Privacy Policy
Effective · Version 3
See also: Terms of Service · Copyright · Accessibility
Contents (15 sections)
In plain English
- We store what you and your team put into the app so the app can work. Your restaurant’s data is separate from every other restaurant’s.
- We don’t sell your information, don’t run ads, and don’t use your data to train AI.
- The website sets no cookies. The app uses only the cookies it needs to keep you signed in and working.
- Our small team looks at restaurant data only to help you, fix problems, run billing or keep things secure — and each time an operator uses “view as” to open your restaurant in the app, it’s logged.
- Text alerts only start after you prove the number is yours; reply STOP to leave, and your number is never shared for marketing.
- If you sign in with Google, we receive only basic profile details (name, email and whether Google verified it, account ID, Workspace domain, profile picture link), and use them to sign you in and run your account.
- Three features send a photo, or a typed question, to an AI service — only when you use them, and the app says so.
- Export your restaurant’s items, vendors, purchase history, waste log and recipes as spreadsheets, and the last 90 days of food-safety logs, any time; email us for a copy of anything else we hold about you or to delete your account.
This summary is here to help you read the document. The numbered sections below are the policy.
What changed in version 3
- For accounts created before September 28, 2026, this version applies from October 28, 2026; until then version 2 applies to them.
- Our team’s access to restaurant data, the AI coding tools our team uses, and the log kept of it (Who can see it).
- Every service provider named, including the stock-photo services, the password breach check, push services and our team’s email (Who can see it).
- Text alerts: the code that proves a number is yours, and the consent record we keep (Text messages).
- Which emails you can turn off, and the one-click unsubscribe on the Monday summary (Email and app notifications).
- Exact retention periods, and what happens to photos when a restaurant is deleted (How long we keep it).
- Suppliers who answer an order, sign-ups that aren’t finished, and photo location data removed (What we collect).
- Minimum ages, Nevada requests, and how to appeal a decision on a privacy request (Your choices and rights).
1. Who this covers and who we are
This Privacy Policy explains how Summit Systems LLC (“Summit Systems,” “we”), a Nevada limited liability company based in Reno, Nevada, doing business as Kitchen on Hand, handles personal information in connection with Kitchen on Hand: the app at app.kitchenonhand.com, the website at kitchenonhand.com, the order pages we host for suppliers, and the emails, app notifications and text messages we send (together, the “Service”).
It applies to visitors to the website, to people who create accounts, to Team Members who are invited to a restaurant’s account or given a login by their restaurant, and to suppliers and their staff who receive an order through the Service. It doesn’t cover the practices of your restaurant, your suppliers or other websites we link to. In this Policy, “Owner,” “Team Member” and “Restaurant Data” have the meanings given in the Terms of Service.
Two roles. For the information a restaurant enters about its business, its staff and its suppliers, the restaurant decides what goes in and who on the team sees it; we process that information on the restaurant’s behalf, as its service provider, under the data processing terms in the Terms of Service. For your account details and for how the website and app are used, we decide how the information is handled. Either way, this Policy tells you what happens.
No sale, no ads. We don’t sell personal information, we don’t share it for cross-context behavioral advertising, and we don’t use it for advertising at all.
2. What we collect
Information you give us
- Account details — email address, username, password (stored only as a one-way hash that we can’t read; while you finish signing up by email — up to about an hour — it is held encrypted so your account can be created when you enter the emailed code, then deleted), and the display name you choose. If your restaurant invites you or makes a login for you, it gives us your name, email address or username. If you sign in with Google, the name, email and profile picture link Google sends us (Section 7). When you create an account we record which version of the Terms you agreed to, and when.
- Mobile number and text-alert consent — only if you turn on text alerts: your number, the exact consent wording you agreed to, when you agreed, and when you confirmed the code we texted to prove the number is yours (Section 8).
- Restaurant information — restaurant name, time zone, the address, phone and reply email you add for orders, and everything your team enters to run the kitchen: items, vendors and their contact details (including rep names, email addresses, phone numbers and the account numbers you save for sending them orders), prices, orders, deliveries, waste logs, inventory counts, sales totals you type in, recipes, calendar tasks, food-safety logs, team notices, and notes.
- Photos — item and recipe photos, delivery-invoice photos, and photos attached to bug reports. Photos are re-saved in the app before they’re uploaded, which removes hidden details such as the location, time and device the picture was taken with. A photo or PDF (of an invoice or order guide, for example) used to add items is read and then discarded; it isn’t stored, and neither is a list you paste in to be read.
- Payment information — when you subscribe, your card details are entered directly with Stripe, our payment processor. We receive only your billing status and subscription details (plan, number of locations, renewal date) — never your card number.
- Messages to us — support emails, bug reports and suggestions (with the page you were on and your browser type and screen size, so we can reproduce a problem), and questions you type into the in-app help assistant.
Information from suppliers
When a restaurant sends a supplier an order through the Service, the supplier’s staff can answer through a private order page with no account: confirm the order, mark items short or out, suggest a substitute or a different price, give a delivery date and leave a note. We store what they send with that order and show it to the restaurant (Section 4).
Information collected automatically
- App activity — the actions you take (for example marking an item as needing an order) and when. Much of this is the product: the app records who checked what and when so the restaurant can see it.
- Device and technical data — browser type, operating system, screen size, IP address (in our hosting and sign-in providers’ logs and session records), and error reports if something goes wrong in the app (Section 6).
- Sign-in protection — to slow down password guessing we count failed sign-ins against two one-way codes, one made from the account’s email address (or the name typed, if it matches no account) and one from the IP address — never the address itself — and delete the counts after a day.
- Sign-ups that aren’t finished — if you start creating an account but don’t enter the emailed code, we keep the email address and restaurant name you typed for 30 days so we can see where sign-up goes wrong. We don’t email you or use it for anything else.
- Website analytics — page views and referring sites on kitchenonhand.com, counted without cookies (Section 6).
- Push notification tokens — if you turn on app notifications, the browser issues a token that lets us send them to that device.
Information we don’t collect
We don’t collect precise location, contacts, biometrics, government ID numbers, dates of birth, or anything about your customers’ identities. The Service is not designed to hold health, allergen or dietary information about any person, and we ask that you not enter it.
3. Why we use it
We use personal information to:
- Provide the Service: sign you in, show your restaurant its data, run the arithmetic, send the orders, emails, notifications and texts you or your restaurant ask for.
- Bill for paid plans and keep the records tax and accounting law requires.
- Answer support requests and bug reports.
- Keep the Service secure: detect misuse, limit abuse (for example how many codes or emails can be sent), enforce permissions, investigate incidents.
- Stop the free trial from being restarted: we keep a one-way fingerprint (a hash) of the email address that started each trial, which lets us recognise that address if it is used again — it is not the address itself, though anyone who already has an address could check it against the fingerprint — and while a restaurant is on its free trial we compare its item names with other accounts’ — when it imports an item list, and once a day. Only our team sees a possible match; it is never shown to another customer.
- Fix problems: error reports tell us where the app broke.
- Understand how the Service is used, in aggregate, so we can improve it.
- Send the account and service emails described in Section 9.
- Comply with the law and protect our rights and yours.
We don’t sell personal information, we don’t use it for advertising, and we don’t use your restaurant’s data to train AI models.
5. Where AI is used
Three features send information to Anthropic, an AI provider, to work. The app says so on the screen where each one is used:
- Adding items from photos, a PDF or a pasted list — when you choose to add items from photos or a PDF (of an invoice or order guide, for example) or from a list you paste in, that photo, PDF or text is sent so the items, units and prices in it can be read. What comes back is shown to you for review before anything is saved, and the photo, PDF or text isn’t kept. A spreadsheet you upload, and cells copied from a spreadsheet (two or more columns) and pasted in, are read in your browser instead and aren’t sent to Anthropic.
- Receiving invoice reader — when you attach a photo of a delivery invoice at check-in, the photo is sent together with the names, units and ordered quantities of the lines on the purchase order it belongs to, so the invoice can be matched against them. What comes back is shown to you for review before anything is changed.
- Help assistant — when you type a question into the in-app help, your question, the conversation so far, your restaurant’s name and your role are sent so it can answer for what your permissions allow. The conversation isn’t saved by us.
Each runs only when you use that feature — for the invoice reader, when you attach an invoice photo; none of them sends anything in the background. (Separately, our team’s own use of AI tools is described under Section 4.) Under Anthropic’s commercial terms, the information is used to produce the response and is not used to train its models; Anthropic may keep it for a limited time under its own policies to run and secure its service. AI output can be wrong; treat it as a suggestion to check, not a fact, and don’t rely on it for legal, safety, medical or financial decisions.
7. Signing in with Google
If you choose “Continue with Google” or “Sign up with Google”, we ask Google only for basic sign-in information (Google’s standard “email” and “profile” sign-in permissions). Google tells us your name, your email address and whether Google has verified that address, your Google account ID, and — for a Google Workspace account — your organization’s domain, and sends a link to your profile picture. We use the domain to check that Google runs the inbox for that address. We use them to sign you in, to set up and identify your account, and to show your name to your team. Your email address is then used the same way as one typed in at sign-up — for the uses in Section 3: service, security and billing emails, your billing record with our payment processor, telling our team a new account was made, and the one-free-trial check. The profile picture link is stored with your sign-in details; we don’t show it or use it for anything else.
- We don’t get your Google password.
- We don’t ask for access to your Gmail, contacts, calendar, files or anything else in your Google account.
- We don’t sell this information, use it for advertising or to train AI, or share it with anyone except the service providers listed in Section 4 (for example our hosting, email, payment and error-reporting providers, our team’s email for new sign-up notices, and our AI coding tools when we investigate a problem), your own restaurant team and suppliers in the ways that section describes (for example your name on an order you send), when the law requires it, or as part of a merger or sale of the business described there. People on our team look at it only when needed for support or security.
- Google sign-in works only with Gmail and Google Workspace addresses, where Google runs the inbox itself. For any other address, sign in with your email or username and password.
- You can add a password in My Account and sign in with that instead. You can remove Kitchen on Hand in your Google Account settings (third-party connections) at any time; Google then stops sharing your details with us unless you choose “Continue with Google” again. To delete your account and what we hold about you, email us (Section 15).
Our use of information received from Google follows the Google API Services User Data Policy, including its Limited Use requirements.
8. Text messages (SMS)
Text alerts may not be available yet. When they are, and if you choose to turn them on under Settings → Notifications → Text alerts, we’ll send you operational messages about the restaurant you work at — for example an item flagged as an emergency. We don’t send marketing texts.
- You opt in yourself, in the app: you enter your own number, tick the consent box, and type back a code we text to that number to prove it’s yours. Nobody else — not your manager, not the Owner — can sign you up, and no alert is sent before you enter the code.
- Message frequency varies with your restaurant’s activity. Message and data rates may apply.
- Reply STOP to any message to opt out. STOP and replies like it (“unsubscribe”, “wrong number”, “take me off”) end your alerts at once; any other reply asking us to stop, in whatever words, ends them within 10 business days. Every reply is kept and read by our team. You can also turn text alerts off in the app. Reply HELP for help.
- We keep a record of your consent — the number, the exact wording you agreed to, and when you agreed, confirmed and stopped — for 5 years after your text alerts end, as proof of consent. The record is visible only to the server, not to anyone at your restaurant.
- If you change your number or give up your phone, turn text alerts off first (or reply STOP), so the next owner of the number doesn’t get your alerts.
- We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Your mobile number and your text-message opt-in are shared only with Twilio, the service that delivers the messages, to deliver them — and, if you text our alerts number anything other than STOP or HELP, with our email providers (Resend, Google) so a person on our team can read it.
9. Email and app notifications
- Account and service emails — sign-up and confirmation codes, invitations (sent to the address a restaurant gives us when it invites you — we don’t use that address for anything else), password resets, security notices (for example when Google sign-in is added to your account), the welcome email, free-trial and yearly-renewal reminders, billing notices, and important changes to the Service or these policies. These are part of having an account and can’t be turned off while the account is open.
- Notification emails — emergency alerts, urgent team alerts, urgent item requests, delivery problems, suppliers’ replies to your orders, and the Monday summary of last week’s spend and waste. You can turn each of these off under Settings → Notifications, or all of them at once. The Monday summary has a one-click unsubscribe link in every email.
- Orders to your suppliers — we email a purchase order to a supplier only when someone on your team presses Send, and only to the addresses your team saved for that supplier. It comes from our orders address in your restaurant’s name (“Your Restaurant via Kitchen on Hand”), shows your restaurant’s name, the order-contact details from Settings and the order itself (with prices only if you chose to share them), and replies go to your restaurant, not to us. A record of each order sent is kept with your order history. The email (and a texted order) carries a private link to that order for the supplier — see “With your suppliers” under Section 4.
- App notifications — only if you enable them on a device; turn them off in the app or in your browser settings at any time.
- We don’t send marketing email. If we ever do, it will go only to people who agreed to it, and every one will have an unsubscribe link and our mailing address.
10. How long we keep it
- Restaurant Data — for as long as the restaurant exists in the Service. When a restaurant is deleted, its data is removed from the live Service immediately and its photos and invoice photos shortly after — at the latest by the next day’s clean-up if the first attempt fails — and copies in backups are overwritten on our database provider’s backup schedule. (A photo that was copied to another of your locations stays with that location.)
- Account details — for as long as the account exists. When you ask us to delete your account, we delete it within 30 days, except for the records listed below that we keep for the times given. A login that no longer belongs to any restaurant can be deleted automatically. What you entered for a restaurant stays with that restaurant, with your name taken off it — except copies of orders you sent to suppliers, which keep the name and email they went out with.
- Record that an account was deleted — the date and a shortened form of the address (for example m•••@gmail.com), in our operators’ log, for 2 years.
- Billing records — Stripe keeps payment records under its own policies, and we keep what tax and accounting law requires, typically seven years.
- Free-trial record — a one-way fingerprint (a hash) of the email address that started a free trial, not the address itself, and when, kept after the account is deleted, for as long as we offer free trials, so the same trial can’t be restarted. A note our team makes when two restaurants’ item lists match keeps the restaurant names, not anyone’s email address.
- Text-alert consent records — 5 years after your text alerts end (Section 8), then deleted. Replies to our alerts number — 5 years, then deleted.
- Record of agreeing to the Terms — which versions of the Terms and this Policy a login agreed to, when and how, any arbitration opt-out, and a one-way fingerprint (a hash) of its email address: kept after the account is deleted, for 7 years after the deletion (the time a claim about the agreement could be brought, plus a margin), then deleted.
- Unfinished sign-ups — 30 days for an email sign-up that never got its code. A login made with Google that never finishes setting up a restaurant stays until you finish or ask us to delete it. Failed sign-in counts — one day.
- Error reports and technical logs — up to 90 days.
- Bug reports and suggestions, with their photos — 2 years, then deleted. Support emails — up to two years, so we can refer back if a problem recurs. That includes our team’s own email copies: notices and forwarded messages in our team’s inboxes are deleted within the same periods.
- Our operators’ activity log (team changes with the names and email addresses involved, restaurant deletions, “view as”) — 2 years, then deleted, even after an account is deleted.
- Invitations — the email address a restaurant invited stays with that restaurant’s pending and past invitations until the restaurant deletes the invitation or the restaurant is deleted.
- Inactive restaurants — if a restaurant has had no sign-ins for 18 months and no active plan, we may delete it after emailing the Owner at least 60 days in advance.
11. How we protect it
We use reasonable technical and organizational measures to protect personal information, including encryption in transit (HTTPS everywhere) and at rest, hashed passwords, checks of new passwords against known breaches, limits on repeated sign-in attempts, row-level access rules in the database so each restaurant can only reach its own data, role-based permissions inside a restaurant, private storage with short-lived links for invoice and bug-report photos, removal of location data from photos, automated backups, error monitoring that strips personal details, and access to production systems limited to the people who need it, with each time an operator uses “view as” to open a restaurant in the app logged.
No system is perfectly secure, and we can’t promise that information will never be accessed or disclosed without authorization. If we learn of a breach that affects your personal information, we will notify you by email at the address on your account, and notify any regulator, as the law requires — including, for Nevada residents, as required by Nevada Revised Statutes 603A.220 — without unreasonable delay.
You can help: use a strong, unique password, remove Team Members who leave, and don’t share logins.
12. Your choices and rights
Things you can do yourself
- Change your name, username, password and notification settings in the app.
- Unsubscribe from the Monday summary with the link in any of those emails.
- Turn text alerts on or off, where they are offered.
- Export your restaurant’s items, vendors, purchases, waste and recipes as spreadsheets, and the most recent 90 days of food-safety logs (Owners, and roles the Owner allows).
- Delete a restaurant (Owners).
Things you can ask us for
Email us (Section 15) to request a copy of the personal information we hold about you, to correct it, to delete your account, or to ask a question about this Policy. We’ll respond within 45 days (we may extend that once by 45 more days if we need to, and we’ll tell you why). We may need to verify that a request comes from the account holder before acting on it — usually by replying from, or confirming with, the email address on the account. You can also have someone else make a request for you; we’ll ask for proof that you authorized them, and we may still confirm the request with you directly. We won’t treat you differently for exercising these rights. If we turn down a request, we’ll say why, and you can appeal by replying with “Appeal” in the subject line; we’ll answer the appeal within 45 days.
If you’re a Team Member
Information you enter into a restaurant’s account (checks, counts, waste logs, notes) belongs to that restaurant and is visible to its Owner. Requests to change or delete it should go to the Owner; we act on the Owner’s instructions for Restaurant Data, and we’ll pass a request we receive to the Owner.
If you’re a supplier
Your contact details and anything you send through an order page are held for the restaurant that sent you the order. Ask that restaurant to correct or delete them; we’ll help it do so.
State privacy laws
Residents of states with consumer-privacy laws (for example California, Colorado, Connecticut, Nevada, Oregon, Texas, Utah and Virginia) may have specific rights to know about, access, correct, delete or get a copy of their personal information, and to opt out of its sale, of targeted advertising and of profiling. We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use it for profiling that has legal or similarly significant effects, and we don’t use or disclose sensitive personal information for anything but providing the Service. We honor the rights above for everyone, regardless of state or of whether a law applies to us. California residents: we don’t share personal information with third parties for their direct marketing.
Nevada residents
We do not sell covered information as defined in Nevada Revised Statutes 603A.300 to 603A.360. You may still send us a request directing us not to sell it, at support@kitchenonhand.com with “Nevada opt-out” in the subject line. We’ll confirm within 60 days. To review or ask us to change the covered information we hold about you, use the same address (Section 15).
Children and young workers
Kitchen on Hand is a business tool, not a service for children. Owners must be 18 or older. Team Members must be at least 14, or the minimum age to work in a restaurant where they are, if higher — restaurants often employ teenagers, and the Owner is responsible for having any permission a young worker needs. No one under 13 may use the Service. We don’t knowingly collect personal information from children under 13; if we learn that we have, we delete it. If you believe a child under 13 has an account, email us.
13. International visitors
Kitchen on Hand is offered to businesses in the United States, and personal information is processed and stored in the United States. If you visit the website or use the Service from somewhere else, your information is transferred to and handled in the United States, where privacy laws may differ from those where you live.
If you are in the European Union, the United Kingdom or another place whose law gives you specific rights over your personal information — such as the right to access, correct, delete, restrict or object to the use of it, or to receive a copy in a portable form — you can exercise them by emailing us (Section 15), and we will honor them as that law requires.
14. Changes to this Policy
We’ll update this Policy when our practices change. If a change materially reduces your rights or changes how we use information you’ve already given us, we’ll email account holders and show a notice in the app at least 30 days before it takes effect. The date and version number at the top of this page identify the version you are reading.
15. Contact
Summit Systems LLC (doing business as Kitchen on Hand), Reno, Nevada. Email support@kitchenonhand.com with “Privacy” in the subject line — it’s the address for every privacy request, including the ones above.
Questions about this document? Email support@kitchenonhand.com.