Effective September 17, 2026
Privacy Policy
HireMaitre (Maitre, we, us) operates hiremaitre.com, the owner dashboard, and the Maitre widget that restaurants embed on their own websites. This policy explains what information those products handle, why, who receives it, how long it is kept, and the rights and choices available to restaurant owners and to guests who talk to the widget.
This document is view-only. It can be read here in full but not selected, copied, printed, or downloaded.
1. Who this policy covers and our role
Restaurant owners and their staff use hiremaitre.com and the dashboard; for that information Maitre is the business that decides how it is used. Guests use the widget on a restaurant's website; for guest information Maitre acts as the restaurant's service provider and processor, under the data processing terms in Section 10 of the Terms of Service. The restaurant's own privacy policy governs its website; this policy describes what Maitre does with the information that reaches it.
A guest who talks to the widget is talking to an AI host operated by Maitre on behalf of the restaurant. The chat is recorded and processed by AI and by the providers listed below, and the restaurant can read it in its dashboard.
2. Information we collect
Owner account and security information: email address, authentication identifiers, email-verification and policy-acceptance records (which policy version was accepted, when, and by which sign-in method), sign-in and trusted-device metadata, multi-factor enrollment state, approximate device, browser, and network information, and records used to detect or investigate abuse.
Restaurant information: name, website, locations and addresses, hours, contact details, cuisine, story, branding, FAQs, policies, reservation and ordering links, pickup details, menu and catalog content, item availability, prices, modifiers, Square configuration, custom instructions for the host, and files or images the owner uploads or approves.
Guest chat information: the messages a guest types, the AI's answers, conversation and request identifiers, timestamps, the restaurant and website the widget was on, the branch the guest chose, dish photos shown, and, when ordering is on, cart selections, quantities, modifiers, order notes, the pickup name the guest enters, and checkout status. A per-turn diagnostic record of what the host did (which menu excerpts it used, which actions it took, timing) is stored with the conversation for the owner's debugging view.
Guest voice information (only when the restaurant has turned voice on and the guest starts a call): the audio stream of the call, the transcript produced from it, and the acoustic characteristics the AI provider analyzes in real time to hear when the guest starts and stops speaking and to tell the guest apart from background sound. Maitre does not store the audio and does not build a voiceprint or any speaker profile that could identify a guest across sessions. Transcripts are kept with the conversation like chat messages.
Network-derived information: the guest's IP address and browser headers. The IP address is converted on our servers into a one-way pseudonymous key that is used for abuse controls and rate limits; the raw address is not shown in the owner dashboard. Cloudflare's network provides an approximate location (city and region, not a precise position) and time zone derived from the connection, which the host uses to give local time and, through a weather data provider, a brief current-weather note. That approximate location is sent to the weather provider only as a city or region; it is not stored in a profile of the guest.
Sensitive information a guest may volunteer: guests often mention food allergies, religious dietary requirements, health-related dietary needs, or disability and accessibility needs. That information is used only to answer the guest's question in that conversation, is stored with the conversation, and is not used to profile the guest or for any other purpose. Guests should confirm all such matters with restaurant staff.
Pre-signup preview and import information: the website address, pages, documents, PDFs, pasted menu text, and Square preview catalog data a prospect submits, and the AI-generated menu drafts and previews produced from them.
Subscription, support, and demo information: Stripe customer, subscription, plan, invoice, payment-state, and billing-portal references; Square merchant, location, order, and checkout references; error and reliability logs; usage and quota records; security events; messages sent through the support or feedback form together with the page address and diagnostic details that form captures; and the name, company, email, phone, and message a person submits when requesting a demo.
3. How we use information
We use information to create and authenticate accounts, authorize trusted devices, complete restaurant setup, import and organize menus, answer guest questions, show dish photos, hold voice conversations, operate the public widget, support carts and pickup ordering, create provider-hosted checkout sessions, manage subscriptions, enforce message allowances, prevent fraud and abuse, send confirmation, recovery, security, and billing emails, respond to demo requests and support, investigate failures, improve reliability, and meet legal and security obligations.
We do not use guest conversations to train our own models, to build profiles across restaurants, or for advertising. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
We do not treat a restaurant id, browser-reported price, cart total, plan name, or checkout-return page as authoritative proof of ownership, payment, entitlement, or price. Provider and server records are revalidated before protected actions.
4. AI processing and transparency
Restaurant menus, FAQs, profile information, ordering context, and guest messages are sent to OpenAI to retrieve the relevant excerpts and generate the host's answer. During a voice call the audio is streamed to OpenAI's real-time API for the same purpose. Under OpenAI's API data policy, API inputs and outputs are not used to train OpenAI's models; OpenAI may retain API data for up to 30 days for abuse and misuse monitoring under its own policy, after which it is deleted, unless a zero-retention arrangement applies to a given endpoint.
The host is always presented as an AI, and it will confirm that it is an AI if asked. AI output can be incomplete, outdated, or incorrect even when the underlying restaurant information is accurate. The host is instructed to use only the restaurant's own information and never to invent a service or fact, but it can still make mistakes. Guests should confirm allergies, ingredients, cross-contact, dietary and religious-diet requirements, prices, availability, alcohol rules, and other safety-sensitive information directly with restaurant staff. Maitre does not provide medical, allergy, dietary, legal, or food-safety guarantees.
6. Payments and ordering
Stripe manages hosted checkout and billing for Maitre subscriptions. Square manages hosted checkout and payment processing for restaurant orders. Payment card details are entered on those providers' pages, never in a Maitre form, and Maitre does not receive or store full card numbers or CVC security codes.
Maitre stores provider identifiers and limited subscription, invoice, order, checkout, status, amount, currency, and display metadata needed to operate and reconcile the service. For a guest order, the restaurant is the merchant of record and receives the order details it needs to prepare and hand over the food.
7. Service providers and subprocessors
Maitre uses Supabase (authentication, database, and file storage, hosted in the United States); Cloudflare (hosting, content delivery, network security, bot checks, and the network-derived approximate location and time zone described above); OpenAI (AI text generation, retrieval embeddings, real-time voice processing, and, when the host has no recorded fact for a venue question such as hours, parking, or policies, a single bounded web search through OpenAI's search tool that sends the question and the restaurant's name, never the guest's identity); Stripe (subscription billing); Square (connected restaurant catalog, ordering, and hosted checkout); Google (sign-in, and Places address lookup during restaurant setup); Resend (transactional email, including demo and support notifications); a weather data provider (a brief current-weather note for the guest's approximate area); and web search and web crawl providers used only during menu import to find and read a restaurant's own public pages.
These providers process information under their own terms and privacy notices and only to provide their service to Maitre. We may also use operational hosting, monitoring, and support tools that are actually enabled for the service. We will update this list when a provider is added or replaced.
8. Sharing and disclosure
Information is shared with the providers above only as needed to operate the requested feature; with the restaurant whose widget received a guest's message, which can read the conversation and any diagnostic record attached to it; at a user's direction; during a merger, acquisition, financing, or sale of assets, subject to this policy; and where reasonably necessary to investigate abuse, protect the rights, safety, and property of Maitre, restaurants, guests, or others, enforce agreements, or comply with law, a subpoena, or a lawful request.
Google services are subject to the Google Privacy Policy and applicable API terms. Square and Stripe process payment-related information under their own notices and terms.
9. Retention
Guest conversations (chat messages, answers, voice transcripts, and the per-turn diagnostic record) are deleted from Maitre's database 90 days after they were created by a scheduled database job that runs daily. A restaurant owner can delete individual messages, whole conversations, or the restaurant's entire history at any time in the dashboard, and those deletions are immediate. Voice audio is not stored by Maitre at all; it is processed in real time and discarded.
Owner account, restaurant, menu, connection, subscription, and configuration records are kept while the account exists. Expired single-use security records, expired guest blocks, webhook de-duplication records, and per-day usage counters are removed on short, bounded schedules by the same cleanup jobs. Demo requests are kept until we have responded and no longer need them, or until the person asks us to delete them.
When an account is deleted, its restaurant, menu, conversation, order, connection, and configuration records are deleted, and connected Square access is revoked. Stripe keeps the invoices, charges, and refunds on the customer record as financial records, because tax and accounting rules and possible chargebacks require it; Square and Google keep their own records under their own policies. Records needed to investigate abuse or to answer a legal claim may be kept for as long as that need lasts. Backups are retained by our hosting provider for a bounded period before they are overwritten.
10. Your rights and choices
Depending on where you live, including under the California Consumer Privacy Act and the Virginia Consumer Data Protection Act, you may have the right to know what personal information we hold about you and how it is used and shared, to access it and receive a portable copy, to correct it, to delete it, to opt out of the sale or sharing of personal information and of targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do not sell or share personal information for advertising and do not use sensitive information for any purpose beyond answering the conversation it was given in, so there is nothing to opt out of on those points; we also honor the Global Privacy Control signal as an opt-out where it applies.
Restaurant owners can correct most restaurant fields, delete guest conversations, disconnect Square, remove the widget, and change per-website settings in the dashboard, and can request access, export, correction, or account deletion through the authenticated support form or at team@hiremaitre.com.
Guests can exercise these rights by contacting the restaurant whose widget they used or by emailing team@hiremaitre.com with the restaurant's name and the approximate date of the conversation. Because Maitre is the restaurant's service provider for guest information, we will act on a verified request ourselves where we can and forward it to the restaurant where the law requires the business to respond.
We will verify a request using the account email or the details of the conversation, respond within 45 days (extendable once by 45 days where the law allows, with notice), and will not require you to create an account. An authorized agent may submit a request with your written permission. If we decline a request, we will explain why, and you may appeal by replying to our decision; Virginia residents who are not satisfied with the appeal may contact the Virginia Attorney General.
11. Security and service status
Maitre uses reasonable technical and organizational safeguards designed to reduce unauthorized access, misuse, and data loss: server-side secrets, row-level database access rules, signed widget sessions bound to the restaurant and website, optional multi-factor authentication for owners, trusted-device checks, bounded request sizes and rate limits, and logging of security events. Owners should use a unique password, protect email and authenticator access, enable multi-factor authentication, and report suspected compromise promptly.
Maitre is offered in a controlled beta program with a limited number of restaurants, and it may contain defects, unavailable features, or undiscovered vulnerabilities. No internet service can guarantee complete security or uninterrupted operation. If we become aware of a breach of security affecting personal information, we will notify the affected restaurant without undue delay and will notify individuals and regulators where the law requires.
12. International processing
Maitre and its providers process information in the United States and in other countries where they operate. Privacy protections and government-access rules there may differ from those where you live. The service is designed for restaurants in the United States; if you use it from elsewhere, you agree to that processing.
13. Children
Maitre accounts are for restaurant businesses and authorized adult representatives. The widget is not directed to children under 13, and the host is instructed not to collect personal information from a child and to end a conversation that appears to be with a young child. If you believe a child has submitted personal information through the widget or the site, contact team@hiremaitre.com and we will delete it.
14. Changes and contact
We may update this policy as the service, its providers, data practices, or legal obligations change. The effective date at the top of this page will change when we do, material changes will be notified to the account email or presented for renewed acceptance where required, and the version accepted by each account is recorded.
Questions, requests, and complaints about privacy can be sent to team@hiremaitre.com or submitted through the authenticated support form in the dashboard. HireMaitre is based in Arlington, Virginia, United States.
Maitre