Bistro Steward ("we," "us," "our") respects your privacy. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have. It applies to our website, signup flow, and the Bistro Steward web app.
Card details are collected and stored by Square, Inc., our payment processor. We receive a tokenized identifier and limited metadata (card brand, last four digits, billing status). We do not see or store your full card number or CVV.
If you sign in using Google Sign-In, Google shares your name, email, and profile photo with us. Payment status updates come from Square webhooks.
We do not sell your personal information. We do not use your Customer Data to train public AI models.
Certain features — including receipt scanning, recipe extraction, and the "Oracle" assistant — send your inputs to Google Gemini for processing. Google processes these requests under its enterprise terms and does not use them to train general-purpose AI models. The AI provider returns a response; we do not share your credentials or cross-tenant data with AI providers.
| Recipient | Purpose |
|---|---|
| Google Cloud / Firebase | Hosting, authentication, database, serverless functions. |
| Google Gemini | AI features (scan, recipe extraction, assistant). |
| Square, Inc. | Payment processing and subscription billing. |
| PostHog, Inc. | Product analytics — aggregated, pseudonymous usage events to understand and improve the Service. IP addresses are dropped at ingestion; no Customer Data, passwords, or payment details are sent. |
| Resend (Resend, Inc.) | Outbound transactional email delivery (receipts, security notices, trial reminders, service updates). |
| Twilio SendGrid | Inbound email parsing — when you forward an invoice or receipt to your scanning address, SendGrid receives that message and relays it to us for processing. |
| Sentry (Functional Software, Inc.) | Error and performance monitoring. Diagnostic event data is sent with sensitive fields (passwords, tokens, card data, request/response bodies) scrubbed before transmission. |
| Professional advisors | Legal, accounting, and compliance counsel as needed. |
| Acquirers | In connection with a merger, acquisition, or asset sale, with appropriate notice. |
| Law enforcement | When required by valid legal process, after we verify the request. |
We require each service provider to protect your information consistent with this Privacy Policy.
Your Customer Data is stored in a tenant-scoped partition identified by your unique tenant ID. Our database security rules enforce that only users who belong to your tenant and have been approved by your owner account can read your data. Server-side functions validate this on every write.
Depending on your jurisdiction, you may have the right to:
To exercise any right, email privacy@bistrosteward.com. We will respond within 30 days.
California residents have the right to know what personal information we collect, the right to delete, the right to correct, the right to opt out of "sale" or "sharing" (we do not sell or share personal information for cross-context behavioral advertising), and the right not to be discriminated against for exercising these rights.
Our legal bases for processing are: (a) performance of a contract with you; (b) our legitimate interests in operating and securing the Service; (c) your consent where applicable; and (d) compliance with legal obligations. Data transfers outside the EEA/UK rely on Standard Contractual Clauses.
We implement reasonable administrative, technical, and physical safeguards including encryption in transit (TLS), encryption at rest, access controls, audit logging, least-privilege role-based permissions, and security rules that enforce per-tenant isolation. No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you in accordance with applicable law.
The Service is intended for restaurants and business users and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
We are based in the United States, and our service providers (including Google Cloud and Square) operate globally. Your information may be transferred to and processed in countries other than your own.
We use strictly-necessary cookies and browser storage to keep you signed in and to provide the Service. We do not use advertising cookies or third-party tracking cookies. You can disable cookies in your browser, but the Service may not function correctly.
We honor the browser "Do Not Track" signal — if DNT is enabled, we do not send any events to PostHog. You can also opt out explicitly at any time:
posthog.opt_out_capturing(). To re-enable, run posthog.opt_in_capturing().Opting out does not affect your ability to use the Service.
We may update this Policy from time to time. Material changes will be communicated by email or in-app notice at least 14 days before taking effect. The "Last updated" date at the top reflects the current version.
For any privacy question or request: