Privacy Policy
Last updated: July 29, 2026
Margin Op ("Margin Op," "we," "us") provides food-cost, invoicing, and back-office software for restaurants and food businesses at marginop.io and app.marginop.io (the "Service"). This policy explains what information we collect, how we use it, and the choices you have. It applies to customers, their staff users, and visitors to our websites.
Information we collect
- Account information. Name, email address, password (stored as a cryptographic hash), role, and the organization you belong to.
- Business data you provide. Vendor invoices (including uploaded photos and PDFs), ingredients, recipes, menus and prices, catering invoices and client records, staff scheduling information, and related operational data you enter into the Service.
- Data from connected services. When you connect a point-of-sale or accounting integration (such as Square, Squarespace, QuickBooks Online, Xero, Stripe, or WooCommerce), we receive the data needed to provide the Service — for example sales transactions, catalog items, chart-of-accounts entries, and invoice or bill records. We store the authorization tokens required to maintain these connections; we never see or store your passwords for those services.
- Payment information. Subscription billing is processed by Stripe. Card numbers are handled by Stripe and never touch our servers. If your business uses a supported payment provider for your own invoices (such as iPOSpays/Dejavoo), your customers' card details are processed by that provider, not by us.
- Usage and device information. Log data, IP address, browser type, pages viewed, and similar analytics collected via cookies and similar technologies, including Google Analytics.
How we use information
- To provide, maintain, and improve the Service — including costing recipes, reconciling sales, generating invoices, and syncing with services you connect.
- AI-assisted invoice scanning. When you upload a vendor invoice, we transmit the document to a third-party AI model provider to extract its contents (vendor, dates, line items, totals). Extracted results are shown to you for review and correction. We do not use your invoices or business data to train our own or third parties' AI models.
- To send transactional email (such as invoices you ask us to send, receipts, and service notices) through our email delivery provider.
- To respond to support requests and communicate about the Service.
- To secure the Service, prevent abuse, and comply with legal obligations.
How we share information
We do not sell your personal information, and we do not share it with third parties for their own advertising. We share information only with:
- Service providers that host and operate the Service on our behalf — including cloud hosting and database infrastructure, AI processing for invoice extraction, email delivery, and payment processing — bound by confidentiality obligations and permitted to use the data only to provide services to us.
- Services you connect. When you enable an integration, we exchange data with that service as directed by you (for example, exporting an approved invoice to your accounting system). Their handling of that data is governed by their own privacy policies.
- Within your organization. Data you enter is visible to other authorized users of your organization according to the roles your administrators assign.
- Legal requirements. If required by law, subpoena, or to protect the rights, safety, or property of Margin Op, our users, or others.
- Business transfers. In connection with a merger, acquisition, or sale of assets, in which case this policy will continue to apply to your information.
QuickBooks, Xero, and other accounting data
When you connect an accounting platform, we access only the data needed for the features you use — typically chart-of-accounts entries, vendor and customer records, and the bills or invoices we create or retrieve at your direction. We store connection tokens securely, refresh them as the platform requires, and delete them when you disconnect the integration. We do not access your accounting data for any purpose other than providing the Service to you.
Data retention
We retain your data for as long as your account is active. When an account is closed, we delete or de-identify customer data within a commercially reasonable period, except where retention is required for legal, tax, or dispute-resolution purposes. Backups roll off on a fixed schedule.
Security
We use industry-standard safeguards: encryption in transit (TLS) and at rest, role-based access controls with row-level data isolation between organizations, hashed credentials, and least-privilege access for our personnel. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your rights and choices
- You can access and update most information directly in the Service.
- You can request a copy, correction, or deletion of your personal information by contacting us at the address below. We will respond as required by applicable law, including for residents of jurisdictions with specific privacy statutes.
- You can disconnect integrations at any time from Settings, which revokes our access tokens for that service.
- You can control cookies through your browser; some features may not function without them.
Children
The Service is for businesses and is not directed to children under 13. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. We will post the revised version here with a new "Last updated" date, and for material changes we will provide notice through the Service or by email.
Contact
Margin Op
[STREET ADDRESS, CITY, STATE ZIP]
privacy@marginop.io