ChefQuote
Privacy Policy

What ChefQuote collects, stores, and sends — in plain terms.

Release-candidate disclosure - not an operative privacy notice. This page describes the inspected source and target deployment boundaries. The live operator, providers, locations, retention, request routes, and legal obligations must be verified and approved before commercial use.

Effective date: September 12, 2026 Version: 1.3 Applies to: ChefQuote — including the daily read, workspace, business-health, crew, and people-protection views

The short version

Scope

This policy covers ChefQuote's marketing site and connected operating views, including the daily read, pricing workspace, business-health, crew, Morale Guard, and people-protection pages. It describes what the software itself does with data. It does not cover how you or your business separately store, share, or protect exported files once saved or sent — that remains subject to your own systems and policies.

What's stored locally, on your device

The pricing workspace and Morale Guard retain a browser working copy using localStorage. In direct loopback inspection that copy stays on the device and is not authoritative. In a hosted, authenticated workspace, supported documents synchronize through ChefQuote's tenant-scoped service so recovery and team access do not depend on one browser — see Account and workspace sync.

What's storedWhat it contains
Current off-premise draftWhatever you've typed into the active off-premise quote — client, menu, labor, pricing, and the related morale/crew fields.
Current on-premise draftWhatever you've typed into the active on-premise shift or decision.
Saved quote historyOff-premise quotes you've explicitly saved, plus their outcomes if you record actuals later.
Closed-loop decision logThe exact-service evidence record IDs, protected method-release label, recommendation shown, values before and after, accept/adjust/reject action, required operator reason, safeguards, and timestamp. This log is local, included in the memory JSON export, and included among supported optional-sync documents.
Daily operating readProtected operating-logic configuration, action wording, version labels and hashes; a reasoned before/after logic-change log; and one generated summary per day retained locally for up to 370 days.
Owner page-edit logPage name, actor label, required reason, save method, timestamp, change count, and before/after page hashes for owner changes made through Page Studio. The browser log is capped at the latest 250 entries and does not contain the full page contents.
Aggregate operating-health recordsBusiness-health history used for operating trends. Manager-entered crew scenarios do not form a People score, and the daily read leaves the People pillar unavailable when no qualifying direct aggregate exists.
Restaurant decision memoryOn-premise decisions you've explicitly saved, plus recorded actuals.
Operating source packetsOperator-reconciled off-premise event/job and on-premise location/service packets keyed by lane, entity, and period; source hash, mapping, control total, missing fields, decision, and reason. Uploaded filenames and raw source rows are not retained.
Persistent operating librariesDated ingredient/vendor costs and fixed-cost rows such as rent and insurance. Fixed costs remain active until you explicitly replace or change them; unrelated imports do not erase them.
Pricing profileDefault rates and assumptions you've set so you don't re-enter them each time.
Panel display preferencesWhich panels you've collapsed or expanded — a display setting, not business data.

Clearing browser site data removes the local working copy and security cookies, but it does not by itself delete synchronized account records. Use the implemented record controls or the contact route for an account-data request.

Route and travel-time estimates

If you use the drive-time, mileage, or toll estimate feature, the start address, destination, and stops are sent through ChefQuote's authenticated relay to the routing provider approved for that deployment. ChefQuote stores a bounded operation record and request digest for idempotency, rate limiting, and security review, but not the address text in that ledger. The routing provider processes the submitted addresses under the provider terms disclosed for your deployment.

If you'd rather not send addresses anywhere, skip the route-estimate feature and enter drive time and mileage manually — every field it fills in can also be typed in by hand.

Account and workspace sync

Hosted operating views require an authenticated ChefQuote account and an active tenant/location membership. A separate direct-loopback inspection mode exists only for reviewing the product locally and cannot create authoritative tenant state.

OpenAI Sites supplies the hosted identity assertion. ChefQuote exchanges that assertion for a revocable, short-lived browser context and resolves organization, location, role, and capabilities from its own authority service. Supported workspace documents synchronize to tenant-scoped PostgreSQL through that service; the browser and edge session store are not the business system of record.

Release boundary: production promotion still requires the deployed identity, MFA administration, encryption/key management, retention/deletion, backup/restore, incident response, sub-processor, and tenant-isolation evidence described by the operator agreement. This source build does not substitute for that deployment-specific verification or legal review.

Membership invitations and account-data requests must use the administrator and support routes configured for the production deployment. You can sign out at any time; clearing one browser does not delete synchronized records.

Morale Guard data

Morale Guard keeps three evidence classes separate: manager-entered operating plans, schedule-derived exposure counts, and direct team-level survey aggregates. Manager plans are not crew sentiment. Schedule counts do not establish morale, emotion, recognition, support, psychological safety, burnout, or health. Direct perceptions appear only when a qualifying aggregate is supplied; missing dimensions are shown as unavailable.

Like the rest of the workspace, this data is stored in your browser's local storage and read by Morale Guard in real time. It is not transmitted anywhere unless you turn on optional cloud sync, in which case it is included in the documents synced to your account. If your business uses these reads to inform real decisions about staffing, scheduling, or performance, treat them the same way you'd treat any other manager notes: subject to your own recordkeeping and employment-law obligations, which this tool does not manage for you.

What we don't collect

Your controls

Because your core data lives in your browser — and, only if you opt in, in your synced account — you already hold the controls that matter:

Data retention & deletion

Local storage persists until you delete it, clear browser data, or uninstall/reset the browser, except the daily-summary history is capped at the latest 370 daily entries and the browser page-edit log is capped at the latest 250 entries. Logic and closed-loop audit logs currently have no automatic expiration or item-level deletion control. If you use optional cloud sync, supported copies are also held in the account until deleted through an implemented product control or an account-data deletion request. Production retention and deletion behavior still requires verification.

Children's privacy

ChefQuote is a business tool built for hospitality operators and is not directed at children. We do not knowingly collect information from anyone under 13.

Third-party links

The workspace links out to public reference material (for example, food-safety, labor, and wage-data resources from government sites) for awareness only. Once you leave this site, that destination's own privacy practices apply, not this one.

Changes to this policy

If what this software collects or sends changes, this page and its effective date will be updated. Material changes for hosted account holders must also use the production deployment's configured in-product or account-contact notice process.

Contact

Questions about this policy or how the software handles data can be sent to support@chefquote.co. ChefQuote is operated by the ChefQuote business owner.

Employee data

What is collected about staff, and who can see it.

Where an operator uses the crew and morale features, information about their employees is processed. This section states how.

  • Schedule-derived data (hours, turnaround, consecutive days, overtime) is visible to the operator, because the operator created it. The structured import path calculates these measures locally and retains the approved aggregate, not the uploaded shift rows or filename.
  • Survey imports are aggregate only. The import path rejects names, email addresses, employee identifiers, comments, free text, and employee cohorts below five responses.
  • Employee aggregates below five responses are rejected. This product floor reduces small-cell disclosure risk but does not guarantee anonymity.
  • Free text is not accepted by the structured import. It is rejected rather than categorised or sentiment-scored.
  • Raw survey responses are not retained by the structured import. Only approved aggregate dimensions, response counts, periods, and safeguards are stored.
  • ChefQuote cannot produce an individual survey record it never received. Requests about source-system responses must go to the operator and the source system under their applicable process.
  • No export path produces individual survey data. The protection cannot be bypassed with a download.

Employment and data-protection law varies by jurisdiction. Operators are responsible for their own compliance and should take legal advice before deploying survey features to staff.

Full data rules →