Draft for legal review

Privacy Policy

Scope

This policy describes how DishStock, a Cirstrata product, processes information when installed on a Wix site.

Information processed

DishStock processes Wix installation, site, user authorization, location, menu configuration, and billing-entitlement references; ingredients, recipes, connections, settings, feedback, inventory activity; and operational order references and snapshots needed to calculate, explain, and recover theoretical inventory changes.

DishStock is designed not to require restaurant customer names, delivery addresses, or payment-card details for inventory accounting. Merchants should not enter that information in feedback or free-text reasons.

Purposes

Providers

Wix supplies the app platform, installation identity, restaurant data, events, and billing source of truth. Railway hosts the application backend. Supabase provides PostgreSQL database infrastructure. See Subprocessors.

Retention and deletion

Tracking stops when the app is uninstalled. Installation data is retained for 30 days to permit recovery after reinstall and then becomes eligible for deletion. Provider backups may follow separate retention cycles; this policy does not promise immediate backup erasure.

Access and requests

Merchants can download an installation-scoped data export from Settings. For other access, correction, or deletion requests, email privacy@cirstrata.com. Identity verification should be proportionate and must not request Wix passwords or card details.

Security

DishStock verifies signed Wix requests, keeps service credentials server-side, uses HTTPS boundaries, tenant/location scoping, row-level security, and restricted privileged database functions. No certification or absolute guarantee is claimed.

Changes

Material policy changes will be posted with an updated effective date.