Privacy Policy
Restaurant OS platform · Effective August 14, 2026
Binary Restaurant Consulting LLC (“Binary,” “we,” “us”) provides the Restaurant OS platform to restaurant businesses. This policy explains what the platform stores, who processes it, how it is protected, and what rights you have. Our public marketing site is covered by a separate policy at binaryconsulting.com/privacy.
Who controls your data
Your restaurant’s data belongs to your restaurant.For the business information you put into the platform — recipes, costs, sales, financials — your restaurant is the controller and we act as a service provider, processing it to run the service for you and on your instructions. We do not sell it, we do not use it to advertise, and we do not use one customer’s business data to benefit another.
For your user account itself, and for the prospect records in our own CRM, Binary is the controller.
What the platform stores
Account information. Your email address, your role, the restaurant or organization you belong to, and a hashed version of your password. We never store your password itself.
Business and operational data. Ingredients and prices, menu items and recipes, inventory counts, sales counts, labor cost totals, profit-and-loss and balance-sheet entries, cost targets, and compliance records and their reminder recipients. Labor is stored as period cost totals — the platform does not keep individual employee records, names, or hours.
Documents you upload. Receipt images submitted for scanning, and bank statement PDFs submitted for import.
Connected accounts. When you link a POS or bank account, we store the access tokens needed to sync, encrypted at rest. We never receive or store your login credentials for those services.
Prospect records (our CRM).Separately from any customer’s data, we keep records about restaurants we may work with: business name, location and address, a contact name, email, phone, status, and our own notes.
Cookies
The platform sets one cookie, rc_session. It holds your signed session token, is marked HttpOnly so scripts cannot read it, and expires after seven days. It is strictly necessary to keep you logged in. We use no advertising, analytics, or cross-site tracking cookies.
Automated processing and AI
Receipt scanning.When you scan a receipt, the image is sent to Anthropic’s API, which extracts the line items and prices and returns them for your review. Anthropic does not use data submitted through its API to train its models. Extraction is a suggestion — nothing is written to your inventory until you accept it.
Bank statements. Uploaded statement PDFs are parsed on our own servers. Their contents are not sent to any external service.
Transaction categorization. Imported bank transactions are categorized by keyword matching in our own code, and you can override any result. No decision the platform makes automatically produces a legal or similarly significant effect on any individual.
Service providers
We share data only with providers that help us deliver the service, each limited to what their function requires. All are located in, or process data in, the United States.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting | Request logs, IP addresses, all data in transit |
| Neon (PostgreSQL) | Primary database | All account and business data at rest |
| Anthropic | AI receipt scanning | Receipt images you upload for extraction |
| Resend | Transactional & campaign email | Recipient email addresses, message content |
| Plaid | Bank account connections | Bank credentials (entered with Plaid, never seen by us), transactions |
| Square, Clover, Toast, Shift4 | POS synchronization | Sales, catalog and labor-cost data from your POS |
| Stripe | Subscription billing | Billing contact and payment details (card data never touches our servers) |
| Microsoft 365 | Our business email | Correspondence you send us |
| Cal.com | Consult scheduling | Name, email and booking details from our website’s booking calendar |
We may also disclose data where the law requires it, or to establish or defend legal claims. If our business is ever transferred, we will tell affected customers before their data moves.
How we protect it
All traffic runs over HTTPS. Passwords are stored as bcrypt hashes, never in readable form. POS and bank access tokens are encrypted at rest with AES-256-GCM. Sessions use signed, HttpOnly cookies.
Every restaurant’s data is isolated by a tenant identifier that the application enforces on every query, and access within a restaurant is further limited by role — an account can only reach the modules its role permits. No system is perfectly secure, but we would rather describe our actual measures than claim guarantees we cannot make.
How long we keep it
We retain your data for as long as your account is active. If your restaurant ends its subscription, we keep the data for 90 days so it can be exported or the account reactivated, and then we delete it. You can ask us to export or delete it sooner. Backups age out on their own schedule shortly afterward, and financial records we are required to keep for tax or accounting purposes are retained for the period the law requires.
Your rights
Depending on where you live — including under the Texas Data Privacy and Security Act and the California Consumer Privacy Act — you may have the right to access the personal information we hold about you, to receive a copy, to correct it, to have it deleted, and not to be treated differently for asking. We do not sell personal information and do not share it for cross-context behavioral advertising.
If you use the platform through your employer’s account, start with your restaurant’s administrator, who controls that data directly. You can always reach us at info@binaryconsulting.com. We may need to verify your identity before acting, and we will respond within the period the applicable law allows.
Email from us
Account email — password resets, compliance reminders, and similar notices — is part of the service and cannot be turned off while your account is active. Marketing email always identifies us, carries our physical address, and explains how to unsubscribe.
Children
The platform is a business tool for adults. We do not knowingly collect personal information from children, and accounts are not made available to them.
Changes
If we change this policy we will update the effective date above, and we will notify account administrators of material changes rather than making them quietly.
Contact us
Binary Restaurant Consulting LLC
5900 Balcones Drive, #33066
Austin, TX 78731, US
info@binaryconsulting.com