Privacy Policy

Our privacy policy and how we use your data

This Privacy Policy explains how RestaurantMate ('we', 'us') collects, uses, stores, and shares information when you visit rmate.ai, request access to our beta, or use the RestaurantMate service, including purchasing agents, email ingestion, point-of-sale integrations, inventory and recipe tools, reports, and AI features. Last updated: July 30, 2026.

1. Information We Collect

We collect information you provide directly, information generated by your restaurant’s operations when you use the Service, and limited technical information from your devices.

  • Account and contact data: your name, email address, restaurant name, location, and anything you submit through our contact form.
  • Team data: names, email addresses, and roles of teammates you invite, and the permissions you assign them.
  • Vendor connection data: the vendors you connect and credentials for their ordering portals, stored encrypted and used only to operate those portals on your instructions.
  • Purchasing data: order guides, carts, approvals, orders, deliveries, invoices and their line items, credits, and the per-item price history built from them.
  • Email data: messages and attachments you route to the Service, either from a connected Gmail or Outlook account or via your dedicated per-location RestaurantMate address.
  • Operations data: inventory counts and valuations, recipes and their ingredients, and sales and labor data ingested from your point-of-sale system.
  • Technical data: log data, device and browser type, IP address, and the identifiers described in our Cookie Policy.

2. How We Use Information

  • To provide the Service: reading vendor prices, assembling and placing approved orders, tracking deliveries, extracting invoice lines, valuing inventory, costing recipes, and producing reports.
  • To operate AI features: answering questions grounded in your workspace data and preparing actions that execute only after your confirmation.
  • To communicate with you about onboarding, support, service changes, and your beta participation.
  • To secure the Service: detecting abuse, enforcing role-based access, and auditing agent activity.
  • To improve the Service, using aggregated or de-identified information that does not identify you or your restaurant.

We do not sell your personal information, we do not use your workspace data to train foundation models, and we do not permit our AI subprocessors to do so.

3. Vendor Credentials

Vendor portal credentials are stored encrypted and are used exclusively by your own purchasing agents to access the vendors you connected, on the instructions you give. Agent sessions are designed to run from hardware at your location rather than a shared cloud environment. You can disconnect a vendor at any time, which stops future use of those credentials.

4. Email Content

When you connect an email account or use a dedicated RestaurantMate inbox address, we process routed messages and attachments to extract orders, invoices, credits, and vendor communications into your workspace. We access connected mailboxes only to the extent needed for these features, we do not use email content for advertising, and disconnecting an account stops future ingestion. Use of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

5. How We Share Information

  • Vendors: when agents place your approved orders, the vendor receives the order and your account details with that vendor, exactly as if you had placed the order yourself.
  • Service providers (subprocessors): infrastructure hosting, database and authentication services, email delivery, error monitoring, and AI model providers used to power assistant and extraction features, each bound to use data only to provide their service to us.
  • Connectors you enable: if you connect your workspace to an external AI tool such as Claude, data you query flows to that tool under its own terms, scoped to your workspace and your role.
  • Legal: when required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets, with notice where legally permitted.

6. Data Retention

We retain workspace data for as long as your workspace is active because longitudinal data, such as price history, is central to the Service. If you close your workspace, we make your data available for export for at least 30 days and then delete or de-identify it, except where retention is required by law or for legitimate business records such as invoices we are required to keep.

7. Security

  • Encryption in transit and at rest for workspace data, with additional encryption for vendor credentials.
  • Row-level tenant isolation so each workspace’s data is only accessible to that workspace.
  • Role-based access controls that you administer for your team.
  • Vendor sessions designed to run on hardware at your own location.
  • No security is perfect; notify us immediately at the contact form if you suspect unauthorized access.

8. Your Rights and Choices

  • Access and export: you can export your workspace data at any time from within the Service.
  • Correction and deletion: you can correct data in the Service, and you can request deletion of your account and workspace.
  • Email choices: you can disconnect connected email accounts and unsubscribe from non-essential emails.
  • Depending on where you live, you may have additional statutory rights (for example under the CCPA for California residents), including the right to know, delete, and non-discrimination; contact us to exercise them.

9. Children

The Service is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children; if you believe a child has provided us information, contact us and we will delete it.

10. International Transfers

We operate from the United States, and information is processed on servers in the United States. If you use the Service from elsewhere, you understand your information will be transferred to and processed in the United States.

11. Changes and Contact

We may update this Privacy Policy from time to time. Material changes will be announced through the Service or by email, and the date above will change. Continued use after the effective date constitutes acceptance. Questions or requests: use the contact form at rmate.ai and we will respond within a reasonable time.