Privacy Policy

Last updated July 2026

Restaurant IQ is an internal operations dashboard, developed and operated by Chattabot Inc. (chattabot.ai), built for a single restaurant business ("the restaurant"). It is not a public product and is not offered to other businesses. This policy describes what data the dashboard collects and how it is used.

What data we collect

  • Point-of-sale data from Toast (sales, orders, menu items, labor/timekeeping records)
  • Accounting data from QuickBooks Online (cash, accounts receivable/payable, profit & loss)
  • Documents the restaurant's team uploads directly (e.g. payroll registers, vendor invoices)
  • Chat messages sent to the dashboard's assistant, and the assistant's responses
  • The name entered at login, used to identify who uploaded a document or asked a question

How data is used

Data is used solely to generate operational insights for the restaurant's own management team — daily briefs, dashboards, and answers to questions asked in the chat interface. Data is not sold, and is not shared with any third party except the service providers below, each of which processes it only to provide the dashboard's functionality.

Service providers

  • Toast, Inc. — point-of-sale data source
  • Intuit Inc. (QuickBooks Online) — accounting data source
  • Anthropic — processes data to generate summaries and answer questions (Claude API)
  • Vercel — application hosting and file storage
  • Supabase — database hosting

Data storage and security

OAuth access tokens for connected integrations are encrypted at rest (AES-256-GCM). Uploaded documents are stored in private object storage and are only accessible through authenticated requests. Access to the dashboard itself is restricted to team members with a shared passcode.

SMS / text messaging

There are two steps before an employee's phone number can receive any text message: (1) as part of standard onboarding, the employee provides their mobile phone number to their manager in person; (2) the manager enters that phone number into the internal, password-protected staff scheduling platform via a web form. No message is ever sent automatically once a number is entered — every one-time login code is sent only in direct response to that employee themselves visiting a private sign-in link and submitting their own phone number to request it, and every status update (shift-swap or time-off decisions) is sent only in response to an action that employee themselves took in the system.

Message frequency varies depending on login and schedule-request activity. Message and data rates may apply. Mobile phone numbers and opt-in data collected for SMS messaging are not shared or sold to third parties or affiliates for marketing or promotional purposes. To stop receiving messages, reply STOP at any time; reply HELP for assistance.

Data retention

Data is retained for as long as the restaurant continues to use the dashboard. A team member can request deletion of specific uploaded documents or chat history at any time.

Contact

Questions about this policy can be directed to the restaurant's management team.