Legal

Privacy Policy

Last updated: June 24, 2026

1. Who We Are

Hubstaurant ("we", "us", "our") is a restaurant management and financial-analytics platform operated by PAKKR LLC (d/b/a Hubstaurant). Our platform helps restaurant operators manage menus, orders, inventory, employees, vendor communications, and — for operators who connect their bank — automatic spending and cash-flow analytics. Our website is hubstaurant.com.

2. Information We Collect

We collect information you provide directly to us, including:

  • Account registration details (name, email address, password)
  • Restaurant information (name, address, logo, menu items)
  • Operational and point-of-sale (POS) sales data used to run your restaurant
  • Payment information (processed securely via Stripe — we do not store card numbers)
  • Financial account & transaction data, only if you choose to connect your bank (see Section 5)
  • Communications you send through our platform (vendor emails, employee messages)
  • Google or Microsoft OAuth tokens when you connect your email account

We also collect usage data automatically, including IP address, browser type, pages visited, and timestamps.

3. How We Use Your Information

  • To provide, operate, and improve the Hubstaurant platform
  • To provide sales, menu, spending, cash-flow, and profit analytics (including machine-learning forecasts) for the connected restaurant
  • To send emails on your behalf when you connect Gmail or Outlook (only with your explicit authorization)
  • To process payments and manage your subscription
  • To send you service notifications and important account updates
  • To respond to your support requests
  • To comply with legal obligations

4. Google API Services

Hubstaurant uses Google APIs to allow operators to send emails from their connected Gmail or Google Workspace account. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request the gmail.send scope, which allows sending email only — we cannot read or delete your emails.

5. Financial Data & Bank Connections (Plaid)

If you choose to connect your business bank account, we use Plaid Inc. to access your financial information on a read-only basis, including account names, types, masks (last digits), balances, and transaction history (amount, date, merchant/description, category). We use this data only to read and analyze it — to power your spending, cash-flow, and profit analytics.

  • We never move money. We do not and cannot initiate payments, transfers, or any movement of funds from your accounts.
  • You enter your bank login directly with Plaid — Hubstaurant never sees or stores your banking credentials.
  • Your Plaid access token is stored encrypted and used solely to retrieve your transactions and balances.
  • You can disconnect at any time from your Cashflow page, which stops all further access.

Your use of Plaid is also governed by the Plaid End User Privacy Policy.

6. Data Sharing

We do not sell your personal or financial information. We share it only with service providers that help us operate the platform, and only as needed to provide their service — including providers for:

  • Hosting and database infrastructure
  • Payment processing
  • Read-only bank-data connections (only if you choose to connect a bank — see Section 5)
  • AI-powered analysis of your restaurant data (to generate forecasts and insights)
  • Email delivery
  • Image storage and delivery
  • Email-account connections (only when you explicitly connect your Google or Microsoft account — see Section 4)

We require these providers to protect your data and use it only to provide services to us; we do not permit them to use it for their own purposes. We may also disclose information when required by law. This list may change as our tooling evolves — a current list of our sub-processors is available on request at hello@hubstaurant.com.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide services. You may disconnect your bank (stopping further financial-data access) and request deletion of your account and associated data — including financial data — at any time by contacting us.

8. Security

We use industry-standard security measures including AES-256 encryption for stored credentials and financial access tokens, TLS 1.2+ (HTTPS) for all data in transit, encryption at rest, row-level security on our database, and multi-factor authentication on administrative access. OAuth and bank access tokens are stored encrypted and never exposed to browsers.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Disconnect your bank, Google, or Microsoft account at any time from your settings
  • Opt out of non-essential communications

10. Cookies

We use essential cookies for authentication (Supabase session cookies). We do not use tracking or advertising cookies.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at privacy@hubstaurant.com.