Privacy Policy

Last updated October 5, 2026

This Privacy Policy explains what TacOS ("TacOS", "we", "us") collects when you use the TacOS website, application, free tools, crew terminal and AI features (the "Service"), how we use and share it, how long we keep it, and the choices you have. It is written for everyone the Service touches: restaurant owners and their teams, consultants, crew members who use a terminal, people who apply for a job through a restaurant's hiring page, and customers who receive a catering quote.

The short version: we collect what we need to run the Service for the restaurants that use it. We do not sell personal information, we do not run advertising, and the only analytics we use is a cookie-free page-view count that does not identify you. Your content is not used to train AI models. Where the Service holds information about a restaurant's employees, applicants or customers, the restaurant decides how that information is used and we act on its behalf.

1. Who is responsible for what

For the account you create and your own use of the Service, we decide how your information is used (we are the "controller" or "business" in privacy-law terms).

Most information in the Service is put there by a restaurant about other people: its employees and crew, its job applicants, its catering customers, its suppliers, the people named in its notes and meetings. For that information the restaurant is the controller: it decides what to collect and why, and it is responsible for the notices and consents the law requires. We are its service provider (its "processor") and use that information only to provide the Service to it. If you are one of those people and want to access, correct or delete your information, ask the restaurant; we will help it respond. Contact us if you cannot reach the restaurant.

2. What we collect

Account and profile information. When you sign up, our sign-in provider Clerk collects your name, email address, password or the identity provider you choose (such as Google), and a profile picture if you add one. We store your account id, your account type (owner or consultant), your roles in each organization and, for consultants, a display name, title and scope of work.

Business information. The restaurant's name, owner name, phone number, address, type of business, brand details and logo, locations and their settings, and plan and billing status. Billing is handled by Stripe; we store Stripe's customer and subscription identifiers, not card numbers.

Content you and your team create or upload. Recipes, procedures, documents, worksheets, photos and videos, menus, prices, invoices, food-cost data, training programs, goals and plans, projects and tasks, meeting notes (which may name attendees and discuss staffing and finances), research documents, messages and voice notes, field notes, assistant conversations, saved tool documents and anything else you put in the Service.

Team and crew information entered by the employer. Crew profiles on the roster (name, position, terminal role, initials, hire date and a hashed terminal PIN), training assignments, progress and certifications, checklist completions, and document acknowledgements. When a crew member signs a handbook on the terminal we keep the typed name, a drawn signature if one was made, the exact text acknowledged, the time, the device's network address and browser information, so the record can be shown later. Saved schedule and tip documents may contain employees' names, hours, pay rates and tips, as entered by the employer.

Job applications. When someone applies through a restaurant's public hiring page we collect what the form asks for: name, phone, email if given, positions and locations of interest, availability, desired pay, transportation, area of town or ZIP code, work history, references (name, relationship, phone), experience and a message, plus the network address the application came from. We do not ask for resumes, dates of birth, Social Security numbers or demographic information. The restaurant adds its own status and notes.

Catering customers. A quote holds the customer's name, phone, email, event details and delivery address as entered by the restaurant. When a customer pays online, Stripe processes the payment and sends us the amount, payment status and the email address used; we do not see card details. We record when a quote link is opened.

Communications with us. Bug reports (what went wrong, the page, the browser and your description) and any email or message you send us.

Technical information. Network addresses and request information in server logs, browser type and device type, approximate location derived from the network address, dates and times of use, and the pages and features used. Network addresses are also used to limit the rate of requests to free tools, job applications and payments. Vercel Web Analytics counts page views and visitors for us without cookies, using a short-lived hash of the request that cannot be traced back to a person and is not shared across sites.

Push notifications. If you turn on notifications we store the subscription your browser gives us. The notification itself (for example the sender's name and the first words of a message) passes through your browser maker's push service (Apple, Google or Mozilla).

Information from connected systems. If a restaurant connects a third-party system such as a point-of-sale, we read the data it chooses to share with us (for example sales totals) on its behalf.

3. How we use information

  • To provide the Service: sign you in, run your organization, store and show your content, run the terminal, deliver hiring pages and quotes, process payments through Stripe and send notifications you asked for.
  • To run the AI features you use: your prompts, uploads and the organization data a feature draws on are sent to our AI provider to produce the output you requested (see AI features below).
  • To bill you and to meter AI credits.
  • To keep the Service secure and working: detect abuse, limit request rates, debug errors, keep audit records of account and ownership changes.
  • To support you and answer your messages.
  • To improve the Service, using usage information in aggregated or de-identified form where possible.
  • To meet legal obligations and to establish or defend legal claims, including keeping records of your acceptance of our Terms.

We do not use personal information for advertising, we do not sell it, and we do not share it for cross-context behavioral advertising. We do not make decisions with legal or similarly significant effects about you by automated means alone.

4. AI features

When you use an AI feature (drafting a document from text or a photo, importing a binder, translating, reading an invoice or menu, summarizing notes or research, planning in the Command Center, asking the assistant, generating training questions), the content involved is sent to Anthropic, which runs the Claude models, to produce the result. Depending on the feature that content can include uploaded photos and PDFs, playbook content, field notes and messages with their authors' names, team members' names and titles, meeting notes, business context and financial figures you entered.

Voice notes and voice messages are transcribed by OpenAI's speech-to-text service; the audio is sent to OpenAI for that purpose.

These providers process your content under commercial terms that do not allow them to use it to train their models, and they keep it only as needed to provide the service and for abuse monitoring. We do not use your content to train AI models. Every AI call is logged in your organization's usage ledger with the feature, the tokens used and the cost, so credits can be metered.

AI output is produced by a model from the inputs described above. It may contain errors. The Terms of Service describe your responsibility to review it before relying on it.

5. Who we share information with

We share personal information only as described here. We do not sell it.

RecipientWhy
ClerkSign-in, accounts, organizations and membership; sends sign-in and invitation emails.
StripeSubscription billing; catering payments through the restaurant's own connected Stripe account; sends receipts. Stripe's privacy policy applies to what it collects directly.
AnthropicRuns the AI models for the AI features.
OpenAITranscribes voice notes and voice messages.
VercelHosts the Service, stores uploaded files, runs scheduled jobs and counts page views (Vercel Web Analytics, cookie-free).
NeonHosts the database.
UpstashHolds short-lived counters used to limit request rates (keyed by account, organization or network address).
OpenStreetMap services (Nominatim, OSRM)Turn a catering delivery address into coordinates and a distance. The address text and coordinates are sent; no name is attached.
Browser push services (Apple, Google, Mozilla)Deliver notifications you turned on.
Connected systems you choosePoint-of-sale or other business systems a restaurant connects, as directed by it.

Within the Service, your information is visible to the people the restaurant has given access to, according to their roles: owners, managers, staff, accountants and consultants of that organization and, in a brand with several locations, brand-level members. A consultant you invite can see what you let them see. A crew terminal shows the location's roster names. Our platform administrators can access organization data to support, secure and operate the Service.

Public pages. A restaurant can publish a hiring page, send a catering quote link and create share images from free tools. A quote link shows the customer's name and event details to anyone who has the link. A share image's web address contains the figures and names typed into the tool. Files uploaded to the Service are stored at long, unguessable web addresses; anyone who has a file's exact address can open it, so share links with care.

We may also disclose information to comply with law, a court order or a lawful request by a public authority; to enforce our Terms; to protect the rights, safety or property of anyone; and in connection with a merger, acquisition, financing or sale of assets, in which case this policy continues to apply to the information transferred.

6. Cookies and browser storage

We use only cookies and browser storage needed to run the Service. There are no advertising cookies and no analytics cookies; the page-view count described above works without any.

  • Sign-in cookies set by Clerk keep you signed in and protect your session.
  • A cookie remembers whether the sidebar is open.
  • Browser storage (localStorage) remembers your language, your color theme, your organization's colors so the page paints correctly, dismissed tips, print preferences, a pending invitation while you sign in, and free-tool drafts so you do not lose work when you close the tab. A free-tool draft can contain whatever you typed, including staff names and pay; it stays in your browser until you clear it or the tool deletes it.
  • If you turn on notifications, a service worker and a push subscription are registered in your browser.

You can clear cookies and site data in your browser at any time; you will be signed out and your preferences reset. The Service does not respond to browser "Do Not Track" signals because it does not track you across other sites.

7. How long we keep information

  • Your account: until you delete it. A deleted account enters a 30-day recovery window, after which the account is permanently deleted from our sign-in provider. Content you created inside an organization (documents, messages, notes, acknowledgements) belongs to that organization's record and stays with it, labeled with your name, until the organization removes or deletes it.
  • Organization data: for as long as the organization exists on the Service. When an owner deletes an organization, its data is marked deleted and no longer accessible to its members; copies may remain in backups and in records we must keep for a limited time afterwards.
  • Uploaded files (photos, videos, PDFs, documents, voice notes): kept at their storage addresses until they are removed. Removing a document or an organization does not yet remove the files behind it automatically; write to us at the contact address to have specific files deleted and we will do so.
  • Acknowledgements and certifications: kept as records for as long as the organization exists, because they exist to prove what was signed and when.
  • Job applications: kept until the restaurant deletes them. Applicants may ask the restaurant to delete theirs.
  • Catering quotes and payment records: kept with the organization. Stripe keeps its own payment records under its policies.
  • Logs, rate-limit counters and bug reports: for a limited period needed to operate and secure the Service.
  • Records of your acceptance of the Terms and of account, ownership and billing events: for as long as needed to establish or defend legal claims.

8. Security

We protect information with access controls based on roles, encrypted connections, hashed terminal PINs, rate limits, audit records of sensitive account actions, and reputable infrastructure providers that hold their own security certifications. No system is perfectly secure; keep your sign-in method private, use the role system rather than sharing accounts, remove people who leave, and tell us promptly if you suspect a problem. If a breach affects your information in a way the law requires us to report, we will notify you and the authorities as required.

9. Your choices and rights

Access and correction. You can see and change your account details in your sign-in settings and your organization's details in Settings.

Deletion. You can delete your account from Settings. An owner must first transfer the organization to another owner. An owner can delete an organization from Settings, which removes its data from the Service for all members.

Export. Ask us and we will provide a copy of your organization's content in a reasonable format.

Notifications. Turn push notifications off in the Service or in your browser settings.

AI features. Each AI feature runs only when you use it. If you do not want certain content sent to an AI provider, do not use the AI features on it.

Depending on where you live, you may have legal rights to know what personal information we hold about you, to correct or delete it, to obtain a copy, to opt out of its sale or sharing (we do none) and not to be discriminated against for exercising these rights. Residents of Texas, California and other states with privacy laws, and residents of the European Economic Area, the United Kingdom and other places with similar laws, may exercise these rights by writing to us at the address below. We will verify your request and answer within the time the law allows. You may also appeal a decision by writing to the same address. If we hold your information on behalf of a restaurant, we will forward your request to it or help it respond.

10. Children and young workers

The Service is for businesses. You must be at least 18 to hold an account, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.

Restaurants sometimes employ workers under 18. A young worker does not hold an account; a crew profile the employer creates for them may be used on the terminal under the employer's supervision. The employer decides whether to do so and is responsible for complying with the laws on employing minors.

11. Where information is processed

We operate from the United States and our providers store and process information there. If you use the Service from elsewhere, your information is transferred to and processed in the United States, where privacy laws may differ from those of your country. By using the Service you agree to that transfer.

12. Changes to this policy

We may update this policy as the Service changes. We will post the new version here with its date and, for material changes, ask you to acknowledge it in the app or notify you by email before it takes effect. Earlier versions are available on request.

13. Contact

Privacy questions and requests: gabe@tacosmexican.com. Put "Privacy" in the subject line and tell us which restaurant or organization your request concerns.

    Privacy Policy 路 TacOS