ServOS Data Policy Effective date: 7 July 2026 Applies to: servOS UK Ltd and servOS Inc (together, "servOS", "we", "us") Our promise servOS was built by people who have stood behind the counter. We know your data is your business: your sales, your menu, your diners, your margins. It is the most valuable thing you hand us, and we treat it that way. So we keep this simple. Your data is yours. We hold it so the system can run for you. We do not mine it, sell it, rent it, or hand it to anyone who would. We do not sell ads. We do not market to your customers on our own behalf. There is no business model hiding behind your data, because our business model is a share of the value we create for you, and nothing else. Everything below is how we make that promise real.
You do. Full stop. - Your business data (orders, payments, menu, pricing, staff records, reports, cash records) belongs to you. - Your customers' data (names, contact details, order history, loyalty balances, gift card records, marketing preferences) belongs to you as well. You are responsible for it as the controller; we process it only to run the service you switched on. - servOS is the custodian of this data. We store it, secure it, and make it work inside the platform. We never become its owner, and we never treat it as ours to exploit. If you leave servOS, your data leaves with you. We provide a full export, and we delete what remains on the schedule set out in Section 9.
We collect only what the platform needs to do its job: - Operational data you and your staff enter or generate: orders, items, modifiers, payments, refunds, tips, cash counts, floor plans, sessions, and reports. - Customer data your venue captures: contact details, order history, loyalty balances and points, gift card balances and history, and any marketing preferences, consents, and opt-outs you hold. - Payment data, handled through our regulated payment partners. Card details are tokenised and processed by the payment provider; servOS does not store raw card numbers. - System and usage data: device profiles, session activity, error logs, performance metrics, and feature usage. This is the data that tells us when something is slow, broken, or worth improving. We do not collect data you have not given us, and we do not buy data about you or your customers from anyone.
There are two distinct kinds of data, and we treat them differently. Your business and customer data is used for exactly one purpose: running servOS for you. Taking orders, processing payments, syncing devices, producing your reports, powering your CRM, loyalty, gift card, and marketing tools, and supporting you when you need help. We do not use it for anything else. Not analytics we sell, not products we pitch, not insights we pass on. Nothing. Aggregated, de-identified system data is what we use to improve the platform. When we look at how servOS performs, where errors happen, or which features get used, we work with data that has been stripped of anything identifying you or your diners. This is how the product gets faster, more stable, and more useful over time. This data is never tied back to your venue, never sold, and never shared with advertisers or third parties. That is the whole list. If a use is not on it, we are not doing it.
These are commitments, not preferences. - We will never sell your data or your customers' data to anyone, for any price, ever. - We will never share your data for another party's own purposes. - We will never manipulate your data for our benefit or anyone else's. - We will never market servOS, or any product of ours, to your customers. servOS does not contact your diners on its own behalf. (You can market to your own customers using the tools in the platform. That is your activity, under your control, and it is covered in Section 5.) - We will never run advertising against your data, and we will never let an advertiser near it. - We will never use your business or customer data to train models, build products, or generate insights that we sell. If any of this ever changes, it will not happen quietly. See Section 10.
servOS includes loyalty, gift cards, and marketing tools so you can build repeat business directly with the people who already walk through your door. Here is exactly how that works and where the lines sit. - The data stays yours. Loyalty balances and points, gift card balances and history, marketing lists, and consent and opt-out records are your data, treated exactly like everything else in this policy. We store it and run it for you. We do not use it for ourselves, and we do not sell it. - Marketing reaches only your own customers. When you use servOS to market your business, it goes to your customers and no one else's. We do not pool diner data across venues or organisations. One operator can never see, borrow, or market to another operator's customers. Your customer base is walled to your organisation. - You are the sender. When you send marketing through servOS, you are the sender and the controller of that activity. You are responsible for holding the right consent, honouring opt-outs and unsubscribes, and complying with marketing law in your market (for example UK PECR and GDPR, or US CAN-SPAM and TCPA). servOS gives you the tools and the controls; the decision to contact a customer is yours. - We do not piggyback. servOS does not insert its own branding, ads, or messages into the communications you send to your customers. Your relationship with your diners is yours alone.
servOS runs on infrastructure we did not build from scratch, and being straight with you means naming it. To deliver the service, your data is processed by a small, vetted set of providers: - Hosting and database infrastructure to store and serve your data. - Payment providers to process card transactions securely and within financial regulation. - Messaging providers to deliver the marketing, loyalty, and transactional communications you choose to send. - Delivery and order-routing partners, where you choose to use them. Every one of these providers works strictly under our instructions. They are contractually bound to process your data only to provide their service to us, and they cannot use it for their own purposes, sell it, or repurpose it. This is the only sense in which your data ever leaves servOS, and it exists solely so the platform can function. We maintain a current list of these providers and will provide it on request. This is not data-sharing in the sense most people fear. It is the plumbing required to run the system you pay for.
Security is not a feature we add later. It is the condition for being trusted with a business's livelihood. - Data is encrypted in transit and at rest. - Access is restricted to what is needed to operate and support the platform, on a least-privilege basis. - Payment data is handled through PCI-compliant payment infrastructure; raw card details never touch our own storage. - The platform is built for offline resilience, so a lost connection never means lost data. No system is perfect, and we will never pretend otherwise. If a breach ever affects your data, we will tell you promptly and tell you the truth.
Your data is yours to see, take, and remove. - Access and export: you can export your data from servOS at any time, in a usable format. - Correction: you can correct inaccurate data through the platform. - Deletion: you can request deletion of your data, and we will honour it within the retention rules below. - Portability: when you leave, you take a complete copy with you. Depending on where you and your customers are based, you may have additional legal rights (for example under UK GDPR or under US state privacy laws such as the CCPA/CPRA in California). We honour those rights, and the controls above are how we deliver them. Where you are the controller of your diners' data, we support you in meeting the requests they make to you.
- We store data in regions appropriate to your market (UK and US), and we keep transfers within frameworks that protect it. - While your account is active, we keep your data for as long as you need it, plus the period required to meet legal, tax, and financial-record obligations. When you leave us When you close your account, you take a full export with you (Section 8). After that, we hold your data for a retention period of [X DAYS]. During that window your data sits dormant. It may still exist on our servers and in our backups, but it is not accessed, used, processed, or shared for any purpose, except where the law requires us to retain or produce it. This window exists for one reason: so that an accidental closure can be reversed, and so our backup cycles can roll over safely. It is not a back door to your data, and it changes none of the promises in this policy. Once the retention period ends, we securely delete your data or irreversibly de-identify it, including as it rolls out of our backups. Aggregated, de-identified system data, which by definition cannot identify you or your customers, may be retained to keep improving the platform.
If we ever change this policy, we will not bury it. We will give you clear, advance notice of any change that affects how your data is used, and we will never weaken the core promises in Sections 3, 4, and 5 without telling you directly and giving you a real choice about it.
Questions, requests, or concerns about your data: [CONTACT EMAIL] servOS UK Ltd / servOS Inc [ADDRESS] This document sets out servOS's commitments and practices. It is not a substitute for the legally binding terms in your service agreement, and it should be reviewed by qualified counsel before publication to confirm it meets your obligations under UK GDPR, applicable US state privacy law, electronic marketing law (UK PECR, US CAN-SPAM and TCPA), and PCI-DSS.