Privacy Policy
Draft for legal review · Last updated July 18, 2026
Plain-language summary
You own your data. We only import it with your consent, the import is read-only, and you can revoke access anytime. We never sell your data or share it with your vendors. We collect what we need to run Varastiq for you — your account details, the restaurant data you give us or authorize us to import, and basic usage information — and we use it for nothing else. The summary is for convenience; the full policy governs.
1. Who we are
This Privacy Policy explains how [LEGAL ENTITY NAME — e.g. Varastiq, Inc.] ("Varastiq", "we", "us") handles personal information in connection with varastiq.com and the Varastiq services — the Tiq app, the owner portal, and related APIs (the "Service"). For data our restaurant customers put into the Service about their own business, we act as a processor/service provider on the customer's instructions; the customer is the controller of that data.
2. Information we collect
Account information. Name, email address, phone number, restaurant name, and role, provided when you request a demo, sign up, or are invited to a workspace.
Restaurant business data. Data you enter or authorize us to import: inventory counts, invoices, recipes, menu items, vendor names and prices, and sales data from your point-of-sale system. POS integrations are read-only and connected only with your explicit authorization, which you can revoke at any time.
Demo requests. If you submit the "Book a demo" form we collect the details you provide (name, email, restaurant, phone, locations, POS, and preferred demo time). We use them only to prepare and schedule your demo.
Usage and device information. Basic technical logs generated by using the Service — IP address, browser/device type, pages viewed, and actions taken — used for security, debugging, and improving the Service.
What we don't collect. We do not collect payment-card data from diners, and the marketing site does not use third-party advertising trackers.
3. How we use information
We use information to: provide and operate the Service; produce your inventory, costing, and reporting figures; respond to demo requests and support; secure the Service and prevent abuse; communicate service updates; and improve the Service. We may use data that is aggregated and de-identified — so that neither you, your restaurant, nor any individual can be identified — for benchmarking and product improvement.
4. How we share information
We do not sell personal information, and we do not share your business data with your vendors. We share information only with:
— Subprocessors that host and run the Service on our behalf, under contracts limiting their use of the data: currently [CONFIRM LIST] Supabase (database and authentication), Vercel (hosting), and Google Workspace (email).
— Your workspace. Users in your restaurant's workspace see the business data appropriate to their role.
— Legal. When required by law, subpoena, or to protect the rights, safety, or property of Varastiq, our customers, or others.
— Business transfers. In a merger, acquisition, or sale of assets, data may transfer with the business, subject to this policy.
5. Your data, your control
Access to imported data is consent-gated: you grant it, and you can revoke it at any time from the Service or by contacting us. Revocation stops future imports. You may export your business data at any time, and on request — or 30 days after your subscription ends — we will delete it from production systems, subject to residual copies in backups that expire on our normal backup schedule (no longer than [BACKUP RETENTION PERIOD — e.g. 35 days]) and records we must keep for legal or accounting purposes.
6. Retention
We keep account information for as long as your account is active. Demo-request details are kept for up to 12 months after the last contact unless you become a customer or ask us to delete them sooner. Usage logs are retained for up to [LOG RETENTION PERIOD — e.g. 12 months].
7. Security
We use industry-standard safeguards: encryption in transit, access controls with role-based permissions, credentialed connections to third-party systems, and hosting with providers that maintain their own audited security programs. No system is perfectly secure; if a breach affects your data, we will notify you as required by law.
8. Cookies
The Service uses cookies and similar technologies only for sign-in sessions and security. The marketing site does not use advertising cookies. [CONFIRM if analytics are added later — this section must be updated.]
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. You can exercise these rights by contacting us at the address below; we will respond as required by applicable law (including, where applicable, the CCPA and GDPR). If we process your data on behalf of a restaurant customer, we may direct your request to that customer. We do not discriminate against you for exercising your rights.
10. Children
The Service is for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
11. International transfers
We are based in [COUNTRY — e.g. the United States] and process data there and in the regions where our subprocessors operate. Where required, we rely on appropriate safeguards for cross-border transfers.
12. Changes to this policy
We may update this policy. Material changes will be announced by email or in-product notice before they take effect, and the "Last updated" date above will change.
13. Contact
Privacy questions or requests: [privacy@varastiq.com — confirm mailbox][POSTAL ADDRESS].