When this version applies. These Terms apply when you expressly accept version 3.0. Publication alone does not replace an existing customer's agreement or remove accrued rights. Existing customers remain subject to their existing agreement until a valid transition or express acceptance. Previous published version (2.2).
These Terms govern business use of Cooklayer (the “Service”). The provider is Marco Di Stefano, operating from Ontario, Canada (“we”, “us”). The customer is the business accepting these Terms through an authorized representative (“Customer”, “you”). A proposed corporation is not a contracting party until it legally exists and an appropriate transfer has taken effect. These Terms do not themselves transfer a contract to Boldrope Inc.
The Service is intended for business operations. If mandatory consumer or other protective laws nevertheless apply, those laws prevail. An invited employee uses the Service under their employer’s workspace permissions; accepting user rules does not make that employee personally responsible for their employer’s subscription fees or business indemnity.
The Service provides restaurant ordering, inventory, invoice processing, recipe costing, staffing, sales analytics and optional integrations or AI features, depending on your plan. You must be authorized to act for your business, provide accurate account information and manage your users’ permissions. Protect credentials and devices and promptly report suspected unauthorized access. We remain responsible for our own applicable security obligations.
We may improve features and perform maintenance. No uptime commitment or response-time guarantee applies unless separately agreed in writing. If we discontinue paid core functionality without a reasonably equivalent replacement, you may terminate the affected service and request a proportionate refund for the unused prepaid period.
AI and optical character recognition are fallible. A successful scan, confidence score, “matched”, “verified” or automatically processed status is not a guarantee of accuracy or independent professional verification. Results may contain omissions, invented or misread values, duplicate lines, wrong product matches, dates, currencies, decimal separators, taxes, discounts, pack sizes, weights or units. Errors can occur even with a clear document.
You remain responsible for your business decisions and for losses to the extent caused by inaccurate or incomplete inputs, unsuitable source documents, incorrect configuration, unauthorized instructions or failure to perform reasonable verification. This allocation does not excuse defects, negligence or other conduct attributable to us beyond the lawful limits in section 10, and does not waive non-excludable rights.
Calculations, AI suggestions, schedules, forecasts and generated content are operational aids, not accounting, tax, legal, employment, food-safety, medical or professional advice. You must independently verify payroll and employment-law compliance, allergens, food handling and safety-critical information. Review generated public content before publication. We do not guarantee savings, profitability, regulatory compliance or any particular business outcome.
We will give at least 30 days’ advance notice of a price increase applying at renewal, or longer if required by law, so you can cancel before it takes effect. A separate signed enterprise agreement controls where it expressly differs.
You retain your rights in uploaded business records. You authorize us and the service providers described in the Privacy Policy to host, process, transmit and display those records as needed to provide and secure your requested features. You must have the necessary rights and lawful authority for employee, supplier and other third-party information. Do not upload unnecessary sensitive information, payment-card security codes or credentials in documents.
We retain rights in the Service and its software, branding and documentation. Your plan gives you a limited right to use it for your business, not ownership of the software. AI output may not be unique or eligible for intellectual-property protection; you must check rights before external use.
Each party must protect the other’s non-public business information with reasonable care, disclose it only to authorized persons who need it for the Service or as legally required, and not use it for an unrelated purpose. Exceptions apply to information lawfully public, independently developed or lawfully received without a confidentiality restriction. Privacy obligations continue to apply.
Use of your company name or logo as a public customer reference requires separate optional authorization. Purchasing a plan or accepting these Terms does not grant that permission.
Optional email, POS, social, payment and mobile services also depend on their providers’ availability, permissions and terms. You authorize the transfers needed for features you connect and should monitor failed, delayed or duplicate synchronization. A record marked sent or received does not guarantee a supplier has read, accepted or fulfilled an order. Revoking an integration stops future authorized access but does not automatically erase records already imported.
Essential account, security and billing notices are separate from optional marketing. Marketing and public-logo permissions are not conditions of using the core Service. Our Google API data practices are described in the Privacy Policy.
Do not use the Service unlawfully, upload malicious content, bypass plan or security controls, access other customers’ data, infringe rights, or resell unauthorized access. Subject to applicable law, the Customer will indemnify us for third-party claims arising from its unlawful uploaded content, infringement of third-party rights or deliberately unauthorized use, to the extent caused by the Customer. This does not cover claims caused by our breach, negligence or misconduct. We must promptly notify you, reasonably cooperate and allow reasonable control of the defence; neither party may impose admissions or non-monetary obligations on the other through settlement without consent.
You may stop using the Service and request closure. Subscription cancellation, disabling an individual login and deleting a company’s records are different actions. Contact us to arrange an available export or a company-data deletion request; keep your own source documents and required business records.
We may restrict access for non-payment, material breach or a credible legal/security risk. Where practicable, we will explain the reason and allow a reasonable opportunity to remedy it. Urgent action may be necessary to protect users. If we terminate a paid subscription for our convenience, we will refund the unused prepaid period. Retention, deletion exceptions and requests are governed by the Privacy Policy; closure does not promise automatic deletion after a fixed period.
We will provide the Service with reasonable care and skill. Except for express commitments in these Terms and rights that cannot lawfully be excluded, the Service and AI outputs are provided “as available”, without warranties of uninterrupted operation, error-free extraction, fitness for a specific business decision or guaranteed results. You should promptly report suspected defects with enough information for investigation, avoiding unnecessary personal information.
To the maximum extent permitted by applicable law, we are not liable for indirect, incidental, special or consequential loss, or loss of anticipated profits, revenue, business opportunity or goodwill arising from the Service. Subject to the exceptions below, our aggregate liability arising from or relating to the Service, whether in contract, tort (including negligence) or otherwise, is limited to the greater of CAD 100 or the fees you paid us for the Service during the 12 months immediately preceding the event giving rise to the claim. Related events constitute one claim for this purpose.
These exclusions and cap do not apply to fraud, fraudulent misrepresentation, wilful misconduct, gross negligence, or liability that cannot lawfully be excluded or limited. They do not waive statutory privacy obligations, mandatory consumer rights, rights to complain to a regulator, or a remedy the law does not permit a contract to exclude. Contractually due refunds and repayment of incorrect charges remain payable. These provisions allocate commercial risk; they are not a promise that we can never be responsible for an error.
We will provide at least 30 days’ advance notice of material changes, with a copy or link identifying the revised terms, unless an urgent legal or security requirement needs earlier action. Changes do not retrospectively remove accrued rights. Where fresh agreement or consent is required, we will request it; merely replacing this page is not proof of acceptance. If a materially adverse change would apply before your prepaid term ends and you reject it before its effective date, you may cancel the affected Service without penalty and receive a proportionate refund for the unused prepaid period, unless we keep your existing terms in place through that term. Mandatory rights remain unaffected.
We may transfer the Service to a successor or newly incorporated operator only in accordance with applicable law, with notice identifying the new operator and without reducing your mandatory rights. These Terms do not by themselves release the existing operator from accrued obligations. Any invalid provision is severed only to the extent necessary; remaining provisions continue. A failure to enforce a provision is not a waiver.
Ontario law and applicable federal Canadian law govern these Terms. Ontario courts have jurisdiction, except where mandatory law requires otherwise. Contact Marco Di Stefano at info@boldrope.com for contractual questions, disputes or notices. Mailing address: 323-4K SPADINA AVENUE, Toronto, Ontario, M5V3Y9, Canada. We encourage you to contact us to resolve an issue, but doing so is not a condition that removes statutory remedies.
This revision corrects and expands descriptions of existing processing, including automation, additional AI features and account closure. It does not authorize new unrelated uses or erase previous commitments. Previous published notice (2.2).
Cooklayer is operated by Marco Di Stefano in Ontario, Canada. This notice explains how personal information is handled through our website, web and mobile applications and connected features. Questions and privacy requests may be directed to info@boldrope.com. Mailing address: 323-4K SPADINA AVENUE, Toronto, Ontario, M5V3Y9, Canada. A future incorporation does not change the operator without an appropriate transition and notice.
We are responsible for personal information we handle for account administration, security, billing, support and our own business operations. For employee, supplier and operational records uploaded by a restaurant, we also act as a service provider to that restaurant. The restaurant determines its operational purposes and authorized users and must provide applicable notices and obtain any required authority or consent. This does not remove our own duties under applicable privacy law.
Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and other laws may apply depending on the information and circumstances. Not all restaurant employment records fall under PIPEDA solely because the restaurant uses our software. Employees may contact their employer for employment-record requests; they may also contact us about our handling of their information.
| Category | Examples and sources |
|---|---|
| Account and profile | Name, email, phone, password hash, role, company/location membership, profile photo or avatar, login and account-security records, supplied by you or your workspace administrator. |
| Workforce | Employee contact details, role, hourly wage or salary, schedules, availability, hours, leave/time-off dates and requests, entered by employees, managers or connected systems. Avoid unnecessary medical explanations or other sensitive details. |
| Business records | Invoice images/PDFs, spreadsheets, purchase orders, supplier contacts, inventory, waste, recipes, sales and POS reports, imported email content/attachments and extracted text. Documents may contain third-party personal information. |
| Connected services | OAuth identifiers and access/refresh credentials, selected integration settings, and the records imported or published through the permissions you grant. |
| Billing | Company and billing contact information, addresses where requested at checkout, plan, subscription identifiers, invoices and payment status. Stripe handles payment credentials through its hosted payment interface; our application does not require you to upload full card details into business documents. |
| Technical and mobile | IP addresses, request/security logs, timestamps, device/session and installation identifiers, push tokens and notification-delivery information, and error diagnostics when monitoring is enabled. |
| Support and public website | Demo/contact submissions, support messages, communications preferences, consent records, and optional pseudonymous website analytics. Screenshots or attachments you send to support may contain personal information. |
| Customer references | Company name/logo and evidence of separate showcase permission, including the approving user, date, consent version and relevant asset details. |
We use information to authenticate users, enforce workspace permissions, provide requested restaurant operations and integrations, process subscriptions, deliver notifications, investigate support requests, prevent fraud and abuse, maintain service reliability and comply with legal obligations. Optional marketing, website analytics and customer-logo publication have separate choices. Declining those optional uses does not remove access to the core paid service.
We do not sell or rent personal information or use restaurant records for third-party advertising. Accepting a contract or uploading a document is not blanket consent to unrelated processing. If a new purpose requires consent, we will seek it before that use. You can withdraw consent subject to legal or contractual restrictions and reasonable notice; we will explain any resulting feature limitations.
Features using Anthropic’s AI services send the information needed for that feature to the provider. Depending on the feature, this may include:
Only use these features with information your business is authorized to provide. Remove unnecessary personal or sensitive details before upload. AI output can be inaccurate or incomplete, even when an image is clear; blur, glare, cropping or missing pages can increase error rates. Check material output against its source and correct it before relying on it. Some workflows automatically file or apply results; consult the workflow’s controls and review processed records and exceptions.
We do not use customer content to train a general-purpose AI model. Processing by external providers remains subject to their applicable service terms, security/abuse controls and retention arrangements; we do not promise zero retention or immediate deletion at those providers. Ask us for the current applicable arrangements before sending information with special confidentiality or residency requirements. Material changes to the provider or processing purposes will be reflected in this notice, with additional notice or consent where required.
We disclose information to providers only as needed for the features and purposes described here, and must use appropriate contractual and other safeguards. Providers and their subprocessors may process information outside Canada, including in the United States. Foreign courts, regulators and law-enforcement authorities may have lawful access. We do not represent that all data remains in Canada.
| Provider | Purpose |
|---|---|
| Render | Application hosting and related technical processing. |
| Supabase | Database and file storage. |
| Anthropic | AI document/report processing, scheduling assistance and content generation described above. |
| Resend | Sending emails, including recipient addresses, message content and delivery metadata. |
| Stripe, when checkout is used | Hosted payment collection, subscription management and billing. Stripe also processes information under its own privacy notice. |
| Sentry, when enabled | Error and reliability diagnostics. Reports may include technical context; avoid putting sensitive information into error messages or support reproductions. |
| Google, Meta and connected POS providers | Optional sign-in, configured email/report or sales import, and social publishing, according to permissions granted. |
| Apple and Google, where push is enabled | Device notification delivery using push tokens and notification content/routing information. |
Ask us for current hosting regions and relevant processing arrangements. Access is also available to authorized personnel who need it for support, security or operations. Information may be disclosed where legally required or to protect lawful rights, using appropriate limits. A business transfer may involve information only subject to applicable law, safeguards and required notices; it is not permission for unrelated marketing.
Google sign-in uses identity/profile information for authentication. Gmail connections request read-only access for configured invoice/report imports. Imported documents may subsequently undergo the AI processing above. We do not use Google API data for advertising or general-purpose model training. Our use and transfer of Google API information must comply with the Google API Services User Data Policy, including Limited Use requirements.
POS integrations may import sales, orders, payment-related operational records or employee records within granted scopes. Meta integrations use the permissions needed for connected pages/accounts and social publishing. Disconnect through the available integration settings or revoke authorization with the provider. Previously imported records are handled under the retention rules below. Device notification permissions can be changed through the device settings.
Session and security cookies support authentication and security. Optional public-site journey analytics use a pseudonymous visitor_id cookie only after acceptance in the banner; the cookie lasts up to one year. Events may record pages, referral source, campaign tags and timestamps. The identifier is not your name, but pseudonymous activity is not necessarily anonymous information. Technical request logs may separately include IP addresses.
Your analytics preference is also stored in browser local storage. To reset it, clear all site data, including cookies and local storage, then decline analytics when asked again; contact us for help or an information request. Deleting browser storage alone does not delete previously recorded server events. Optional marketing requires an appropriate consent basis and a working withdrawal method; promotional consent is separate from essential account communications.
Company name/logo display on the public site requires separate opt-in by an authorized representative. That choice may permit resizing and monochrome presentation as described when consent is requested. You may withdraw it in the relevant settings or by contacting us; withdrawal stops future showcase use, while necessary consent records may be retained.
We retain information only for as long as reasonably necessary for its identified purposes, service delivery, security, applicable legal requirements and legitimate dispute handling. Retention differs by category and context; it is not a single period measured from cancellation.
Contact info@boldrope.com to request access, correction, withdrawal of consent, deletion where applicable, or an explanation of our practices. We use proportionate identity and authority checks and avoid requesting unnecessary identity documents. PIPEDA access requests are generally answered within 30 days, subject to lawful extensions and exceptions, which we will explain where applicable. Deletion is not an unconditional right to erase records another party must lawfully retain.
Staff may initially contact their employer about employer-controlled records; we assist with valid requests and remain contactable regarding our own processing. You may complain to the Office of the Privacy Commissioner of Canada or another competent authority. Contractual liability language does not remove privacy rights or prevent a regulatory complaint.
Safeguards include password hashing, HTTPS, access controls and security/audit logging. No service can guarantee absolute security. Keep account credentials and devices protected and report suspected exposure promptly. Where PIPEDA applies, a breach presenting a real risk of significant harm requires reporting to the Commissioner and notification of affected individuals as soon as feasible; other applicable notification duties may also apply. Required breach records must be retained even for incidents not meeting the reporting threshold. We will assist affected business customers with their applicable obligations.
The operator identified above is responsible for privacy inquiries and oversight. We will identify revisions by date/version and provide appropriate notice of material changes. We will obtain fresh consent where required, rather than treating a changed webpage as blanket consent. For requests or complaints, contact info@boldrope.com or 323-4K SPADINA AVENUE, Toronto, Ontario, M5V3Y9, Canada.