Privacy Policy
Effective August 5, 2026
Pantry Books is a back-of-house record keeping tool for restaurants and bars, operated by TODO: your legal name or LLC (“we”, “us”). This policy explains what we collect, why, who we share it with, and what control you have over it. It applies to the Pantry Books web application and any email addresses we provide for forwarding invoices.
Information we collect
Account information
Your name, email address, password (stored only as a salted hash by our authentication provider), the organization you belong to, and your role within it. If someone invites you to a team, we store the invitation and who sent it.
Business records you provide
The operational data you enter or upload, including vendor invoices and their image or PDF files, vendor names and contacts, item and pricing records, inventory counts, recipes, waste logs, and sales figures or point-of-sale reports you import. This is your business data; we hold it to run the service for you.
Email you forward to us
If you use a Pantry Books forwarding address, we receive the messages sent to it, including sender address, subject, body, and attachments, so we can turn attached invoices into records in your account. Messages that do not contain a usable invoice are discarded.
Technical information
Standard server and application logs: IP address, browser type, pages requested, timestamps, and error diagnostics. We use these to keep the service running and to investigate problems. We do not use advertising trackers, and we do not sell or rent personal information to anyone.
How we use information
- To provide the service: parsing invoices, matching items, costing recipes, and producing reports.
- To authenticate you and keep your organization’s data separated from every other organization’s.
- To send transactional email you asked for, such as team invitations and notifications about your account.
- To diagnose failures, prevent abuse, and improve accuracy of the features you use.
- To comply with law and enforce our terms.
Service providers
We share information with a small set of vendors who process it only on our instructions and only to deliver the service:
- Vercel — application hosting and delivery.
- Supabase — database, authentication, and file storage for uploaded invoice documents.
- Anthropic — invoice documents and images you upload are sent to the Claude API to extract their contents. Anthropic processes this data as our service provider and does not use it to train its models.
- Google Cloud Vision — optical character recognition on some uploaded images.
- SendGrid — receives email sent to Pantry Books forwarding addresses.
- Resend — delivers outbound transactional email such as team invitations.
- Intuit — only if you choose to connect QuickBooks, as described below.
We may also disclose information if required by law, or in connection with a merger or sale of the business, in which case we will give notice before your information becomes subject to a different policy.
QuickBooks connection
Connecting QuickBooks Online is optional and off unless you turn it on. If you connect it:
- What we read — your chart of accounts and vendor list, so you can map purchases to the accounts you already use and so bills attach to the right vendor.
- What we write — vendor bills that you have explicitly approved for export. If you void an export batch, we attempt to remove the bills we created; QuickBooks may decline that once a bill has been matched to a payment, and we tell you which ones need your attention in QuickBooks instead.
- What we store — your QuickBooks company identifier, access and refresh tokens held in encrypted form, the account and vendor identifiers you mapped, and the identifier of each bill we created so we never post the same invoice twice.
- What we never touch — customer records, payroll, employee data, bank credentials, and payment card data. We do not read or store any of it.
You can disconnect QuickBooks at any time from the app, which revokes our tokens and stops all further access. Records already sent to QuickBooks remain in your QuickBooks account and are governed by Intuit’s terms and privacy policy.
Security
Data is encrypted in transit with TLS and encrypted at rest by our database and storage providers. Access between organizations is separated at the database level so that one organization cannot read another’s records. Third-party credentials are stored encrypted, and administrative access to production systems is limited to those who need it. No system is perfectly secure, but we work to keep the exposure of your records small.
Retention and deletion
We keep your records for as long as your account is active, because the value of the product is its history — last year’s invoices are what make this year’s prices meaningful. You may delete individual records at any time. If you ask us to delete your account, we will delete your organization’s data, including uploaded documents, within 30 days, except where we must keep something to comply with law. Backups are purged on their normal rotation.
Your choices
You can access and correct your information directly in the app, export your records, or ask us for a copy. Depending on where you live, you may have additional rights to access, correct, delete, or restrict processing of your personal information, and to be free from discrimination for exercising them. To make a request, email us at the address below; we may need to verify your identity first.
Children
Pantry Books is a tool for businesses and is not directed to anyone under 16. We do not knowingly collect information from children.
Changes
If we change this policy in a way that materially affects how we handle your information, we will update the effective date above and notify account owners by email before the change takes effect.
Contact
Questions or requests: TODO: support@pantrybooks.com.