Overview
This Privacy Policy describes how Zendeyo LLC (“Company,” “we,” “us,” or “our”) collects, uses, discloses, and protects information relating to you when you use KitchenBot — including the website at kitchenbot.io and the KitchenBot application on the Clover App Market (collectively, the “Service”).
This Privacy Policy is incorporated into and part of KitchenBot’s Terms of Service. By accessing or using the Service, you acknowledge that you have read and agree to this Privacy Policy. If you do not agree, please discontinue use of the Service.
For purposes of this Policy:
- Merchant / Client means a business owner or authorized representative who subscribes to KitchenBot through the Clover App Market.
- Employee means a staff member of a Merchant whose data (time-clock, payroll, tips) is managed through KitchenBot.
- End Customer means a person who places an online order through a Merchant’s KitchenBot ordering page.
- Visitor means anyone who accesses kitchenbot.io without registering.
Data We Collect
We collect information in the following categories, depending on your relationship with KitchenBot:
Merchant / Business Account Data
- Business name, address, and contact information
- Clover merchant account ID and linked location data
- Subscription and billing status (managed via Clover)
- Menu items, pricing, and operational settings you configure
- Support correspondence and communication history
Employee Data
Because KitchenBot is a workforce management tool, we process data about your employees on your behalf as a data processor:
- Name and employee ID (from Clover employee records)
- Time-clock entries: clock-in and clock-out timestamps
- Calculated hours, overtime, and break records
- Tip amounts allocated to each employee
- Payroll report data generated from the above
- Role and department assignment (from Clover)
End Customer Data (Online Ordering)
When a customer places an online order through a Merchant’s KitchenBot storefront:
- Name and contact information (email, phone) for order confirmation and notifications
- Delivery address (for delivery orders)
- Order contents, special instructions, and order history
- Payment method type (card type, last 4 digits) — full card data is handled by Clover/Fiserv and never stored by KitchenBot
Automatically Collected Technical Data
- IP address and approximate geographic location (country/city)
- Browser type, version, and operating system
- Clover device type and model
- Pages and features accessed, timestamps, and session duration
- Referring URL or source
- Error logs and crash reports
How We Use Your Data
To Provide the Service
- Displaying employee time-clock data, payroll reports, and tip summaries to authorized Merchants
- Processing and displaying online orders from End Customers
- Sending order confirmation notifications to End Customers via email or SMS
- Operating the Kitchen Display System (KDS) to route and display orders in the kitchen
- Maintaining your account, subscription status, and settings
To Improve the Service
- Analyzing usage patterns and feature adoption to prioritize improvements
- Identifying and resolving bugs, performance issues, and errors
- Conducting aggregated, anonymized research on how restaurants use workforce and ordering tools
To Communicate With You
- Sending service-related announcements, updates, and security notices
- Responding to support requests and inquiries
- Notifying you of material changes to these policies
- Sending product updates or offers (you may opt out at any time)
To Comply With Legal Obligations
- Maintaining records as required by applicable law
- Responding to valid legal process, court orders, or government requests
- Enforcing our Terms of Service and other agreements
Data Sharing & Disclosure
We do not sell your personal information. We may share data only in the limited circumstances described below.
Service Providers (Processors)
We engage trusted third-party vendors to help us operate the Service. These vendors process data only on our behalf under contractual obligations. Current categories of service providers include:
- Cloud hosting and infrastructure providers
- Email and SMS notification delivery services
- Analytics tools for internal product improvement (aggregated, not advertising)
- Customer support software
- Security and fraud-monitoring services
Clover / Fiserv
Because KitchenBot is a Clover-native application, certain data flows through Clover’s infrastructure. Clover’s own privacy policy governs data that Clover collects or processes on its platform.
Legal Requirements
We may disclose data if we believe in good faith that disclosure is necessary to: (a) comply with applicable law or a valid legal process; (b) protect the rights, property, or safety of Zendeyo LLC, our users, or the public; or (c) detect, prevent, or address fraud, security, or technical issues.
Business Transfers
If Zendeyo LLC is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify affected users before data is transferred and becomes subject to a different privacy policy.
Cookies & Tracking Technologies
Types of Cookies We Use
- Strictly Necessary Cookies: Required for the Service to function (e.g., session authentication, security tokens). Cannot be disabled.
- Functional Cookies: Remember your preferences and settings to improve your experience.
- Analytics Cookies: Help us understand how the Service is used so we can improve it. Data is aggregated and anonymized.
Managing Cookies
You can configure your browser to refuse all cookies or to indicate when a cookie is being sent. However, refusing cookies may limit your ability to use certain features of the Service.
Web Beacons
We may use web beacons in our website and emails to determine whether a page or email has been viewed. This helps us measure the effectiveness of our communications and improve our Service.
Do Not Track
Because there is no industry-wide standard for how to respond to Do Not Track signals, KitchenBot does not currently respond to such signals. We will revisit this policy as standards develop.
Clover Integration & Payment Data
KitchenBot accesses data in your Clover account through Clover’s official APIs. This includes employee records, time-clock data, transaction records, tip data, and menu information. This access is strictly limited to what is required to provide the features you have activated.
Payment Card Data
KitchenBot does not collect, process, store, or transmit full payment card numbers, CVV codes, or cardholder PINs. All payment processing for online orders is handled exclusively by Clover Network LLC / Fiserv. KitchenBot only receives confirmation of successful payment and limited metadata (card type, last 4 digits) for display purposes in order records.
PCI Compliance
Because KitchenBot does not handle raw payment card data, it operates outside the scope of PCI DSS requirements applicable to card processors. However, we maintain industry-standard security practices for all data we do handle.
Data Security
We implement reasonable and appropriate technical and organizational security measures to protect your data. These measures include:
- SSL/TLS encryption for all data transmitted between your devices and our servers
- Encryption of sensitive data at rest
- Role-based access controls limiting which employees can access your data
- Regular security reviews and monitoring
- Secure, password-protected infrastructure with multi-factor authentication for administrative access
You are responsible for maintaining the security of your Clover account credentials. Notify us immediately at support@kitchenbot.io if you suspect unauthorized access to your account.
Data Retention
We retain personal data for as long as is necessary to fulfill the purposes for which it was collected, including to:
- Provide the Service to active subscribers
- Comply with applicable legal, regulatory, and tax obligations
- Resolve disputes and enforce our agreements
- Maintain accurate business records
Upon cancellation of your subscription, we will retain your account data for a period of up to 12 months from the date of cancellation, after which it will be permanently deleted or anonymized, unless a longer retention period is required by law or requested by you in writing.
Anonymized and aggregated data (which cannot identify any individual or business) may be retained indefinitely for internal research and analytics purposes.
To request early deletion of your data, contact us at support@kitchenbot.io. We will respond within 30 days.
Your Rights & Choices
Regardless of your location, you have the following general rights with respect to your personal data:
- Access: Request a copy of the personal data we hold about you or your business.
- Correction: Request that we correct inaccurate or incomplete data.
- Deletion: Request that we delete your personal data, subject to legal retention requirements.
- Restriction: Request that we restrict how we process your data in certain circumstances.
- Portability: Request a machine-readable copy of your data to transfer to another service.
- Objection: Object to our processing of your data where we rely on legitimate interests.
- Opt-out of marketing: Unsubscribe from promotional emails at any time using the unsubscribe link in each message, or by emailing support@kitchenbot.io.
To exercise any of these rights, contact us at support@kitchenbot.io. We will respond within 30 days. We may need to verify your identity before processing a request.
California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Your California Rights
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected, covering the preceding 12 months.
- Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising purposes.
- Right to Non-Discrimination: We will not discriminate against you for exercising your California privacy rights.
Categories of Personal Information Collected (Last 12 Months)
| Category | Collected? | Sold? | Shared for Advertising? |
|---|---|---|---|
| Identifiers (name, email, phone, IP address) | Yes | No | No |
| Commercial Information (order history, subscription) | Yes | No | No |
| Geolocation Data (city/region from IP) | Yes | No | No |
| Internet/Network Activity (pages visited, session data) | Yes | No | No |
| Professional/Employment Information (employee records) | Yes | No | No |
| Financial Information (payment card data) | No | No | No |
| Biometric Information | No | No | No |
| Sensitive Personal Information (SSN, health data) | No | No | No |
How to Submit a California Rights Request
Email us at support@kitchenbot.io with the subject line “California Privacy Request.” We may need to verify your identity before responding. We have not sold any personal information in the preceding 12 months.
EU / UK Data Subjects (GDPR & UK GDPR)
KitchenBot is primarily designed for use in the United States. If you are located in the European Economic Area (EEA) or the United Kingdom, the following applies:
Legal Basis for Processing
- Contract: Processing necessary to fulfill our subscription agreement with you.
- Legitimate Interests: Processing for our legitimate interest in improving the Service, preventing fraud, and maintaining security.
- Legal Obligation: Processing required to comply with applicable law.
- Consent: For marketing communications, where required by law.
Your GDPR Rights
In addition to the rights in Section 9, you have the right to: (a) withdraw consent at any time where processing is consent-based; (b) lodge a complaint with your national data protection supervisory authority (see edpb.europa.eu); and (c) object to processing based on legitimate interests.
Data Transfers
KitchenBot is operated from the United States. If you access the Service from the EEA or UK, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) or other appropriate transfer mechanisms as required by applicable data protection law.
Contact for GDPR Inquiries
To exercise your GDPR rights or for data protection inquiries, contact us at support@kitchenbot.io. We will respond within 30 days.
Children’s Privacy
The KitchenBot Service is intended for use by business owners and authorized employees, and is not directed to children under the age of 13 (or under 16 in the EEA/UK). We do not knowingly collect personally identifiable information from children under 13.
If you believe that a child under 13 has provided personal information to us without appropriate parental consent, please contact us immediately at support@kitchenbot.io. If we become aware that we have collected personal data from a child under 13, we will take prompt steps to delete that information from our servers.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Effective Date” at the top of this page.
- Post a prominent notice on the Service.
- For existing users, send notice via email to the address associated with your account at least 14 days before the changes take effect.
Your continued use of the Service after any changes take effect constitutes your acceptance of the revised Privacy Policy. We encourage you to review this Policy periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out. We aim to respond to all privacy inquiries within 5 business days.
Zendeyo LLC / KitchenBot
Waxhaw, North Carolina, USA
Email: support@kitchenbot.io
Phone: 704-287-4009
For data deletion requests, access requests, or other privacy rights exercises, please email us with the subject line “Privacy Request” and include your name, the email address associated with your account, and a description of your request.
Questions about your data?
We’re committed to transparency. Reach out any time with questions about how we handle your information.