Margin.Sign in

Privacy Policy

What Margin collects, why, who else can see it, and how it is deleted.

Version 2026-08-28 · Effective August 28, 2026

1. What this covers

This policy describes what Margin collects, why, and what happens to it. It covers only what the product actually does today.

2. Account and profile data

When you create an account we store your email address, and your name if you provide one. Passwords are handled by our authentication provider and are never stored by us in readable form. If you sign in with Google, we receive the basic profile information that sign-in returns.

3. Restaurant and operational data

The working data you enter is stored so the product can calculate and display it back to you:

  • restaurant profile, locations and cost targets
  • vendors, ingredients, purchase prices and price history
  • recipes and recipe ingredients
  • menu items and prices
  • invoices, invoice line items, and invoice files you upload
  • inventory counts, count lines and waste logs
  • sales imports, daily sales items and item mappings
  • team memberships, roles and invitations
  • alerts and insight dismissals

4. Uploaded files

Invoice images and documents you upload are stored in a private file bucket that is not publicly readable. They are retrieved only for members of the restaurant they belong to, and are deleted when the restaurant is deleted.

5. Point-of-sale connections

If you connect Toast or Square we store connection metadata — provider, environment, merchant or location identifiers, connection status, sync timestamps and error messages — plus the credentials or access and refresh tokens needed to sync your sales.

Those credential records are held in tables that no browser client can read: they are excluded from every data export, are never sent to the front end, and are only used server-side to talk to the provider. Deleting a restaurant deletes them, and for Square we also attempt to revoke the token with the provider.

6. Authentication, sessions and technical data

Signing in creates a session. The session token is kept in your browser's local storage so you stay signed in between visits, and it is sent to our server to authorize each request. We also keep a small local record of which restaurant you last had selected. We do not use advertising or third-party tracking cookies.

Our infrastructure providers process ordinary technical request data, such as IP address and browser user agent, in the course of serving and securing requests.

8. How your data is used

We use your data to:

  • operate the product and show you your own numbers
  • calculate costs, margins, variance, alerts and insights
  • sync sales from a point-of-sale provider you connected
  • authenticate you and keep accounts separated from one another
  • diagnose errors and keep the service secure and working

9. Who else sees it

Your restaurant data is visible to members of that restaurant, at the level their role allows. We do not sell your data and we do not share it for advertising.

We rely on service providers to run the product: Supabase for database, authentication and file storage, and our hosting provider for serving the application. Toast and Square receive requests only for the connection you authorize. Providers process data on our behalf to deliver the service.

We may disclose data if legally required, or where necessary to protect the service or its users.

10. Retention and deletion

Data is kept while your account and restaurants exist. Deleting a restaurant removes its uploaded invoice files first and then its database records, including its credential rows. Deleting your account removes your authentication identity, your profile, your restaurant memberships and your legal acceptance records; invitations you sent keep the invitation but drop the reference to you.

Backups and provider logs may retain copies for a limited period as part of normal infrastructure operation.

11. Your controls

You can edit or delete most records directly in the product. An owner can export a restaurant's data as CSV, and can delete a restaurant. Any user can delete their own account from Settings.

12. Security

Access is enforced at the database with row-level security so accounts and restaurants stay separated, credentials are stored in tables unreachable from the browser, uploaded files sit in a private bucket, and privileged operations are authorized on the server. No service can promise perfect security, and we do not claim to be completely secure.

13. Regulatory disclosures

We do not currently claim any certification, audit or formal compliance status. If that changes, specific disclosures will be added to this section and the policy version will be updated.

14. Children

The service is intended for business users. It is not directed at children, and we do not knowingly collect data from them.

15. Changes to this policy

When we make a material change we publish a new version and ask you to accept it before continuing to use the product.

16. Contact and data requests

Privacy questions and data requests: [privacy contact email — to be provided by the operator of Margin]. Controller entity: [legal entity name — to be provided by the operator of Margin].