This policy explains how Sanora Labs handles personal data about the businesses that use the platform and the people who sign in to it, and how we process guest and staff data on a business's behalf.
1. Our two roles
For console accounts, billing and our relationship with your business, Sanora Labs is the controller.
For the data a business puts into the platform about its guests and staff — orders, customer profiles, attendance, messages — the business is the controller and we are its processor. We process that data only on its instructions and to run, secure and support the service.
2. What we collect
Account details: name, email address, phone number, role, and a hashed password or PIN.
Business details: business name, locations, tax and billing information, and the plan you are on.
Data you add: menus, orders, customers, staff records and, where you use those features, staff photos and time-clock records.
Usage and device data: sign-in history, IP address, browser and device information and activity logs, used for security and support.
Communications: support requests and the messages you send us.
3. How we use it
To provide and secure the platform, authenticate users, bill for plans, give support, prevent fraud and abuse, improve the service with aggregated information, and meet legal obligations. We send product and service messages; marketing emails only with an opt-out.
4. Legal bases
Performing our contract with your business, our legitimate interests in running a secure and reliable service, compliance with the law, and consent where it is required.
5. Service providers
We use trusted providers for hosting, payments, email and text messages, telephony and voice features, and maps. They process data only for us, under contracts that protect it. A list of sub-processors is available on request.
We do not sell personal data.
6. Retention
We keep account and business data for as long as the account is active, then for up to 30 days to allow export, then delete it — except records we must keep for tax or legal reasons. Security logs are kept for a limited period.
7. Security
Data is encrypted in transit, access is limited by role and logged, and each business’s data is kept separate from every other business’s. No system is perfectly secure; we will tell affected businesses without undue delay about a breach that affects their data.
8. International transfers
Our providers may process data outside your country. Where they do, we use appropriate safeguards such as standard contractual clauses.
9. Your rights
You can ask to access, correct, delete or export your personal data, and to object to or restrict its use. Guests and staff of a business should contact that business first; we will help it respond. You can also complain to your data protection authority.
10. Contact
Privacy questions and requests: privacy@sanoralabs.com. We may update this policy; the date at the top shows the latest version.