PrimeOps Privacy Policy
The short version
- PrimeOps is a business tool for restaurant operators. We collect the information needed to run it: your account details, your business's operating data, billing records, and the technical logs that keep the service secure.
- Your business's operating data belongs to your business. We process it to provide the service you configured — not to advertise to anyone.
- We do not sell personal information. We do not run advertising trackers. We do not let AI providers train general models on your data.
- Trusted providers help us run the service — identity, hosting, payments, email — and each gets only what its job requires.
- You can ask us to access, correct, delete, or export your information; Section 13 explains how, and Section 13.2 explains how to appeal if you disagree with our answer.
This summary is for convenience. The full Policy below is what governs.
This Privacy Policy (the "Policy") explains how PrimeOps LLC ("PrimeOps," "we," "us," or "our") collects, uses, discloses, and protects personal information through getprimeops.ai, its subdomains, and the PrimeOps applications, APIs, reports, support channels, and related services (together, the "Service").
PrimeOps provides a business-to-business hospitality operations platform. This Policy applies to business contacts, account holders, authorized users, website visitors, support contacts, and other people whose personal information PrimeOps handles for its own business purposes. The PrimeOps Terms of Service are available at getprimeops.ai/terms.
Our role, and your business's data
PrimeOps plays different privacy roles depending on the context:
- For account administration, website operation, billing, security, support, and our own business records, PrimeOps decides the purposes and means of processing.
- For data a business customer submits, connects, or directs us to process through the Service ("Customer Data"), the customer decides the business purpose. We process that data to provide the Service and follow the customer's authorized instructions, subject to our agreements and applicable law.
Customers are responsible for giving legally required privacy notices to — and getting required permissions from — their employees, contractors, guests, vendors, and other people whose information they provide to PrimeOps. If your information appears in Customer Data, you may contact the relevant customer directly; we will assist customers with applicable requests as our agreements and the law require.
Personal information we collect
What we collect depends on how the Service is configured and used. It may include the following categories.
2.1 Account and identity information
- name, business email address, display name, and contact information;
- identity-provider subject identifier, email-verification status, and sign-in status;
- organization, workspace, membership, role, invitation, and access information; and
- authentication, authorization, account-recovery, and consent records.
An identity provider may collect passwords or other authentication factors directly under its own privacy terms. PrimeOps generally receives identity and verification results — not your password.
2.2 Organization and location information
- business name, domain, location name, address or external reference;
- time zone, currency, operating settings, and location metadata; and
- authorized administrators, users, service accounts, permissions, and scopes.
2.3 Hospitality operational information
Depending on the integrations and features a customer chooses, Customer Data may include:
- sales, orders, checks, menu or item performance, discounts, refunds, and delivery information;
- schedules, roles, hours, labor cost, payroll-related operational totals, and employee or contractor identifiers the customer supplies;
- invoices, credits, purchasing, supplier, item-price, inventory, and cost information;
- deposits, settlements, reconciliation records, and financial operating totals;
- operating notes, supporting evidence, uploaded files, report inputs, and data-quality information; and
- decisions, approvals, assigned actions, outcomes, report history, and audit events.
Customers should minimize personal information in operational records and must not submit highly sensitive or specially regulated information that PrimeOps has not expressly agreed in writing to support.
2.4 Billing information
Our payment processor may collect payment-card and payment-account details directly. PrimeOps may receive billing contacts, processor customer and subscription identifiers, plan information, payment status, invoice and transaction metadata, and limited card descriptors (such as brand and last four digits) where available. PrimeOps does not intend to receive or store complete payment-card numbers or card verification codes.
2.5 Integration and connection information
- identifiers and configuration for point-of-sale, payroll, delivery, purchasing, accounting, payment, and other customer-authorized systems;
- connection status, synchronization history, source lineage, and error records; and
- credentials or tokens stored through approved secret-management mechanisms.
Do not place passwords, private keys, API secrets, or access tokens in ordinary free-text fields, uploads, support requests, or reports.
2.6 Usage, device, and security information
- IP address, browser and device type, operating system, request and session identifiers, timestamps, referring or requested pages, and general usage events;
- authentication attempts, access decisions, administrative activity, error information, audit records, and security signals; and
- diagnostic information needed to protect, maintain, and troubleshoot the Service.
2.7 Communications and support information
We collect what is included in account correspondence, support requests, sales or pilot inquiries, feedback, meeting notes, and other communications. A website inquiry may include the sender's email address, subject, message, business context, and delivery metadata.
2.8 Reports, analytics, and automated outputs
We process report inputs, requested reporting periods, generated reports, recommendations, forecasts, alerts, explanations, and related evidence or approval records. Outputs may reflect Customer Data and therefore may contain personal information when the customer supplies it.
2.9 Optional voice or AI features
If a user deliberately activates a voice-input feature, the user's browser, device, or speech provider may process audio under that provider's terms. PrimeOps may receive the resulting command or text. PrimeOps does not use voice input to create a voiceprint or to uniquely identify a person.
If a customer enables a feature that uses an external artificial-intelligence provider, PrimeOps sends only the minimum prompts, operational context, or content reasonably necessary for that feature, subject to contract, security, and configuration controls. PrimeOps does not authorize an external provider to use Customer Data to train a general-purpose or cross-customer model unless the customer expressly agrees in writing.
This subsection describes features inside the Service, which a customer enables. The operating advisor on the public website is a separate case: it is available to any visitor without an account, and Section 3.1 describes what it sends, what is stored, and what it is instructed not to do.
Website visitors and consultation requests
The public website at getprimeops.ai is hosted on Vercel and uses Vercel Web Analytics and Vercel Speed Insights to measure page usage and performance. Our application analytics send only registered event names with a small set of categorical properties; names, email addresses, company names, free-form messages, and raw calculator amounts are not sent in those events. The public website does not use third-party advertising cookies or cross-context behavioral advertising trackers.
If you submit the consultation form, we collect the information you enter (name, work email, restaurant group, and the optional fields you complete) and deliver it by a signed server-side channel to our named consultation mailbox. It is used to respond to your request — there is no automatic sales sequence. Abuse-prevention records for this form (rate-limit counters and idempotency records) are stored as hashed values and expire on short schedules; operational logs for the form record identifiers and outcomes, not your contact details. The in-browser estimate tool runs in your browser; the numbers you type are not required to include contact information and are not sent in our analytics events.
3.1 The operating advisor
Some versions of the public website offer an operating advisor: a panel where a visitor can type a question about running a restaurant and receive an answer written by Claude, a model operated by Anthropic, PBC. Using it is entirely optional. There is no account, you are not asked to identify yourself, and nothing about you is attached to the question.
What is sent. Only the text of the conversation you type. Your question, together with the earlier turns of that same conversation, is sent to a PrimeOps server and from there to Anthropic, PBC, which operates the model that writes the answer. Nothing else about your visit is included: no name, no email address, no analytics identifier, and no record of the pages you viewed. The conversation exists only in your browser tab — closing or reloading the page ends it, and it is not linked to any other conversation you have.
What PrimeOps stores. Nothing from the conversation. The exchange is held in memory for the length of the request and is not written to a database or an application log. The one record that is stored is an abuse-prevention counter. Its key is a one-way hash of your network address, your browser's user-agent string, and the website the request came from, combined with a secret held on our server; the address itself is not stored, and the hash cannot be reversed back to it. The counter exists to limit how many questions a single source may ask, and it expires five minutes after your last question. It is the same mechanism the consultation form uses.
What Anthropic does with the text is governed by its own terms and by any agreement PrimeOps has with it, not by this Policy. [ANTHROPIC RETENTION AND MODEL-TRAINING POSITION] must be confirmed against that agreement and stated here before this Policy is published.
What the advisor is told. Its instructions state that it holds none of your business data and must not quote or estimate a figure about your business. It answers general operating questions and points to pages on this website. It can still be wrong, and it is not professional advice.
What not to type into it. Treat the advisor as a public feature rather than a private channel. Do not enter personal information about yourself or anyone else, credentials, or confidential business records. If you want to discuss something specific to your business, use the consultation form or write to the address in Section 18.
Where personal information comes from
- directly from you — when you create an account, communicate with us, configure the Service, or submit information;
- from a customer, authorized administrator, coworker, or representative;
- from customer-authorized integrations and connected systems;
- automatically from browsers, devices, identity systems, and Service activity;
- from payment, hosting, email, security, and other service providers; and
- from public or commercial sources when lawfully used for a legitimate business purpose.
How we use personal information
We use personal information as reasonably necessary to:
- provide, configure, operate, maintain, and support the Service;
- authenticate users, manage workspaces and locations, enforce permissions, and preserve tenant separation;
- connect customer-authorized systems, ingest and validate data, and maintain source lineage;
- generate reports, analyses, forecasts, alerts, recommendations, and other requested outputs;
- administer trials, subscriptions, payments, invoices, and account status;
- communicate about accounts, incidents, support, product changes, legal terms, and service administration;
- detect, investigate, and prevent fraud, abuse, unauthorized access, security threats, and violations of our agreements;
- monitor reliability, troubleshoot errors, test features, and improve the Service;
- create aggregated or de-identified analytics, benchmarks, and product insights;
- comply with law, valid legal process, and tax and accounting duties, and enforce our rights; and
- protect PrimeOps, customers, users, and the public.
Where applicable law requires a legal basis, processing may rest on performance of a contract, steps you request before entering a contract, legitimate business interests, compliance with legal obligations, protection of rights and safety, or consent. Where processing is based on consent, you may withdraw it — this does not undo lawful processing already completed or processing supported by another legal ground.
We limit collection to information that is adequate, relevant, and reasonably necessary for the purposes we disclose, and we do not use personal information for a materially incompatible purpose without an appropriate legal basis and any required notice or consent.
Automated analysis and significant decisions
PrimeOps provides operational decision support: the Service may rank issues, identify anomalies, estimate effects, or suggest actions. These outputs can be incomplete or incorrect and are not intended to be the sole basis for decisions that have legal or similarly significant effects on a person.
The public operating advisor described in Section 3.1 is generative: its answers are written by a language model and can be wrong. They are general operating information, not advice about your business, and not accounting, legal, employment, or financial advice. The advisor has no access to your data and does not make or influence any decision about you.
Customers are responsible for qualified human review, accurate source data, and lawful use of outputs — especially for employment, scheduling, compensation, discipline, safety, credit, financial, or other decisions that materially affect people. PrimeOps does not process personal information for targeted advertising, and does not engage in consumer profiling that produces legal or similarly significant effects.
When we disclose personal information
7.1 Customer administrators and authorized users
Workspace owners and administrators may access and manage information associated with their organization, locations, users, reports, and connected systems. Authorized users receive information based on their roles and permissions.
7.2 Service providers
We use service providers for identity and authentication, website and cloud hosting, databases, payments, transactional email, security, monitoring, customer support, file processing, and optional AI features. Each may process only the information reasonably necessary to perform its services for PrimeOps, under contractual or legal restrictions appropriate to its role.
Providers expected to require final verification before publication: Vercel (website hosting and analytics), Auth0 (identity), Railway (hosting and database infrastructure), Stripe (payments), Resend (transactional email), and Anthropic, PBC (the model behind the optional public operating advisor described in Section 3.1, and any in-Service AI feature a customer enables).
7.3 Customer-authorized integrations
At a customer's direction, we disclose or receive information through connected point-of-sale, payroll, delivery, purchasing, accounting, payment, storage, or other systems. Those third parties process information under their own terms and privacy notices; customers control which integrations they authorize.
7.4 Professional advisors and corporate transactions
We may disclose information to attorneys, accountants, auditors, insurers, financing sources, and other professional advisors under appropriate duties, and in connection with a proposed or completed merger, financing, acquisition, reorganization, bankruptcy, or sale of assets — subject to appropriate confidentiality protections.
7.5 Legal, safety, and enforcement purposes
We may disclose information when we reasonably believe disclosure is required by law or valid legal process, or is necessary to protect rights, safety, accounts, systems, customers, users, PrimeOps, or the public. Where lawful and practical, we will notify the affected customer before producing Customer Data.
No sale. No ad targeting.
PrimeOps does not sell personal information or sensitive personal information. We do not share personal information for cross-context behavioral advertising and do not process personal information for targeted advertising. We do not knowingly use sensitive personal information to infer characteristics about a person.
Because we do not engage in these activities, we do not currently display a "Do Not Sell or Share My Personal Information" link. If these practices ever change, we will update this Policy and implement every legally required notice, consent, opt-out, and universal opt-out control — including recognized opt-out preference signals — before the change takes effect.
De-identified and aggregated information
We may create and use aggregated or de-identified information for analytics, benchmarking, security, research, and Service improvement. When we do, we will:
- take reasonable measures designed to prevent the information from being associated with an identified or identifiable person, customer, or location;
- publicly commit not to re-identify the information, except to test and improve our de-identification safeguards or as required by law; and
- require recipients to honor the same restrictions against re-identification and unauthorized use.
Cookies, authentication technologies, and browser signals
PrimeOps and its identity provider use authentication and session technologies that are necessary to sign users in, protect accounts, preserve security state, and operate the Service. The application may temporarily store bounded authentication state in the browser during an authorization flow. Identity providers may set their own necessary cookies under their privacy notices.
We do not use third-party advertising cookies or tracking technologies for cross-context behavioral advertising. Before publication, the production website and all subdomains must be scanned and verified against this statement.
Do Not Track and opt-out signals. Because we do not track visitors across third-party websites or sell or share personal information, our sites do not respond to browser "Do Not Track" signals. If we ever engage in selling or sharing that makes opt-out preference signals (such as Global Privacy Control) legally operative, we will honor them as the law requires.
Your browser settings may let you delete or block cookies, but blocking necessary authentication technologies may prevent sign-in or other Service functions.
How long we keep information
We retain personal information only as long as reasonably necessary for the purposes in this Policy — providing the Service, maintaining security and audit integrity, complying with law, resolving disputes, enforcing agreements, and keeping legitimate business records. Retention depends on the information and context:
- Account and workspace information is generally kept while the account or customer relationship is active, and for a limited period afterward.
- Customer Data is kept according to the customer's subscription and our agreements. After termination, an authorized customer may request an export for 30 days; we may then delete or de-identify Customer Data, subject to legal, security, backup, dispute, and accounting requirements.
- Billing, transaction, consent, security, and audit records may be kept longer where needed for tax, accounting, fraud prevention, legal compliance, or the integrity of the Service.
- Operating advisor conversations are not retained by PrimeOps at all. The exchange exists only for the length of the request. The abuse-prevention counter described in Section 3.1 expires five minutes after your last question. Retention on the model provider's side is governed by our agreement with it, which must be confirmed before publication.
- Routine backups may retain information until overwritten on the applicable backup cycle. Backup data is protected and is not restored to ordinary business use after deletion, except for disaster recovery or another lawful purpose.
PrimeOps must approve a detailed internal retention schedule before this Policy is published.
Security, and what happens if something goes wrong
PrimeOps uses reasonable administrative, technical, and organizational measures designed to protect the confidentiality, integrity, and availability of personal information — including access controls, tenant scoping, encryption in transit, authentication, audit records, secure development practices, environment separation, monitoring, incident response, and service-provider oversight appropriate to the data and the Service.
If we determine that a security incident has affected personal information in a way the law treats as a breach, we will notify affected customers and individuals, and any required regulators, without unreasonable delay and within the time applicable law requires — including New Jersey's breach-notification law and the laws of other affected states.
No internet, storage, or transmission system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur. Please protect your credentials, use appropriate account security, assign least-privilege access, and report suspected compromise promptly to support@getprimeops.ai.
Your privacy rights and choices
Depending on where you live and the law that applies, you may have the right to:
- confirm whether we process your personal information, and access it;
- correct inaccurate personal information;
- delete personal information, subject to legal exceptions;
- obtain a portable copy of information you provided, or information otherwise covered by applicable law;
- opt out of sale, targeted advertising, or certain profiling;
- limit certain uses of sensitive personal information;
- withdraw consent where processing depends on consent; and
- receive equal service — we will not unlawfully discriminate against you for exercising a privacy right.
PrimeOps does not sell personal information, use it for targeted advertising, or use consumer personal information for covered significant-effect profiling. We will treat an applicable opt-out request as a request to preserve that status for you.
13.1 Submitting a request
Email support@getprimeops.ai with the subject "Privacy Request." Say which right you want to exercise and give us enough information to find the relevant records. You do not need to create a new account to submit a request, though we may ask you to use an existing authenticated account where appropriate.
We will verify your identity using information appropriate to the request and the sensitivity of the data, and will not ask for more personal information than reasonably necessary. An authorized agent may submit a request where the law permits; we may verify the agent's authority and, where allowed, confirm the request with you directly.
We aim to respond within 45 days where that period applies. We may extend the period where legally permitted and will explain any extension. Requests are generally free, but applicable law may permit a reasonable fee — or denial — for requests that are manifestly unfounded, excessive, fraudulent, or repetitive.
Some information may be exempt — for example, where retention is required for security, fraud prevention, legal compliance, accounting, dispute resolution, the rights of others, or completing a service you requested. If we deny a request, we will explain why and describe the available appeal process where required.
13.2 Appeals
To appeal a privacy-request decision, reply to the decision or email support@getprimeops.ai with the subject "Privacy Appeal," including the original request reference and the reason for your appeal. We will respond in writing within 45 days where required. If we deny an appeal, we will provide the regulator or complaint information the law requires.
State-specific information
14.1 New Jersey
Where the New Jersey Data Privacy Act applies, New Jersey consumers may access, correct, delete, and obtain a portable copy of their personal data, and opt out of covered sale, targeted advertising, or significant-effect profiling. Consumers may appeal a denied request using Section 13.2. These consumer rights generally do not apply to people acting in a commercial or employment context, though other laws and customer obligations may still apply. PrimeOps does not sell sensitive data, limits collection and use to disclosed and reasonably necessary purposes, and obtains consent for sensitive-data processing when required.
14.2 California
If PrimeOps becomes subject to the California Consumer Privacy Act, California residents may have rights to know, access, correct, delete, and obtain information about collection and disclosure; to opt out of sale or sharing; to limit certain uses and disclosures of sensitive personal information; and not to receive discriminatory treatment for exercising their rights. PrimeOps does not sell personal information, does not share it for cross-context behavioral advertising, and does not offer financial incentives in exchange for personal information. Requests may be submitted using Section 13.1.
14.3 Other states
Residents of other states with comprehensive privacy laws (for example Colorado, Connecticut, Virginia, Texas, and Oregon) may have similar rights where those laws apply to PrimeOps. Use Section 13.1 to submit a request; we honor applicable rights regardless of which state's law grants them. Nothing in this section extends a law beyond its scope or limits a right another applicable law provides.
Children
The Service is for business users who are at least 18 years old. PrimeOps does not knowingly collect personal information directly from children and does not offer the Service to them. Do not provide children's personal information to PrimeOps unless PrimeOps has expressly agreed in writing to support the use and all legally required permissions and safeguards are in place. If you believe a child provided personal information directly to PrimeOps, contact support@getprimeops.ai so we can investigate and take appropriate action.
Where information is processed
PrimeOps is based in the United States. The Service and its providers may process information in the United States and other locations where they operate, and those locations may have different privacy laws than where you live. Where applicable law requires a transfer mechanism or additional safeguard, PrimeOps will implement an appropriate mechanism before the transfer.
Changes to this Policy
We may update this Policy to reflect changes in the Service, the law, or our practices. We will post each updated version with a new Effective Date. For a material change, we will give reasonable additional notice — by email, through the Service, or another appropriate method — before the change takes effect, and will request consent where the law requires it. Previous versions are retained in PrimeOps' legal records so the company can identify the notice associated with each recorded consent.
Contact PrimeOps
Questions, privacy requests, and appeals:
PrimeOps LLC
Attn: Privacy
72 Halsey Street
Newark, New Jersey 07102
support@getprimeops.ai