Legal

Privacy policy

Last updated 2026-09-25 — template, review with a lawyer before production

This policy explains how Sanora Labs handles personal data about the businesses that use the platform and the people who sign in to it, and how we process guest and staff data on a business's behalf.

1. Our two roles

For console accounts, billing and our relationship with your business, Sanora Labs is the controller.

For the data a business puts into the platform about its guests and staff — orders, customer profiles, attendance, messages — the business is the controller and we are its processor. We process that data only on its instructions and to run, secure and support the service.

2. What we collect

Account details: name, email address, phone number, role, and a hashed password or PIN.

Business details: business name, locations, tax and billing information, and the plan you are on.

Data you add: menus, orders, customers, staff records and, where you use those features, staff photos and time-clock records.

Usage and device data: sign-in history, IP address, browser and device information and activity logs, used for security and support.

Communications: support requests and the messages you send us.

3. How we use it

To provide and secure the platform, authenticate users, bill for plans, give support, prevent fraud and abuse, improve the service with aggregated information, and meet legal obligations. We send product and service messages; marketing emails only with an opt-out.

4. Legal bases

Performing our contract with your business, our legitimate interests in running a secure and reliable service, compliance with the law, and consent where it is required.

5. Service providers

We use trusted providers for hosting, payments, email and text messages, telephony and voice features, and maps. They process data only for us, under contracts that protect it. A list of sub-processors is available on request.

We do not sell personal data.

6. Retention

We keep account and business data for as long as the account is active, then for up to 30 days to allow export, then delete it — except records we must keep for tax or legal reasons. Security logs are kept for a limited period.

7. Security

Data is encrypted in transit, access is limited by role and logged, and each business’s data is kept separate from every other business’s. No system is perfectly secure; we will tell affected businesses without undue delay about a breach that affects their data.

8. International transfers

Our providers may process data outside your country. Where they do, we use appropriate safeguards such as standard contractual clauses.

9. Your rights

You can ask to access, correct, delete or export your personal data, and to object to or restrict its use. Guests and staff of a business should contact that business first; we will help it respond. You can also complain to your data protection authority.

10. Contact

Privacy questions and requests: privacy@sanoralabs.com. We may update this policy; the date at the top shows the latest version.