1. Overview
This Privacy Policy explains how Trionix Global (“we”, “us”) handles personal data in connection with the RestaurantOS platform and this website. It is intended to be read alongside our Terms & Conditions.
Where a restaurant chain uses RestaurantOS to process data about its own guests and staff, that chain is the Data Controller and we act as a Data Processor on its documented instructions.
2. Data We Collect
We collect three broad categories of data:
- Account data — names, work email addresses, phone numbers, roles and billing contacts of the people who administer a tenant;
- Customer Data — the operational records a tenant enters into the platform, such as orders, inventory, ledger entries, guest profiles and consent records;
- Usage and diagnostic data — log entries, device and browser information, IP addresses, feature usage and error reports used to keep the platform reliable and secure.
3. How We Use Data
We use data to:
- Provide, operate, secure and support the Services;
- Authenticate users and enforce role-based permissions;
- Detect, investigate and prevent fraud, abuse and security incidents;
- Produce aggregated, non-identifying statistics about platform performance;
- Communicate about service changes, incidents, invoices and support requests.
We do not sell personal data, and we do not use Customer Data to train third-party models.
4. Tenant Isolation
Every record in RestaurantOS is scoped to a tenant and a branch, and access is enforced at the database level through row-level security rather than only in the application layer.
Trionix personnel do not access tenant data in the ordinary course of business. Access occurs only where a tenant raises a support request that requires it, or where we must investigate a security or integrity incident — and every such access is written to the audit log.
5. Third-Party Processors
We rely on a limited set of vetted subprocessors, which may include:
- Cloud hosting and database providers;
- Payment processors for subscription billing;
- Email, SMS and WhatsApp messaging providers used for notifications and consented campaigns;
- Error monitoring and analytics providers.
A current list of subprocessors is available on request, and material changes are notified to tenant administrators.
6. Data Retention
Customer Data is retained for as long as the tenant’s subscription is active, and thereafter for a limited wind-down period during which the tenant may export its data.
Tenants control retention periods for their own guest records and consent logs within the platform. Audit log retention follows the tenant’s plan.
7. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, restrict or delete personal data we hold about you.
If you are a guest of a restaurant using RestaurantOS, please contact that restaurant first — they control your record. We will support them in fulfilling your request.
8. Contact
Questions about this policy, or a data protection request, can be sent to tech@trionixit.com. We respond to verified requests within the timeframe required by applicable law.
Questions about this document? Write to tech@trionixit.com or contact our team.