Preview privacy information

What the current application stores and how its controls work.

This is a development notice, not a finalized production privacy policy. Workflow Corporation is the operator. Support contact, hosting region and retention arrangements must be confirmed before collecting real customer or employee information.

Accounts and restaurant records

The application stores account names and email addresses, hashed passwords when used, provider account links, restaurant memberships and staff permissions. Restaurant records can include customer contact and delivery details, staff and attendance information, orders, inventory and financial entries.

Sessions and preferences

Cookies maintain sign-in, the active restaurant, language and colour preferences. Account controls can end signed-in sessions. Suspended accounts cannot sign in; restaurant owners and managers control staff access according to their permissions.

Activity and integrations

Audit records describe consequential actions and may record an IP address. The restaurant activity screen excludes personal account events and IP addresses. API request logs store method, path, status, elapsed time and key identity; request bodies, secrets and query strings are not retained in that log.

Service providers

Depending on deployment configuration, linked sign-in providers authenticate users and an email provider delivers password-reset and invitation messages. Without a mail provider, development email is written to the server console; production email delivery is refused. Database and hosting arrangements depend on the operator of this installation.

Access, export and deletion

Use Your account for profile and session controls, and report CSV exports for restaurant figures. Restaurant deletion removes the restaurant's records; it does not delete the separate login account. Contact the administrator who provided this installation for account requests, retention and backup details.