Maitre
TermsPrivacySign in

Effective July 31, 2026

Privacy Policy

Maitre is a controlled-beta service for restaurant owners. This policy describes the information the current product handles, why it is used, the providers involved, and the choices available to owners and widget guests.

On this page
Information we collectHow we use informationAI processing and limitationsPublic widget conversationsCookies and browser storagePayments and orderingService providersSharing and disclosureRetentionAccess, correction and deletion requestsSecurity and controlled-beta statusInternational processingChildrenChanges and contact

Information we collect

Account and security information may include an owner's email address, authentication identifiers, email-verification and policy-acceptance records, sign-in and trusted-device metadata, multi-factor enrollment state, approximate device/browser/network information, and records used to detect or investigate abuse.

Restaurant information may include the restaurant name, website, location, hours, contact details, cuisine, story, branding, FAQs, policies, reservation and ordering links, pickup details, menu and catalog content, item availability, prices, modifiers, Square configuration, and files or images the owner uploads or approves.

Guest-widget and ordering information may include guest questions, AI answers, conversation and request identifiers, timestamps, usage records, cart selections, item quantities, modifiers, order notes, pickup names, checkout status, and pseudonymous network-derived abuse signals. Restaurant owners may view permitted guest conversation information for their own restaurant.

Subscription and support information may include Stripe customer, subscription, plan, invoice, payment-state and billing-portal references; Square merchant, location, order and checkout references; error and reliability logs; usage and quota records; security events; and communications sent through the support or feedback channel.

How we use information

We use information to create and authenticate accounts, authorize trusted devices, complete restaurant onboarding, import and organize menus, answer guest questions, operate the public widget, support carts and ordering, create provider-hosted checkout sessions, manage subscriptions, enforce message allowances, prevent fraud and abuse, send confirmation/recovery/security emails, provide support, investigate failures, improve reliability, and meet legal or security obligations.

We do not use a restaurant id, browser-reported price, cart total, plan name, or checkout-return page as authoritative proof of ownership, payment, entitlement, or price. Provider and server records are revalidated before protected actions.

AI processing and limitations

Restaurant menus, FAQs, profile information, ordering context, and guest questions may be provided to AI service providers to retrieve relevant information and generate an answer. AI output can be incomplete, outdated, or incorrect even when the underlying restaurant information is accurate.

Restaurant owners are responsible for reviewing and maintaining their restaurant information. Guests should confirm allergies, ingredients, cross-contact risk, dietary requirements, prices, availability, alcohol rules, and other safety-sensitive information directly with restaurant staff. Maitre does not provide medical, allergy, dietary, legal, or food-safety guarantees.

Public widget conversations

Restaurant widgets run on public restaurant websites. A guest's question is transmitted to Maitre and may be stored with the generated answer and limited conversation context for service operation, security, support, analytics, usage accounting, and review by the restaurant owner whose widget received it.

We may process a one-way pseudonymous value derived from network information to enforce restaurant-scoped abuse protections. The owner dashboard does not intentionally expose raw network addresses or internal security identifiers.

Cookies and browser storage

Maitre uses essential session, authentication, recovery, device-authorization, and trusted-device cookies or browser storage. These support sign-in and security rather than advertising. A short-lived widget credential remains in page memory and is not intentionally stored in localStorage.

The public widget may store an in-progress cart and selected menu in the guest's browser for convenience. Cart data is treated as untrusted and is revalidated against current server records before display and checkout. Current cart storage expires after about one day or is cleared when it no longer matches the restaurant/menu or checkout completes.

The current application does not intentionally set marketing or cross-site advertising cookies. If optional analytics or marketing technologies are added, this policy and any required consent controls must be updated first.

Payments and ordering

Stripe manages hosted checkout and billing for Maitre subscriptions. Square may manage hosted checkout and payment processing for restaurant orders. Payment credentials are provided to those payment providers, not to Maitre's own card form.

Maitre does not intentionally receive or store full card numbers or CVC security codes. It may store provider identifiers and limited subscription, invoice, order, checkout, status, amount, currency, and display metadata needed to operate and reconcile the service.

Service providers

The current service uses Supabase for authentication, database and storage services; Cloudflare for hosting, delivery and edge security; OpenAI for AI processing; Stripe for subscription billing; Square for connected restaurant catalog, ordering and hosted checkout; Resend and configured email infrastructure for transactional email; and Google services for sign-in and restaurant/place features where selected.

Those providers may process information under their own terms and privacy notices. Maitre may also use operational hosting, monitoring, support, or email tools that are actually enabled for the service. Maitre does not currently describe itself as selling personal information or using guest conversations for behavioral advertising.

Sharing and disclosure

Information is shared with service providers only as needed to operate requested features, with the relevant restaurant owner for that owner's restaurant, at a user's direction, during a legitimate business transfer, or where reasonably necessary to investigate abuse, protect rights and safety, enforce agreements, or comply with law.

Google services are subject to the Google Privacy Policy and applicable API terms. Square and Stripe process payment-related information under their own notices and terms.

Retention

Account, restaurant, menu, connection, subscription, and configuration records are kept while needed to provide the account and for legitimate security, billing, tax, dispute, or legal purposes. Payment providers may retain their own records independently.

Current database cleanup logic is designed to remove widget conversation records after 90 days, expired checkout attempts after a short operational window, and expired or consumed authentication/security records after short safety windows. Usage counters and webhook-processing records also have bounded cleanup targets. A monitored production schedule for all cleanup functions has not yet been confirmed, so these deletion targets are not guaranteed until that operational work is complete.

Backup retention and a fully tested account-deletion/restore procedure are not yet documented as completed production controls. Data may remain longer in provider systems, security records, billing/tax records, dispute files, or backups where operationally necessary or legally required.

Access, correction and deletion requests

Restaurant owners can correct many restaurant fields in the dashboard, disconnect Square where available, remove the widget from their website, and use the authenticated feedback/support form to request access, correction, export, or deletion. The current product does not promise a complete self-service account-deletion workflow or a fixed completion deadline.

A request may require identity and authority verification. Some records may be retained for fraud prevention, security, billing, tax, legal, dispute, provider, or backup obligations. Deleting a Maitre account does not automatically delete records that Stripe, Square, Google, or another provider must retain under its own obligations.

Security and controlled-beta status

Maitre uses reasonable technical and organizational safeguards designed to reduce unauthorized access, misuse, and data loss. Sensitive provider credentials are intended to remain server-side. Owners should use a unique password, protect email and authenticator access, enable multi-factor authentication when appropriate, and report suspected compromise promptly.

Maitre is currently approved only for a controlled beta, not unrestricted public scale. It may contain defects, unavailable features, operational gaps, or undiscovered vulnerabilities. Monitoring, alerting, retention scheduling, backup/restore rehearsal, email-delivery operations, and independent human testing still require additional production work. No internet service can guarantee complete security or uninterrupted operation.

International processing

Maitre and its service providers may process information in the United States and other jurisdictions where they operate. Privacy protections and government-access rules may differ from those in the user's location.

Children

Maitre accounts are intended for restaurant businesses and authorized adult representatives, not children. The service is not directed to children under 13. If a child is believed to have submitted personal information, an authorized adult should contact Maitre through the support channel for review.

Changes and contact

This policy may be updated as the controlled beta, providers, data practices, or legal obligations change. Material changes will be presented for renewed acceptance where required, and policy-version acceptance may be recorded.

Account holders may use the authenticated feedback/support form for privacy and account requests. A dedicated public privacy email, legal business identity, and mailing address have not yet been approved for publication and must be supplied by the owner before broad production launch.