Privacy Policy

How CooperFlow collects, uses, stores, and shares information.

Last updated 30 August 2026

1. Introduction

This Privacy Policy explains how the operator of CooperFlow (“we”, “us”, “our”) collects, uses, discloses, and protects information in connection with the CooperFlow website, applications, and related services (the “Service”).

By accessing or using the Service, you acknowledge this Policy. If you do not agree, do not use the Service. Our Terms of Service also apply and include important limits on our liability.

2. Who is responsible for personal information

CooperFlow is a multi-tenant operations platform. How privacy law treats a piece of information depends on who it is about:

  • Account and operator data. When you create a user account, sign in, or contact us, we decide how that account information is processed to provide and secure the Service.
  • Workspace (tenant) data. Products, customers, orders, restaurant tables, payments, custom fields, invitations, and similar business records belong to the organisation that owns the workspace. That organisation is responsible for its own legal basis, notices, and requests from its staff, guests, and customers. We process that data to provide the Service to that workspace.
  • Guest dining. If you scan a table QR code or join a dining session, the restaurant (workspace) is responsible for that guest experience. We store the session and order information needed to run that visit.

If you are a customer or guest of a business that uses CooperFlow, please contact that business first about your personal information.

3. Information we collect

We collect information in the following categories.

Account and profile. Name, email address, password (stored as a one-way hash, never in plain text), locale, theme, avatar, optional profile fields (such as phone or date of birth if you provide them), role and permission assignments, and UI layout preferences.

Authentication. If you sign in with Google, GitHub, or Microsoft, the provider shares the identity details you authorise (typically name, email, and a unique provider identifier). We record when an email address has been verified.

Workspace content. Business records you or your colleagues enter or import, including products, customers, orders, inventory, taxes, discounts, floors and tables, kitchen and waiter activity, invitations, custom fields, and uploaded images.

Payments. When card payments are taken through Stripe, we receive payment status, amount, and related transaction identifiers. We do not store full card numbers or card security codes. Cash and other till tenders are recorded as ordinary order data in the workspace.

Device and usage. Technical logs such as IP address, browser type, approximate time of access, and error diagnostics, used to operate, secure, and improve the Service. Realtime features use a short-lived signed token so the browser can receive live status updates.

We do not require you to provide information beyond what is needed to create an account or run a workspace feature you choose to use.

4. Cookies and similar technologies

We use cookies and similar storage that are required to run the Service. These are not advertising trackers. They include:

  • a signed session cookie so we know who is signed in;
  • an active-workspace cookie so data stays scoped to the company you selected;
  • locale and theme cookies so the interface matches your preference;
  • a dining-session cookie for QR self-order guests;
  • a till-session cookie for POS clock-in on a device.

You can block cookies in your browser, but sign-in, workspace switching, guest dining, and the till will not work correctly without them.

5. How we use information

We use information only as needed to:

  • create and authenticate accounts, including OAuth and email verification;
  • provide the modules, apps, and features a workspace has enabled;
  • keep tenant data isolated and apply roles and permissions;
  • process payments through Stripe and record settlement or voids;
  • send transactional messages such as email verification or invitations;
  • operate live updates for dining, station, waiter, and kitchen screens;
  • secure the Service, prevent abuse, and diagnose faults;
  • comply with law, enforce our Terms, and defend legal claims;
  • improve reliability and usability of the Service.

We do not sell personal information.

6. How we share information

We share information only as follows:

  • Inside a workspace. Other members of the same tenant who have been granted access can see that workspace’s records. People in a different tenant cannot.
  • Service providers. Processors that help us run the Service, including hosting and database infrastructure, Auth.js / OAuth identity providers (Google, GitHub, Microsoft), Stripe for card payments, and Google Places when address lookup is enabled. Each provider processes data under its own terms and privacy policy.
  • Legal and safety. We may disclose information if we reasonably believe it is required by law, court order, or to protect the Service, our users, or the public from harm, fraud, or abuse.
  • Business transfer. If the Service is transferred as part of a reorganisation, sale, or similar event, information may move with it, still subject to this Policy or a successor policy that is at least as protective.

We do not share information with advertisers or data brokers.

7. Payments

Card payments are processed by Stripe. Stripe’s privacy policy governs the card data it collects. We receive confirmation of payment, identifiers, and amounts so we can mark orders paid or voided. We are not a bank, card issuer, or payment facilitator, and we do not store complete payment-card numbers on our servers.

8. International transfers

The Service and its providers may process information in New Zealand and in other countries. Those countries may have different data-protection laws than your home country. Where we transfer personal information internationally, we take steps we consider reasonable to protect it, but you understand that no transfer can be guaranteed to be free of legal process in the destination country.

9. Retention

We keep account information for as long as the account exists and for a reasonable period afterwards if needed for security, backups, dispute resolution, or legal compliance. Workspace records remain until the workspace owner deletes them or the workspace is removed. Guest dining sessions and till sessions expire. Backups and logs are kept only as long as needed for recovery and security, then deleted or overwritten in the ordinary course of operations.

10. Security

We use industry-standard measures appropriate to the Service, including hashed passwords, signed sessions, tenant scoping, and access control. No method of transmission or storage is completely secure. You are responsible for choosing a strong password, keeping PINs and devices secure, and using roles carefully inside your workspace. We are not responsible for unauthorised access that results from credentials, devices, or invitations you control.

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. You may also have the right to complain to a supervisory authority.

Account holders can update much of their profile in the Service. To request access or deletion of account data we control, contact us through the Service. We may need to verify your identity and may decline or limit a request where the law allows (for example, where information is needed to complete a transaction, detect fraud, or comply with a legal obligation).

Requests about a business’s customers, guests, or staff records should be sent to that business. We will assist the workspace where we are legally required to do so.

12. Children

The Service is directed at businesses and adults. It is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided information, contact us and we will take reasonable steps to delete it.

13. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date at the top will change. Material changes will be indicated by publishing the revised Policy on this page. Continued use of the Service after the updated Policy is posted means you accept the revised Policy. If you do not agree, you must stop using the Service and close your account.

14. Contact

Questions about this Policy can be sent through the CooperFlow application or to the contact details the operator publishes on the Service. If you are a customer or guest of a workspace, contact that business first.

Related: Terms of Service.