Legal

Privacy Policy

Effective date: July 15, 2026

B Botz (“we,” “our,” or “us”) operates a self-checkout and order management platform for restaurants. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our platform — whether you are a restaurant owner, a staff member, or a customer placing an order. We are committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian privacy law.

1. Information We Collect

From restaurant owners and staff

  • Name and email address (used to create and manage your account)
  • Restaurant name, address, phone number, and timezone
  • Stripe API credentials (stored encrypted; used solely to process your customers' payments)
  • Menu content, pricing, and promotional configuration

From customers placing orders

  • Name and mobile phone number (required to create an order and send order-ready notifications)
  • Email address (optional; provided by the customer to receive a receipt)
  • Order details including items, modifiers, and special instructions
  • Payment method details — processed directly by Stripe; B Botz only stores the card brand and last four digits

Automatically collected

  • IP address and general usage information for rate limiting and security
  • Session cookies required for authentication (staff login)

2. How We Use Your Information

  • To create and manage restaurant accounts and staff access
  • To process customer orders and payments through Stripe
  • To send customers order-status SMS notifications via Twilio (e.g. “Your order is ready”)
  • To send email receipts when requested by the customer
  • To operate the loyalty stamp program and deliver reward codes via SMS
  • To provide restaurant owners with analytics about their own orders and revenue
  • To send one-time login codes (OTP) to staff email addresses
  • To prevent fraud, enforce rate limits, and maintain platform security

We do not use customer data for advertising, profiling, or any purpose beyond operating the ordering platform on behalf of the restaurant.

3. Information We Share

We do not sell personal information. We share information only with the following service providers, solely to operate the platform:

Stripe

Payment processing. Customer payment details are submitted directly to Stripe and governed by Stripe's privacy policy. B Botz does not store card numbers or CVVs.

Twilio

SMS delivery. Customer mobile phone numbers are transmitted to Twilio to send order-ready and loyalty notifications.

Supabase

Database and file storage. All platform data is stored in Supabase's infrastructure, hosted on AWS in the United States.

Google (Gmail / SMTP)

Email delivery. Staff OTP codes and customer receipt emails are sent via Gmail.

We may also disclose information if required by law, court order, or to protect the rights and safety of users or the public.

4. Data Retention

Order records (including customer name and phone) are retained for as long as the restaurant account remains active, to support refund processing, loyalty tracking, and reporting. Restaurant owners may request deletion of their account and associated data by contacting us at support@bbotz.com. Customer data is stored on behalf of the restaurant; deletion requests from individual customers should also be directed to us and we will action them within 30 days.

5. Your Rights Under PIPEDA

You have the right to:

  • Know what personal information we hold about you
  • Access and correct inaccurate information
  • Withdraw consent and request deletion, subject to legal obligations
  • File a complaint with the Office of the Privacy Commissioner of Canada

To exercise any of these rights, contact us at support@bbotz.com.

6. Cookies

We use strictly necessary cookies to maintain staff login sessions and to identify the restaurant associated with a QR code scan (via a session cookie set at the time of scan). We do not use tracking, advertising, or analytics cookies.

7. Security

We use industry-standard security practices including HTTPS encryption in transit, row-level security on our database, and HMAC-signed authentication tokens. Stripe API keys provided by restaurant owners are stored in encrypted form. No system is completely secure, and we encourage you to contact us immediately at support@bbotz.com if you suspect unauthorized access.

8. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Restaurant owners will be notified by email of material changes. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.

9. Contact Us

For any privacy questions or requests, contact our Privacy Officer at: