1. Scope
ServePoint is a white-label restaurant software platform. This Policy applies to personal information we process about the following groups:
- Restaurants (our customers): businesses, and the owners and administrators acting for them, that subscribe to or evaluate the Services.
- Restaurant staff: employees and workers of our restaurant customers who use the Services in the course of their work.
- Guests: diners and customers who place orders, transact, or otherwise interact with a restaurant through the Services.
- Website visitors: individuals who visit our marketing website, request a demo, or contact us.
Our restaurant customers are independent businesses that maintain their own privacy practices. Except as described in this Policy, we are not responsible for how a restaurant independently collects or uses information outside the Services. If you are a guest or a member of restaurant staff, the restaurant you interact with or work for may provide additional notices that govern its own practices.
2. Definitions
- “Services” means the ServePoint software and related products, including the tablet POS applications, the admin portal, the online ordering site, the employee portal, our mobile applications, our marketing website, and related restaurant-management features (such as menu management, orders, customers, reporting, staff management, and loyalty and marketing features).
- “Restaurant”(or “customer”) means a business that has contracted to use, or is evaluating, the Services.
- “Guest” means an individual who transacts with a Restaurant through the Services.
- “Personal information” means information that identifies, relates to, or could reasonably be linked with an individual.
- “Controller” means the party that determines the purposes and means of processing personal information.
- “Processor” (or service provider) means a party that processes personal information on behalf of, and under the instructions of, a Controller.
3. Our Roles (Controller & Processor)
ServePoint plays two distinct roles depending on the information involved:
- As a processor / service provider. For guest and staff information that a Restaurant processes through the platform (for example, guest order and contact records, or staff scheduling records), the Restaurant is the controller (or business) and ServePointacts as a processor that handles that information on the Restaurant's behalf and under its instructions. The Restaurant owns its business data.
- As a controller. For information we collect about our own website visitors, prospective customers, account administrators, billing contacts, and our own marketing and product-analytics activities, ServePoint acts as the controller.
4. Information We Collect
From Restaurants:
- Business name, address, contact details, and account administrator information.
- Subscription, plan, and billing contact information.
- Menus, pricing, locations, tax settings, and operational configuration.
From restaurant staff (on behalf of the Restaurant):
- Name, work contact details, role, and login credentials.
- Scheduling, shift, timekeeping, and role-permission records.
- Where a Restaurant enables the optional payroll integration, information necessary to pass to the third-party payroll provider is handled under that provider's terms (see Sections 6 and 7).
From guests (on behalf of the Restaurant):
- Name and contact details such as phone number and email.
- Order and transaction details, order history, and preferences.
- Loyalty and rewards participation, where a Restaurant enables such features.
- Payment card details, which are collected and processed by our third-party payment processor and are not stored in full by ServePoint (see Section 6).
From website visitors:
- Name, email, phone number, and message content when you contact us or request a demo.
Collected automatically:
- Device, browser, operating system, and IP address.
- Usage, diagnostic, and reliability telemetry.
- Information collected through cookies and similar technologies (see Section 9).
5. How We Use Information
- Provide, maintain, and support the Services and related features.
- Authenticate users and protect account and platform security.
- Process orders and enable payment through our third-party payment processor.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Provide support, service notices, and product communications.
- Improve and develop the Services, including reliability and analytics.
- Comply with legal obligations and enforce our agreements.
Where we act as a processor for a Restaurant, we use guest and staff information only to provide the Services to that Restaurant and as otherwise permitted by our agreement with it and applicable law.
7. Service Providers & Sub-processors
To deliver the Services we rely on a limited set of trusted providers, each engaged only to provide the Services and each subject to confidentiality and security obligations:
- Cloud hosting and infrastructure: Microsoft Azure.
- Payment processing: Stripe (through Stripe Connect).
- Payroll integration: Gusto (only where a Restaurant enables it).
- Messaging: an SMS and messaging provider used to transmit transactional messages that you request.
8. Mobile Information and SMS Messaging
Mobile information and messaging (SMS/text) consent are not shared with any third parties or affiliates for marketing or promotional purposes.
When you provide a mobile number and opt in to text messages, we use it only to send the messages you requested — such as order updates, delivery status, account and security notifications, and support replies. Your opt-in and mobile number are never sold, rented, or shared with third parties or affiliates for their own marketing.
We share mobile data only with service providers that help us deliver these messages (for example, our SMS or messaging provider), strictly to transmit the messages on our behalf and under confidentiality and security obligations. Marketing text messages are sent only where you have opted in. Message and data rates may apply. Message frequency varies. Reply STOP to unsubscribe or HELP for help at any time. Consent to receive text messages is never a condition of any purchase.
10. AI-Assisted Features
Some features use machine-learning or generative AI to classify, summarize, suggest, extract, or help automate operational tasks. AI outputs are probabilistic and may be inaccurate, incomplete, or outdated, and should be reviewed by a person before being relied upon for high-impact decisions. We describe the operational aspects of AI features further in our Terms of Service.
11. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal information, and to object to or restrict certain processing. Where we act as a processor for a Restaurant, please direct requests about guest or staff information to that Restaurant, which is the controller; we will assist the Restaurant in responding as required. Where ServePoint is the controller, you can contact us using the details in Section 18. We may need to verify your identity before acting on a request, and some requests may be limited by legal or contractual obligations.
12. Data Retention
We retain personal information only as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Where we act as a processor, retention of a Restaurant's guest and staff data is governed by our agreement with that Restaurant. When information is no longer needed, we delete or de-identify it, subject to backups and legal-hold requirements.
13. Security
We apply administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. International Transfers
We and our providers are based primarily in the United States, and information we process may be stored and processed there. If you access the Services from outside the United States, you understand that your information may be transferred to and processed in jurisdictions where we or our providers operate, with appropriate safeguards where required by law.
15. Children
The Services are intended for businesses and are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.
16. Third-Party Links
The Services may link to websites or services we do not operate, including those of our Restaurants and integration partners. We are not responsible for the privacy practices of those third parties, and we encourage you to review their policies.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will revise the effective date above and, where appropriate, provide additional notice.
18. How to Contact Us
Questions about this Policy or our privacy practices can be sent to info@servepoint.me or by phone at (301) 649-5466.