The short version: AppyServe collects data needed to provide the Service to restaurants and their staff. We do not sell your data or your guests' data to third parties. You can request export or deletion of your data at any time.
This Privacy Policy describes how AppyServe ("we," "us," or "our") collects, uses, and shares information in connection with your use of the AppyServe platform ("Service"). This policy applies to restaurant operators ("Customers"), their staff ("Authorized Users"), and the guests of those restaurants whose data Customers may input into the platform.
1. Information We Collect
1a. Information You Provide Directly
- Account information: Name, business name, email address, phone number, and password when you register
- Billing information: Payment method details processed through our payment processor (we do not store full card numbers)
- Business data: Menu items, pricing, floor layouts, staff profiles, and operational configurations you enter into the platform
- Customer/guest data: Information about your restaurant guests that you enter on their behalf, including names, contact information, loyalty program enrollment, dietary notes, and visit history
- Support communications: Messages you send to our support team
1b. Information Collected Automatically
- Usage data: Features used, pages viewed, actions taken within the platform, and session duration
- Device and browser information: IP address, browser type and version, operating system, and device identifiers
- Log data: Server logs including timestamps, error events, and access records
- Cookies and similar technologies: Session cookies for authentication and preference storage; analytics cookies to understand platform usage
2. How We Use Information
| Purpose | Legal Basis / Rationale |
|---|---|
| Providing and operating the Service | Contract performance |
| Processing payments and managing subscriptions | Contract performance |
| Sending transactional communications (receipts, account alerts) | Contract performance |
| Providing customer support | Legitimate interest |
| Improving the platform and developing new features | Legitimate interest |
| Security monitoring and fraud prevention | Legitimate interest / legal obligation |
| Sending product updates and marketing communications | Consent (opt-in); legitimate interest for existing customers |
| Complying with legal obligations | Legal obligation |
We do not use your data or your guests' data to train AI models, build advertising profiles, or sell to data brokers.
3. Guest Data
When your restaurant uses the loyalty, CRM, or online ordering features, you may collect personal information about your restaurant guests (such as names, email addresses, phone numbers, and purchase history). In this context:
- You are the data controller for your guests' data; AppyServe acts as a data processor on your behalf
- You are responsible for obtaining any required consent from guests and for complying with applicable privacy laws
- We process guest data only as directed by you and as necessary to provide the Service
- We do not use guest data for our own marketing or share it with third parties except as necessary to provide the Service
4. Sharing of Information
We share information only in the following circumstances:
- Service providers: Trusted vendors who help us operate the Service (payment processors, cloud hosting, email delivery, analytics). All vendors are bound by data processing agreements.
- Legal requirements: When required by applicable law, court order, or governmental authority
- Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice to affected users
- With your consent: In any other circumstance where you have explicitly authorized sharing
We do not sell personal information to third parties.
5. Data Retention
We retain Customer account data for as long as the account is active plus a 90-day grace period following cancellation to allow for data export. Operational data (orders, payments, reports) is retained for 3 years to support your tax and audit needs unless you request earlier deletion. Server logs are retained for 90 days. After applicable retention periods, data is securely deleted or anonymized.
6. Security
We implement industry-standard security measures including encryption of data in transit (TLS 1.2+), encryption of sensitive data at rest, staff access controls, regular security reviews, and audit logging of sensitive operations. No system is perfectly secure; we will notify you without undue delay if a breach affecting your data occurs.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention obligations)
- Portability: Request your data in a machine-readable format
- Restriction: Request that we restrict processing of your data in certain circumstances
- Opt-out of marketing: Unsubscribe from marketing communications at any time via the unsubscribe link in any email or by contacting us
To exercise any of these rights, contact us at support@appyserve.com. We will respond within 30 days.
8. Cookies
AppyServe uses cookies and similar technologies for the following purposes:
- Essential cookies: Required for authentication and maintaining your session. Cannot be disabled without breaking core functionality.
- Preference cookies: Store your settings such as location selection and display preferences.
- Analytics cookies: Help us understand how the platform is used so we can improve it. These do not identify individual users by default.
You can control cookies through your browser settings. Disabling essential cookies will prevent login.
9. Children's Privacy
The Service is intended for use by restaurant businesses and their staff. We do not knowingly collect personal information from individuals under 16 years of age. If you believe a minor has provided us with personal information, please contact us and we will promptly delete it.
10. International Data Transfers
AppyServe is operated from the United States. If you access the Service from outside the US, your data may be transferred to and processed in the United States. We apply appropriate safeguards for such transfers in accordance with applicable law.
11. California Privacy Rights (CCPA)
California residents have the right to know what personal information we collect, to request deletion, to opt out of sale (we do not sell data), and to non-discrimination for exercising their rights. To submit a CCPA request, contact us at support@appyserve.com with "CCPA Request" in the subject line.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the Service at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
If you have questions, concerns, or requests related to this Privacy Policy, please contact us at:
AppyServe
Email: support@appyserve.com