RestoStack AI
Security at RestoStack AI
Restaurants trust RestoStack AI with operational data, customer interactions, delivery channel workflows, social media access, and AI voice agent activity. This page describes the security practices we use to protect the platform and customer data.
Last updated: April 1, 2026
1. Security Program
RestoStack AI maintains a security program designed to protect customer data, restaurant operations, connected integrations, and platform availability. Our approach focuses on data minimization, least-privilege access, secure software development, vendor review, monitoring, and incident response.
Our security program is designed for a restaurant technology environment where availability, order accuracy, account protection, integration security, and customer trust are critical.
2. Data Protection
- Encryption in transit: We use HTTPS/TLS to protect data transmitted between users, browsers, applications, APIs, and supported integrations.
- Encryption at rest: We use encryption for production databases, storage systems, backups, and sensitive data stores where supported by our infrastructure providers.
- Data minimization: We aim to collect and retain only the information needed to provide, secure, support, and improve the services.
- Retention controls: We maintain retention practices for operational data, logs, backups, call records, transcripts, and support records based on business, legal, security, and customer requirements.
- Deletion support: We support deletion and export workflows as described in customer agreements and product capabilities.
3. Access Controls
- Role-based access: Access to production systems and customer data is limited based on job responsibilities and business need.
- Least privilege: We limit internal access to the minimum required for support, operations, security, and engineering work.
- Authentication controls: We use secure authentication practices for internal systems and encourage customers to use strong passwords and unique user accounts.
- Account lifecycle: We review and remove access when personnel or role changes occur.
- Customer permissions: Restaurant administrators are responsible for managing their own users, roles, connected accounts, and integration permissions.
4. Infrastructure and Application Security
- Cloud infrastructure: RestoStack AI uses reputable cloud, hosting, database, communications, and infrastructure providers to operate the services.
- Environment separation: We separate production and non-production environments and restrict production access.
- Secure development: We use code review, dependency management, testing, and security-focused development practices to reduce application risk.
- Logging and monitoring: We collect security and operational logs to help detect suspicious activity, troubleshoot issues, and maintain service reliability.
- Backups: We use backup and recovery practices designed to support service continuity and data recovery.
- Vulnerability management: We monitor, evaluate, and remediate vulnerabilities based on severity, exploitability, and impact.
5. AI Voice Agent and Call Security
RestoStack AI voice agents may process phone numbers, call audio, transcripts, summaries, order or reservation details, and missed-call information. We design these workflows with controls intended to protect call data and reduce unauthorized access.
- Call recordings and transcripts are restricted to authorized users and systems based on customer configuration and operational need.
- AI voice agent outputs may be logged for quality, troubleshooting, security, and service improvement purposes.
- Restaurants are responsible for providing legally required notices and obtaining legally required consents for call recording, transcription, AI interactions, and automated communications.
- Restaurants should review AI-generated order details, summaries, and suggested responses before relying on them for sensitive or high-impact actions.
6. Integration Security
RestoStack AI connects to restaurant systems and third-party services such as POS providers, delivery marketplaces, social media platforms, telephony systems, messaging providers, analytics tools, and payment processors.
- We use supported authentication and authorization methods such as OAuth, API keys, tokens, or signed webhooks where available.
- We store integration credentials and tokens using access controls and protection mechanisms appropriate to the sensitivity of the credential.
- Customers should grant only the permissions needed for the intended workflow and revoke unused or unnecessary integrations.
- Third-party integrations are subject to the third party's own security, privacy, availability, and compliance practices.
7. Payment Security
RestoStack AI may use third-party payment processors to collect subscription fees, implementation fees, and other charges. We do not intend to store full payment card numbers on RestoStack AI systems. Payment processing is handled by payment providers subject to their own security and compliance programs.
If RestoStack AI supports restaurant payment workflows or POS payment integrations, those workflows may be governed by additional payment processor terms, PCI-related requirements, and customer configuration responsibilities.
8. Vendor and Subprocessor Review
We use vendors and subprocessors to support hosting, infrastructure, data storage, email, analytics, customer support, telephony, AI, monitoring, payments, and other service components. We evaluate vendors based on the type of data processed, the sensitivity of the service, operational needs, contractual protections, and security posture.
9. Incident Response
RestoStack AI maintains procedures for identifying, investigating, containing, remediating, and communicating security incidents. If we determine that an incident affects customer data, we will notify affected customers as required by applicable law and contract obligations.
10. Business Continuity
We use backup, monitoring, recovery, and operational processes designed to support availability and continuity of the services. No system can guarantee uninterrupted availability, and restaurants should maintain appropriate backup procedures for critical business operations.
11. Customer Security Responsibilities
Security is shared between RestoStack AI and our customers. Restaurants and account administrators should:
- Use strong, unique passwords and enable multifactor authentication where available.
- Limit administrator access to trusted personnel.
- Review users, roles, and connected integrations regularly.
- Remove access promptly for former employees, agencies, contractors, or vendors.
- Keep POS, delivery marketplace, social media, telephony, and payment platform credentials secure.
- Train staff on phishing, social engineering, customer data handling, and call privacy.
- Notify RestoStack AI promptly if you suspect unauthorized access or misuse.
12. Compliance and Certifications
RestoStack AI is committed to building and maintaining trustworthy security practices. We do not claim SOC 2, ISO 27001, PCI DSS, HIPAA, or other formal certifications unless expressly stated in a signed agreement or official RestoStack AI compliance document.
13. Responsible Disclosure
We welcome responsible reports of security vulnerabilities. To report a suspected vulnerability, email [email protected] with a description of the issue, steps to reproduce, affected URLs or accounts, and your contact information.
Please do not access, modify, delete, or exfiltrate data that does not belong to you; do not disrupt the services; do not run destructive tests; and do not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and remediate it.
RestoStack AI does not offer a paid bug bounty unless a separate written bounty program states otherwise.
14. Contact
Security questions may be sent to:
RestoStack AI Security
RestoStackAI
Email: [email protected]