Your restaurant's data
is our top priority.
RestaurantOS holds the lifeline of a restaurant's day — reservations, sales, staff, and customer information. So security isn't decoration or a policy document; it's wired in from the very first line of the design.
Three promises
Before the technical detail, three promises that come first. Everything else is held against them.
Encryption
Bank-grade encryption protects your data both at rest and in transit.
You own the data
Your restaurant owns the data. We just hold it for you.
Take it with you, anytime
Decide to leave? We return all your data, in full, anytime.
Data protection
Data is encrypted throughout — from the moment it leaves a store device until long after it's stored. Even if traffic were intercepted or a server physically removed, without the key, the data would take centuries to crack.
In transit
Traffic from store devices to our servers is always encrypted. HTTPS is required; unencrypted traffic is rejected.
At rest
Data in the cloud is kept securely, protected with bank-grade encryption.
Zero-knowledge principle
We don't use passwords at all — sign-in is via Google account or passkey only, so there's no password for us to ever store. Beyond that, the sensitive core of your personal information, such as payment details, can't be read directly even by our own staff. We aim for a design where, even if data leaks, the key to decode it isn't held on our side.
Infrastructure & operations
The cloud foundations we use, and the operational mechanisms that protect data.
Access control
Who can touch which data — managed strictly, both technically and operationally.
- Role-based access control (RBAC) — granular permissions for owner / manager / staff / part-time.
- Passkey authentication — safer sign-in without relying on passwords.
- Audit logs — every sensitive action (exports, permission changes, staff additions) is recorded.
- Session management — idle sessions disconnect automatically after a period.
- Our staff only touch production data on a support request, only the minimum needed, and every action is logged.
Privacy stance
Your data is yours. We will never sell it to third parties or use it for ad targeting.
- We do not sell or transfer personal information to third parties.
- We do not use your data for ad targeting or behavioural tracking.
- We may use your data, after anonymization (with personally identifying information removed), to train our AI models.
- On account closure, we completely delete your data within 30 days.
- If any data transfer abroad becomes necessary, we always disclose it in advance.
Regulatory compliance
Regulations we currently comply with, and the ones we plan to tackle next — written honestly.
Currently compliant
- Act on the Protection of Personal Information (Japan) — across collection, use, and storage.
- Guidelines on Electronic Commerce — foundation for online service provision.
- Act on Specified Commercial Transactions — disclosure compliance (see the Commercial Disclosure page).
Future work
- Obtain Privacy Mark (P-Mark) certification.
- Obtain ISMS (ISO/IEC 27001) certification.
- GDPR compliance (for EU customers).
- SOC 2 Type II report (for large chains).
* The "future work" items above are not yet obtained. Once obtained, we'll update this page and display certification badges.
Vulnerability disclosure
If you find a security issue in RestaurantOS, please let us know. We take honest reports seriously and respond honestly.
Where to send it
Where to send it depends on what you found. For the RestaurantOS app itself, use the in-app Bug Report feature. For this website (restaurant.plugin-os.ai), use the contact form and choose "Security report" as the type. Include reproduction steps and impact wherever possible.
Our commitments
- We send a first reply within 48 hours.
- If we credit the reporter publicly, we always ask for permission first.
- We will not pursue legal action against good-faith reporters.
- We follow up with a thank you once important reports are fixed.
Frequently asked
Q.What happens to our restaurant's data if you get hacked?
If an incident occurs, we contact you promptly and make any reports required by law. We maintain the ability to restore from backups, and encrypted data is unreadable even if exfiltrated.
Q.What happens to my data if RestaurantOS shuts down?
If service termination is decided, we'll notify you at least 90 days in advance. During that window, you can export all your data as CSV / JSON. After the deadline, data is fully deleted.
Q.Can your staff look at our data without permission?
No. Production data is only touched on a support request, with the minimum action needed. All access is logged in audit logs, and we can share that history with you on request.
Q.Could our data get mixed up with another restaurant's?
Each restaurant's data is fully logically isolated in the database (by tenant ID). One restaurant seeing another's data is not technically possible.
Q.Will the customer contacts I enter be used to train your AI?
AI features work by referencing data within your store. In addition, we may use your data — after anonymization, with personally identifying information removed — as training data for our AI models.