Data Processing Addendum
Who is responsible for the data your restaurant sends us, what we do with it, and how to get the signed copy.
Last updated 6 September 2026
Effective 6 September 2026
What this page is
This page states the terms of our Data Processing Addendum, the agreement that governs personal data we handle on your behalf. It forms part of our Terms of Service.
The executable copy — the one with signature blocks and the current list of the providers we use — is sent to you on request. Ask for it before you open an account if your own compliance rules need it in hand first.
Who is responsible for what
You are the controller of the personal data you and your point of sale send us. We are the processor. We handle that data only on your documented instructions, which are: these Terms, this Addendum, your settings in the product, and anything else you ask us in writing to do. If we ever believe an instruction breaks the law, we tell you and we do not carry it out.
Two things are outside this Addendum, because for them we are the controller and not your processor: your own account information (the person who signed up, their email, their IP address when they sign in), and our billing relationship with you.
What we process, and for whom
We receive order data from your point of sale, store it, display it on screens you control, print it, and produce operating statistics for you. We do that for as long as you have an account, plus the retention periods below.
The people whose data is involved are your guests, and your own staff who use the product.
From your point of sale we receive a guest’s name, phone number, any note left on the order, and, where the order type calls for it, a delivery address, the delivery service’s details, and a vehicle description for curbside and drive-thru. We take what your system sends us. We never ask a guest for anything directly, and we do not record a guest’s IP address, because guests never touch our software.
We do not receive guest email addresses, and we do not receive guest payment card data of any kind.
From your side we hold a name, an email address, a role, and the IP address recorded at sign-in, at password reset, and when a screen or printer connects to us.
No special-category data is requested, required, or expected. If your notes field is used to record any, you are sending it to us outside the purpose of this Addendum.
How we protect it
This is what is in place today, not what is planned.
- Encryption in transit. Traffic between you and us, and between our own components, is encrypted in transit. We do not claim encryption of stored data, because it is not confirmed. When it is confirmed in writing by our infrastructure owner, this line changes and you are told.
- Tenant separation. Each restaurant’s data is separated at the database layer, not only in application code.
- Secrets handling. Credentials are held in a secrets manager and never appear in the application or in logs.
- Support access. When our support team needs to look at your data, you have to let them, and the access is logged.
- Backups. Backups are encrypted. Daily backups are kept 30 days, monthly backups 12 months.
- Personnel. Everyone with access is bound to confidentiality.
The providers we use, and how you hear about a change
We use a small number of providers to run the service, and each is bound by its written terms with us, which limit it to providing that service to us. The current list is part of the signed copy of this Addendum rather than this page; ask for it at [email protected] and we will send it to you.
We use no advertising provider, no analytics provider, and no data broker of any kind, and none of your data or your guests’ data is sold, rented, or shared for anyone else’s marketing.
We tell you at least 30 days before we add or replace a provider that handles your data or your guests’ data. Notice goes by email to the account address. If you object on reasonable data-protection grounds within those 30 days, tell us; if we cannot offer you a reasonable alternative, you may terminate the affected part of the service without penalty and we refund any prepaid, unused fees.
Where the data is
We make no commitment on this page about the country your data sits in, in either direction, because we will not publish a residency claim we have not verified in writing. Our edge network also routes requests through globally distributed points of presence that are not guaranteed to be in any one country.
If your own compliance rules need a written commitment about data location, ask for one at [email protected] before you open an account, and we will answer you in writing.
How long we keep it, and getting it back
- Guest names and phone numbers are kept until you ask us to remove them. Your account carries a retention setting, 90 days unless you change it. That setting is recorded and reported, but no automatic job reads it and erases anything yet.
- Order records are kept 25 months, then archived rather than destroyed — moved aside and locked so the application can no longer read them. Moved aside is not erased.
- Raw copies of what your point of sale sent us are kept 7 days by policy, also not yet automatic.
- Operating statistics are kept indefinitely. Because guest details are not yet purged on a schedule, assume the statistics still sit alongside them.
- Your account data is kept for as long as you have an account.
On termination, at your choice, we export your data to you or delete it, within 30 days of your written request. We do both by hand today; there is no button in the product. After that window we delete it, except where the law requires us to keep it.
A backup is a snapshot of the whole system, so a record you asked us to delete can remain inside an older backup until that backup expires on the schedule above. We do not use backups to look up or restore individual records.
If a guest or a member of your staff comes to us directly, we point them to you and tell you. We can already produce a complete export of everything held about a person, and we action removals by hand, without extra charge, within 10 business days of your request.
We give you the information you reasonably need for a data protection impact assessment or a regulator’s question, in writing.
If there is a breach
If personal data we process for you is breached, we notify you within 72 hours of confirming it, by email to the account address, with what we know: what happened, what data and roughly how many people are affected, what we have done, and what we recommend you do. We publish a post-incident review. We do not wait for the investigation to finish before telling you.
Checking us
Once per twelve months, on 30 days’ written notice, you may ask for and we will provide our current security documentation and a written answer to a reasonable vendor-security questionnaire. Where a regulator or your own binding legal obligation requires more than that, we will agree a reasonable on-site or remote audit scope with you, at your cost, during business hours, without disrupting the service, and subject to confidentiality.
Liability, governing law and disputes
Our liability under this Addendum is subject to the limitation of liability in our Terms of Service.
This Addendum is governed by the laws of the State of Wyoming, without regard to its conflict-of-law rules. A dispute goes to court, in the same forum as our Terms of Service: the courts of Sheridan County, Wyoming are where it is brought, and both sides waive a jury trial.
There is no arbitration clause and no class-action waiver in this Addendum.
How to get the signed copy
Write to [email protected] from the email address on your account and ask for a signed Data Processing Addendum. A person reads it and sends you a countersigned copy, with the current list of providers.
MiniRestaurants is operated by Bobb LLC – MiniRestaurants Series, a Wyoming protected series of Bobb LLC, Bobb LLC – MiniRestaurants Series, 30 N Gould St Ste R, Sheridan, WY 82801-6317.