Privacy Policy
Last Updated: September 5, 2026
Foresio AI, LLC, a Georgia limited liability company (“Foresio,” “we,” “us”), provides restaurant intelligence services to U.S. restaurants. This Policy explains how we handle information on our website, dashboard, advisor services, integrations, and messaging programs (the “Service”). For privacy questions or requests, email hello@foresioai.com or use Contact Us in the Service.
We do not sell or rent client data, disclose one client’s private data to another client, or provide personal information to advertisers for their own use. We use necessary service providers and make disclosures authorized by clients or required by law, as described below. AI processing is part of the Service. General/shared model training is permitted only with the protected, non-identifying material described in Section 6; identifiable guest records and confidential client information are excluded.
1. Whose information this Policy covers
This Policy covers restaurant owners, managers, staff, website visitors, business contacts, and people whose information a restaurant lawfully processes through Foresio, including guests, reviewers, and supplier contacts.
For our own account administration, billing, security, support, and business relationships, Foresio generally acts as controller or business where those legal terms apply. For guest records, restaurant messages, and other personal information processed on a restaurant’s behalf, the restaurant generally decides why it is used, and Foresio acts as processor or service provider. Appendix A to our Terms of Service contains the contractual Data Processing Addendum for that processing. These roles depend on the activity and applicable law.
If you are a restaurant guest, the restaurant’s privacy notice also applies. Contact that restaurant about its orders, offers, consent collection, or use of your information. You may also contact us; we will direct the request appropriately and assist where required. Independent POS systems, payment services, public review platforms, and other sites may handle information for their own purposes under their own notices. That does not remove our responsibility for processing we perform.
2. Information we collect and its sources
Collection depends on the features used, permissions granted, and information available. We do not treat access to an entire connected account as permission to collect every available field.
| Category | Examples | Sources |
|---|---|---|
| Account and user information | Names, restaurant name, email, phone number, role, invitations, age certification, authentication and session records, account preferences | You, the account owner, authorized users, authentication services |
| Billing and subscription information | Plan, renewal date, payment status, invoices, limited payment metadata, Stripe payment-method identifier/fingerprint, promotion redemption, tax/business address | You and Stripe; full card numbers and card security codes are collected by Stripe rather than directly received or stored by Foresio |
| POS and restaurant operations | Orders, timestamps, line items, modifiers, totals, discounts, cover counts, menu configuration, connected location identifiers, and relevant guest identifiers or order history | Authorized POS connections, including supported Square, Clover, Toast, or SpotOn connections, and restaurant CSV imports |
| Inventory, recipes, and supplier records | Ingredients, quantities, units, yields, costs, optional ingredient allergen tags, recipes, deliveries, expiration dates, waste, recounts, supplier contacts, uploaded receipt images and extracted line items | Restaurant users, uploads, receipt processing, and confirmed corrections |
| Business profile and local demand | Google Business Profile information, business address, operating hours, location, cuisine, Place ID, reviews, and local keyword demand data | Authorized Google connections, Google Places, Foresio-managed Google Ads Keyword Planner queries, and operator corrections |
| Guest messages and consent | Phone number, program enrollment, consent wording and version, source and timestamp, affirmative opt-in event, opt-out/suppression status, number deliverability information, messages, delivery logs, private ratings, service-recovery threads, and incentives | Restaurant's authorized collection, guest QR/SMS interactions, POS data, Foresio consent tools, and Twilio |
| Promotion measurement and advisor information | Approval history, audience selection, holdout assignment, redemption, matched visits/purchases where available, forecasts, recommendations, review replies, corrections, brand voice examples, and Rundown records | Restaurant data, authorized users, consented guest interactions, and generated analysis |
| Public competitor information | Business names, addresses, published menu prices, categories, public social handles and offer details, source links, collection dates, and comparison records | Google Places, lawfully accessible delivery listings and public social posts, authorized collection services, and manual entry |
| Support and technical information | Support requests, strategy-call scheduling and account-management notes, IP address, browser/device information, sign-in events, error and security logs, feature usage, and audit records | Your communications and interactions with the Service, and infrastructure providers |
Account-management records do not mean that strategy calls are automatically audio/video recorded. Any recording requires advance notice and consent where required. We do not collect guests’ precise device geolocation for marketing; restaurant location and geographic information needed to apply lawful messaging windows are distinct. Optional ingredient allergen tags describe food, not a guest’s medical history.
Guest complaints may incidentally mention illness, injury, or another sensitive matter. We use those details only as needed for restaurant-directed handling, safety, legal obligations, and restricted support, not for shared-model training or advertising profiles. Do not submit medical records, government identifiers, biometric templates, complete payment credentials, or other sensitive data unrelated to the Service.
3. How we use information
We use information for the following specified purposes:
- Deliver the subscribed advisors: manage inventory and recipes through Stock Watch; forecast demand and run approved promotions through Full House; handle consented ratings, service recovery, and authorized Google replies through Review Responder; analyze menus and tests through Menu Engineer; extract and confirm receipt costs through The Ledger; compile role-filtered Rundown summaries; and provide lawfully sourced Competitor Intelligence comparisons.
- Administer the account: authenticate users, enforce roles, connect authorized systems, provide support and account management, bill through Stripe, manage trials, detect duplicate trial eligibility using relevant account/payment/location identifiers, and process cancellations and refunds.
- Operate messaging responsibly: capture and maintain consent evidence, identify the restaurant sender, check program eligibility, enforce approvals, send windows and frequency, process withdrawal, and prevent unauthorized re-enrollment.
- Measure approved promotions:compare outcomes for recipients and randomized holdout groups using available visit/redemption records. This analysis serves that restaurant’s program; it does not share its guest list or private results with other restaurants.
- Protect and maintain the Service: troubleshoot, investigate misuse, secure systems, document user actions, and improve reliability. Client-specific mappings and settings remain associated with that account; broader model improvement is limited by Section 6.
- Meet legal obligations: respond to lawful requests, exercise or defend legal rights, preserve necessary consent and billing evidence, and handle privacy requests.
We do not use guest contact information for Foresio’s own marketing, create cross-client guest profiles, pool private restaurant metrics into a client benchmarking product, or use personal information for cross-context behavioral advertising. Local keyword queries and competitor research do not authorize disclosure of a restaurant’s confidential recipes, costs, or guest list to those sources.
4. SMS programs and public reviews
Restaurant guests
Full House provides restaurant promotions. Review Responder provides private visit ratings, service-recovery exchanges, and public-review invitations. Messages identify the restaurant and may be automated or AI-assisted. A phone number in a POS record is not sufficient permission for these programs. Foresio checks for the applicable recorded consent before sending.
The enrollment flow explains the named sender, program, frequency, automated messages, message/data rates, that consent is not a purchase condition, and how to stop. In the QR flow, the guest sees the disclosures before choosing to send the prepared opt-in message. Scanning the QR code alone does not enroll anyone. We keep evidence of the affirmative action and the wording shown. Program consent is not transferred to a different restaurant or unrelated program. Where consent is collected externally, the restaurant must provide valid evidence for the applicable program.
Reply STOP, UNSUBSCRIBE, CANCEL, END, QUIT, REVOKE, or OPT OUT to stop that restaurant’s Full House and Review Responder texts. Recognized keywords trigger immediate suppression and one nonpromotional confirmation. You can also withdraw by another reasonable method, including contacting the restaurant or hello@foresioai.com. Other requests are processed as soon as practicable, within ten business days or a shorter applicable legal deadline. Reply HELP for assistance. Re-enrollment requires fresh affirmative consent. Withdrawal stops future program texts but does not erase the evidence needed to honor or document it. A restaurant’s withdrawal does not automatically change consent you separately gave another restaurant.
Frequency is disclosed by program. The default marketing cap is two messages per week, reduced when the disclosure or law requires a lower limit; feedback and service messages have separate disclosed frequency. Guest messages follow lawful recipient-local send windows, using an 8 a.m. to 8 p.m. default and stricter rules where applicable. Message/data rates may apply. Carriers are not liable for delayed or undelivered messages.
Private ratings and service-recovery messages remain private within the restaurant’s authorized users, Foresio personnel, and necessary providers. They are not automatically posted as public reviews. All eligible guests who submit a rating receive the same public-review invitation schedule and wording regardless of score or service-recovery status, subject to consent, opt-outs, delivery restrictions, and duplicate prevention. A nonresponse to the initial private rating request ends further requests for that visit. Clicking a Google review link takes the guest to Google; a review they choose to submit there is public under Google’s terms. A restaurant’s authorized public reply is also public.
Owners and staff
Operator-facing SMS, including Rundown and operational alerts, requires that recipient’s separate affirmative opt-in. Frequency depends on preferences and enabled features. Operator recipients are kept separate from guest lists. STOP or another reasonable withdrawal request ends that operator’s SMS program; necessary billing, security, or account notices can continue through email or the dashboard. Account acceptance alone does not supply SMS consent.
5. Who receives information
We disclose information only within the limited categories below, for the described purposes, and subject to applicable confidentiality and privacy requirements.
| Recipient | Purpose and limits |
|---|---|
| The client and its authorized users | Access to its own information and outputs according to role. Staff do not receive unrestricted financial, billing, or consent information. One client does not receive another client's private data. |
| Foresio personnel and necessary professional advisers | Restricted access to provide support, maintain systems, administer the business, or address legal/security matters, with appropriate confidentiality duties. |
| Supabase and Railway | Database, authentication/storage where used, application hosting, and infrastructure processing necessary to operate the Service. Their authorized infrastructure subprocessors may participate under applicable provider agreements. |
| Stripe | Payment collection, subscriptions, invoices, refunds, tax handling, and related payment/fraud administration. Stripe may also act independently for its own legally required and payment-network functions. |
| Twilio and delivery-chain providers | SMS delivery and replies, per-restaurant numbers, number validation, registration, and consent/opt-out operation. Carriers and registration entities receive information needed to deliver or authorize traffic. |
| OpenRouter and selected underlying AI providers | Inference and related model processing of relevant inputs, subject to Section 6's data-use restrictions. OpenRouter is a routing layer; underlying providers also receive routed inputs. |
| Receipt OCR, email delivery, and operational support providers | Extract receipt fields, deliver account/advisor emails, and support diagnostics or security only to the extent a selected provider needs the relevant data. Foresio does not disclose guest lists to an unrelated analytics or advertising service. |
| Authorized POS and Google services | Exchange data or publish changes instructed through supported POS, Google Business Profile, Google Places, and Google Ads Keyword Planner functions. Public replies and approved profile changes are public disclosures; private source records are not automatically published. |
| Competitor collection services | Sian Agency's Uber Eats menu scraper and Apify's Instagram scraper, where lawfully usable, receive necessary public competitor URLs, handles, and collection parameters. They do not need the client's guest list, recipes, or private POS transactions. |
| Recipients you specifically authorize | For example, a guest receiving an approved restaurant message or a verified recipient receiving a secure compliance report. Authorization is limited to the requested disclosure. |
For Google Maps/Places features, the Google Privacy Policy is incorporated as the notice governing Google’s own handling of information. It does not expand Foresio’s permitted uses of client information.
The current list of providers handling client personal information, their identities, functions, and processing locations—including selected underlying AI, receipt OCR, and email providers—is available by emailing hello@foresioai.com. A category above is not permission for unrestricted vendor access. We select providers and require appropriate agreements before giving them personal information. Clients receive planned subprocessor-change notices and objection rights under Appendix A to the Terms.
We may also disclose the minimum information reasonably necessary to comply with a binding legal obligation or valid legal process, investigate unlawful activity, protect rights or safety, or establish or defend a legal claim. We notify the affected client where lawful and practicable. These exceptions are not permission for unrelated commercial use.
If Foresio undergoes a merger, financing, reorganization, acquisition, or sale of the relevant business, necessary information may be disclosed under confidentiality and data-protection safeguards. Identifiable guest records are not ordinary diligence material. A successor must assume the applicable protections; we notify clients of a transfer. This is not permission to sell client datasets separately, disclose private data to competing clients, or materially expand its use without a lawful basis and any required consent.
6. AI inference, account learning, and shared-model training
Inference means processing inputs to generate a result, such as a drafted review reply, parsed receipt, or recommendation. Relevant information may pass through OpenRouter to a selected model provider. We limit inputs to what the function needs and restrict access and reuse. Inference is not the same as permission to train a general model.
Account-specific learningincludes remembering a restaurant’s confirmed vendor mappings, approved voice examples, and corrections to improve its own results. Those records remain protected as that client’s information.
General/shared model improvement may use lawfully obtained public or licensed information, synthetic examples, and material derived from client records only after both de-identification and confidentiality screening. This material must not reasonably identify a person or restaurant, expose private messages, reveal confidential recipes or identifiable financial records, or permit reconstruction of client secrets. Removing names or replacing phone numbers with a reversible identifier does not by itself meet this standard. Providers receiving such material must be restricted from re-identifying it or exposing protected client information. We publicly commit to maintain qualifying de-identified information in de-identified form and not attempt re-identification, except lawful testing of the protections.
These shared model improvements may benefit multiple clients. We do not disclose their underlying private records to each other. We do not use identifiable guest records, consent evidence, private conversations, credentials, or identifiable/confidential client data to train general/shared models, and do not permit inference providers to use those inputs for that purpose. Foresio must restrict routing and provider settings accordingly. Applicable API and source restrictions also control Google-sourced and other licensed data, even after de-identification; this Policy does not authorize training prohibited by those restrictions. Information that cannot meet the de-identification and confidentiality standard is excluded from shared training.
Providers can have different safety logging, retention, and processing locations. We do not promise that every model endpoint has zero retention, or that every model listed by OpenRouter is eligible for Foresio’s confidential workloads. Vendor selection must satisfy our processing commitments. De-identified information that no longer identifies you is not necessarily retrievable by account, and completed lawful model training is not necessarily reversible after an account closes. This does not excuse retaining or training on identifiable personal information contrary to this Policy.
7. Cookies, technical information, and security
We use cookies or similar storage needed for authentication, sessions, preferences, and security. Operational logs and limited usage information help us diagnose errors and maintain the Service. These activities are not permission to deploy advertising pixels or cross-site tracking. Any optional nonessential tracking will be disclosed and offered with consent controls where required before it operates. You can manage browser storage; disabling necessary storage can prevent login or other features.
We do not sell personal information or share it for cross-context behavioral advertising. We honor legally required opt-out preference signals, including Global Privacy Control where applicable. Older browser “Do Not Track” signals do not have a uniform implementation; our no-sale/no-advertising-sharing commitments apply regardless.
We use reasonable safeguards appropriate to the information, including encrypted transmission, account and role access controls, restricted privileged access, credential protection, audit records, vendor review, and incident-response procedures. Multi-factor authentication is available on all tiers and required for paid-plan owners. No system is completely secure. We do not claim that use of a particular infrastructure provider alone certifies Foresio’s security. Where an incident affects personal information, we provide notices and assistance required by law and our Data Processing Addendum.
8. Retention and deletion
We retain information for the stated purpose and period, with restricted legal/evidence exceptions. Different records have different retention needs; a consent record is not treated like a routine inventory report.
| Record type | Retention rule |
|---|---|
| Operational and advisor history, including receipt images | Basic: rolling 90 days. Signal: rolling 24 months. Cascade: full history during continuous paid service. Source-specific restrictions and valid deletion requests may require earlier deletion. |
| Current account configuration, recipes, active contacts, and operational settings | While needed for the active account, then the closure/deletion schedule below. A record is not deleted merely because its creation date predates the history window if it is still needed as current configuration. |
| Cascade history after a downgrade to Signal | Previously collected Cascade history is retained, with unavailable features locked, during continuous paid service, subject to source restrictions and valid deletion requests. Newly created Signal history follows Signal's rolling window. |
| Ordinary records after paid service ends or a free account closes | A 90-day read-only/export period; deletion from active systems within 30 days after that period ends. A valid earlier deletion request can shorten this period. Paid closure does not automatically activate Basic. |
| Backups of deleted ordinary records | Expire within 90 days after active-system deletion. They are access-restricted, not used for ordinary business, and deletion instructions are reapplied if a backup is restored. |
| SMS consent and limited related message evidence | Active consent is kept while relied upon; supporting evidence is retained for five years after the later of the last relevant message or withdrawal. Only records needed to demonstrate consent, delivery, withdrawal, or resolve a claim are retained beyond ordinary history. |
| Suppression identifiers | While the restaurant's messaging program operates and for five years after it ends, to honor withdrawal and prevent improper re-enrollment. Stored separately with restricted use. |
| Billing, tax, and payment-dispute records | Seven years after the relevant transaction, or longer if applicable law requires. Full payment-card credentials are not Foresio records. |
| Routine technical logs | Up to 90 days, unless specific records are needed for an incident, dispute, or legal obligation. Account action/audit histories tied to operational records follow the applicable history/evidence period. |
| Support correspondence and account-management notes | Up to 24 months after the matter closes, unless specific records support an ongoing relationship, incident, dispute, or legal obligation. |
| Integration access credentials | Revoked or deleted when disconnected or service ends, once needed disconnection steps complete, and within 30 days; not held for the 90-day export window. |
Before a plan change requires deletion of otherwise retained history, we provide at least 30 days to export permitted records. Upgrading does not restore previously deleted data. “Full history” and unchanged past Rundown records do not mean permanent retention after closure. Public-source content may need earlier removal or refresh under source terms.
We may preserve specified records longer under a legal hold or other applicable legal requirement, using them only for that purpose and deleting them when the exception ends. We do not preserve an entire guest database merely because a limited consent or billing record must remain. Client-controlled retained personal data remains protected under the Data Processing Addendum. Qualifying de-identified training material is governed by Section 6 and is not maintained as an identifiable client archive. Independent platforms control copies they hold for their own purposes; deleting Foresio records does not automatically remove a public Google review or independently held POS record.
9. Access, secure reports, and privacy rights
Account owners and authorized users may access and correct permitted information in the Service. Operational CSV exports are available during active service and the 90-day closure window. Ordinary exports do not include raw guest phone-number lists.
A verified restaurant owner may request a secure consent-evidence report through hello@foresioai.com for a documented compliance, dispute, or lawful rights purpose. The report contains only the relevant evidence, including phone identifiers when needed to associate consent with the recipient, timestamps, disclosure wording/version, source, and withdrawal status. We verify authority, use an expiring protected delivery method, and log the release. Reports may not be used as marketing lists or to bypass withdrawal. This safeguard does not restrict a legally required individual access or portability response.
Depending on your residence, the information, our legal role, and whether the applicable law covers the processing, you may have rights to know/access personal information, correct it, delete it, receive a portable copy, obtain information about disclosures or recipients, limit certain sensitive-data uses, withdraw consent, or opt out of sale, targeted advertising, or specified profiling. We do not engage in sale or cross-context behavioral advertising as described above. The Service’s restaurant forecasts and recommendations are not intended to make decisions producing legal or similarly significant effects about individual guests or staff.
Submit a request to hello@foresioai.com or through Contact Us. State the request, the relevant restaurant/account, and enough information to locate your records; do not send passwords or full payment-card details. We verify identity and authority using information proportionate to the request. An authorized agent may act where permitted, with appropriate proof; we may also verify the individual directly. We will not discriminate against you for exercising applicable rights.
We respond within the period required by applicable law, generally within 45 days for covered U.S. state privacy requests, and notify you of a lawful extension and its reason where needed. Some requests have shorter deadlines. A deletion request may be limited by fraud prevention, suppression, legal obligations, or other applicable exceptions; we explain an applicable denial and the records retained. Where we act for a restaurant, we forward the request and assist its response rather than independently deciding its use of the data.
If we deny a request and an appeal right applies, reply to hello@foresioai.com with “Privacy appeal” and the request details. We review and respond within the applicable legal period, generally within 45 days unless a different period applies, and explain the outcome and any available route to the relevant regulator. You may complain to your state attorney general or other competent privacy authority. Our Terms’ arbitration agreement with restaurant clients does not restrict an individual’s right to complain to a regulator.
10. Age restrictions and incidental guest information
The platform is not directed to children under 16. Contracting owners must be 18 or older; authorized users aged 16 or 17 may use an adult-owned account under supervision. We do not knowingly enroll children under 16 as platform users or guest SMS subscribers. If we learn of such enrollment, we stop the affected use and delete the information except limited records needed to honor suppression or satisfy law.
Restaurants may serve families, so lawfully provided POS records or messages can incidentally concern a minor. Platform age limits do not establish that every guest is an adult. Restaurants must avoid unnecessary children’s information and comply with applicable notice and consent requirements. Contact hello@foresioai.com if you believe a child has provided information improperly; we will coordinate appropriate restriction, deletion, and any legally required response.
11. Geographic scope and changes
We currently offer the Service to U.S. restaurants. Infrastructure, support, and selected providers may process information in the United States or other countries. U.S. customer eligibility does not mean all data stays in the United States. Where a transfer is subject to legal safeguards, we use the required arrangements; accepting this Policy alone does not substitute for them. Additional jurisdictions or materially different processing require review and any necessary notice or agreements before expansion.
We update this Policy when practices change. The date above identifies the latest revision. For a material change, we provide at least 30 days’ advance email or prominent in-Service notice to account owners, except when a legal or urgent security reason requires faster action, in which case we provide notice as soon as practicable. We provide additional notice to affected individuals and obtain consent when legally required. Continued use alone is not consent to a materially different use that requires affirmative consent. A future policy cannot retroactively authorize a prior unlawful disclosure or override an existing contractual data restriction.
Contact: Foresio AI, LLC, Georgia, United States — hello@foresioai.com. You may also use Contact Us in the Service or visit foresioai.com.