Legal

Privacy Policy

Last updated: July 2026

The Pass is based in Ontario, Canada, and handles personal information in line with Canada's federal privacy law (PIPEDA). This policy explains what we collect, why, and who else sees it.

1. What we collect

When you or your restaurant use The Pass, we collect:

CategoryExamples
Account infoYour name, email, and password (stored securely hashed, never in plain text)
Restaurant infoRestaurant name, and whatever you enter about it (menu, recipes, prep lists)
Staff infoNames, emails, and roles for anyone you invite to your restaurant's workspace
Operational dataRecipes, prep lists, orders, bar inventory counts, 86 board entries, events
Scanned documentsPhotos or PDFs of invoices, order confirmations, and recipes you upload to be scanned
Usage dataBasic technical info like login timestamps, needed to keep sessions secure

2. How we use it

We do not sell your data, or your restaurant's data, to anyone.

3. Who else sees your data

The Pass relies on a small number of infrastructure providers to run the Service. We don't have our own servers — your data lives with these providers, under agreements that restrict them from using it for anything other than providing their service to us:

We don't share your data with any other third party, and never with advertisers.

4. Where your data is stored

Our infrastructure providers may store and process data on servers outside Canada, including in the United States. By using The Pass, you consent to your information being processed in those locations, under the privacy commitments described in this policy.

5. Data security

Every restaurant's data is isolated at the database level — staff and admins can only ever see data belonging to their own restaurant, enforced by row-level security policies, not just by the app's interface. Data is encrypted in transit. Sensitive credentials (like API keys) never reach the browser and are only used server-side.

6. How long we keep it

We keep your data for as long as your account is active. If you close your account, we'll delete your restaurant's data within a reasonable period, except where we're required to retain records (e.g. billing history) for legal or accounting reasons.

7. Your rights

You can access, correct, or request deletion of your personal information at any time by emailing us. If you're a staff member invited to a restaurant's workspace (not the account owner), you can ask us or your restaurant's admin to remove your access.

8. Cookies & local storage

The Pass uses your browser's local storage to keep you logged in between visits — this is a session token, not a tracking cookie. We don't use third-party advertising or analytics trackers.

9. Children's privacy

The Pass is a business tool for restaurant operators and staff, not intended for use by children, and we don't knowingly collect information from anyone under 16.

10. Changes to this policy

We may update this policy as the product changes. We'll post the updated version here with a new "last updated" date.

11. Contact

Questions about this policy, or want to exercise your data rights? Email adityamenonsreeraj@gmail.com.