Data processing addendum
Last updated September 27, 2026
The short version
- When you put your staff's and suppliers' details into Cortado, they are your data. We only handle them to run the service for you.
- We never sell or share them, never use them for anything of our own, and never combine them with other data.
- We tell you about a breach within 72 hours, and about a new subprocessor 14 days before it starts.
- Delete your account and it all goes at once, with the last encrypted backups gone within 30 days.
- This is part of the terms automatically. There is nothing to sign.
This box is a summary, not the agreement. Everything below it is.
1. What this is
This addendum is part of the terms of service between you and Cortado. It applies whenever we handle personal information on your behalf in providing Cortado ("your personal data"), such as the names, hours and pay rates of your staff and the contact details of your suppliers. Where it conflicts with the terms about personal data, this addendum wins.
2. Who does what
You decide why and how your personal data is used. You are the "business" or "controller" under the laws that use those words. We handle it only for you, as your "service provider" or "processor".
You are responsible for having a lawful basis to put your personal data into Cortado and for giving the people it is about any notice the law requires. A notice for your staff is available to help.
3. Following your instructions
We process your personal data only to provide, secure and support Cortado for you, as set out in the terms, the settings you choose, and what you do in the app. Together those are your instructions. If we believe an instruction breaks the law, we will tell you. If the law requires us to process your personal data some other way, we will tell you first unless the law forbids it.
4. What we will not do
These promises meet the service provider requirements of the California Consumer Privacy Act and similar laws. We will not:
- sell your personal data, or share it for cross-context behavioral advertising;
- keep, use or disclose it for any purpose other than providing Cortado to you, including any commercial purpose of our own;
- keep, use or disclose it outside our direct business relationship with you;
- combine it with personal information we get from anyone else, except as the law allows a service provider to;
- use it to train AI models, or let anyone else do so.
We will give it the same level of privacy protection the law requires of you, tell you if we can no longer meet these obligations, and let you take reasonable steps to stop and fix any use that is not allowed. We certify that we understand and will comply with these restrictions.
5. The people who can see it
Only people who need access to run Cortado can see your personal data, and they are bound to keep it confidential. Today that is one person, the operator, who looks at customer data only to fix a problem you reported or to keep the service running.
6. Security
We protect your personal data with the measures in Annex 2. We may change them as better options come along, but not in a way that lowers the overall protection.
7. Subprocessors
You authorize us to use the subprocessors in Annex 3, listed with what each one sees on the subprocessors page. Each is bound by written terms that protect your personal data at least as well as this addendum, and we are responsible for what they do with it.
We will email you at least 14 days before a new subprocessor starts handling your personal data. If you object on reasonable data protection grounds, tell us. If we can't resolve it, you may close your account and we will refund any period you have paid for but not used.
8. Helping you answer people
Most requests from your staff about their information you can handle in the app yourself. Their details can be viewed, corrected and exported, a pay rate or note can be cleared, and someone who leaves can be marked inactive. Their name stays on the counts and checks they made, because those records are your audit trail and an inspector may ask for them. If a request needs someone removed entirely, email us and we will do it for you, or tell you what the law lets you keep.
If a request reaches us instead of you, we will pass it to you and not answer it ourselves, unless you ask us to. We will also give you reasonable help with anything else the law requires of you about your personal data, such as a risk assessment.
9. Breaches
If we become aware of a breach of security that leads to your personal data being lost, altered, disclosed or accessed without permission, we will tell you without undue delay, and within 72 hours. We will tell you what happened, what data was affected, what we have done about it and what you may need to do, and keep you updated as we learn more.
10. When it ends
You can export your data at any time. When you close your account, your personal data is deleted from the live database immediately, and from our encrypted backups as they age out, within 30 days. We keep nothing afterwards, except anything the law requires us to keep, which does not include your staff or supplier data.
11. Showing we comply
On reasonable request, we will answer your written questions about how we protect your personal data and give you the information you need to show you have met your own obligations, including a completed security questionnaire. We do not offer on-site audits at this stage, except where the law requires one.
12. Where it is kept
Your personal data is stored and processed in the United States, by us and by the subprocessors in Annex 3. We will not move it outside the United States without telling you first under section 7.
Annex 1: The processing
| Subject and purpose | Providing Cortado: stock, ordering, menu costing, sales, scheduling and food-safety records for your shops. |
|---|---|
| Duration | For as long as you have an account, then deletion as in section 10. |
| What we do with it | Store it, show it to you, calculate with it (including overtime, break checks and tip splits), send the emails you asked for, sync it to services you connect, back it up. |
| Whose data | Your staff, your suppliers' contacts, and people with a sign-in to your account. |
| What data | Names, roles, hourly rates, employment type, weekly hour limits, an age band for minors, start dates, notes, availability, shifts, time clock punches and breaks with any corrections and their reasons, tip pool shares, the name attached to each record they made, and supplier contact names, emails and phone numbers. |
| Sensitive data | None is needed, and the app has no place for it. Whether someone is under 18 is kept only so the schedule follows the rules on their hours. |
Annex 2: Security measures
Encryption
- All traffic is HTTPS only.
- The database is encrypted at rest by Supabase.
- Google and Square access tokens are encrypted again by Cortado (AES-256-GCM) before they are stored, so a copy of the database alone cannot use them.
- Backups are encrypted before they leave the machine that makes them. Backblaze and iCloud hold files they cannot read.
Accounts and access
- Passwords and shop PINs are stored only as salted hashes.
- Sessions are signed, expire after a period of inactivity the owner chooses, and last seven days at most.
- Sign-in, password reset and PIN entry are rate limited.
- Deleting an account needs the password, the shop name typed out and a code sent by email.
- The database key that can read every shop is kept only in the hosting environment and on the operator's own machine. It is never given to the build and test system.
Keeping shops apart
- Every query for shop data is filtered by the shop it belongs to.
- An automated check runs on every change, looks for any query that is not filtered, and fails the build if it finds one.
Resilience
- Encrypted backups are taken daily, and each one is decrypted and read back after it is written, to prove it can be restored.
- A failed backup or an unusual burst of errors alerts the operator by email.
- The staff counting screen keeps working without a signal and sends when it can.
People
- One person operates Cortado and is the only one with access to production systems.
- Customer data is looked at only to fix a problem the customer reported or to keep the service running.
More detail, and how to report a security problem, is on the security page.
Annex 3: Subprocessors
| Company | What for | What they see | Where | When |
|---|---|---|---|---|
| Supabase | Database | Everything stored in the app, encrypted at rest | United States | Always |
| Vercel | Hosting the website and app | Requests as they pass through, and cookieless page-view counts on the public site | United States | Always |
| Resend | Sending email | Your email address and the email itself | United States | Always |
| Backblaze | Off-site backups | Encrypted backup files it has no key to read | United States | Always |
| Apple (iCloud Drive) | A second copy of the encrypted backups | Encrypted backup files it has no key to read | United States | Always |
| Anthropic | The AI features | Only what one request contains, such as the invoice you asked it to read | United States | Only when you use an AI feature |
| Stripe | Taking payment | Your name, email and card. The card goes only to Stripe | United States | If you subscribe |
| Calendar sync | The shifts you choose to put on the calendar, and the calendar account's email address | United States | If you connect Google Calendar | |
| Square | POS sync | Cortado reads your completed orders and menu from Square and writes nothing back | United States | If you connect Square |
Questions about any of this? Email sen@cortado.services and a person will answer.