ApogeePricing →
Legal

Privacy Policy

Effective July 26, 2026

1. Introduction

This Privacy Policy explains how Apogee OI ("we," "us") collects, uses, shares, and protects information in connection with our restaurant operations platform (the "Service"). It applies to our customers (the businesses that subscribe), their staff whose information is stored in the Service, and visitors to our website.

2. Our two roles

We handle information in two capacities:

  • As a controller — for the account, contact, billing, and website information of the businesses that subscribe.
  • As a processor — for the operational and personnel data a customer uploads about its own business and staff. In that case, the customer is the controller and we process the data only on the customer's instructions.

If you are an employee of one of our customers, that customer (your employer) controls your information in the Service — please direct access or deletion requests to them.

3. Information we collect

  • Account & contact data: name, email, phone, business name, and role.
  • Billing data: subscription and payment status. Card payments are processed by our payment processor; we do not store full card numbers.
  • Customer operational data: inventory, invoices, vendors, recipes, sales, schedules, reports, and similar records you add.
  • Personnel data (uploaded by customers about their staff): names, dates of birth, contact details, government identifiers such as Social Security numbers, onboarding and tax documents (e.g., W-4, I-9, direct deposit, IDs), wages, hours, and tips.
  • Integration data: information from services you connect, such as point-of-sale sales/labor data and events/catering data.
  • Location data: your business location (used to generate weather-aware forecasts).
  • Usage & device data: log data, IP address, device/browser information, and session cookies needed to keep you signed in.

4. How we use information

  • Provide, operate, secure, and support the Service.
  • Generate features you request, including forecasts, reports, invoice extraction, and the AI assistant.
  • Process subscriptions and payments.
  • Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Improve and develop the Service.
  • Comply with legal obligations and enforce our Terms.

5. AI processing

Some features send relevant data to AI providers to generate results — for example, extracting line items from invoices, answering assistant questions, and producing demand forecasts. We limit what is sent to what is needed for the feature. Our AI provider processes this data on our behalf as a subprocessor and does not use it to train its general models on terms we have accepted. AI outputs may be inaccurate and should be verified before you rely on them.

6. How we share information

We do not sell personal information. We share it only with:

  • Subprocessors that help us run the Service — currently including our AI provider (Anthropic), payment processor (Stripe), hosting (Vercel), database (Neon), file storage (Cloudflare R2), transactional email (Resend), error monitoring (Sentry), a weather-data provider, and the point-of-sale/events platforms you choose to connect (e.g., Toast, Tripleseat).
  • Authorities or others when required by law, or to protect rights, safety, and the security of the Service.
  • A successor in connection with a merger, acquisition, or sale of assets, subject to this Policy.

Each subprocessor is bound to protect the information and use it only to provide services to us.

7. Security

We use industry-standard safeguards, including encryption in transit and at rest, additional encryption of sensitive identifiers such as Social Security numbers, role-based access controls, multi-factor authentication, audit logging, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Data retention

We retain information for as long as your account is active and as needed to provide the Service, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. On termination, we make data available for export for a limited period and then delete or de-identify it in the ordinary course, unless retention is required by law.

9. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To exercise these rights for account data, contact us at hello@apogeeoi.app. For personnel data held on behalf of a customer, contact that customer, who controls it; we will assist them as required.

Residents of states such as Texas and California may have additional rights under applicable privacy laws, including the right to be free from discrimination for exercising them.

10. Cookies

We use only the cookies and similar technologies necessary to operate the Service — primarily to keep you securely signed in. We do not use advertising or cross-site tracking cookies.

11. Children

The Service is intended for businesses and their staff who are adults of working age. It is not directed to children, and we do not knowingly collect information from children under 16.

12. Data location

We store and process information in the United States. If you access the Service from outside the U.S., you consent to processing there.

13. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email or in-app) and update the effective date above.

14. Contact

Questions or requests about privacy? Contact us at hello@apogeeoi.app.

Terms of Service →Pricing