GlossPlate Privacy Policy
Effective date: July 16, 2026 Last updated: August 12, 2026
This Privacy Policy explains how GlossPlate, Inc. ("GlossPlate," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the GlossPlate service available at https://glossplate.com (the "Service"). In this Policy, "you" or "Customer" means the restaurant or hospitality business that holds a GlossPlate account, and "Guest" means a diner who views a menu we power.
GlossPlate is a business-to-business software product. Our direct customers are businesses (restaurants and cafes), not consumers. The individual who signs up must be at least 18 years old and authorized to bind the business.
This standalone Privacy Policy is the single, canonical statement of our privacy practices. It is incorporated by reference into our Terms of Service. If any privacy summary contained in the Terms of Service appears to conflict with this Policy, this Policy controls.
If you have questions about this Policy or your personal information, contact us at [email protected].
1. Who We Are
GlossPlate, Inc. is a Delaware corporation, incorporated on July 8, 2026 under the Delaware General Corporation Law. GlossPlate provides a hosted software service that turns a restaurant's own dish photographs into glossy, magazine-quality interactive digital menus, delivered through a table-side QR code and a TV/cafe-screen display mode.
Address for legal notices: GlossPlate, Inc. c/o Legalinc Corporate Services Inc. 131 Continental Drive, Suite 305 Newark, DE 19713, USA
For all other inquiries, including privacy requests: [email protected].
2. Scope of This Policy
This Policy applies to personal information we process:
- when a business creates and uses a GlossPlate account (Customer data); and
- when a Guest scans a QR code or views a GlossPlate-powered menu (Guest data).
Guest interactions are minimal and are handled primarily as aggregate analytics. Guests do not create accounts and are never asked to make a payment through GlossPlate (see Section 12).
This Policy does not govern the practices of the restaurants that use our Service or any third-party websites or services we do not control.
3. Information We Collect and Why
We collect the following categories of information.
3.1 Account information
Owner name, email address, a securely hashed password (we use bcrypt hashing and never store passwords in plaintext), and the names and email addresses of team members you invite. Why: to create and secure your account, authenticate users, and provide the Service.
3.2 Restaurant profile
Restaurant name, street address, city, phone number, website, cuisine type, POS (point-of-sale) provider, Instagram handle, "how you heard about us," and your marketing-consent choices. Why: to set up and operate your menu, support you, and (only where you have opted in) send you marketing.
3.3 Content you upload
Dish photographs you upload, the AI-enhanced images and videos we generate from them, and dish names, descriptions, and prices. Why: to create and display your interactive menu and to perform the AI photo enhancement you request. See Section 4 for how enhancement works and Section 14 for the license you grant.
3.4 Payment information
Payments are processed by Stripe. We do not store full card numbers — Stripe does. We retain limited billing metadata: card brand, last four digits, expiration date, subscription status, and invoices. Why: to bill your subscription, manage renewals and cancellations, and keep billing records.
3.5 Owner activity and approval records
A tamper-evident record of the actions account users take on the menu — in particular, each time someone approves a dish for display (which account, the dish, the image approved, where it was approved, and when), along with menu publishing, imports, and similar administrative actions. These records are append-only: they cannot be edited or deleted from within the Service, by you or by us. Why: the restaurant's per-dish approval is the control our Terms rely on for menu accuracy (Terms Section 11.5), so the record has to be trustworthy after the fact — to answer a Guest complaint, a regulator, or an allergen claim, and to show who did what in your account. See Section 9 for how long we keep it.
3.6 Usage and analytics data
Menu opens, dish views, QR scans, device and browser type, IP address, approximate (coarse) location, and cookies for session, theme, and language. Guest-level interactions are collected on an aggregate basis. Why: to operate, secure, measure, and improve the Service.
3.7 Communications
We send transactional and lifecycle emails that are necessary to administer your account — for example, welcome messages, receipts, cancellation confirmations, and account or security notices.
Trial and renewal reminders. Before your 3-day free trial converts to a paid subscription, and before any change to your subscription price takes effect, we send you a reminder that includes clear instructions on how to cancel. These reminders are part of administering your subscription.
Marketing communications are sent only with your consent:
- Marketing email is sent only where you have opted in, consistent with the CAN-SPAM Act. Every marketing email includes an unsubscribe link, which we honor promptly.
- Marketing SMS is sent only where you have given prior express written consent through a dedicated opt-in that identifies GlossPlate as the sender and states that consent is not a condition of purchase, consistent with the Telephone Consumer Protection Act (TCPA). You may opt out at any time by replying STOP.
- "Win-back" messages (sent to encourage a former or lapsed customer to return) are treated as marketing/commercial communications, not transactional messages. We send them only to recipients who have not opted out, and each includes an unsubscribe/opt-out mechanism that we honor.
Why: to administer your account and subscription and, with your consent, to market to you.
4. How AI Enhancement Works
The core feature of the Service is honest AI enhancement of the restaurant's own uploaded photos. We clean or replace the background to an editorial style and apply a light gloss/light mask to the food, without altering the actual dish — the plate, ingredients, portion, garnish, count, color, and texture are left untouched. An optional free "living photo" motion effect and a premium 360-degree spin (built from four real photographed angles) may also be produced.
AI-enhanced images are stylized representations intended for presentation only. Nothing reaches a diner automatically: every dish stays private until the restaurant enlarges the result, confirms that the food matches the real dish, and approves it. We record each approval — which account approved which dish and image, and when.
The restaurant is solely responsible for the accuracy of all menu information — dish descriptions, prices, ingredients, allergens, nutrition/health claims, and availability — including as presented alongside AI-enhanced images. GlossPlate does not verify and is not responsible for menu accuracy, and disclaims all liability for allergen, health, dietary, or consumer-protection claims arising from a restaurant's menu content or from enhanced images displayed to Guests. Each restaurant confirms, dish by dish, that what a diner sees matches what it serves, and is responsible for any allergen or other disclosure the law requires of it; GlossPlate does not make those disclosures on a restaurant's behalf. The Customer's indemnity and insurance obligations relating to Guest and third-party claims (including personal-injury and allergen claims) are set out in our Terms of Service.
5. How We Use Information
We use personal information to:
- provide, operate, maintain, and secure the Service;
- perform the AI photo enhancement and menu features you request;
- create, authenticate, and manage accounts and team access;
- process payments, manage subscriptions and renewals, and maintain billing records;
- send transactional and lifecycle communications;
- send marketing communications where you have opted in (and, for SMS, where you have given TCPA-compliant express written consent);
- measure and improve the Service through aggregate analytics;
- detect, prevent, and respond to fraud, abuse, security incidents, and technical issues; and
- comply with legal obligations and enforce our agreements.
AI subprocessing of your content. To produce the enhanced images and videos you request, your uploaded content is processed by the AI subprocessors listed in Section 6 (Google and fal.ai for images and video; Anthropic for menu captions and nutrition estimates generated from your dish text). We use these providers solely to generate the output you ask for, and we do not use your content to train our own models. Each provider's processing of submitted content is also governed by that provider's own terms, and — depending on the service tier that applies — a provider may retain and process submitted content to provide and improve its services. We work to obtain data-processing terms that restrict these providers from using your content to train their general-purpose or foundation models; where such terms are not in place, the provider's standard terms govern. We encourage you not to upload content you are not comfortable processing under those conditions.
6. How We Share Information — Subprocessors
We share personal information only with the service providers ("subprocessors") that help us operate the Service, and only as needed for them to perform their role. We do not permit them to use your information for their own independent purposes, except as noted for AI subprocessors in Section 5.
| Subprocessor | Role |
|---|---|
| Stripe, Inc. | Payment processing and card storage |
| Google LLC (Gemini / Veo) | AI image and video generation from your dish photos |
| fal.ai (Features & Labels, Inc.) | AI video generation from your dish photos |
| Anthropic, PBC (Claude) | Generating menu captions and nutrition estimates from dish text |
| Resend | Transactional email delivery |
| Cloudflare, Inc. | CDN, DNS, WAF/security, and R2 object storage for backups |
| Fly.io | Application hosting and database (United States) |
All data, including uploaded photos and the database, is hosted and backed up in the United States.
Apart from these subprocessors, we may disclose information (a) to comply with law, legal process, or valid government requests; (b) to enforce our terms or protect the rights, safety, and property of GlossPlate, our customers, or others; and (c) in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
7. We Do Not Sell or Share Your Personal Information
GlossPlate does not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA/CPRA"). We have not sold or shared personal information in the preceding twelve months. We do not exchange personal information for money or other valuable consideration.
Because we do not sell or share personal information, there is nothing for you to opt out of in that respect. Even so, we honor recognized browser-based opt-out preference signals, including the Global Privacy Control (GPC), as described in Section 8.
8. Cookies, Tracking Signals, and Similar Technologies
We use a limited set of cookies and similar technologies for session management, remembering your theme preference, and remembering your language preference, and to support basic, aggregate analytics of menu interactions. We do not use cookies for cross-site advertising. Most browsers let you refuse or delete cookies through their settings; disabling essential cookies may prevent parts of the Service from working.
Do-Not-Track and opt-out preference signals. Some browsers offer a "Do-Not-Track" (DNT) setting. Because there is no consistent industry standard for how to respond to DNT signals, and because we do not track users across third-party sites for advertising, we do not currently take action in response to DNT signals. We do, however, recognize and honor the Global Privacy Control (GPC) and similar opt-out preference signals as a valid request to opt out of any sale or sharing of personal information — although, as explained in Section 7, we do not sell or share personal information in the first place.
9. Data Retention
We retain personal information only for as long as necessary for the purposes described in this Policy, and then delete or de-identify it. Our retention periods and criteria by category are:
- Account and restaurant-profile data: retained for the life of the account and for up to 90 days after account closure (to allow reactivation and to complete deletion), after which it is deleted or de-identified.
- Content (uploaded and enhanced photos and videos, dish names, descriptions, and prices): retained for the life of the account; removed from active systems within 90 days of account closure.
- Owner activity and approval records (Section 3.5): retained for up to 7 years, and not deleted when the account closes. These records exist to evidence who approved which dish image and when, so they must survive the event they are meant to prove — an allergen or consumer-protection claim can be brought long after a restaurant has stopped using the Service. They are append-only and cannot be edited. After that period they are deleted or de-identified. Because this record is kept to establish and defend legal claims, a deletion request under Section 11 does not remove it; we will, on request, restrict its use to that purpose.
- Billing records and invoices: retained for up to 7 years to meet tax, accounting, and audit obligations.
- Usage and analytics data: retained in identifiable form for up to 24 months, after which it is aggregated or de-identified. Aggregate and de-identified data that does not identify you may be retained indefinitely.
- Backups: cycled on a rolling basis, typically within 30–90 days, after which deleted data ages out of backup copies.
We may retain information for longer where required or permitted by law, to resolve disputes, or to enforce our agreements.
10. Security
We implement technical and organizational measures designed to protect personal information, including:
- encryption in transit using TLS;
- passwords stored only as bcrypt hashes, never in plaintext;
- access controls limiting who can access personal information;
- delegation of card storage to Stripe, a PCI-DSS-compliant payment processor; and
- hosting and backups in the United States with a reputable infrastructure and security provider.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
11. Your Privacy Rights and How to Exercise Them
Depending on where you live, you may have rights to:
- access the personal information we hold about you;
- correct inaccurate personal information;
- delete your personal information;
- opt out of marketing communications; and
- request a portable copy of certain information.
To exercise any of these rights, email [email protected] from the email address associated with your account, or otherwise provide enough information for us to verify your identity and locate your records. We will respond within the timeframes required by applicable law. We will not discriminate against you for exercising your rights. You may also designate an authorized agent to make a request on your behalf, subject to verification. As noted in Sections 7 and 8, we also honor GPC and similar opt-out preference signals.
Because our direct relationship is with businesses, Guest-facing menus are controlled by the restaurant. If you are a Guest and wish to exercise rights regarding information a restaurant holds, please contact that restaurant directly; we will assist our Customers in responding to such requests.
12. Guest Data
Guests use the Service by scanning a QR code and browsing a menu. There are no Guest accounts. The "cart" / selection feature lets a Guest show their selection to a waiter or cashier. Where a restaurant has connected its point-of-sale provider (e.g., Square) and enabled payments, a Guest may also submit that selection as an order and pay on the POS provider's own hosted checkout page. In that case we process the order contents (dishes, quantities, any notes the Guest types, and an optional table number or name) solely to transmit the order to the restaurant's POS and to show the Guest their confirmation. Payment-card details are entered only on the POS provider's pages and are handled under that provider's privacy policy — GlossPlate never receives or stores them. Please do not type sensitive personal information into order notes beyond meal preferences (e.g., allergies). Any transaction between a restaurant and its Guests is solely between them and the POS provider. Beyond this, Guest data we process is limited to minimal, aggregate analytics such as menu opens, dish views, and QR scans, along with technical data such as device/browser type, IP address, and coarse location as described in Section 3.6.
13. California (CCPA/CPRA) Notice
This section supplements the Policy for California residents.
- Categories collected. In the preceding twelve months, we have collected the categories of personal information described in Section 3, which may include identifiers (name, email, IP address); customer records (billing metadata, phone, address); commercial information (subscription and transaction records); internet/network activity (usage and analytics); coarse geolocation; and audio/visual information (uploaded and enhanced photos and videos of food, and any incidental information they contain).
- Sources. We collect information directly from you, automatically through your use of the Service, and from our payment and infrastructure providers.
- Purposes. As described in Section 5.
- Disclosures. We disclose personal information to the subprocessors listed in Section 6 for business purposes. We do not sell or share personal information (Section 7).
- Retention. We retain each category of personal information as described in Section 9.
- Sensitive personal information. We do not use or disclose sensitive personal information for purposes that require an opt-out right under the CCPA/CPRA.
- Your rights. California residents have the rights to know, access, correct, and delete personal information, to opt out of sale/sharing (which we do not do), and to non-discrimination. Exercise these rights as described in Section 11. We honor GPC opt-out preference signals as described in Section 8.
14. Owner Content and License
You represent and warrant that you own or have all necessary rights to every photo and item of content you upload, and that it infringes no third-party rights (including copyright, trademark, and rights of publicity or privacy). You grant GlossPlate a limited, worldwide, non-exclusive, royalty-free license to host, store, process, AI-enhance, reproduce, and publicly display that content solely to operate and provide the Service, including displaying it to your Guests.
Marketing examples. We use your content in our own marketing only as follows:
- Anonymized examples (menus or images that do not identify your business by name, logo, or marks) may be used on an opt-out basis; you may opt out at any time by contacting [email protected].
- Identifiable or branded use — any use of your business name, logo, trademarks, or other identifiable branding in our marketing — requires your prior opt-in consent. We will not imply your endorsement or feature your identity in marketing without that affirmative permission.
You agree not to upload illegal, infringing, or stolen content; not to upload photos you did not take or do not own; and not to attempt to break, scrape, or misuse the Service.
15. GDPR / UK Notice for EU and UK Users
The Service is hosted in the United States. If you access the Service from the European Economic Area, the United Kingdom, or Switzerland, the following applies.
- Controller. GlossPlate, Inc. is the controller of Customer account and billing data. For content you upload about identifiable individuals, you are typically the controller and GlossPlate acts as your processor.
- Lawful bases. We process personal data on the bases of: performance of a contract (to provide the Service you sign up for); our legitimate interests (to secure, operate, and improve the Service and to communicate with customers); consent (for marketing where required); and compliance with legal obligations.
- International transfers. Because we and our subprocessors are located in or transfer data to the United States, your data will be transferred to and processed in the U.S. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, and equivalent Swiss measures) with our subprocessors.
- Your rights. Subject to applicable law, you have rights of access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent, as well as the right to lodge a complaint with your local supervisory authority. Exercise these rights via [email protected].
16. Children's Privacy
The Service is intended for businesses and is not directed to individuals under 18, and it is not directed to children under 13 (or under 16 where a higher age applies). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact [email protected] and we will delete it.
17. Account Closure and Data Deletion
You may cancel your subscription at any time from the billing page; cancellation stops future charges, and access continues until the end of the current paid period. You can permanently delete your account and all associated data yourself at any time from Settings → Delete account (type your restaurant name to confirm); deletion is immediate and cancels any active subscription. You may also request deletion by emailing [email protected], or see glossplate.com/data-deletion for full instructions. Upon account closure or a valid deletion request, we will delete or de-identify your personal information as described in Section 9, subject to legal retention requirements (such as billing and tax records).
Our subscription is a recurring US$99 per month auto-renewing plan with a 3-day free trial that requires a payment card to start. Consistent with applicable automatic-renewal laws (including the California Automatic Renewal Law and federal negative-option rules), we clearly and conspicuously disclose the recurring charge, we send you a reminder with cancellation instructions before the free trial converts to a paid subscription and before any price change, and cancellation is self-service and available in-app at any time. Full billing terms are described in our Terms of Service.
18. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice by email to the account owner or through an in-app notice before the changes take effect. Your continued use of the Service after an update becomes effective constitutes acceptance of the revised Policy.
19. Governing Law
This Policy and any dispute arising out of or relating to it or the Service are governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws rules, and the state and federal courts located in Delaware have exclusive jurisdiction and venue, to the extent permitted by applicable law.
20. Contact Us
GlossPlate, Inc. c/o Legalinc Corporate Services Inc. 131 Continental Drive, Suite 305 Newark, DE 19713, USA Email: [email protected] Website: https://glossplate.com