Privacy Policy

Effective date: July 31, 2026

This policy explains what information Sazon ("the Service") collects, why it is collected, and who it is shared with. It describes the Service as it is actually built today.

The Service is operated by Alexis A. Barajas Cabrera ("we", "us"). Subscription payments are processed by Paddle.com Market Limited ("Paddle") as merchant of record.

1. Who operates the product

Sazon is provided by Alexis A. Barajas Cabrera, operating from Nevada, United States. Questions about this policy can be sent to Anemxela68@gmail.com.

A business that subscribes to the Service (the “Business”) controls the operational records it enters. We process those records to provide the Service.

2. Information businesses provide

  • Business name, timezone, currency, language and operating settings.
  • Owner name, email address and account credentials handled by our authentication provider.
  • Menu items, categories, modifiers, prices and plate configuration.
  • Inventory items, recipes, purchases, counts and stock movements.
  • Orders and order contents, including employee and complimentary (non-revenue) orders.
  • Expense records, labor records and generated financial reports.
  • Session records, including scheduled start times, load-outs and closing counts.
  • Support requests and the messages exchanged in them.
  • Notification destinations configured by the platform operator (for example an operator email address).

3. Information employees provide

  • Employee display name and assigned role (Owner, Worker, Cook).
  • An internal employee identifier used to attribute orders and sessions.
  • A hashed access PIN. PINs are stored as one-way hashes in a private database schema and are never returned to the application.
  • A hashed shared-device access code and device registration records, including registration time and last use.
  • Employee email address where the employee has an individual sign-in account.

4. Information collected automatically

We do not operate an advertising network and the Service does not embed third-party advertising or marketing trackers.

  • Authentication session data issued by our backend provider, including access and refresh tokens stored in your browser.
  • Security and audit log entries recording administrative and support actions taken on an account.
  • Application error reports generated when a page fails, which may include the route and error message.
  • Standard server request metadata, such as IP address, user agent and timestamps, processed by our hosting and backend providers as part of delivering the Service.
  • Billing customer and subscription identifiers returned by Paddle, together with subscription status, period dates and invoice records.

5. How information is used

  • To provide order entry, kitchen display, inventory, staffing and reporting features.
  • To authenticate users and enforce role-based access within a Business.
  • To calculate subscription entitlement and apply read-only restrictions when a subscription lapses.
  • To respond to support requests and to notify the operator that a request was submitted.
  • To detect, investigate and prevent abuse, fraud and security incidents.
  • To diagnose faults and improve reliability of the Service.

6. Service providers and subprocessors

We use the following providers. Each processes data only to deliver the function described.

  • Lovable Cloud (application hosting, database, authentication, storage and server functions).
  • Paddle.com Market Limited (merchant of record for subscriptions, billing, tax and invoicing).
  • An email delivery provider, where the operator has configured one, used to send operator support notifications and authentication emails.
  • An SMS delivery provider, where the operator has configured one, used to send operator support notifications.

7. Paddle billing and merchant-of-record processing

Paddle is the merchant of record for subscription purchases. Paddle collects and independently processes billing details, including payment method data, billing address and tax information, under its own terms and privacy policy.

The Service does not receive or store full payment card numbers. We receive only identifiers and status information — customer id, subscription id, plan, status, period dates, cancellation state and invoice references. See Paddle's Buyer Terms (https://www.paddle.com/legal/checkout-buyer-terms) and Privacy Policy (https://www.paddle.com/legal/privacy).

8. Data sharing

We do not sell personal information.

  • With the providers listed above, to operate the Service.
  • With the Business that owns the records, through its Owner account and role-based access.
  • With platform support staff, where a Business grants or the operator opens a time-limited support session; those actions are recorded in an audit log.
  • Where required by law, legal process, or to protect the rights and safety of users and the operator.
  • As part of a merger, acquisition or asset sale, subject to this policy.

9. Data retention

Operational records (orders, inventory, sessions, expenses, reports) are retained while the Business account exists, because they are the Business's own books.

Audit and security logs are retained to support incident investigation. Billing records are retained as long as required for tax and accounting purposes, including by Paddle.

Records are deleted or made inaccessible after an account deletion request is completed, subject to legal retention obligations. A retention period specific to your jurisdiction can be requested at the contact address below.

10. Security practices

No system can be guaranteed secure. We do not claim certification against any security standard.

  • Access to Business data is enforced at the database level with row-level security scoped to the Business.
  • Employee PINs and shared-device access codes are stored as one-way hashes in a private schema that the application role cannot read.
  • Privileged operations run through audited, server-side functions rather than direct client writes.
  • Administrative and support access is tiered and recorded in an audit log.

11. Business and employee privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict or port your personal information, to object to certain processing, and to complain to a supervisory authority.

Employees should contact their employer (the Business) first, since the Business controls its own records. Requests can also be sent to Anemxela68@gmail.com and we will route them to the responsible Business.

12. Account deletion and data export

An Owner may request deletion of a Business account, or an export of its records, by writing to Anemxela68@gmail.com from the Owner's registered email address. We verify the requester before acting.

Deleting an account is separate from cancelling a subscription. Cancelling billing does not by itself delete stored records.

13. Cookies and local storage

The Service uses browser storage for functional purposes only:

  • Authentication session tokens stored by the backend client so you stay signed in.
  • Language preference (`ttot.language`).
  • A shared-device registration token identifying an authorised device.
  • The currently selected employee and session state on a shared device.
  • A short-lived password-recovery flag used to complete a reset link.

14. Children's privacy

The Service is a business tool and is not directed to children. We do not knowingly collect personal information from children. If you believe a child's information was provided, contact us and we will remove it.

15. International processing

Our providers may process and store data in countries other than yours, including the United States. Where required, transfers rely on the safeguards those providers make available, such as standard contractual clauses.

16. Changes to this policy

We may update this policy. Material changes will be reflected in the effective date at the top of this page, and where appropriate we will notify Owners inside the application.

17. Contact

Questions or requests: Anemxela68@gmail.com (Alexis A. Barajas Cabrera, Nevada, United States).

This document was prepared by the operator of the Service. It has not been reviewed by an attorney and is not legal advice.