Privacy Policy
Last updated: [TO BE COMPLETED: publication date]
Who we are
Valora AI (“Valora”, “we”) provides restaurant operating analytics to businesses. Our registered entity and address: [TO BE COMPLETED: legal entity name, registered address, and any EU/UK representative].
For data you upload or connect about your restaurant, you are the controller and Valora is a processor acting on your instructions. For your own account details and our marketing, Valora is the controller.
What we collect
Account data. Name, work email, hashed password, business name, locations, role and access scope, and your subscription status.
Point-of-sale data. When you authorise Square, Clover or Toast, Valora reads transactional records from that provider:
- Orders and line items, including item names, quantities, modifiers, discounts and voids
- Timestamps, order channel and location identifiers
- Payment totals, tax and tip amounts at the order level
- Your menu or catalogue structure, and your locations and their trading hours
Access is read-only. Valora does not receive card numbers, cardholder names or any payment credentials, and cannot move money, issue refunds or modify anything in your POS.
Usage data. Pages viewed, features used, approximate location derived from IP, browser and device type, and error diagnostics.
Communications. Emails you send us, demo bookings, and support requests.
What we do with it
- Produce the analytics, forecasts and recommendations that are the product
- Generate written explanations of your metrics using an AI model (see below)
- Operate, secure, debug and improve the service
- Bill you and manage your subscription
- Send service messages, and marketing you can opt out of at any time
- Meet legal obligations and enforce our terms
[TO BE COMPLETED: confirm the lawful basis relied on for each purpose if serving UK/EU customers — typically contract for the first four, legitimate interests or consent for marketing]
AI processing
Valora sends your operating metrics to Google’s Gemini API to generate written insight and recommendations. What is sent is aggregated business data — figures, trends and comparisons — not raw customer records.
Google processes this as our sub-processor. [TO BE COMPLETED: confirm and state whether your Gemini tier is excluded from model training, and link the applicable Google terms] This matters to operators and should be stated plainly rather than buried.
Who else processes your data
We use the following sub-processors. Each is bound to confidentiality and security terms.
- Vercel — application hosting and delivery
- Render — background processing and scheduled data syncs
- Neon — managed PostgreSQL database hosting
- Google (Gemini API) — AI-generated insight
- Stripe — subscription payments and billing
- Resend — transactional email
- Cal.com — demo scheduling
- Square, Clover and Toast — the POS providers you choose to connect
We do not sell your data, and we do not share it with advertisers. [TO BE COMPLETED: confirm this list is complete against current production infrastructure]
Where your data is held
Data is stored and processed in [TO BE COMPLETED: primary hosting region(s)]. If you are outside that region, your data is transferred there. [TO BE COMPLETED: state the transfer mechanism for UK/EU customers — Standard Contractual Clauses or equivalent]
How long we keep it
We keep your data for as long as your account is active. After you cancel, we retain it for [TO BE COMPLETED: retention window, e.g. 30 or 90 days] so the account can be restored, and then delete or anonymise it. You can request earlier deletion at any time.
Billing records are kept longer where tax or accounting law requires it: [TO BE COMPLETED: statutory retention period].
Security
- Data is encrypted in transit and at rest
- Each customer's data is isolated per tenant at the database level, and access within an account is scoped per user and per location
- POS credentials are stored encrypted and are never exposed in the interface
- Access to production systems is limited to personnel who need it
No system is perfectly secure. If a breach affects your data we will notify you and any relevant regulator as required by law. [TO BE COMPLETED: notification timeframe commitment, e.g. within 72 hours of becoming aware]
Your rights
Depending on where you are, you may have the right to access, correct, delete, export or restrict processing of your personal data, to object to processing, and to complain to a supervisory authority. To exercise any of these, email support@valoraai.us. We respond within [TO BE COMPLETED: response window, e.g. 30 days].
[TO BE COMPLETED: add the California-specific disclosures (CCPA/CPRA) if you have California customers, including the “do not sell or share” statement]
Cookies
We use cookies that are necessary to keep you signed in, and [TO BE COMPLETED: confirm whether analytics or marketing cookies are in use — if so, a consent banner is required for UK/EU visitors].
Children
Valora is a business tool and is not directed at anyone under 16. We do not knowingly collect their data.
Changes
We will post any material change here and update the date above. If the change meaningfully affects how we handle your data, we will tell you by email before it takes effect.