Who owns your restaurant's data, and what actually protects it
How one restaurant's data is kept separate from another's, what an audit trail proves, how to get your data out, and the questions worth asking any vendor before you sign.
“Is my data safe?” is really three questions in one: can someone else see it, can I get it back, and can anyone prove what happened to it. They have different answers and deserve to be separated.
Can another restaurant see it
This is the one that matters most in shared software, and it should not depend on developers remembering to filter every query.
Every record carries the identity of the restaurant it belongs to, and that filter is applied at the database layer for every read — not added by hand to each query. A missing where clause in one report cannot leak another restaurant’s orders, because the constraint is not in the report.
Above that sits the login itself. A staff token carries the restaurant it belongs to, and a request that arrives without a resolvable one is refused rather than served with a guess.
Can someone inside see what they should not
That is a different problem, and it is answered by roles. Nine role levels decide what each screen shows; a branch manager is restricted to their own branch by the system rather than by instruction; a cashier never sees payroll.
Under it are the ordinary defences: passwords stored as hashes, not text. An account locked after five failed sign-in attempts. Long-lived sessions that rotate rather than living forever, and can be revoked per device. Rate limits on login, password reset, payments and ordering, so a script cannot grind away at them.
None of this is exotic. It is table stakes, and the reason to list it is that “we take security seriously” is not an answer to any question.
Can anyone prove what happened
Two records run under everything: an activity log of what staff did, and an audit trail of what changed — with before and after values, the user, and the time.
This is the part people underrate until they need it. Posted accounting entries are reversed rather than edited, precisely so that history stays readable. A system in which last month’s numbers can quietly change is a system that cannot answer a question honestly, however secure it is.
Can you get your data out
Here is the honest test of ownership, and it is not a clause in a contract — it is a button.
Your menu, your customers, your orders, your stock and your books are yours. Reports export to spreadsheet and PDF, and the underlying data is exportable rather than trapped. The right question for any vendor is not “do you own my data” — every vendor says no. It is: “show me the export.”
Ask a second one while you are there: what happens to that data if you stop paying? A read-only period is reasonable. Instant deletion is not, and it is worth knowing which you are agreeing to.
Privacy requests, from staff and from strangers
Two obligations turn up in practice: an employee asking what is held about them or asking for it to be deleted, and a member of the public making the same request through your website. Both are recorded as requests with a status, so they can be tracked to completion instead of living in someone’s inbox. Employee consents for data processing, marketing and analytics are recorded with a date, and can be withdrawn.
Whether these apply to you depends on where you operate. The mechanism being there means the answer is a process rather than a panic.
Backups, honestly stated
Backups are the hosting provider’s job, not a feature you configure. What you should establish before signing with anyone — us included — is three things: how often backups are taken, how long they are kept, and whether a restore has ever been tested. The third one is the question most vendors are not asked and the only one that proves the first two.
The five questions worth asking any vendor
- How is my data separated from other customers’ — technically, not in principle?
- Show me the export. All of it, not a summary report.
- What happens to my data if I stop paying, and for how long?
- Can you show me who changed a price last month?
- When did you last test restoring a backup?
A vendor who answers all five plainly is a vendor you can hold to it later. That, more than any certificate on a marketing page, is what “safe” means in practice.
Run all of this from one system
POS, kitchen, inventory, recipe costing, staff and accounting — connected, and free to start.
Create your free account