Privacy Policy

Last updated July 29, 2026

Restaurant OS (“Restaurant OS,” “we,” “us,” or “our”) provides restaurant operations software that connects to the point-of-sale (POS) system you already use. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using Restaurant OS at app.runros.app (the “Service”), you agree to this policy.

Information we collect

  • Account information. When you create a restaurant account we collect your name, email address, and an encrypted password so we can secure and administer your account.
  • POS data via authorized connections. When you connect your POS (for example, Clover) you authorize us, through the POS provider's OAuth flow, to access a limited set of your business data. For Clover we request read-only access to: orders, inventory, employees, and merchant details. We use this to display sales, item, labor, and location insights inside the Service. We do not request write access, and we do not access customer payment card numbers.
  • Connection credentials. To keep your POS connected we store the access and refresh tokens issued by the POS provider. These tokens are encrypted at rest using AES-256-GCM before being written to our database.
  • Usage and technical data. We may collect basic technical information such as log entries, IP address, and browser type to operate, secure, and troubleshoot the Service.

How we use information

  • To provide, maintain, and improve the Service and its analytics features.
  • To sync and display your POS data (sales, items, labor, locations).
  • To authenticate you and keep your account and connections secure.
  • To communicate with you about your account, security, and support requests.

We do not sell your data, and we do not use your POS business data for advertising.

How we share information

We share information only as needed to run the Service: with infrastructure providers that host our application and database, and with the POS providers you choose to connect. We may disclose information if required by law or to protect the rights, safety, and security of our users and the Service. We do not otherwise share your data with third parties.

Data retention

We retain your account and synced data for as long as your account is active. You can disconnect a POS connection at any time from the Integrations page, which stops further syncing and removes the stored connection tokens. On request we will delete your account and associated data.

Security

We use industry-standard measures to protect your data, including encryption of POS tokens at rest, encrypted transport (HTTPS) for all traffic, and signed session cookies. No method of transmission or storage is completely secure, but we work to protect your information and limit access to it.

Your choices

You can disconnect any POS integration at any time, and you can request access to, correction of, or deletion of your account data by contacting us. Disconnecting a provider revokes our stored tokens for that connection.

Contact us

If you have questions about this Privacy Policy or your data, contact us at support@runros.app.