Qryptraveller LLC (operating the service as RestaurantOS; "we") sets forth this Privacy Policy (the "Policy") regarding the handling of users' personal information as follows.
Article 1 (Definition of personal information)
"Personal information" means "personal information" as defined in Japan's Act on the Protection of Personal Information — information about a living individual that can identify that specific individual through descriptions such as name, address, phone number, or contact details (personal identification information).
Article 2 (How we collect personal information)
We may ask for personal information such as name, address, phone number, email address, and credit card number when a user registers to use the service. We may also receive transaction records and payment-related information, including users' personal information exchanged between users and our partners (including information providers, advertisers, and ad placements) from those partners.
Article 3 (Purposes of collecting and using personal information)
We collect and use personal information for the following purposes:
- To provide and operate our service.
- To respond to user inquiries (including identity verification).
- To send emails about new features, updates, campaigns, and other services we offer.
- For maintenance, important notices, and other necessary communications.
- To identify users who violate the Terms of Service or attempt to use the service for fraudulent or improper purposes, and to refuse them service.
- To allow users to view, change, delete, or check the status of their own registered information.
- To bill users for paid services.
- Any purpose incidental to the above.
Article 4 (Changes to the purpose of use)
We may change the purpose of use of personal information only when the change is reasonably deemed related to the prior purpose. Where the purpose is changed, we will notify users by the methods we prescribe, or publish the change on this website.
Article 5 (Provision of personal information to third parties)
Except in the cases listed below, we do not provide personal information to third parties without obtaining the user's prior consent — other than cases permitted by the Act on the Protection of Personal Information and other laws.
Article 5-2 (Exceptions to third-party provision)
The following do not constitute provision to a third party:
- When we outsource all or part of the handling of personal information within the scope necessary to achieve the purpose of use (e.g. payment processors, cloud providers).
- When personal information is provided in connection with a business succession due to a merger or other reason.
- When disclosure or provision is required under laws and regulations.
Article 5-3 (Payment information and cross-border transfer)
Payment information is handled by our payment processor FastSpring, Inc., and we do not retain card numbers or similar details. In providing the Service, personal information is transferred to us (a U.S. corporation) and to FastSpring, Inc. (United States). Users agree to this cross-border transfer to the United States when using the Service.
Article 6 (Outsourcing the handling of personal information)
We may outsource all or part of the handling of personal information within the scope necessary to achieve the purpose of use. In such cases, we will exercise necessary and appropriate supervision over the contractor.
Article 7 (Disclosure of personal information)
When a user requests disclosure of personal information under the Act on the Protection of Personal Information, we will disclose it without delay after confirming the request is from the user (and notify them if no such information exists). However, we may decline to disclose all or part of it where disclosure could harm the rights or interests of the individual or a third party, among other cases.
Article 8 (Correction and deletion of personal information)
If the personal information we hold about a user is incorrect, the user may request correction, addition, or deletion by the method we prescribe. We will conduct the necessary investigation and respond without delay based on the results.
Article 9 (Suspension of use, etc.)
If we are asked to suspend use or erase personal information on the grounds that it is handled beyond the scope of the purpose of use or was obtained improperly, we will conduct the necessary investigation without delay and respond based on the results.
Article 10 (Handling of cookies, etc.)
Our website may use cookies and similar technologies to improve service quality and analyze usage. You can disable cookies in your browser settings, but some features may become unavailable.
Article 10-2 (AI chat on this website)
The AI chat on our website records the questions entered, the AI's responses, the language used, the timestamp, and a hashed value of the IP address used for rate limiting. The IP address itself is not stored; it is converted into a non-reversible salted hash. This information is used solely to improve the quality of the AI's answers, understand common questions, and prevent abuse or excessive use. Text you enter is sent to Google LLC's generative AI service (Gemini API) in order to generate a response, and that company's handling of the data is governed by its own terms. Please do not enter personal or confidential information such as names, phone numbers or credit card numbers into the AI chat.
Article 10-3 (Data handled while operating the Service)
While a merchant (restaurant) uses RestaurantOS for day-to-day store operations (reservations, orders, payments, timekeeping, etc.), we handle the following data, separate from the data described above in connection with your subscription contract and billing with us.
- Staff location data: When staff clock in or out, we obtain the GPS location of the device used, solely to confirm the staff member is physically at the store. It is not used for any other purpose.
- Guest information: Through the Service, a merchant may handle reservation details (name, phone number, party size, the body of reservation emails, etc.), waitlist details (name, phone number, LINE user identifier, etc.), order and payment history, delivery destination details (recipient name, phone number, address, etc.), and allergy/dietary restriction information. This information is controlled by the merchant, and we process it under our contract with the merchant.
- Merchant staff information: Through the Service, a merchant may handle staff information such as name, name reading (furigana), email address, phone number, employee code, hire date, hourly wage, clock-in/clock-out records, and the content of internal chat and internal bulletin board posts, as well as job applicant information such as name, age, and preferred conditions. This information is controlled by the merchant, and we process it under our contract with the merchant.
- Food delivery platform integrations: When a merchant accepts orders via food delivery platforms (e.g. Uber Eats, Wolt, Rakuten, Demaecan) through the Service, information necessary for those orders is shared with the relevant platform.
- In-store payment processing: Payment processing for a merchant's own transactions with its guests is handled via Stripe or Square. This is separate from your subscription payment to us via FastSpring, described in Article 5-3.
- Voice input and document scanning: The Service provides a feature to convert in-store voice input into text, and a feature to capture and read text from receipts, invoices, and similar documents. The resulting voice and document content is stored as text.
- AI assistant conversation records: We store the content of conversations you have with the Service's AI assistant feature, and records of operational policies and decisions extracted from those conversations.
- Transmission to AI providers: In connection with the Service's AI assistant feature, voice-to-text conversion, document reading, and similar features, we may transmit information to providers of external generative AI services. The providers we transmit to, the scope of information transmitted, and the information we do not transmit are set out in Article 10-7.
- Data storage location: The data described in this Article is stored on servers located in Japan (database provider: Supabase).
Article 10-4 (Security measures)
We separate data access permissions by merchant so that no merchant can access another merchant's data. Especially sensitive information (such as allergy information) is walled off from analytics features that are not intended to access it. Encryption of stored data is currently being implemented and will be strengthened going forward.
Article 10-5 (Handling of data after account deletion)
When a user deletes their account, we handle their data as follows.
- Deleted immediately: login credentials (linkage with external accounts), the public display name, the hash of the phone number, and any appearance in the rankings. For users with no payment records, the account itself is deleted.
- Retained for a limited period: payment and billing records (transaction date and time, amount, contract type, and the history of discounts applied using points). Japan's Corporation Tax Act, Consumption Tax Act, and related laws impose retention obligations on transaction records, so they cannot be deleted at the moment of account deletion.
- Excluded from the retained records: the original statements received from our payment processor, which may include a name and billing address, are deleted at the time of account deletion. What we retain is limited to the items required for accounting (date and time, amount, and type).
- Retention period and deletion: the records described in the preceding two items are deleted once the statutory retention period (seven years in principle) has elapsed. After deletion, we hold no information that can identify the user.
- Handling during the retention period: while these records are retained, they are used only to fulfil legal obligations and for tax and accounting purposes, and for no other purpose.
Article 10-6 (Information transmitted from this website to external providers)
This website transmits information from your device to the external providers listed below. You can stop these transmissions by disabling cookies in your browser (some features may then be unavailable). This Article concerns browsing this website; data handled while operating the Service is covered by Article 10-3.
- Google Analytics (Google LLC, United States): transmits the URL of the page viewed, the referrer, your device and browser type, language settings, an identifier stored in a cookie, and an anonymized IP address. The purpose is to understand which pages are viewed and how often, in order to improve the site. You can also opt out using the browser add-on provided by Google.
- Microsoft Clarity (Microsoft Corporation, United States): transmits the URL of the page viewed, your interactions such as clicks, scrolling and mouse movement together with a recording of the screen as displayed (session replay), your device and browser type, and an identifier stored in a cookie. The purpose is to find where the interface is difficult to use and improve it.
- Formspree (Formspree, Inc., United States): transmits the contents you submit through the contact form, in order to receive your enquiry. Transmission occurs only when you submit the form.
- Supabase (Supabase, Inc.): when you use the login feature, transmits the information needed to maintain your signed-in state. Nothing is transmitted if you do not sign in.
- Embedded demo: when a demo is displayed on this website, the access information needed to render it is transmitted to our demo environment (hosted on Railway).
Article 10-7 (Use of external generative AI services)
To provide features such as the AI assistant, voice-to-text conversion, document reading, and draft-text generation within the Service, we may transmit information about guests and merchant staff to providers of external generative AI services.
- Providers we transmit to: We transmit information to the following provider, located outside Japan (United States): Google LLC (Gemini API).
- Information transmitted: The following information may be included. (1) Reservation and visit information — name, phone number, email address, LINE user identifier, party size, seating preference, requests or notes, allergy or other dietary-restriction information, and the body of reservation emails. (2) Order and payment information — order details, amount, payment method, points used, coupon usage, and an ID used to identify the guest (we do not transmit the credit card number itself). (3) Delivery and takeout information — the recipient's name, phone number, address, and delivery-related requests. (4) Information derived from voice and images — voice input converted to text, and images of receipts, invoices, and similar documents together with the text read from them. (5) Merchant staff information — name, name reading (furigana), email address, phone number, employee code, hire date, hourly wage, clock-in/clock-out records, the content of internal chat and internal bulletin board posts, and job applicants' name, age, and preferred conditions.
- Purpose of transmission: (1) So that the Service's AI assistant feature can respond to a merchant's operational inquiries or carry out requested operations. (2) To convert or generate content, such as converting voice to text, transcribing documents, and drafting text.
- Information we do not transmit: We do not transmit the following to providers of external generative AI services: encryption keys and other authentication credentials, access tokens used to connect to external storage services, information about merchants other than the one you are using, and credit card numbers.
- Google LLC's handling of this information: (1) We use the Gemini API provided by Google LLC as a Paid Service. (2) Content we transmit (including prompts, system instructions, cached content, and files such as images, video, and documents) and Google's responses are never used to train Google's AI. Google's Gemini API Additional Terms of Service (https://ai.google.dev/gemini-api/terms) provide that, for Paid Services, such content is not used to improve Google's products, and is processed in accordance with Google's data processing terms. (3) At the same time, Google's Abuse Monitoring policy (https://ai.google.dev/gemini-api/docs/abuse-monitoring) provides that Google may log transmitted content and responses for up to 55 days to maintain the safety and security of the service, to detect and prevent violations of its prohibited-use policies, and where disclosure is legally or regulatorily required, and that authorized Google personnel may review such content where safety filters or abuse-detection mechanisms flag it as potentially problematic. (4) The treatment described in (2) above is what Google provides for cases where we use its service as a Paid Service. (5) Each of the foregoing may be changed by Google.
Article 11 (Changes to this Privacy Policy)
Except for matters otherwise provided by law or in this Policy, the contents of this Policy may be changed without notice to users. The revised Policy takes effect when posted on this website.
Article 12 (Contact point)
For inquiries regarding this Policy, please contact info@plugin-os.ai (hours: weekdays 10:00–18:00, excluding weekends, public holidays, and year-end).
If you have any questions, please feel free to reach out. info@plugin-os.ai You can contact us by email.