Legal
Privacy Policy
Last updated April 25, 2026
Summary
Platevox is a restaurant management platform. We collect the data we need to run your account and provide the service — nothing more. We don't sell your data, and we don't share it with advertisers. This page describes what we collect, why, and the rights you have.
What we collect
- Account data — name, email, phone, business name, and the role you have within your restaurant.
- Operational data — menus, orders, customers, payments, inventory, staff records, and other data you enter to run your restaurant on Platevox.
- Technical data — IP address, browser type, device identifiers, and usage logs that help us detect abuse and debug issues.
- Voice data — if you enable AI Voice Waiter, we process audio of phone calls to understand orders. Audio is retained for a short window (default 30 days) for quality and dispute resolution, then deleted.
How we use it
We use the data above to run your account, deliver features you asked for, send transactional notifications (receipts, password resets, security alerts), and improve the product. We use aggregated, de-identified data to understand how the platform is used.
Who we share it with
We share data only with sub-processors that help us run the service — for example, Stripe for payments, Twilio for SMS, and our cloud infrastructure provider for hosting. We don't sell your data, and we don't share it with advertisers or data brokers.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you. To exercise any of these rights, email privacy@platevox.io. We respond within 30 days.
Data retention
We keep your operational data for as long as your account is active. If you cancel, we keep it for 30 days so you can export it, then delete it. Backups are purged on a 30-day rolling cycle. Some records (invoices, fraud signals) we retain longer when required by tax or anti-fraud law.
Security
All traffic uses HTTPS/TLS. Sensitive credentials (payment-gateway keys, SMS-provider tokens) are stored AES-256 encrypted at the application layer. Tenant data is isolated at the database level and access is role-scoped. We're not currently SOC 2 certified — happy to share specifics on request for procurement reviews.
Changes to this policy
If we change this policy in a way that affects you, we'll email you and update the “last updated” date above before the change takes effect.
Contact
Questions? Reach us at privacy@platevox.io or via the contact page.