Your restaurant's data
is our top priority.
RestaurantOS holds the lifeline of a restaurant's day — reservations, sales, staff, and customer information. So security isn't decoration or a policy document; it's wired in from the very first line of the design.
Three promises
Before the technical detail, three promises that come first. Everything else is held against them.
暗号化
保管中も移動中も、銀行レベルの暗号化技術であなたのデータを守ります。
所有権はあなた
データの所有権はあなたのお店にあります。私たちは預かるだけ。
いつでも持ち出し可能
やめたいと思った時、いつでもあなたのデータをまるごとお返しします。
Data protection
Data is encrypted throughout — from the moment it leaves a store device until long after it's stored. Even if traffic were intercepted or a server physically removed, without the key, the data would take centuries to crack.
In transit
Traffic from store devices to our servers is always encrypted. HTTPS is required; unencrypted traffic is rejected.
At rest
Data in the cloud is kept securely, protected with bank-grade encryption.
Zero-knowledge principle
Even our own staff cannot read your passwords or the sensitive core of your personal information directly. We aim for a design where, even if data leaks, the key to decode it isn't held on our side.
Infrastructure & operations
The cloud foundations we use, and the operational mechanisms that protect data.
Access control
Who can touch which data — managed strictly, both technically and operationally.
- ロールベースのアクセス制御 (RBAC) — オーナー / 店長 / 一般スタッフ / アルバイトで権限を細かく分離
- Passkey (パスキー) 認証対応 — パスワードに頼らない、より安全なログイン方式
- 監査ログ — 重要な操作 (データ書き出し・権限変更・スタッフ追加など) はすべて記録
- セッション管理 — 一定時間操作のないセッションは自動で切断
- 弊社スタッフの本番データへのアクセスは、サポート要請時の最小限のみ、かつ操作はすべてログ化
Privacy stance
Your data is yours. We will never sell it to third parties or use it for ad targeting.
- 個人情報を第三者へ販売・譲渡しません
- 広告ターゲティングや行動追跡には一切利用しません
- お客様のデータは、匿名化した(個人を特定できる情報を除去した)うえで、AI の学習データとして利用することがあります
- 退会時、保有しているお客様のデータを 30 日以内に完全削除します
- 海外への移転が発生する場合は、必ず事前に明示します
Regulatory compliance
Regulations we currently comply with, and the ones we plan to tackle next — written honestly.
Currently compliant
- 個人情報保護法 (日本) — 個人情報の取得・利用・保管の全工程
- 電子商取引及び情報財取引等に関する準則 — オンラインサービス提供の根幹
- 特定商取引法 — 表記義務の遵守 (特定商取引法ページ参照)
Future work
- プライバシーマーク (Pマーク) の取得
- ISMS (ISO/IEC 27001) 認証取得
- GDPR 準拠 (EU 圏のお客様向け)
- SOC 2 Type II レポート (エンタープライズ向け)
* The "future work" items above are not yet obtained. Once obtained, we'll update this page and display certification badges.
Vulnerability disclosure
If you find a security issue in RestaurantOS, please report it via the in-app Bug Report feature. We take honest reports seriously and respond honestly.
Where to send it
Vulnerability reports are accepted only via the in-app Bug Report feature inside the RestaurantOS app — not through this website. Include reproduction steps and impact wherever possible.
Our commitments
- 48 時間以内に初回応答します
- 報告者のお名前を公表する場合は、必ず事前に許可を得ます
- 誠実な報告者を法的に追及することはありません
- 重要な報告には、改修後にお礼をお伝えします
Frequently asked
Q.もしハッキングされたら、私たちのお店のデータはどうなりますか?
万一のインシデント発生時は、速やかにお客様へご連絡し、法令に従って必要な報告を行います。バックアップから復旧できる体制を整えており、暗号化されたデータは攻撃者が持ち出せても解読できません。
Q.RestaurantOS のサービスが終わったら、データはどうなりますか?
サービス終了が決まった場合は、最低 90 日前にお知らせし、その期間内であればすべてのデータを CSV / JSON 形式でダウンロードできます。期限経過後、データは完全に削除されます。
Q.弊社のスタッフが、私たちのデータを勝手に見ることはありますか?
ありません。本番データへのアクセスは、サポート要請をいただいた場合に限り、最小限の操作のみ行います。アクセスはすべて監査ログに記録され、必要であればお客様に履歴を開示します。
Q.他のお店のデータと混ざってしまうことはありませんか?
各店舗のデータは、データベース上で論理的に完全に分離されています (テナント ID による分離)。一つの店舗のデータが、別の店舗から見えることは技術的に発生しません。
Q.私たちが入力した顧客の連絡先を、AI の学習に使われませんか?
AI 機能は、あなたの店舗内のデータを参照して動作します。加えて、お客様のデータを匿名化した(個人を特定できる情報を除去した)うえで、当社の AI モデルの学習データとして利用することがあります。