Privacy policy
RestoMS is a multi-tenant, local-first restaurant point-of-sale platform. This summary explains, in plain terms, what data the platform handles. The business that licenses RestoMS (the operator) controls the data it records about its staff and customers; RestoMS hosts and processes that data on the operator’s behalf. For privacy questions, contact info@creatopia.tech.
WHAT WE COLLECT
Staff accounts hold an email, name, role, login times, and per-session IP and browser details; passwords and any staff PINs are stored only as Argon2id hashes, and optional two-factor secrets are encrypted. Loyalty customers may have a name, phone, email, birthday, notes, points, and spend. Tenant applicants and testimonial authors provide a name and contact details. Where a statutory PWD or Senior-Citizen discount is applied, the beneficiary name and government ID number are recorded with the sale. Business tax and VAT registration numbers are also stored.
QR GUEST ORDERING
Guests who order by scanning a table QR code are not asked for any identity. We store only a hashed session token, the table, and the items selected — no name, phone, or email.
PAYMENTS
We never collect or store card numbers, CVV, or other cardholder data. For each payment we keep only the method (such as cash, card, or e-wallet) and an optional free-text reference, for example an e-wallet transaction reference.
HOW WE USE DATA
Data is used to run the point-of-sale, authenticate users, operate loyalty programs, produce reports for the operator, provide support, and keep the platform secure through audit logging and abuse protection.
THIRD PARTIES
When the AI module is enabled, a minimal, per-tenant slice of business data (aggregated sales metrics, product, ingredient and category names, expense details, and staff-typed chat messages) is sent to an external AI provider — Google Gemini by default, with OpenAI or Anthropic optional. Customer name, phone, and email are excluded from these requests, and data is never combined across tenants. Transactional emails (invitations and password resets) are sent via Resend. Optional error monitoring (Sentry) receives only unhandled server errors and a request identifier. Google Analytics runs only on our public marketing and legal pages, never inside the POS app. Uploaded images stay on the self-hosted server’s local disk.
SECURITY AND ISOLATION
Each tenant’s data is isolated using Postgres row-level security. We use separate authentication realms for staff, guests, and platform operators, rate limiting, account lockout, strict security headers, an append-only audit log, and redaction of sensitive fields in logs.
RETENTION
To be transparent: most records are soft-deleted rather than erased immediately, and the audit log and financial ledgers are append-only. There are currently no automated purge jobs and no self-service account or tenant deletion — operators who need data removed should contact us.
YOUR RIGHTS
You may request access to, correction of, or deletion of your personal data by emailing info@creatopia.tech. Where we process data on an operator’s behalf, we will route your request to that operator.
The operator publishes its own full privacy policy. This is the current summary; for any privacy question, contact info@creatopia.tech.