1. Roles: who decides how data is used
For website visitors, account contacts, prospects, support contacts, billing contacts and Sundae workforce users, Sundae is generally the controller/business deciding the purposes of processing.
For data an organization uploads or connects to operate its account (“Customer Data”), the organization generally decides the purposes and means. It may be the controller/business (including employer, venue operator or service provider), and Sundae generally acts as its processor/service provider. The organization is responsible for notices, lawful basis, permissions and responding to its employees’, applicants’, guests’ and customers’ requests. A DPA, order form or reseller agreement may allocate roles differently for a particular service.
2. Categories of information
Account and identity: name, username, email, phone, password credentials, MFA/SSO/WebAuthn metadata, role, organization, language, timezone and preferences.
Organization and commercial: legal entity, business address, tax/VAT identifiers, locations/outlets, billing contacts, subscription/SKU, invoices, payment status, support entitlements and reseller relationship. Payment-card numbers are handled by payment providers; Sundae does not intentionally store full card numbers.
Core business data: POS orders and line items, revenue, tenders, discounts, refunds, delivery economics, inventory, purchasing, suppliers, reservations, accounting/P&L, marketing campaigns, reviews, guest interactions, forecasts, benchmarks, reports and operational notes. These may contain names, emails, phone numbers, addresses or free-text personal information supplied by the Customer.
Crew workforce data: employee/member profiles, legal/preferred names, contact and emergency contacts, employee numbers, job roles, departments, managers, outlet/site assignments, employment status/type, hire/termination dates, work authorization, availability, schedules, shift swaps, time and attendance, breaks, corrections, leave and balances, performance/workforce signals, compensation/rates, tips, expenses, loans, deductions, garnishments, benefits, dependents, recruiting applications, e-signatures, contracts, policies, certifications and employee self-service activity.
Sensitive or special-category data where enabled by the Customer: government ID/passport/residency and tax identifiers, bank/payment details, biometric or kiosk tokens, geolocation associated with attendance, demographic/DEI attributes, health or leave documents, benefit/dependent information and other data protected by local law. These fields are optional or permission-gated where supported and should be collected only where the Customer has a lawful basis and necessity.
Guest, customer and event data: CRM profiles, loyalty/visit history, reservations, reviews, feedback, cases, catering delivery contacts and marketing preferences.
Communications and content: support tickets, chat messages, Ask Sundae questions, uploaded files, call/email/calendar information where connected, survey responses, feedback and e-signature evidence.
AI and derived information: prompts, query text, selected context, generated answers, classifications, confidence/provenance, action approvals, prompt hashes, model/route, token/credit usage, decision/replay records and redacted diagnostics. We design the AI path to scope tenant access and redact or minimize personal information, but Customers must not submit unnecessary sensitive data.
Integration and security data: connector identifiers, OAuth/API metadata, webhook events, sync cursors, file names, health status, masked credential metadata, IP address, device/browser, logs, audit events, session data, approximate location, fraud/security signals and incident records.
Cookies and similar technologies: essential session/authentication identifiers, preferences, analytics and (where separately consented) marketing measurement identifiers.
3. Sources
We receive information from you; your organization or its administrators; employees, applicants, guests and customers through Customer Data; connected systems and partners; payment, hosting, analytics, email, security and support providers; publicly available sources; and your browser/device.
4. Purposes and legal bases
We use information to provide and secure the Services, authenticate users, enforce organization scope and permissions, synchronize integrations, generate reports/benchmarks/forecasts, operate Crew workflows, produce payroll readiness and exports, deliver payslips and support documents, provide support, communicate service notices, process billing, prevent fraud and abuse, monitor reliability, investigate incidents, improve products, create Aggregated Data, comply with law and handle disputes. Where required, bases include contract, legitimate interests balanced against rights, consent, legal obligations and vital/public-interest grounds recognized by local law. Customers choose the basis for their Customer Data.
We do not use Customer Data for a purpose incompatible with the Customer’s instructions. We do not knowingly sell personal information for money. Any “sharing” or targeted-advertising opt-out available under local law is honored through the applicable preference mechanism.
5. AI processing
AI requests pass through Sundae’s controlled gateway to approved providers and are subject to tenant scope, route controls, safety checks, credit metering and audit. We may retain prompts/outputs or hashes for the periods in Section 9 to provide the feature, prevent abuse, resolve disputes, measure cost and improve reliability. We do not knowingly send identifiable Customer Data to a general model-training program except as expressly agreed; Aggregated or de-identified data may be used for product improvement and research. AI output is probabilistic and must not be used as the sole basis for employment, pay, benefit, credit, safety or similarly significant decisions.
6. Sharing and recipients
We share only what is necessary and permitted with: cloud hosting/database/backup providers; authentication, email, SMS and support providers; security, logging, monitoring and analytics providers; payment processors; AI model providers through the gateway; payroll/HRIS, POS, accounting, delivery, reservations, CRM and other integrations selected by the Customer; authorized resellers and regional partners; professional advisers and insurers; authorities or other persons where law, safety or legal claims require it; and a buyer or successor in a merger, financing or asset transfer. A current subprocessor list and DPA describe provider names, purposes, locations and safeguards.
7. Payroll, HR and special-category safeguards
Customer is normally the employer/controller for employee, applicant, dependent and payroll data. Access is role, organization, legal-entity, outlet and confidential-field scoped. Payroll and statutory records may be retained for mandatory periods even after an account closes. Bank and government identifiers may be hashed or encrypted; they are not placed in ordinary observability logs. Biometric/geolocation, demographics, health and dependent data require Customer-controlled lawful basis, necessity, access and retention. Sundae is not the employer, tax authority, payroll provider or legal adviser and does not decide the Customer’s wage, classification or filing obligations.
8. International transfers and data residency
Sundae is headquartered in the United States and may process data in countries where Sundae or providers operate. We use adequacy decisions, Standard Contractual Clauses, the UK IDTA/Addendum or another lawful mechanism where required, together with contractual, technical and organizational safeguards. Customer residency choices are resolved by the most-specific approved organization/partner setting; changing a setting does not automatically migrate existing data. Contact privacy@sundae.io for the safeguards relevant to your account.
9. Retention
We retain information only as long as needed for the stated purpose, the account relationship, legal obligations, disputes, security and audit. The operational schedule is maintained in our data-governance registry and may vary by jurisdiction and Customer policy. Current target windows include: attendance and guest/reservation data generally up to 24 months; AI/chat/usage records generally up to 18 months; notifications/invites generally up to 12/3 months; employee identity and commercial signature evidence generally up to six years or the applicable legal-claims period; payroll, bank, tax, statutory and employee documents for the applicable statutory floor; marketing suppression records indefinitely to honor opt-outs; and append-only audit evidence for statutory/SOC-control purposes. Backups age out under controlled cycles. Properly Aggregated Data may be retained indefinitely because it no longer identifies a person or Customer.
10. Rights and choices
Subject to local law, individuals may request access, correction, deletion, restriction, portability, objection, withdrawal of consent, and marketing/cookie opt-out. California residents may have rights to know, access, delete, correct, opt out of sale/sharing or targeted advertising, limit certain sensitive-information uses, and receive equal treatment. EEA/UK, UAE (including DIFC/ADGM) and other jurisdictions may provide additional rights, representatives or complaint routes.
Send requests to privacy@sundae.io. We may verify identity, ask for the relevant organization/account, and route Customer Data requests to the Customer where it is the controller. We respond within the time required by applicable law and explain any lawful exception, including statutory retention, legal claims, security logs, suppression records or third-party/public data. Authorized agents may act where local law permits.
11. Cookies and preferences
Essential cookies support authentication, security and session continuity. Preference cookies remember language/theme/settings. Analytics cookies help measure reliability and product use. Marketing cookies or pixels are used only where permitted and, where required, after consent. You can withdraw consent through the cookie-preference tool or browser controls; disabling essential cookies may break sign-in or security features.
12. Security and incidents
We use encryption in transit and at rest where supported, least-privilege and scoped access, MFA/SSO options, tenant isolation, logging, monitoring, backups, vulnerability management, provider due diligence and incident-response procedures. No method is perfect. If we confirm a personal-data incident, we notify affected Customers and authorities as required by law and the DPA. Our security materials describe readiness and controls and do not imply that Sundae holds a SOC 2 Type II certification unless expressly stated on the current security page.
13. Children
The Services are business services intended for adults acting for an organization. We do not knowingly collect children’s personal information through our own services where prohibited. A Customer must not upload children’s data unless it has a lawful basis, required notices/consents and appropriate safeguards.
14. Changes
We may revise this Policy for product, legal or operational changes. We publish the new version and date, provide additional notice for material changes where required, and obtain renewed consent when law or our registration flow requires it. Translations are provided for convenience unless a local agreement says otherwise; the controlling-language version will be identified at acceptance.
15. Contact
Sundae Technologies Inc. · 1007 N Orange St, 4th Floor, Suite 1382 · Wilmington, DE 19801, United States
Privacy team: privacy@sundae.io · Legal: legal@sundae.io · Security: security@sundae.io