Privacy Policy

Last updated: July 15, 2026 · Version 2.2

margherita is a restaurant management platform operated by Boldrope Inc. (incorporation pending in Ontario, Canada) ("we", "us", "our"). This policy explains what personal information we collect, why, who we share it with, and the rights you and the people whose data you bring onto the platform have under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Our two roles

We handle personal information in two distinct capacities:

2. What we collect

CategoryExamplesSource
Account dataEmail, hashed password, role, last loginYou, at signup/login
Employee dataNames, personal emails, hourly wages, shifts, hours, time-off requestsEntered by your restaurant's managers
Business recordsSupplier invoices, orders, inventory, recipes, sales reportsUploaded or entered by your team; may incidentally contain personal data (e.g. a supplier rep's name)
Connected accountsGmail OAuth tokens (read-only invoice/report import), Meta tokens (social posting)Only if you connect them
Technical dataIP address, timestamps, request logs, audit and impersonation logsAutomatic, for security
Demo leadsName, email, restaurant name, IPThe public demo on our website

We collect only what the service needs (PIPEDA limiting-collection principle). We use no advertising or cross-site tracking cookies — the cookies we do use are described in section 2a below.

2a. Cookies on our public pages

Before you have an account, our landing, demo and legal pages use two kinds of cookie:

You can withdraw consent at any time by clearing your browser cookies for margherita or by contacting us (see section 10).

3. Why we use it

4. Service providers (subprocessors)

We use a small set of providers to run the service. Some are located in the United States, which means information may be processed outside Canada and be subject to the laws of those jurisdictions:

ProviderPurposeLocation
RenderApplication hostingUSA
SupabaseDatabase & file storageUSA
AnthropicAI document extractionUSA
ResendTransactional email deliveryUSA
SentryError monitoring (technical error reports may include the account email of the affected user)USA
Google / MetaOnly if you connect Gmail or social accountsUSA

Payment processing is not currently integrated. When paid plans launch, the provider (e.g. Stripe) will be disclosed here and in the Terms.

5. Google API data

Our use of data obtained from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements:

6. Retention and deletion

7. Your rights

Under PIPEDA you may request access to, correction of, or deletion of your personal information, withdraw consent (which may limit the service we can provide), and ask questions about our practices. We respond within 30 days. Restaurant owners can also request a full export of their company's data or its deletion. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada.

8. Security and breach notification

Passwords are hashed, connections are encrypted (HTTPS), administrative access is logged, and tenant data is isolated per company. If a breach of security safeguards creates a real risk of significant harm, we will notify the Privacy Commissioner and affected individuals as required by PIPEDA.

9. Changes

We will post updates here with a new date and version, and notify account owners by email of material changes at least 30 days before they take effect.

10. Privacy Officer & contact

Boldrope Inc. has designated a Privacy Officer responsible for PIPEDA compliance. For privacy questions, access requests, or complaints: privacy@boldrope.com.

← Terms & overview