Legal
Last updated: June 24, 2026
Hubstaurant ("we", "us", "our") is a restaurant management and financial-analytics platform operated by PAKKR LLC (d/b/a Hubstaurant). Our platform helps restaurant operators manage menus, orders, inventory, employees, vendor communications, and — for operators who connect their bank — automatic spending and cash-flow analytics. Our website is hubstaurant.com.
We collect information you provide directly to us, including:
We also collect usage data automatically, including IP address, browser type, pages visited, and timestamps.
Hubstaurant uses Google APIs to allow operators to send emails from their connected Gmail or Google Workspace account. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only request the gmail.send scope, which allows sending email only — we cannot read or delete your emails.
If you choose to connect your business bank account, we use Plaid Inc. to access your financial information on a read-only basis, including account names, types, masks (last digits), balances, and transaction history (amount, date, merchant/description, category). We use this data only to read and analyze it — to power your spending, cash-flow, and profit analytics.
Your use of Plaid is also governed by the Plaid End User Privacy Policy.
We do not sell your personal or financial information. We share it only with service providers that help us operate the platform, and only as needed to provide their service — including providers for:
We require these providers to protect your data and use it only to provide services to us; we do not permit them to use it for their own purposes. We may also disclose information when required by law. This list may change as our tooling evolves — a current list of our sub-processors is available on request at hello@hubstaurant.com.
We retain your data for as long as your account is active or as needed to provide services. You may disconnect your bank (stopping further financial-data access) and request deletion of your account and associated data — including financial data — at any time by contacting us.
We use industry-standard security measures including AES-256 encryption for stored credentials and financial access tokens, TLS 1.2+ (HTTPS) for all data in transit, encryption at rest, row-level security on our database, and multi-factor authentication on administrative access. OAuth and bank access tokens are stored encrypted and never exposed to browsers.
Depending on your location, you may have the right to:
We use essential cookies for authentication (Supabase session cookies). We do not use tracking or advertising cookies.
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at privacy@hubstaurant.com.