Legal

Privacy Policy

This Privacy Policy explains how ServePointcollects, uses, shares, and protects personal information across our restaurant point-of-sale software, admin portal, online ordering site, employee portal, mobile applications, marketing website, and related features (collectively, the “Services”).

Effective date: July 12, 2026

Looking for the summary? Read the short Privacy Policy.

1. Scope

ServePoint is a white-label restaurant software platform. This Policy applies to personal information we process about the following groups:

  • Restaurants (our customers): businesses, and the owners and administrators acting for them, that subscribe to or evaluate the Services.
  • Restaurant staff: employees and workers of our restaurant customers who use the Services in the course of their work.
  • Guests: diners and customers who place orders, transact, or otherwise interact with a restaurant through the Services.
  • Website visitors: individuals who visit our marketing website, request a demo, or contact us.

Our restaurant customers are independent businesses that maintain their own privacy practices. Except as described in this Policy, we are not responsible for how a restaurant independently collects or uses information outside the Services. If you are a guest or a member of restaurant staff, the restaurant you interact with or work for may provide additional notices that govern its own practices.

2. Definitions

  • “Services” means the ServePoint software and related products, including the tablet POS applications, the admin portal, the online ordering site, the employee portal, our mobile applications, our marketing website, and related restaurant-management features (such as menu management, orders, customers, reporting, staff management, and loyalty and marketing features).
  • “Restaurant”(or “customer”) means a business that has contracted to use, or is evaluating, the Services.
  • “Guest” means an individual who transacts with a Restaurant through the Services.
  • “Personal information” means information that identifies, relates to, or could reasonably be linked with an individual.
  • “Controller” means the party that determines the purposes and means of processing personal information.
  • “Processor” (or service provider) means a party that processes personal information on behalf of, and under the instructions of, a Controller.

3. Our Roles (Controller & Processor)

ServePoint plays two distinct roles depending on the information involved:

  • As a processor / service provider. For guest and staff information that a Restaurant processes through the platform (for example, guest order and contact records, or staff scheduling records), the Restaurant is the controller (or business) and ServePointacts as a processor that handles that information on the Restaurant's behalf and under its instructions. The Restaurant owns its business data.
  • As a controller. For information we collect about our own website visitors, prospective customers, account administrators, billing contacts, and our own marketing and product-analytics activities, ServePoint acts as the controller.

4. Information We Collect

From Restaurants:

  • Business name, address, contact details, and account administrator information.
  • Subscription, plan, and billing contact information.
  • Menus, pricing, locations, tax settings, and operational configuration.

From restaurant staff (on behalf of the Restaurant):

  • Name, work contact details, role, and login credentials.
  • Scheduling, shift, timekeeping, and role-permission records.
  • Where a Restaurant enables the optional payroll integration, information necessary to pass to the third-party payroll provider is handled under that provider's terms (see Sections 6 and 7).

From guests (on behalf of the Restaurant):

  • Name and contact details such as phone number and email.
  • Order and transaction details, order history, and preferences.
  • Loyalty and rewards participation, where a Restaurant enables such features.
  • Payment card details, which are collected and processed by our third-party payment processor and are not stored in full by ServePoint (see Section 6).

From website visitors:

  • Name, email, phone number, and message content when you contact us or request a demo.

Collected automatically:

  • Device, browser, operating system, and IP address.
  • Usage, diagnostic, and reliability telemetry.
  • Information collected through cookies and similar technologies (see Section 9).

5. How We Use Information

  • Provide, maintain, and support the Services and related features.
  • Authenticate users and protect account and platform security.
  • Process orders and enable payment through our third-party payment processor.
  • Detect, prevent, and investigate fraud, abuse, and security incidents.
  • Provide support, service notices, and product communications.
  • Improve and develop the Services, including reliability and analytics.
  • Comply with legal obligations and enforce our agreements.

Where we act as a processor for a Restaurant, we use guest and staff information only to provide the Services to that Restaurant and as otherwise permitted by our agreement with it and applicable law.

6. How We Share Information

We do not sell personal information. We share information only as needed to operate the Services:

  • With the relevant Restaurant. Guest and staff information is made available to the Restaurant the individual interacts with or works for.
  • Payment processing. Card payments are collected and processed by a third-party payment processor (Stripe, through Stripe Connect). ServePointis a software provider and is not a bank, money transmitter, card network, or the merchant of record for card funds. Settlement and processing of card payments are performed by Stripe and its financial-institution partners under Stripe's own terms and privacy policy.
  • Payroll integration.Where a Restaurant enables payroll, it is provided through a third-party integration with Gusto, under Gusto's own terms and privacy policy. ServePoint does not operate its own payroll, benefits, or tax-filing service.
  • Service providers and sub-processors. Vetted providers that help us host and deliver the Services, under confidentiality and security obligations (see Section 7).
  • Third-party integrations you enable.Integrations a Restaurant turns on are governed by each provider's own terms.
  • Legal and safety. Where required by law or valid legal process, or to protect rights, safety, and the integrity of the Services.
  • Business transfers. In connection with a merger, acquisition, financing, or asset transfer, subject to this Policy.

We may also create and share aggregated or de-identified information that does not identify any individual.

7. Service Providers & Sub-processors

To deliver the Services we rely on a limited set of trusted providers, each engaged only to provide the Services and each subject to confidentiality and security obligations:

  • Cloud hosting and infrastructure: Microsoft Azure.
  • Payment processing: Stripe (through Stripe Connect).
  • Payroll integration: Gusto (only where a Restaurant enables it).
  • Messaging: an SMS and messaging provider used to transmit transactional messages that you request.

8. Mobile Information and SMS Messaging

Mobile information and messaging (SMS/text) consent are not shared with any third parties or affiliates for marketing or promotional purposes.

When you provide a mobile number and opt in to text messages, we use it only to send the messages you requested — such as order updates, delivery status, account and security notifications, and support replies. Your opt-in and mobile number are never sold, rented, or shared with third parties or affiliates for their own marketing.

We share mobile data only with service providers that help us deliver these messages (for example, our SMS or messaging provider), strictly to transmit the messages on our behalf and under confidentiality and security obligations. Marketing text messages are sent only where you have opted in. Message and data rates may apply. Message frequency varies. Reply STOP to unsubscribe or HELP for help at any time. Consent to receive text messages is never a condition of any purchase.

9. Cookies and Tracking Technologies

We use cookies and similar technologies for essential session continuity, security, feature preferences, and analytics. Where required, we provide consent controls so you can manage non-essential categories. You can also adjust browser-level cookie settings, though some functionality may be reduced if essential cookies are blocked.

10. AI-Assisted Features

Some features use machine-learning or generative AI to classify, summarize, suggest, extract, or help automate operational tasks. AI outputs are probabilistic and may be inaccurate, incomplete, or outdated, and should be reviewed by a person before being relied upon for high-impact decisions. We describe the operational aspects of AI features further in our Terms of Service.

11. Your Rights and Choices

Depending on your jurisdiction, you may have rights to access, correct, delete, or export personal information, and to object to or restrict certain processing. Where we act as a processor for a Restaurant, please direct requests about guest or staff information to that Restaurant, which is the controller; we will assist the Restaurant in responding as required. Where ServePoint is the controller, you can contact us using the details in Section 18. We may need to verify your identity before acting on a request, and some requests may be limited by legal or contractual obligations.

12. Data Retention

We retain personal information only as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Where we act as a processor, retention of a Restaurant's guest and staff data is governed by our agreement with that Restaurant. When information is no longer needed, we delete or de-identify it, subject to backups and legal-hold requirements.

13. Security

We apply administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. International Transfers

We and our providers are based primarily in the United States, and information we process may be stored and processed there. If you access the Services from outside the United States, you understand that your information may be transferred to and processed in jurisdictions where we or our providers operate, with appropriate safeguards where required by law.

15. Children

The Services are intended for businesses and are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.

17. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will revise the effective date above and, where appropriate, provide additional notice.

18. How to Contact Us

Questions about this Policy or our privacy practices can be sent to info@servepoint.me or by phone at (301) 649-5466.