Skip to content

Privacy Policy — version 2 (previous)

Effective · Last updated · Version 2

See also: Current Privacy Policy · Terms of Service

In plain English

  • We store what you and your team put into the app so the app can work. Your restaurant’s data is separate from every other restaurant’s.
  • We don’t sell your information, don’t run ads, and don’t use your data to train AI.
  • The website sets no cookies. The app uses only the cookies it needs to keep you signed in, remember your restaurant and protect sign-up.
  • If you ever opt in to text alerts, you can reply STOP to leave, and your number is never shared for marketing.
  • If you sign in with Google, we receive only your name, email and profile picture link, and use them only to sign you in.
  • Three features send a photo, or a typed question, to an AI service — only when you use them.
  • Export or delete your data any time; email us for a copy of what we hold about you.

This summary is here to help you read the document. The numbered sections below are the policy.

What changed in version 2

  • This is the previous version, kept for reference. It applies to accounts created before September 28, 2026 until October 28, 2026. The current policy is at kitchenonhand.com/privacy.
  • The one-way fingerprint we keep of the email address that starts a free trial, so the trial can’t be restarted, and the item-name check for repeat trials (Why we use it, How long we keep it).
  • What we receive when you sign in with Google (Signing in with Google).
  • Clearer wording on text message alerts (Text messages).
  • Sending orders to your suppliers, and what a supplier sees through the private order link (Who can see it).

1. Who this covers and who we are

This Privacy Policy explains how Summit Systems LLC (“Summit Systems,” “we”), a Nevada limited liability company based in Reno, Nevada, handles personal information in connection with Kitchen on Hand: the app at app.kitchenonhand.com, the website at kitchenonhand.com, and the emails, app notifications and any text messages we send (together, the “Service”).

It applies to visitors to the website, to people who create accounts, and to Team Members who are invited to a restaurant’s account. It doesn’t cover the practices of your restaurant, your suppliers or other websites we link to. In this Policy, “Owner,” “Team Member” and “Restaurant Data” have the meanings given in the Terms of Service.

Two roles. For the information a restaurant enters about its business and staff, the restaurant’s Owner decides what goes in and who on the team sees it; we process that information on the restaurant’s behalf. For your account details and for how the website and app are used, we decide how the information is handled. Either way, this Policy tells you what happens. Owners who need a data processing agreement for their restaurant can request one by email (Section 15).

2. What we collect

Information you give us

  • Account details — email address, username, password (stored only as a one-way hash; we can’t read it), and the display name you choose. If you sign in with Google, the name, email and profile picture link Google sends us (Section 7).
  • Mobile number — only if you add one for text alerts (Section 8).
  • Restaurant information — restaurant name, time zone, the address, phone and reply email you add for orders, and everything your team enters to run the kitchen: items, vendors and their contact details (including the addresses and account numbers you save for sending them orders), prices, orders, deliveries, waste logs, inventory counts, sales totals you type in, recipes, calendar tasks, food-safety logs, team notices, and notes.
  • Photos and files — item photos, invoice and order-guide photos, and screenshots attached to bug reports.
  • Payment information — when you subscribe, your card details are entered directly with Stripe, our payment processor. We receive only your billing status and subscription details (plan, number of locations, renewal date) — never your card number. Card details stay with Stripe.
  • Messages to us — support emails, bug reports and questions you type into the in-app help assistant.

Information collected automatically

  • App activity — the pages you open, the actions you take (for example marking an item as needing an order), and when. Much of this is the product: the app records who checked what and when so the restaurant can see it.
  • Device and technical data — browser type, operating system, screen size, IP address, and error reports if something goes wrong (which may include the page you were on and what the app was doing).
  • Website analytics — page views and referring sites on kitchenonhand.com, collected without cookies (Section 6).
  • Push notification tokens — if you turn on app notifications, the browser issues a token that lets us send them to that device.

Information we don’t collect

We don’t collect precise location, contacts, biometrics, government ID numbers, or anything about your customers’ identities. The Service is not designed to hold health, allergen or dietary information about any person.

3. Why we use it

We use personal information to:

  • Provide the Service: sign you in, show your restaurant its data, run the arithmetic, send the notifications you’ve turned on.
  • Bill for paid plans and keep the records tax and accounting law requires.
  • Answer support requests and bug reports.
  • Keep the Service secure: detect misuse, enforce permissions, investigate incidents.
  • Stop the free trial from being restarted: we keep a one-way fingerprint of the email address that started each trial (enough to recognise that address if it is used again, not to read it back), and while a restaurant is on its free trial we compare its item names with other accounts’ — when it imports an item list, and once a day. Only our team sees a possible match; it is never shown to another customer.
  • Fix problems: error reports tell us where the app broke and for whom.
  • Understand how the Service is used, in aggregate, so we can improve it.
  • Send the account and service emails described in Section 9.
  • Comply with the law and protect our rights and yours.

We don’t sell personal information, we don’t use it for advertising, and we don’t use your restaurant’s data to train AI models.

4. Who can see it

Inside your restaurant

The Owner of a restaurant can see all of its data, including what each Team Member entered. Team Members see what their role allows. Every restaurant’s data is separated from every other restaurant’s; a person can only see restaurants they have been added to.

Service providers

We share information with companies that help us run the Service. Each receives only what it needs, is bound by its own privacy commitments, and may not use the information for its own purposes:

ProviderWhat it doesWhat it receives
SupabaseDatabase and sign-inAccount details and all Restaurant Data (stored in the United States)
VercelHosting and website analyticsRequests to the app and website, including IP address; cookieless page-view counts for the website
StripePaymentsThe email and card details you enter on Stripe’s payment page; it reports your billing status back to us
ResendEmail deliveryEmail address and the content of emails we send you, and orders you choose to email to your suppliers (supplier email addresses and order contents)
TwilioText-message delivery, where text alerts are offeredMobile number and the content of alerts, only if you opt in
SentryError reportingTechnical details of errors, the page involved and the app version — no name, email or user id
AnthropicAI featuresThe photo you submit for import; the delivery-invoice photo plus the names and quantities on the purchase order it is matched against; or your question to the help assistant with the conversation so far, your restaurant’s name and your role

We’ll update this table before a new provider starts receiving personal information, and we’ll email Owners when one is added.

Other situations

  • Legal requirements — if we’re required to by law, subpoena or court order, or to protect the safety or rights of any person or of the Service.
  • Business changes — if Summit Systems is acquired, merges or sells the Service, the information would transfer with it; we’d notify Owners when that happens, or as soon as we are permitted to, and this Policy would continue to apply until changed as described in Section 14.
  • With your direction — for example, when you export data and send it elsewhere.
  • With your suppliers, when you send them an order — an emailed or texted order includes a private link. Anyone who opens it (no account needed) sees that one order: your restaurant’s name, the address and phone you added for orders, your account number with that supplier, the items and quantities, your note, and prices only if you chose to share them. The supplier can use it to confirm the order and send back changes and a note, which we store with the order and show to your team. The link stops working when the order is received or cancelled, when you send the order again or turn the link off, and 30 days after sending.

We do not share personal information with data brokers, advertisers or anyone else for their marketing.

5. Where AI is used

Three features send information to Anthropic, an AI provider, to work:

  • Photo import — when you choose to import from a photo of an invoice or order guide, that image is sent so the items, units and prices on it can be read. What comes back is shown to you for review before anything is saved.
  • Receiving invoice reader — when you photograph a delivery invoice at check-in, the photo is sent together with the names, units and ordered quantities of the lines on the purchase order it belongs to, so the invoice can be matched against them. What comes back is shown to you for review before anything is saved.
  • Help assistant — when you type a question into the in-app help, your question, the conversation so far, your restaurant’s name and your role are sent so it can answer for what your permissions allow.

All three are things you start yourself; nothing is sent in the background. Under our agreement with the provider, the information is used only to produce the response and is not used to train its models. AI output can be wrong; treat it as a suggestion to check, not a fact.

6. Cookies, analytics and tracking

  • The website (kitchenonhand.com) sets no cookies. We count page views with Vercel Web Analytics, which does not use cookies, does not store IP addresses, and does not follow you across other sites.
  • The app (app.kitchenonhand.com) uses only strictly necessary cookies: the ones that keep you signed in, remember which restaurant you have open, and protect the sign-up flow. It stores some information in your browser’s local storage so the walkthrough and inventory count keep working without a connection and so you aren’t shown the same tip twice.
  • There are no advertising cookies, no third-party tracking pixels, and no cross-site tracking anywhere in the Service. Because we don’t track visitors across sites, we don’t respond differently to “Do Not Track” or Global Privacy Control signals — there is nothing to opt out of.

7. Signing in with Google

If you choose “Continue with Google” or “Sign up with Google”, Google tells us your name, your email address and whether Google has verified that address, and sends a link to your profile picture. We use them only to sign you in, to set up and identify your account, and to show your name to your team. The profile picture link is stored with your sign-in details; we don’t show it or use it for anything else.

  • We don’t get your Google password.
  • We don’t ask for access to your Gmail, contacts, calendar, files or anything else in your Google account.
  • We don’t sell this information or share it with anyone else, and we don’t use it for advertising or to train AI.
  • Google sign-in works only with Gmail and Google Workspace addresses, where Google runs the inbox itself. For any other address, sign in with your email or username and password.
  • You can add a password in My Account and sign in with that instead. You can remove Kitchen on Hand in your Google Account settings (third-party connections) at any time; Google then stops sharing your details with us unless you choose “Continue with Google” again. To delete your account and what we hold about you, email us (Section 15).

Our use of information received from Google follows the Google API Services User Data Policy, including its Limited Use requirements.

8. Text messages (SMS)

Text alerts are not yet available in every account. When they are, and if you add a mobile number under Settings → Notifications and agree to text alerts, we’ll send you operational messages about the restaurants you work at — for example an item flagged as an emergency. We don’t send marketing texts.

  • You opt in yourself, in the app. Nobody can sign you up for texts on your behalf.
  • Message frequency varies with your restaurant’s activity. Message and data rates may apply.
  • Reply STOP to any message to opt out, or remove your number in the app. Reply HELP for help.
  • We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Your mobile number and your text-message opt-in are shared only with Twilio, the service that delivers the messages, and only to deliver them.

9. Email and app notifications

  • Account and service emails — sign-up codes, invitations, password resets, billing receipts and notices, and important changes to the Service or these policies. These are part of having an account and can’t be turned off while the account is open.
  • Operational emails — emergency alerts, item requests, receiving issues and the Monday summary of last week’s spend and waste. You can turn each of these off under Settings → Notifications.
  • Orders to your suppliers — we email a purchase order to a supplier only when someone on your team presses Send, and only to the addresses your team saved for that supplier. It shows your restaurant’s name, the order-contact details from Settings and the order itself (with prices only if you chose to share them), and replies go to your restaurant, not to us. A record of each order sent is kept with your order history. The email (and a texted order) carries a private link to that order for the supplier — see “With your suppliers” under sharing.
  • App notifications — only if you enable them on a device; turn them off in the app or in your browser settings at any time.
  • We don’t send marketing email today. If we ever do, it will have an unsubscribe link and you won’t receive it unless you’ve agreed to.

10. How long we keep it

  • Restaurant Data — for as long as the restaurant exists in the Service. When an Owner deletes a restaurant, its data is removed from the live Service immediately and from backups on our hosting provider’s backup schedule.
  • Account details — for as long as the account exists. When you ask us to delete your account, we delete it within 30 days, except for what we must keep (below).
  • Billing records — for as long as tax and accounting law requires, typically seven years.
  • Free-trial record — a one-way fingerprint of the email address that started a free trial (not the address itself), and when, kept after the account is deleted so the same trial can’t be restarted. A note our team makes when two restaurants’ item lists match keeps the restaurant names, not anyone’s email address.
  • Error reports and technical logs — 90 days.
  • Support emails and bug reports — up to two years, so we can refer back if a problem recurs.
  • Inactive restaurants — if a restaurant has had no sign-ins for 18 months and no active plan, we may delete it after emailing the Owner at least 60 days in advance.

11. How we protect it

We use reasonable technical and organizational measures to protect personal information, including encryption in transit (HTTPS everywhere) and at rest, hashed passwords, row-level access rules in the database so each restaurant can only reach its own data, role-based permissions inside a restaurant, signed short-lived links for private photos, automated backups, error monitoring, and access to production systems limited to the people who need it.

No system is perfectly secure, and we can’t promise that information will never be accessed or disclosed without authorization. If we learn of a breach that affects your personal information, we will notify you by email at the address on your account, and notify any regulator, as the law requires.

You can help: use a strong, unique password, remove Team Members who leave, and don’t share logins.

12. Your choices and rights

Things you can do yourself

  • Change your username, password and notification settings in the app.
  • Add or remove your mobile number and turn text alerts on or off, where they are offered.
  • Export your restaurant’s items, vendors, purchases, waste and recipes as spreadsheets (Owners, and roles the Owner allows).
  • Delete a restaurant (Owners).

Things you can ask us for

Email us to request a copy of the personal information we hold about you, to correct it, to delete your account, or to ask a question about this Policy. We’ll respond within 45 days. We may need to verify that a request comes from the account holder before acting on it. You can also have someone else make a request for you; we’ll ask for proof that you authorized them, and we may still confirm the request with you directly. We won’t treat you differently for exercising these rights.

If you’re a Team Member

Information you enter into a restaurant’s account (checks, counts, waste logs, notes) belongs to that restaurant and is visible to its Owner. Requests to change or delete it should go to the Owner; we act on the Owner’s instructions for Restaurant Data.

State privacy laws

Residents of states with consumer-privacy laws (for example California and Nevada) may have specific rights to access, correct, delete or limit the use of their personal information, and the right to know whether it is sold or shared. We do not sell or share personal information for cross-context advertising, and we honor the rights above for everyone regardless of state. Nevada residents may submit a request to us at the address in Section 15 to record a preference not to have their information sold, even though we don’t sell it.

Children

Kitchen on Hand is a business tool. Owners must be 18 or older and Team Members 16 or older. We don’t knowingly collect information from anyone under 16, and never from children under 13. If you believe we have, email us and we’ll delete it.

13. International visitors

Kitchen on Hand is offered to businesses in the United States, and personal information is processed and stored in the United States. If you visit the website or use the Service from somewhere else, your information is transferred to and handled in the United States, where privacy laws may differ from those where you live.

If you are in the European Union, the United Kingdom or another place whose law gives you specific rights over your personal information — such as the right to access, correct, delete, restrict or object to the use of it, or to receive a copy in a portable form — you can exercise them by emailing us (Section 15), and we will honor them as that law requires.

14. Changes to this Policy

We’ll update this Policy when our practices change. If a change materially reduces your rights or changes how we use information you’ve already given us, we’ll email account holders and show a notice in the app at least 30 days before it takes effect. The date and version number at the top of this page identify the version you are reading.

15. Contact

Summit Systems LLC is based in Reno, Nevada. Email support@kitchenonhand.com with “Privacy” in the subject line.

Questions about this document? Email support@kitchenonhand.com.