Cooklayer

Privacy Policy

Version 3.0 · Updated September 20, 2026

This revision corrects and expands descriptions of existing processing, including automation, additional AI features and account closure. It does not authorize new unrelated uses or erase previous commitments. Previous published notice (2.2).

Cooklayer is operated by Marco Di Stefano in Ontario, Canada. This notice explains how personal information is handled through our website, web and mobile applications and connected features. Questions and privacy requests may be directed to info@boldrope.com. Mailing address: 323-4K SPADINA AVENUE, Toronto, Ontario, M5V3Y9, Canada. A future incorporation does not change the operator without an appropriate transition and notice.

1. Responsibilities and scope

We are responsible for personal information we handle for account administration, security, billing, support and our own business operations. For employee, supplier and operational records uploaded by a restaurant, we also act as a service provider to that restaurant. The restaurant determines its operational purposes and authorized users and must provide applicable notices and obtain any required authority or consent. This does not remove our own duties under applicable privacy law.

Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and other laws may apply depending on the information and circumstances. Not all restaurant employment records fall under PIPEDA solely because the restaurant uses our software. Employees may contact their employer for employment-record requests; they may also contact us about our handling of their information.

2. Information we handle

CategoryExamples and sources
Account and profileName, email, phone, password hash, role, company/location membership, profile photo or avatar, login and account-security records, supplied by you or your workspace administrator.
WorkforceEmployee contact details, role, hourly wage or salary, schedules, availability, hours, leave/time-off dates and requests, entered by employees, managers or connected systems. Avoid unnecessary medical explanations or other sensitive details.
Business recordsInvoice images/PDFs, spreadsheets, purchase orders, supplier contacts, inventory, waste, recipes, sales and POS reports, imported email content/attachments and extracted text. Documents may contain third-party personal information.
Connected servicesOAuth identifiers and access/refresh credentials, selected integration settings, and the records imported or published through the permissions you grant.
BillingCompany and billing contact information, addresses where requested at checkout, plan, subscription identifiers, invoices and payment status. Stripe handles payment credentials through its hosted payment interface; our application does not require you to upload full card details into business documents.
Technical and mobileIP addresses, request/security logs, timestamps, device/session and installation identifiers, push tokens and notification-delivery information, and error diagnostics when monitoring is enabled.
Support and public websiteDemo/contact submissions, support messages, communications preferences, consent records, and optional pseudonymous website analytics. Screenshots or attachments you send to support may contain personal information.
Customer referencesCompany name/logo and evidence of separate showcase permission, including the approving user, date, consent version and relevant asset details.

3. Purposes and choices

We use information to authenticate users, enforce workspace permissions, provide requested restaurant operations and integrations, process subscriptions, deliver notifications, investigate support requests, prevent fraud and abuse, maintain service reliability and comply with legal obligations. Optional marketing, website analytics and customer-logo publication have separate choices. Declining those optional uses does not remove access to the core paid service.

We do not sell or rent personal information or use restaurant records for third-party advertising. Accepting a contract or uploading a document is not blanket consent to unrelated processing. If a new purpose requires consent, we will seek it before that use. You can withdraw consent subject to legal or contractual restrictions and reasonable notice; we will explain any resulting feature limitations.

4. AI-assisted processing and its risks

Features using Anthropic’s AI services send the information needed for that feature to the provider. Depending on the feature, this may include:

Only use these features with information your business is authorized to provide. Remove unnecessary personal or sensitive details before upload. AI output can be inaccurate or incomplete, even when an image is clear; blur, glare, cropping or missing pages can increase error rates. Check material output against its source and correct it before relying on it. Some workflows automatically file or apply results; consult the workflow’s controls and review processed records and exceptions.

We do not use customer content to train a general-purpose AI model. Processing by external providers remains subject to their applicable service terms, security/abuse controls and retention arrangements; we do not promise zero retention or immediate deletion at those providers. Ask us for the current applicable arrangements before sending information with special confidentiality or residency requirements. Material changes to the provider or processing purposes will be reflected in this notice, with additional notice or consent where required.

5. Providers, integrations and international processing

We disclose information to providers only as needed for the features and purposes described here, and must use appropriate contractual and other safeguards. Providers and their subprocessors may process information outside Canada, including in the United States. Foreign courts, regulators and law-enforcement authorities may have lawful access. We do not represent that all data remains in Canada.

ProviderPurpose
RenderApplication hosting and related technical processing.
SupabaseDatabase and file storage.
AnthropicAI document/report processing, scheduling assistance and content generation described above.
ResendSending emails, including recipient addresses, message content and delivery metadata.
Stripe, when checkout is usedHosted payment collection, subscription management and billing. Stripe also processes information under its own privacy notice.
Sentry, when enabledError and reliability diagnostics. Reports may include technical context; avoid putting sensitive information into error messages or support reproductions.
Google, Meta and connected POS providersOptional sign-in, configured email/report or sales import, and social publishing, according to permissions granted.
Apple and Google, where push is enabledDevice notification delivery using push tokens and notification content/routing information.

Ask us for current hosting regions and relevant processing arrangements. Access is also available to authorized personnel who need it for support, security or operations. Information may be disclosed where legally required or to protect lawful rights, using appropriate limits. A business transfer may involve information only subject to applicable law, safeguards and required notices; it is not permission for unrelated marketing.

6. Google and other connected accounts

Google sign-in uses identity/profile information for authentication. Gmail connections request read-only access for configured invoice/report imports. Imported documents may subsequently undergo the AI processing above. We do not use Google API data for advertising or general-purpose model training. Our use and transfer of Google API information must comply with the Google API Services User Data Policy, including Limited Use requirements.

POS integrations may import sales, orders, payment-related operational records or employee records within granted scopes. Meta integrations use the permissions needed for connected pages/accounts and social publishing. Disconnect through the available integration settings or revoke authorization with the provider. Previously imported records are handled under the retention rules below. Device notification permissions can be changed through the device settings.

7. Cookies, analytics and marketing

Session and security cookies support authentication and security. Optional public-site journey analytics use a pseudonymous visitor_id cookie only after acceptance in the banner; the cookie lasts up to one year. Events may record pages, referral source, campaign tags and timestamps. The identifier is not your name, but pseudonymous activity is not necessarily anonymous information. Technical request logs may separately include IP addresses.

Your analytics preference is also stored in browser local storage. To reset it, clear all site data, including cookies and local storage, then decline analytics when asked again; contact us for help or an information request. Deleting browser storage alone does not delete previously recorded server events. Optional marketing requires an appropriate consent basis and a working withdrawal method; promotional consent is separate from essential account communications.

Company name/logo display on the public site requires separate opt-in by an authorized representative. That choice may permit resizing and monochrome presentation as described when consent is requested. You may withdraw it in the relevant settings or by contacting us; withdrawal stops future showcase use, while necessary consent records may be retained.

8. Retention, account closure and deletion

We retain information only for as long as reasonably necessary for its identified purposes, service delivery, security, applicable legal requirements and legitimate dispute handling. Retention differs by category and context; it is not a single period measured from cancellation.

9. Access, correction and complaints

Contact info@boldrope.com to request access, correction, withdrawal of consent, deletion where applicable, or an explanation of our practices. We use proportionate identity and authority checks and avoid requesting unnecessary identity documents. PIPEDA access requests are generally answered within 30 days, subject to lawful extensions and exceptions, which we will explain where applicable. Deletion is not an unconditional right to erase records another party must lawfully retain.

Staff may initially contact their employer about employer-controlled records; we assist with valid requests and remain contactable regarding our own processing. You may complain to the Office of the Privacy Commissioner of Canada or another competent authority. Contractual liability language does not remove privacy rights or prevent a regulatory complaint.

10. Security and incidents

Safeguards include password hashing, HTTPS, access controls and security/audit logging. No service can guarantee absolute security. Keep account credentials and devices protected and report suspected exposure promptly. Where PIPEDA applies, a breach presenting a real risk of significant harm requires reporting to the Commissioner and notification of affected individuals as soon as feasible; other applicable notification duties may also apply. Required breach records must be retained even for incidents not meeting the reporting threshold. We will assist affected business customers with their applicable obligations.

11. Changes and accountability

The operator identified above is responsible for privacy inquiries and oversight. We will identify revisions by date/version and provide appropriate notice of material changes. We will obtain fresh consent where required, rather than treating a changed webpage as blanket consent. For requests or complaints, contact info@boldrope.com or 323-4K SPADINA AVENUE, Toronto, Ontario, M5V3Y9, Canada.

← Terms & overview