Yes Chef (“we”, “us”) provides restaurant operations software with a focus, for Square Marketplace partners, on food safety, due diligence, compliance evidence, corrective actions, and audit trail. This policy explains how we handle personal and business data when you use Yes Chef.
Square remains responsible for POS and transaction processing. Yes Chef does not replace Square’s commerce systems.
1. Who we are
Controller contact for privacy requests: hello@yeschefai.co.uk.
2. Data we process
- Account identity (name, email), organisation and site details you provide.
- Due diligence / food-safety records, evidence files, and audit logs you create in Yes Chef.
- Subscription and billing metadata processed via our payment provider (Stripe), not via Square.
- Optional third-party integration data when you connect Square (see section 6).
3. Purposes
- Provide and secure the Yes Chef service.
- Support food-safety and due-diligence workflows and audit evidence.
- Bill subscriptions / trials and communicate service notices.
- Comply with legal obligations.
4. Storage and security
Data is stored in managed cloud databases and object storage with access controls. Secrets and OAuth tokens are encrypted at rest using AES-256-GCM where applicable. Access is limited to systems and personnel who need it to operate the service.
5. Retention and deletion
We retain account and compliance records while your organisation uses Yes Chef and for a limited period afterward as needed for audits, disputes, and legal requirements. You may request account deletion from Settings (signed-in). Organisation closure follows our in-product process.
LEGAL REVIEW REQUIRED: exact retention periods for anonymised audit logs and multi-site organisational records after account deletion.
6. Square integration
Connecting Square is optional and initiated only when you (or an authorised user) choose Connect Square in Yes Chef Settings → Integrations and approve access on Square’s hosted OAuth screen.
Data we receive from Square (current Marketplace v1 implementation):
- Merchant identifier (`merchant_id`).
- OAuth access token and refresh token.
- Location identifiers and display names via Square Locations API.
- Revocation notices via the `oauth.authorization.revoked` webhook when Square notifies us.
Scopes: We request only MERCHANT_PROFILE_READ (least privilege for merchant profile / locations). We do not request Square Payments, Orders, Catalog, or Inventory scopes in this integration version.
Purpose: Bind your Square merchant to your Yes Chef organisation; map Square locations to Yes Chef sites; enable site-scoped food-safety / due-diligence workflows. We do not sync Square POS tickets, payments, or inventory for this integration.
Storage / security: Access and refresh tokens are stored AES-256-GCM encrypted. Merchant id, scopes, connection status, and location mappings are stored as operational metadata. Tokens are not returned to browsers in API responses.
Retention: Connection metadata and encrypted credentials are kept while the connection is active. On disconnect or Square-side revocation we mark the connection revoked and clear usable token material (tombstone). Location mappings may remain for reconnect convenience but are unusable while disconnected.
LEGAL REVIEW REQUIRED: precise post-disconnect retention window for revoked connection metadata and whether location mapping rows are deleted vs retained on reconnect.
Disconnect / revocation: You may disconnect from Yes Chef (Settings → Integrations → Disconnect), which attempts to revoke the Square OAuth token and disables the connection. You may also revoke Yes Chef in Square; we process Square’s revocation webhook and disable the connection. Disconnecting Square does not cancel your Yes Chef subscription.
Deletion: Account deletion / organisation closure in Yes Chef follows our standard Settings flows and removes or anonymises personal account data per that process. Square OAuth tokens are cleared when the connection is revoked.
No sale of Square seller data: We do not sell Square merchant, location, or token data. We use it only to operate the integration described above.
7. Sharing
We use processors (hosting, database, email, Stripe billing) under contract. We do not sell personal data.
8. Your rights
Depending on your location you may have rights to access, correct, delete, or restrict processing. Contact hello@yeschefai.co.uk.
9. Changes
We may update this policy. Material changes will be reflected by updating the version date above and, where required, re-acceptance in product.