Moonnoobs Privacy Policy

Effective Date: May 29, 2026

1. Introduction

Moonnoobs("we", "us", or "our") operates a private business-operations application (the "App") that integrates with point-of-sale and third-party ordering platforms on behalf of the restaurants and businesses that use it. The App connects to the Clover point-of-sale platform and to third-party delivery marketplaces (such as Grubhub, DoorDash, Uber Eats, and ChowNow), accounting services, and other systems a merchant chooses to connect. This Privacy Policy explains how we collect, use, store, and disclose information obtained through the App when it is installed and used by a merchant ("Merchant"). By installing or using the App, you agree to the practices described in this policy.

2. Scope and Role

Moonnoobs acts as a data processor on behalf of the Merchant that has connected our App to their accounts. The Merchant is the data controller responsible for establishing a lawful basis for our processing of personal data. Each platform a Merchant connects is also a controller of certain data and maintains its own privacy notice, including:

  • Clover Network, Inc. — clover.com/privacy-policy
  • The delivery marketplaces, accounting services, and other providers a Merchant connects, each under their own published privacy policies.

3. Data We Collect

Through the APIs of the platforms a Merchant connects — and through files a Merchant uploads directly to the App — we may access and process the following categories of data:

  • Orders & Inventory: Order details, line items, item names, prices, quantities, categories, and inventory levels.
  • Payments & Transactions: Transaction IDs, payment amounts, tender types, tips, refund data, payout and settlement records, and transaction timestamps. We do not store raw card numbers or full payment card data.
  • Delivery Marketplace Data: Order, fee, commission, payout, and performance data from connected third-party delivery platforms (such as Grubhub, DoorDash, Uber Eats, and ChowNow).
  • Employee & Labor Data: Employee names, roles, identifiers, scheduled and actual hours, tip allocations, and disciplinary records that a Merchant maintains in a connected platform or uploads to the App (for example, scheduling, hours-variance, tip, and write-up files).
  • Financial & Supplier Data: Profit-and-loss figures, invoices, and supplier records that a Merchant uploads or syncs from a connected accounting service.
  • Customer Data: Customer names, contact information, and purchase history as stored by the Merchant in a connected platform.
  • Account & Usage Data: Email addresses of users a Merchant invites to the App, authentication records, and basic technical logs used to operate and secure the service.

We collect only the data necessary to provide the functionality of the App. We do not collect data beyond what is required for the App's stated purpose.

4. How We Use Data

We use collected data solely for the following purposes:

  • To provide, operate, and maintain the App and its features for the Merchant.
  • To aggregate, analyze, and report on the Merchant's own sales, labor, delivery, and financial performance within the App.
  • To process transactions and sync data as directed by the Merchant.
  • To generate, at the Merchant's direction, summaries and answers using artificial intelligence features (see Section 5).
  • To diagnose technical issues and improve App performance.
  • To comply with applicable laws, regulations, and the developer requirements of the platforms we integrate with.

We do not use Merchant, employee, or customer data for advertising, marketing to end-customers, or any purpose beyond operating the App for the Merchant.

5. Data Sharing and Disclosure

We may share data in the following limited circumstances:

  • Cloud Hosting & Infrastructure: We use third-party cloud providers to host and operate the App, including Vercel Inc. (application hosting) and Supabase Inc. (database, authentication, and file storage, hosted on Amazon Web Services). These providers process data on our behalf under appropriate data processing agreements.
  • Artificial Intelligence Processing: When a Merchant uses the App's AI features (such as the assistant or automated document extraction), relevant business data is sent to our AI provider, Anthropic, PBC, solely to generate the requested output. This data is not used to train third-party models.
  • Email Delivery: We use an email service provider (Resend) to send sign-in links and Merchant-requested reports and summaries.
  • Analytics: We may use analytics tools to monitor App performance and usage patterns. Any analytics data is aggregated or anonymized where possible.
  • Legal Requirements: We may disclose data to government or law enforcement authorities as required by law, or to protect our rights, the Merchant's interests, or the safety of others.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, Merchant data may be transferred as part of that transaction, subject to the same privacy protections described here.

We do not sell Merchant, employee, or customer personal data to third parties, and we do not share it for cross-context behavioral advertising.

6. Data Retention

We retain data only for as long as necessary to provide the App's services, or as required by law. When a Merchant disconnects a platform, uninstalls the App, or terminates their account, we will delete or anonymize their associated data within a reasonable timeframe, unless retention is required by applicable law or legal obligation.

7. Data Security

We implement commercially reasonable technical and organizational measures to protect data against unauthorized access, loss, or disclosure. This includes encryption in transit (TLS), encryption of stored integration credentials, and role-based access controls. However, no system is completely secure, and we cannot guarantee absolute security.

Our App integrates with the Clover platform and adheres to Clover's Payment Card Industry (PCI) security guidance for developers. For more information, see Clover's PCI security guidance.

8. Your Privacy Rights

Depending on your jurisdiction (for example, under the California Consumer Privacy Act or the EU/UK General Data Protection Regulation), individuals may have rights to access, correct, delete, or restrict the processing of their personal data, and to object to certain processing.

Because we process most personal data as a processor on behalf of a Merchant, requests from a Merchant's customers or employees should generally be directed to the relevant Merchant, who acts as the data controller. We will assist Merchants in responding to such requests as required by law. To exercise rights with respect to data we control, or for help with a request, contact us using the details in Section 11.

9. Merchant Responsibilities

The Merchant is responsible for informing their customers and employees about data collection and processing activities that occur through the Merchant's use of our App, including by maintaining their own privacy policy. The Merchant must ensure they have a lawful basis for providing customer and employee data to our App and for our processing of that data, and that they are authorized to connect each platform they link to the App.

10. Children's Privacy

Our App is designed for use by businesses and their employees. We do not knowingly collect personal information from children under the age of 13. If we become aware that such data has been collected, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify affected Merchants of material changes by posting the updated policy at our website or via the App. Your continued use of the App after changes take effect constitutes acceptance of the revised policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us: