Legal Pages

Data Usage Policy

Detailed rules for data ownership, permitted uses, advertising, AI, analytics, retention, sensitive data, exports, deletion, and restaurant guest data.

Version 2026.06.07 | Effective June 7, 2026 | Last updated June 7, 2026

Data ownership and roles

  • Restaurants own or control their restaurant content and guest/customer relationship data, subject to their own legal obligations and customer promises.
  • HostKit uses restaurant and guest data to provide contracted services, maintain the platform, comply with law, improve products, and conduct disclosed marketing and advertising activities.
  • Where HostKit processes guest data only on restaurant instructions, HostKit acts as a service provider/processor. Where HostKit uses data for its own security, analytics, marketing, legal compliance, or product improvement, HostKit may act as an independent business/controller.

Permitted data uses

  • Operate digital menus, QR/NFC links, review tools, reservations, missed-call workflows, SMS/email campaigns, websites, checkout, onboarding, support, analytics, reporting, and billing.
  • Build restaurant segments, insights, conversion reports, attribution, recommendations, service health reports, and AI-assisted drafts.
  • Use aggregated or de-identified data for benchmarking, internal product improvement, forecasting, quality assurance, and AI feature improvement.

Advertising and retargeting

  • HostKit may use restaurant account data, client data, guest data, cookies, pixels, hashed contact data, and conversion events for HostKit marketing and restaurant marketing when enabled and legally permitted.
  • Users can opt out of sale/sharing, targeted advertising, and marketing communications through privacy choices, cookie preferences, GPC, unsubscribe links, STOP messages, or support requests.
  • Opt-outs do not stop transactional service messages, security notices, legal notices, billing messages, or messages needed to complete requested services.

AI and automation

  • AI features may draft review responses, menu descriptions, marketing copy, insights, segmentation suggestions, summaries, and operational recommendations.
  • HostKit may use aggregated or de-identified data to improve AI-assisted features and product quality. Sensitive guest information is excluded from advertising and model-training use.
  • Human review is required before sending customer-facing AI-generated messages, publishing AI-generated content, or acting on AI-generated legal, pricing, safety, allergen, or customer-service recommendations.

Retention schedule

  • Account, restaurant, billing, and contract records: For the active account term plus up to 7 years for tax, dispute, audit, and business records.
  • Restaurant guest CRM, reservations, messages, reviews, preferences, and segments: For the active restaurant account plus up to 5 years unless deletion, opt-out, law, or contract requires a shorter period.
  • Marketing, advertising, and consent records: For as long as needed to honor opt-outs, prove consent, prevent suppression-list reimport, and comply with messaging/email rules.
  • Analytics, QR/menu events, conversion data, and product telemetry: Up to 7 years in identifiable or account-linked form, and longer when aggregated or de-identified.
  • Privacy, accessibility, security, legal, and support requests: Up to 7 years after closure for proof of handling, disputes, audits, and compliance operations.
  • Security logs, abuse records, and fraud prevention signals: Up to 5 years, or longer when needed to protect the service, investigate incidents, or comply with law.
  • Deleted or canceled accounts: Deletion begins after account closure and legal hold checks; backups expire on their normal cycle.

Deletion, exports, and legal holds

  • Verified privacy requests can trigger export, correction, deletion, opt-out, or limitation workflows unless an exception applies.
  • HostKit may preserve data needed for fraud prevention, security, tax, billing, legal claims, chargebacks, audit, suppression lists, or compliance records.
  • Deleted data may remain in backups until backup cycles expire.
Questions: support@hostkitapp.comMailing address: HostKit Legal, North Carolina, United StatesRequest pricing