Draft — awaiting legal review
This document is a starter draft and is not the authoritative legal text. Please contact legal@mezbano.app for the binding version before relying on this policy.
1. What We Collect
- Account information — name, email address, role, organization metadata you provide during sign-up or invite acceptance.
- Usage data — request logs, audit-trail entries, device and browser metadata, and IP addresses captured for security and troubleshooting.
- Operational data — the sales, expenses, purchases, ingredient and recipe costs, labour records, checklists, and related evidence your team enters into the platform.
- Cookies and local storage — necessary session and authentication-flow cookies, an authenticated-shell layout preference cookie, and a local browser theme preference. We do not use advertising or tracking cookies.
2. How We Use It
- to provide, maintain, and improve the Service;
- to authenticate users and protect against fraud, abuse, and unauthorized access;
- to send transactional email (sign-in verification, password reset, invitations) through Resend when that integration is configured;
- to comply with legal obligations and enforce our Terms of Service.
3. Sharing
The current subprocessor list describes the fixed providers and the optional, deployment-selected integrations that the implemented Service can send data to. In summary:
- Cloudflare — hosting, database and file storage, and optional Turnstile bot protection;
- Resend — transactional email delivery when configured;
- Stripe — hosted checkout and subscription billing when configured; and
- operator-selected providers — an optional off-provider backup target and optional incident-alert receiver. Their legal names, regions, and activation state are deployment-specific and must be disclosed before use.
Better Auth is an authentication library executed within the application, not a separate hosted processor. A workspace may also direct sign-in through its own identity provider; that is a customer-selected integration.
When the optional incident receiver is configured, its alert contains only service and deployment labels, severity, a generic error code and class, a correlation request ID, the parameterized route ID, HTTP status when available, and timestamp. Raw error messages, stack traces, causes, provider bodies, interpolated paths, and user fields are not sent.
We do not sell personal data to third parties. We may disclose data when required by law, court order, or to defend the rights and safety of users and the Service.
4. Retention
Operational data is retained while the account is active and for a reasonable period after termination to allow for export and dispute resolution. Soft-deleted records may be retained in audit logs for compliance purposes. Deactivating an account in the app revokes access but retains data; it is not a deletion. To request deletion of customer data, contact us at the address below — deletion requests are verified and fulfilled manually, subject to legal hold and financial record-keeping requirements.
5. Security
The application uses Better Auth session controls, password hashing, optional two-factor authentication, server-side authorization, and audit attribution for protected business and administrative changes. HTTPS responses carry transport-security headers, and Cloudflare provides platform encryption for D1 and R2. Domain, TLS, provider, and staff-access operating controls still require deployment verification; see the security page for the exact evidence boundary.
6. Your Rights
Where applicable law (such as GDPR or CCPA-equivalent regimes) provides them, you have the right to access, correct, export, or delete your personal data. To exercise these rights, contact us at the email address below. We will respond within the timelines required by applicable law.
7. Cookies
Better Auth sets strictly necessary, HTTP-only cookies for sessions and temporary
authentication flows such as two-factor verification. They use SameSite=Lax and
are marked Secure in HTTPS environments. The authenticated app can also set a
non-sensitive mezbano-rail layout-preference cookie scoped to /app,
using SameSite=Lax and Secure on HTTPS. Cross-site request protection uses same-site
cookie attributes and origin validation; the application does not set a separate CSRF-token cookie.
The light, dark, or system theme preference is stored in browser local storage under mode-watcher-mode, not in a cookie. We do not set advertising, cross-site
tracking, or analytics-fingerprinting cookies.
8. Children’s Data
The Service is intended for business use by adults. It is not directed to individuals under 18, and we do not knowingly collect personal data from children.
9. International Transfers
Data is hosted on Cloudflare’s global edge network, which means it may be processed in countries other than the one where it was collected. The binding policy and applicable data processing agreements must identify the transfer mechanism used for the customer and deployment; this draft does not claim that a particular contractual mechanism has already been executed.
10. Changes
We will provide notice of material changes to this policy via in-app banner or email, with the updated effective date shown above.
11. Contact
Privacy questions, data-rights requests, or security concerns? Email legal@mezbano.app.