Skip to main content
SECURITY · By design

Your restaurant's data
is our top priority.

RestaurantOS holds the lifeline of a restaurant's day — reservations, sales, staff, and customer information. So security isn't decoration or a policy document; it's wired in from the very first line of the design.

PROMISES

Three promises

Before the technical detail, three promises that come first. Everything else is held against them.

Encryption

Bank-grade encryption protects your data both at rest and in transit.

You own the data

Your restaurant owns the data. We just hold it for you.

Take it with you, anytime

Decide to leave? We return all your data, in full, anytime.

SECTION 01

Data protection

Data is encrypted throughout — from the moment it leaves a store device until long after it's stored. Even if traffic were intercepted or a server physically removed, without the key, the data would take centuries to crack.

In transit

Traffic from store devices to our servers is always encrypted. HTTPS is required; unencrypted traffic is rejected.

At rest

Data in the cloud is kept securely, protected with bank-grade encryption.

Zero-knowledge principle

We don't use passwords at all — sign-in is via Google account or passkey only, so there's no password for us to ever store. Beyond that, the sensitive core of your personal information, such as payment details, can't be read directly even by our own staff. We aim for a design where, even if data leaks, the key to decode it isn't held on our side.

SECTION 02

Infrastructure & operations

The cloud foundations we use, and the operational mechanisms that protect data.

Hosting
Run on a reliable, established cloud foundation
Data storage
Stored securely, in encrypted form
Backups
Backed up automatically on a regular basis
Reliability
Operated for high, stable availability
SECTION 03

Access control

Who can touch which data — managed strictly, both technically and operationally.

  • Role-based access control (RBAC) — granular permissions for owner / manager / staff / part-time.
  • Passkey authentication — safer sign-in without relying on passwords.
  • Audit logs — every sensitive action (exports, permission changes, staff additions) is recorded.
  • Session management — idle sessions disconnect automatically after a period.
  • Our staff only touch production data on a support request, only the minimum needed, and every action is logged.
SECTION 04

Privacy stance

Your data is yours. We will never sell it to third parties or use it for ad targeting.

  • We do not sell or transfer personal information to third parties.
  • We do not use your data for ad targeting or behavioural tracking.
  • We may use your data, after anonymization (with personally identifying information removed), to train our AI models.
  • On account closure, we completely delete your data within 30 days.
  • If any data transfer abroad becomes necessary, we always disclose it in advance.
SECTION 05

Regulatory compliance

Regulations we currently comply with, and the ones we plan to tackle next — written honestly.

Currently compliant

  • Act on the Protection of Personal Information (Japan) — across collection, use, and storage.
  • Guidelines on Electronic Commerce — foundation for online service provision.
  • Act on Specified Commercial Transactions — disclosure compliance (see the Commercial Disclosure page).

Future work

  • Obtain Privacy Mark (P-Mark) certification.
  • Obtain ISMS (ISO/IEC 27001) certification.
  • GDPR compliance (for EU customers).
  • SOC 2 Type II report (for large chains).

* The "future work" items above are not yet obtained. Once obtained, we'll update this page and display certification badges.

SECTION 06

Vulnerability disclosure

If you find a security issue in RestaurantOS, please let us know. We take honest reports seriously and respond honestly.

Where to send it

Where to send it depends on what you found. For the RestaurantOS app itself, use the in-app Bug Report feature. For this website (restaurant.plugin-os.ai), use the contact form and choose "Security report" as the type. Include reproduction steps and impact wherever possible.

Our commitments

  • We send a first reply within 48 hours.
  • If we credit the reporter publicly, we always ask for permission first.
  • We will not pursue legal action against good-faith reporters.
  • We follow up with a thank you once important reports are fixed.
SECTION 07

Frequently asked

Q.What happens to our restaurant's data if you get hacked?

If an incident occurs, we contact you promptly and make any reports required by law. We maintain the ability to restore from backups, and encrypted data is unreadable even if exfiltrated.

Q.What happens to my data if RestaurantOS shuts down?

If service termination is decided, we'll notify you at least 90 days in advance. During that window, you can export all your data as CSV / JSON. After the deadline, data is fully deleted.

Q.Can your staff look at our data without permission?

No. Production data is only touched on a support request, with the minimum action needed. All access is logged in audit logs, and we can share that history with you on request.

Q.Could our data get mixed up with another restaurant's?

Each restaurant's data is fully logically isolated in the database (by tenant ID). One restaurant seeing another's data is not technically possible.

Q.Will the customer contacts I enter be used to train your AI?

AI features work by referencing data within your store. In addition, we may use your data — after anonymization, with personally identifying information removed — as training data for our AI models.