Back to Home

RestoManage LLC

Privacy Policy

Effective date: August 11, 2026

License No.: 2644702.01 (Shams, Sharjah Media City)

1. Scope

This Privacy Policy explains how RestoManage LLC ("RestoManage", "we", "our", or "us") handles personal data through getrestomanage.com and the RestoManage Service, including the restaurant portal, supplier portal, point-of-sale software, sales and administration workflows, support channels, and related services.

This policy is written with the UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data in mind, together with other applicable privacy and data-protection requirements. Specific contractual arrangements may impose additional obligations.

2. When RestoManage is a controller or processor

RestoManage as controller

RestoManage generally determines the purposes and means of processing for its own website enquiries, supplier and restaurant applications, account administration, billing, contracts, service security, support, business communications, and internal administration. For those activities, RestoManage generally acts as a controller.

RestoManage as processor for Customer Data

Restaurants and suppliers use the Service to run their own businesses. Where a Customer determines why and how personal data about its staff, diners, delivery customers, contacts, or other individuals is processed through RestoManage, that Customer generally acts as the controller and RestoManage processes the data on the Customer's behalf to provide the Service.

The exact legal role depends on the processing activity and applicable law. If you are an employee, diner, delivery customer, or other individual whose information was entered by a RestoManage Customer, the Customer that collected your information may be the appropriate first contact for a privacy request.

3. Personal data we process

3.1 Account and business information

Names, email addresses, phone numbers, organization and branch information, user IDs, roles and permissions, business addresses, VAT or tax information, trade-license or onboarding details, and other information needed to create and manage business accounts.

3.2 Website forms and applications

Demo requests, contact messages, restaurant applications, supplier applications, career applications, and similar forms can include names, email addresses, phone numbers, company names, branch counts, service areas, business details, free-text messages, CV or application information, and other information you choose to submit.

3.3 Supplier documents

Supplier applicants may upload catalogs or price lists, including PDF or CSV files. These files may contain business contact details, product and pricing information, or other information included by the applicant. Supported supplier uploads are stored privately for application review and onboarding workflows rather than intentionally published as public website assets.

3.4 Restaurant operational data

Depending on the features used, RestoManage can process orders, sales and tender records, refunds and voids, table and kitchen activity, channel tags, menus, modifiers, recipes, ingredients, inventory, branch configuration, supplier purchase orders, invoice records, compliance tasks, audit records, and related operational information.

3.5 Diner and delivery-customer information

The POS supports order-linked customer context that can include a customer's name, phone number, normalized phone number, delivery address, delivery notes, customer notes, source channel, and the associated order history. Restaurants decide when to collect and use this information through their operations.

3.6 Staff and operator information

The Service can process staff or operator names, user IDs, email addresses, roles, branch assignments, shift and activity records, authentication state, secured or hashed authentication-factor data where applicable, and audit events such as login, manager-authorization, payment-reconciliation, or order-control actions.

3.7 Billing, payment, and contract information

We process plan information, invoice and contract amounts, currencies, payment status, payment-link and charge identifiers, billing references, and related reconciliation records. Contract-signing workflows can also record the signatory's name, account identity, signing time, IP address, and browser or user-agent information as evidence of the signing event.

3.8 Device, security, and technical information

RestoManage can process terminal or device identifiers, application and device logs, error or diagnostic messages, timestamps, request metadata, IP-address information, authentication and session information, security events, and anti-abuse verification results needed to operate, troubleshoot, protect, and audit the Service.

4. Offline POS and local device data

RestoManage's desktop POS is designed for offline-first operation. Supported operational data, authentication state, configuration, audit information, and synchronization state may therefore be stored on the restaurant's local POS device and later synchronized with RestoManage's cloud services when connectivity is available.

Restaurants control the physical devices and local operating-system environment. Device security, operating-system accounts, local network controls, and timely deprovisioning are therefore part of the shared-responsibility model described in our Security and Trust Center.

5. Where personal data comes from

  • directly from you when you contact us, apply, sign a contract, make a payment, or use an account;
  • from a restaurant, supplier, employer, or other RestoManage Customer that enters or generates information through the Service;
  • from authorized users, terminals, and devices during normal operation;
  • from payment, email, authentication, hosting, security, and other service providers when they return transaction or technical information to us; and
  • from connected commercial counterparties where a restaurant and supplier use the shared purchasing workflow.

6. How we use personal data

  • provide, operate, synchronize, maintain, and support the Service;
  • authenticate users and terminals and enforce organization, branch, role, and permission boundaries;
  • process restaurant orders, customer and delivery context, staff workflows, inventory, reporting, purchasing, invoicing, and other requested features;
  • process subscription, invoice, and contract payments and reconcile payment status;
  • record contract acceptance and signing evidence;
  • respond to enquiries, demos, applications, onboarding, support, and security reports;
  • send transactional, account, operational, billing, security, and service communications;
  • detect abuse, investigate errors, preserve audit integrity, secure accounts and devices, and respond to incidents;
  • comply with legal, accounting, tax, regulatory, and dispute-resolution obligations; and
  • improve the reliability, usability, and security of RestoManage using information we are permitted to process for those purposes.

We process personal data where permitted by applicable law, including where processing is needed to perform a contract or requested service, comply with legal obligations, establish or defend legal rights, protect the Service and its users, or where valid consent is required and obtained.

7. Delivery platforms and third-party channel names

Delivery-platform names such as Talabat, Deliveroo, Careem, Noon, or other channels can be stored as order-source tags for reporting. Unless a specific connected integration is expressly identified in the Service, RestoManage does not claim that it directly receives or verifies order data from that delivery platform merely because the platform's name appears as a channel tag.

8. Service providers and sharing

We share information only as reasonably necessary for the Service, a permitted business purpose, Customer instructions, or applicable law. Current examples of service providers include:

  • Supabase: managed database, authentication, and private storage services.
  • Cloudflare: hosting, network delivery and security, and Turnstile anti-abuse verification.
  • Resend: transactional and operational email delivery.
  • MamoPay: payment-link and payment-processing functionality for RestoManage subscription, invoice, or contract payment flows where used.

RestoManage may also share relevant data with authorized users within the same Customer organization, participating suppliers or restaurants where needed for a shared purchase-order relationship, professional advisers acting under confidentiality obligations, authorities where disclosure is legally required, or a successor in connection with a merger, financing, reorganization, sale, or transfer of the relevant business.

We do not sell personal data. We do not use Customer operational data for third-party behavioral advertising.

9. Payment-provider boundary

When RestoManage creates a payment flow through MamoPay, we can send information such as the amount, currency, payment description, RestoManage organization or resource identifiers, and a transaction reference needed to bind the payment to the correct account, bill, or contract. Payment credentials entered on MamoPay's payment page are handled by MamoPay under its own terms and privacy practices.

RestoManage's application receives and stores the payment status and identifiers needed to reconcile the transaction, such as payment-link, external-reference, or charge identifiers. The RestoManage workflow is not designed to require card numbers to be entered directly into RestoManage.

10. Supplier Network data sharing

When restaurants and suppliers use the connected purchasing workflow, RestoManage shares the information needed for the relevant commercial relationship, such as organization details, purchase-order contents, products, quantities, prices, order status, invoice information, delivery status, and permitted payment-trust or credit-profile context for parties that have traded with each other or are otherwise allowed to access that information.

Restaurants and suppliers are independent businesses and are responsible for their own use of personal data they receive through the transaction. RestoManage does not treat operational payment-trust context as a regulated consumer credit report or a guarantee that a business will pay or perform.

11. Cookies, sessions, and anti-abuse technology

RestoManage web applications may use cookies, browser storage, or similar technical mechanisms where necessary for authentication, session continuity, security, preferences, and application operation. Public website forms use Cloudflare Turnstile to reduce automated abuse, which involves technical processing by Cloudflare to assess whether a request is likely to be legitimate.

RestoManage does not currently rely on third-party behavioral-advertising trackers as part of the core Service described by this policy. If that changes materially, this policy and any required consent controls should be updated before the new processing is relied upon.

12. International and cross-border processing

RestoManage is based in the United Arab Emirates, but cloud, security, email, payment, and other service providers may process or store information in other countries. Where personal data is transferred outside the UAE, RestoManage will use measures intended to satisfy applicable UAE requirements for cross-border processing, such as transfers to jurisdictions with appropriate protection, contractual safeguards, consent where valid and required, or another lawful transfer mechanism.

13. Retention

We keep personal data only for as long as reasonably needed for the purpose for which it was collected, Customer instructions, security and audit integrity, dispute handling, and applicable legal, tax, accounting, or regulatory requirements. Retention therefore varies by record type.

  • Account and business records: generally for the active relationship and a reasonable period afterward where needed for administration, disputes, or legal obligations.
  • Billing and contract records: for the period needed to reconcile payments and meet accounting, tax, contractual, and legal-retention requirements.
  • POS transaction and audit records: according to Customer operational needs, integrity requirements, applicable retention duties, and the architecture of synchronized and offline records.
  • Website applications and enquiries: while we review, respond, onboard, recruit, or reasonably follow up, then deleted or minimized when no longer needed unless another lawful reason requires retention.
  • Supplier uploads: during application review, onboarding, and any continuing supplier relationship where the document remains relevant, then removed when it is no longer reasonably needed.
  • Security and diagnostic information: for periods reasonably necessary to investigate incidents, troubleshoot systems, detect abuse, and preserve security evidence.

Deletion from active systems may not immediately remove information from protected backups, immutable audit records, or records that must be retained by law. Such copies remain subject to access controls and are removed or aged out according to the applicable retention process.

14. Security

RestoManage uses technical and organizational measures intended to protect personal data according to the nature and risk of the processing. Current controls include encrypted network connections, scoped organization and branch access, role and permission checks, private supplier-document storage, authentication protections, audit records, and security controls around public forms and POS synchronization.

No internet-connected or device-based system can guarantee absolute security. If we become aware of a personal-data breach, we will investigate and make notifications to affected parties or authorities where required by applicable law.

Read the Security and Trust Center

15. Your privacy rights

Subject to applicable law, identity verification, and lawful exceptions, you may have rights to request information about personal data processed about you, obtain access, request correction or erasure, restrict or object to processing in applicable circumstances, request portable data where the legal conditions are met, and object to certain automated decisions. You may also have the right to complain to the competent UAE data-protection authority.

If RestoManage processes the relevant information only on behalf of a restaurant, supplier, employer, or other Customer, we may refer the request to that Customer or assist the Customer in responding. We will not delete or change Customer-controlled records merely because a third party asks us to do so where the Customer is the responsible controller or where retention is legally required.

16. Automated processing

RestoManage may calculate reports, operational indicators, payment status, or commercial context from data in the Service. RestoManage does not currently use solely automated processing on its own behalf to make decisions about natural persons that are intended to produce legal or similarly significant effects. If a Customer uses RestoManage data as an input to its own employment, commercial, fraud, or customer decisions, that Customer is responsible for its decision-making process and applicable legal obligations.

17. Children

RestoManage is a business service and is not directed to children for account creation or direct marketing. Customers should not intentionally submit personal data about children unless it is necessary for a lawful business purpose and they have the authority and safeguards required to process it.

18. Changes to this policy

We may update this Privacy Policy when the Service, providers, law, or our processing practices change. The current version will be posted on this page with a revised effective date. Where a change materially affects how existing personal data is used, we will provide additional notice where required or reasonably appropriate.

19. Contact and privacy requests

To ask a privacy question or exercise a privacy right, contact us using the details below. Please include enough information for us to understand the request and identify the relevant account, restaurant, supplier, or interaction. We may need to verify identity or authority before acting on a request.

Privacy Policy | RestoManage