Privacy Policy

Last updated: May 21, 2026

Introduction

At OctBoss, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our digital menu platform and services.

Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the Service.

1. Information We Collect

1.1 Personal Information

When you register for an account, we collect:

  • Name and business name
  • Email address
  • Phone number
  • Business address
  • Payment information (processed securely through third-party payment processors)

1.2 Menu Content

We collect and store the content you upload to create your digital menu:

  • Menu item names and descriptions
  • Food and beverage images
  • Pricing information
  • Category and organizational data
  • Uploaded menu photos for AI scanning

1.3 Usage Data

We automatically collect certain information when you use our Service:

  • IP address and device information
  • Browser type and version
  • Pages visited and time spent
  • QR code scans and menu views
  • Feature usage and interaction patterns

2. How We Use Your Information

We use the collected information for various purposes:

  • To provide and maintain our Service
  • To process your transactions and manage your subscription
  • To send you technical notices, updates, and support messages
  • To respond to your comments, questions, and customer service requests
  • To provide analytics and insights about menu performance
  • To improve and optimize our Service
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations

3. AI Processing and Data

When you use our AI-powered menu scanning feature:

  • Uploaded menu images are processed by our AI systems
  • Images may be temporarily stored for processing purposes
  • We use the data to improve our AI accuracy and performance
  • Processed data is associated with your account

We do not share your menu images with third parties except as necessary to provide the AI processing service (e.g., cloud AI providers with strict data protection agreements).

4. Data Sharing and Disclosure

We may share your information in the following situations:

4.1 Service Providers

We share data with third-party service providers who perform services on our behalf:

  • Cloud hosting providers (Vercel, Supabase)
  • Payment processors
  • AI and machine learning services
  • Analytics providers
  • Email service providers

4.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities.

4.3 Business Transfers

If OctBoss is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5. Data Security

We implement appropriate technical and organizational security measures to protect your information:

  • Encryption of data in transit and at rest
  • Regular security assessments and updates
  • Access controls and authentication
  • Secure cloud infrastructure
  • Regular backups and disaster recovery procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee its absolute security.

6. Data Retention

We retain your information for as long as necessary to:

  • Provide you with our Service
  • Comply with legal obligations
  • Resolve disputes
  • Enforce our agreements

When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal purposes.

7. Your Privacy Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your personal information
  • Portability: Request transfer of your data to another service
  • Objection: Object to processing of your information
  • Restriction: Request restriction of processing

To exercise these rights, please contact us at privacy@octboss.com.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Maintain your session and preferences
  • Understand how you use our Service
  • Improve user experience
  • Provide analytics and performance monitoring

You can control cookies through your browser settings. However, disabling cookies may affect the functionality of our Service.

9. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies before providing any information.

10. Children's Privacy

Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending you an email notification (for material changes)

You are advised to review this Privacy Policy periodically for any changes.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

OctBoss Privacy Team

Email: privacy@octboss.com

Email: support@octboss.com

Website: www.octboss.com

For European Users (GDPR)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to withdraw consent at any time
  • Right to lodge a complaint with a supervisory authority
  • Right to data portability
  • Right to object to automated decision-making