed passwords (we never store plain-text passwords)

• Authentication tokens (access and refresh tokens)

2.4 Technical Information

• Login timestamps and session activity

• Basic device and browser information for security purposes

3. How We Use Your Information

We use the information we collect to:

• Provide and operate the ProfitPlate platform

• Calculate dish-level food costs, margins, and profitability

• Generate reports (P&L snapshots, break-even analysis, channel performance)

• Maintain account security and prevent unauthorized access

• Communicate with you regarding your account, billing, and service updates

• Improve and maintain the reliability of the Service

We do not sell your business data, ingredient prices, recipes, or financial information to third parties.

4. Data Storage & Security

All data is stored in a secure PostgreSQL database with multi-tenant isolation, meaning your organization's data is logically separated from other organizations. Email addresses are stored using encryption. Passwords are stored using industry-standard hashing (bcrypt) and are never visible to ProfitPlate staff.

Access to your data is restricted by role-based permissions within your organization. We use caching and queuing infrastructure to improve performance; cached data is automatically refreshed and does not persist indefinitely.

While we take reasonable technical and organizational measures to protect your data, no system is completely secure, and we cannot guarantee absolute security.

5. Data Retention

We retain your business and operational data for as long as your account remains active. If your subscription is suspended or cancelled, your data may be retained for a reasonable period to allow for reactivation, after which it may be archived or deleted in accordance with our internal data retention practices.

6. Sharing of Information

We may share information only in the following circumstances:

• With your consent — if you explicitly authorize us to share data with a third party.

• Service providers — trusted providers who help us operate the platform (e.g., hosting, email delivery), bound by confidentiality obligations.

• Legal requirements — if required by law, regulation, or valid legal process.

• Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, subject to this policy.

7. Payments

ProfitPlate currently uses manual payment verification (e.g., Payoneer, bank transfer, EasyPaisa, JazzCash). Payment receipts and transaction references are recorded by our admin team for verification purposes. We do not store full payment card details.

8. Your Rights

Depending on your role and applicable law, you may have the right to:

• Access the personal and business data associated with your account

• Request correction of inaccurate information

• Request export of your data

• Request deletion of your account and associated data, subject to legal and contractual obligations

To exercise these rights, contact your account administrator or reach out to us using the contact details below.

9. Cookies & Tracking

ProfitPlate uses essential session-related storage (such as authentication tokens) to keep you logged in securely. We do not use third-party advertising trackers.

10. Children's Privacy

ProfitPlate is a business tool intended for use by restaurant owners, managers, and staff. It is not directed at children, and we do not knowingly collect information from individuals under the age of 18.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify users of material changes via email or through the platform. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or how your data is handled, please contact us at:

Email: support@profitplate.io