Privacy Policy
Last updated: August 24, 2026
The short version. We collect what we need to run the Service and nothing we do not. Your business and employee data belongs to you — we process it on your instructions. We do not sell personal information, and we do not use your financial data to train AI models. You can export or delete your data.
1. Two different roles, and why it matters
This is the distinction that governs everything below.
For your account information — the name and email of whoever signs up, billing details, and how the app is used — we are the controller. We decide why it is collected, and this policy explains it.
For everything you put into the Service — invoices, counts, recipes, sales, payroll and employee records — you are the controller and we are your processor. We handle it on your instructions, to run the Service for you. Your own privacy notice to your employees is your responsibility, not ours.
2. What we collect
Account and billing. Name, work email, business name, role, and (through our payment processor) subscription and payment status. We never see or store full card numbers.
Customer Data you upload or connect. Vendor invoices, inventory counts, recipes, product costs, sales figures, and — where you use those modules — bank transactions, payroll records, wages, tips, and employee identifiers.
Photos. The mobile app can use your device camera to photograph invoices and to scan barcodes. Images are uploaded so their contents can be read into your records. The app requests camera access only when you use those features, and does not access your photo library in the background.
Technical. IP address, device and browser type, timestamps, and error diagnostics — used to keep the Service secure and working.
We do not collect precise geolocation, advertising identifiers, contacts, or biometrics, and we do not track you across other companies’ apps and websites.
3. Employee data — read this if you run payroll through us
If you use modules that handle payroll or scheduling, you are uploading other people’s personal information. We process it only to provide the Service to you.
If you employ minors — common in food service — their records are subject to additional protections in many states. You are responsible for lawful handling and for any notice or consent your jurisdiction requires. The Service is not directed to children and we do not knowingly collect information directly from anyone under 13.
4. Why we use it
To provide, secure, and support the Service; to bill you; to detect and prevent abuse; to communicate about your account and material changes; and to meet legal obligations.
We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined under US state privacy laws. We run no advertising.
5. AI features, stated precisely
Some features use AI to read documents you submit — for example extracting line items and costs from a photographed invoice.
For those features, the document contents are sent to our AI provider solely to return a result to you. Your financial data is not used to train AI models, by us or, under our configuration, by the provider. AI output is a draft: it can be wrong and is meant to be reviewed by a person before you rely on it.
6. Who we share it with
Only these categories, and only as needed:
- Infrastructure and database — hosting, application runtime, and the database holding your records.
- Payment processing — to take subscription payments. They receive billing data; we do not receive card numbers.
- AI document processing — as described in Section 5.
- Email delivery and error monitoring — to send account email and to diagnose failures.
- Integrations you enable — such as your POS, payroll, or bank connection. You choose these, and data flows because you connected them.
We also disclose information if required by law, to enforce our Terms, or in connection with a merger or sale of the business — in which case we will notify you and the buyer remains bound by this policy. Current subprocessors are available on request at hello@profitforged.com.
7. How it is protected
Encryption in transit; per-tenant isolation enforced at the database level so one customer cannot reach another’s records; role-based access; multi-factor authentication; encrypted, verified backups; audit logging of sensitive operations; and a written security protocol we test and revise.
No system is perfectly secure. If a breach affects your data we will notify you without undue delay and no later than 72 hours after confirming it.
8. How long we keep it
Customer Data is kept while your subscription is active. After termination we hold it for 30 days so you can export, then delete it on a scheduled purge. Some records — billing history, and logs needed for security or legal obligations — are retained longer where the law requires.
9. Your rights
Depending on where you live you may have the right to access, correct, delete, or receive a copy of your personal information, and to opt out of sale or sharing (we do neither). Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws have these rights, and we will not discriminate against you for exercising them.
Exercise them at hello@profitforged.com. We respond within 45 days. If your request concerns data your employer uploaded, we will refer you to them, because they control it.
10. Where data is processed
The Service is operated from and intended for use in the United States. Data is stored and processed in the US. We do not currently offer the Service in the European Economic Area or the United Kingdom.
11. Changes
We will update this policy as the Service changes. Material changes get at least 30 days’ notice by email or in-app, and the “last updated” date above always reflects the current version.
Contact: hello@profitforged.com — Vivid Software LLC, a Florida limited liability company. Write to us at that address for any question about this policy, to exercise a privacy right, or to request our current list of subprocessors.