What ChefQuote collects, stores, and sends — in plain terms.
Release-candidate disclosure - not an operative privacy notice. This page describes the inspected source and target deployment boundaries. The live operator, providers, locations, retention, request routes, and legal obligations must be verified and approved before commercial use.
The short version
- Public pages do not receive your operating records. Protected workflows use your authenticated ChefQuote workspace; direct loopback inspection keeps its synthetic review data on that device.
- Route estimates are optional. If enabled and you request one, the addresses and stops you enter are relayed to the deployment's approved routing provider; manual time and mileage entry remains available.
- Only necessary first-party security cookies. Hosted workspaces use short-lived context and request-protection cookies. ChefQuote includes no advertising pixels, cross-site trackers, heatmaps, or session-recording scripts.
- Nothing is sold or used for advertising. Optional account data is processed to provide authentication, sync, and team access.
- You have controls, with stated limits. In-app deletion covers supported records; separate audit logs and synced copies follow the controls and retention limits described below.
Scope
This policy covers ChefQuote's marketing site and connected operating views, including the daily read, pricing workspace, business-health, crew, Morale Guard, and people-protection pages. It describes what the software itself does with data. It does not cover how you or your business separately store, share, or protect exported files once saved or sent — that remains subject to your own systems and policies.
What's stored locally, on your device
The pricing workspace and Morale Guard retain a browser working copy using localStorage. In direct loopback inspection that copy stays on the device and is not authoritative. In a hosted, authenticated workspace, supported documents synchronize through ChefQuote's tenant-scoped service so recovery and team access do not depend on one browser — see Account and workspace sync.
| What's stored | What it contains |
|---|---|
| Current off-premise draft | Whatever you've typed into the active off-premise quote — client, menu, labor, pricing, and the related morale/crew fields. |
| Current on-premise draft | Whatever you've typed into the active on-premise shift or decision. |
| Saved quote history | Off-premise quotes you've explicitly saved, plus their outcomes if you record actuals later. |
| Closed-loop decision log | The exact-service evidence record IDs, protected method-release label, recommendation shown, values before and after, accept/adjust/reject action, required operator reason, safeguards, and timestamp. This log is local, included in the memory JSON export, and included among supported optional-sync documents. |
| Daily operating read | Protected operating-logic configuration, action wording, version labels and hashes; a reasoned before/after logic-change log; and one generated summary per day retained locally for up to 370 days. |
| Owner page-edit log | Page name, actor label, required reason, save method, timestamp, change count, and before/after page hashes for owner changes made through Page Studio. The browser log is capped at the latest 250 entries and does not contain the full page contents. |
| Aggregate operating-health records | Business-health history used for operating trends. Manager-entered crew scenarios do not form a People score, and the daily read leaves the People pillar unavailable when no qualifying direct aggregate exists. |
| Restaurant decision memory | On-premise decisions you've explicitly saved, plus recorded actuals. |
| Operating source packets | Operator-reconciled off-premise event/job and on-premise location/service packets keyed by lane, entity, and period; source hash, mapping, control total, missing fields, decision, and reason. Uploaded filenames and raw source rows are not retained. |
| Persistent operating libraries | Dated ingredient/vendor costs and fixed-cost rows such as rent and insurance. Fixed costs remain active until you explicitly replace or change them; unrelated imports do not erase them. |
| Pricing profile | Default rates and assumptions you've set so you don't re-enter them each time. |
| Panel display preferences | Which panels you've collapsed or expanded — a display setting, not business data. |
Clearing browser site data removes the local working copy and security cookies, but it does not by itself delete synchronized account records. Use the implemented record controls or the contact route for an account-data request.
Route and travel-time estimates
If you use the drive-time, mileage, or toll estimate feature, the start address, destination, and stops are sent through ChefQuote's authenticated relay to the routing provider approved for that deployment. ChefQuote stores a bounded operation record and request digest for idempotency, rate limiting, and security review, but not the address text in that ledger. The routing provider processes the submitted addresses under the provider terms disclosed for your deployment.
If you'd rather not send addresses anywhere, skip the route-estimate feature and enter drive time and mileage manually — every field it fills in can also be typed in by hand.
Account and workspace sync
Hosted operating views require an authenticated ChefQuote account and an active tenant/location membership. A separate direct-loopback inspection mode exists only for reviewing the product locally and cannot create authoritative tenant state.
OpenAI Sites supplies the hosted identity assertion. ChefQuote exchanges that assertion for a revocable, short-lived browser context and resolves organization, location, role, and capabilities from its own authority service. Supported workspace documents synchronize to tenant-scoped PostgreSQL through that service; the browser and edge session store are not the business system of record.
Release boundary: production promotion still requires the deployed identity, MFA administration, encryption/key management, retention/deletion, backup/restore, incident response, sub-processor, and tenant-isolation evidence described by the operator agreement. This source build does not substitute for that deployment-specific verification or legal review.
Membership invitations and account-data requests must use the administrator and support routes configured for the production deployment. You can sign out at any time; clearing one browser does not delete synchronized records.
Morale Guard data
Morale Guard keeps three evidence classes separate: manager-entered operating plans, schedule-derived exposure counts, and direct team-level survey aggregates. Manager plans are not crew sentiment. Schedule counts do not establish morale, emotion, recognition, support, psychological safety, burnout, or health. Direct perceptions appear only when a qualifying aggregate is supplied; missing dimensions are shown as unavailable.
Like the rest of the workspace, this data is stored in your browser's local storage and read by Morale Guard in real time. It is not transmitted anywhere unless you turn on optional cloud sync, in which case it is included in the documents synced to your account. If your business uses these reads to inform real decisions about staffing, scheduling, or performance, treat them the same way you'd treat any other manager notes: subject to your own recordkeeping and employment-law obligations, which this tool does not manage for you.
What we don't collect
- No advertising, cross-site tracking, or nonessential third-party cookies.
- No heatmaps, session recording, or advertising analytics in this build.
- No advertising pixels or ad-network scripts.
- No hosted operating access without an authenticated account and active workspace membership.
- No newsletter collection; demo-request intake remains disabled until its retention and abuse controls are configured.
- No data is sold, rented, or shared with third parties for marketing.
Your controls
Because your core data lives in your browser — and, only if you opt in, in your synced account — you already hold the controls that matter:
- Delete a saved quote or restaurant decision using the delete controls inside the workspace — this removes that record from local storage immediately.
- Closed-loop audit entries are retained separately from the quote they document. The current build has no item-level audit-entry deletion control. Export the memory JSON first if you need a copy, then clear this site's browser storage to remove the local audit log.
- Daily logic can be previewed, exported, changed, or restored to published defaults by an owner. Saving or resetting requires a written reason and creates a before/after audit record. Preview does not alter the audit or daily history.
- Advanced source control is a local browser-folder feature. It requires explicit folder permission, a written reason, a downloaded backup, and a pre-write entry in
COMPLIANCE-RECORD.md. The compliance ledger is not editable through that control. - Page Studio lets an owner change visible copy, page metadata, link labels and destinations, and image source/alternative text without coding. Draft download creates a companion compliance entry; folder save is blocked unless the central ledger can receive a pre-write entry.
- Clear everything at once by clearing your browser's site data / local storage for this site (in most browsers: site settings → clear data, or clearing browsing data for this site specifically).
- Move to a new device by manually exporting/printing what you need — there is no automatic transfer, by design.
Data retention & deletion
Local storage persists until you delete it, clear browser data, or uninstall/reset the browser, except the daily-summary history is capped at the latest 370 daily entries and the browser page-edit log is capped at the latest 250 entries. Logic and closed-loop audit logs currently have no automatic expiration or item-level deletion control. If you use optional cloud sync, supported copies are also held in the account until deleted through an implemented product control or an account-data deletion request. Production retention and deletion behavior still requires verification.
Children's privacy
ChefQuote is a business tool built for hospitality operators and is not directed at children. We do not knowingly collect information from anyone under 13.
Third-party links
The workspace links out to public reference material (for example, food-safety, labor, and wage-data resources from government sites) for awareness only. Once you leave this site, that destination's own privacy practices apply, not this one.
Changes to this policy
If what this software collects or sends changes, this page and its effective date will be updated. Material changes for hosted account holders must also use the production deployment's configured in-product or account-contact notice process.
Contact
Questions about this policy or how the software handles data can be sent to support@chefquote.co. ChefQuote is operated by the ChefQuote business owner.
What is collected about staff, and who can see it.
Where an operator uses the crew and morale features, information about their employees is processed. This section states how.
- Schedule-derived data (hours, turnaround, consecutive days, overtime) is visible to the operator, because the operator created it. The structured import path calculates these measures locally and retains the approved aggregate, not the uploaded shift rows or filename.
- Survey imports are aggregate only. The import path rejects names, email addresses, employee identifiers, comments, free text, and employee cohorts below five responses.
- Employee aggregates below five responses are rejected. This product floor reduces small-cell disclosure risk but does not guarantee anonymity.
- Free text is not accepted by the structured import. It is rejected rather than categorised or sentiment-scored.
- Raw survey responses are not retained by the structured import. Only approved aggregate dimensions, response counts, periods, and safeguards are stored.
- ChefQuote cannot produce an individual survey record it never received. Requests about source-system responses must go to the operator and the source system under their applicable process.
- No export path produces individual survey data. The protection cannot be bypassed with a download.
Employment and data-protection law varies by jurisdiction. Operators are responsible for their own compliance and should take legal advice before deploying survey features to staff.
Full data rules →1. Two different relationships
Most privacy policies describe one relationship. This product has two, and they carry different obligations. Being explicit about which is which is the whole basis of the rest of this page.
- You, the operator, would be the product customer. The live parties, purposes, and contracts determine the data-protection roles. This static review build does not certify a controller, joint-controller, or processor role for account or operational data.
- Your employees are not our customers. Data-protection roles depend on the actual deployment, contracts, and processing facts. This review build does not determine or certify whether an operator or service provider is a controller, joint controller, or processor.
2. What is collected, by category
| Category | Examples | Source | Role |
|---|---|---|---|
| Account | Name, email, business name, authentication tokens | You | Depends on live deployment and contract |
| Operational | Quotes, menus, costs, margins, calendar events, actuals | You | Depends on live deployment and contract |
| Schedule-derived (Class A) | Shift length, turnaround, consecutive days, overtime, workload concentration | You or your scheduling data | Depends on live deployment and contract |
| Survey aggregate (Class B) | Team-level averages for recovery, fairness, voice, recognition, support, and intent to stay | Operator-provided aggregate export | Depends on deployment and contract; not determined by this build |
| Technical | Browser type, error logs, approximate region derived from IP | Automatic | Depends on live deployment and contract |
We do not knowingly collect special-category data — health diagnoses, biometric identifiers, racial or ethnic origin, religion, union membership, sexual orientation or political opinions. The survey instruments are written to avoid eliciting them. Do not enter such data into free-text fields.
3. Employee survey data — the current implemented boundary
The structured intake in this build accepts aggregate result CSVs only. The separate questionnaire page is a static, single-session prototype whose sample answers clear on reload; it is not a production survey or aggregation service.
- Individual survey responses are never disclosed to management. Not in any screen, report or export.
- Aggregate suppression. No team-level output is released from fewer than five responses, and no manager-specific readout is produced for a manager with fewer than five direct reports.
- Free text is rejected by the structured intake. It is not categorised or sentiment-scored.
- Escalation routing is not implemented in this static build. A production survey service would require tested routing, access control, notice, and retention before deployment.
- The structured intake does not receive raw responses. It retains approved aggregate dimensions, counts, period, source hash, mapping, control total, operator decision, and reason.
- No export path produces individual Class B data. The protection cannot be bypassed with a download.
4. Retention schedule
| Data | Kept for | Then |
|---|---|---|
| Questionnaire prototype answers | Current page session only | Cleared on reload; no production submission occurs |
| Approved aggregate survey dimensions | Life of the account or until local/site data is cleared | Subject to the configured account-deletion process; production deletion behavior is not independently verified in this build |
| Approved schedule aggregates and intake audit | Local/site storage until cleared in this build | Raw shift rows are not retained by the import path; production account deletion is not verified |
| Quotes and operational records | Local/site storage until cleared in this build | A production export and deletion schedule must be configured and tested |
| Account, billing, technical, and error records | Not implemented by this static build | The production operator must publish and verify the actual schedule |
This table describes the inspected build, not a certified production retention program. Any legal hold, accounting retention, account closure, or deletion workflow must be specified and verified for the live deployment.
5. Who else processes this data
This repository references infrastructure categories, but contracts, provider identities, locations, and sub-processor status were not available for verification. A live notice must name the actual providers.
| Provider | Purpose | Location |
|---|---|---|
| Database/authentication, hosting/CDN, and email providers | Potential production infrastructure | Not verified in this build |
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We run no advertising trackers on this site.
We may disclose data where legally compelled, to protect rights or safety, or in connection with a merger or acquisition — in which case the acquirer is bound by these commitments or you will be given notice and an opportunity to export and close the account.
6. International transfers
Our infrastructure is primarily located in the United States. If you or your employees are in the United Kingdom, the European Economic Area or Switzerland, using the service involves transferring personal data to the United States. Where we do so we rely on the UK and EU Standard Contractual Clauses, or another lawful transfer mechanism, and apply supplementary technical measures including encryption in transit and at rest.
7. Your rights
Everyone
- Access a copy of the personal data held about you.
- Correction of data that is inaccurate.
- Deletion, subject to legal retention duties.
- Portability — a machine-readable export.
- Complain to your supervisory or data-protection authority.
Employees of an operator
If an employer uses a production deployment, the privacy notice must identify the responsible party and tested request route. This static build does not certify that role or implement request routing. It also does not hold individual survey scores; imported survey results are qualifying team-level aggregates.
United Kingdom and European Economic Area
The production operator must identify and document the lawful basis for each purpose in each jurisdiction. This static build does not select or certify contract, legitimate interests, legal obligation, or consent as the applicable basis.
California
California privacy and employment rules may provide rights and duties depending on the entity, person, data, and processing. The live operator must publish the applicable disclosures and tested request process; this build does not establish CCPA coverage or certify a sale/share position.
Other United States states
Other state privacy statutes differ in scope, exemptions, and rights. The live operator must assess the states in which it operates; no cross-state request process is implemented or verified here.
8. Automated decision-making
The product produces scores, risk estimates and recommendations. It is important to be precise about what these are and are not:
- No decision about a person is made automatically. The product does not decide anything about hiring, firing, discipline, promotion, pay or hours. It produces information for a human to consider.
- It generates no output recommending discipline or termination. There is no screen where such a recommendation appears, for anyone.
- A human decides, always. Every output is advisory, is presented with its inputs and confidence, and can be overridden by the operator.
Where automated decision-making law grants a right to an explanation or to human review, the product is designed to support it: each figure shows its components and source. Emerging laws on automated decision-making technology in employment continue to develop, and operators are responsible for their own compliance in their jurisdictions.
9. Younger workers
Hospitality employs people under 18. Where an operator processes data about a minor employee through this product, the operator is responsible for any additional consent, notice or restriction that applies under local employment or privacy law. The service is not directed to children, and we do not knowingly collect data from anyone under 13.
10. Security and breach notification
The production design requires encryption in transit and at rest, tenant-scoped database controls, least-privilege administration, revocable sessions, and audit logging. The source includes fail-closed authorization and database verification suites; each deployment must prove those controls against its managed identity, database, key, backup, monitoring, and incident-response systems.
No system is perfectly secure. A production incident-response and notification process must be approved, staffed, tested, and reflected in the operative notice before customer data is accepted. Applicable notification duties and timing depend on the live operator, contracts, facts, and law.
11. Changes and contact
An operative production notice must state the actual material-change notification process. This release-candidate template does not promise in-product or email notice.
For privacy questions, requests, or to identify our data-protection contact, use the contact route published on this site.
Accessibility statement
We want this product to be usable by everyone who operates a kitchen, including people who use screen readers, keyboard navigation, magnification or voice control.
Standard we work to
The product targets WCAG 2.1 Level AA. This is an engineering target, not a certification or legal conclusion; independent accessibility review remains a commercial-release gate.
What is in place
- A skip link to main content as the first focusable element on every page.
- Every form control has a programmatic label, not only a visual one.
- Core text contrast and responsive behavior have automated checks; independent full-surface accessibility verification remains required.
- Status is communicated by shade and by text, never by colour alone.
- Full keyboard operation, with a visible focus indicator designed for light and dark surfaces.
- Landmarks, heading structure and accessible names for icon-only controls.
- Motion is reduced automatically when the operating system requests it.
- Layout reflows to 320 px and remains usable at 200% text zoom.
Known limitations
The workspace is a dense analytical tool with a large number of interdependent fields. We are continuing to improve its screen-reader experience, particularly announcements when a figure recalculates. Some inline links within body text are smaller than 24 px; this is permitted under the inline exception, but we are reviewing it.
If something does not work
Tell us, using the contact route on this site, and include the page and what you were trying to do. We treat accessibility defects as functional defects, not as enhancement requests, and we will provide the information or transaction by another means while we fix it.