Privacy Policy

Restoke Privacy Policy

Last updated: October 2025

Restoke Pty Ltd (“Restoke”, “we”, “our”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our website, platform, or related services (collectively, the “Services”).

1. Who We Are

Restoke Pty Ltd (ABN 99 636 328 553) is headquartered in Australia at:
3/574 Plummer St, Port Melbourne, VIC, Australia.

We act as:

  • A Data Controller under the EU and UK GDPR, and
  • An APP Entity under the Australian Privacy Act 1988.

For any privacy questions or requests:
📧 privacy@restoke.ai

We do not yet have an EU/UK representative, but we are in the process of appointing one and will update this policy when available.

2. The Data We Collect

We collect personal data to provide, improve, and support our Services. The information we collect depends on how you interact with Restoke — for example, when you create an account, connect integrations, contact support, or use our platform.

We may collect identity information, such as your name, business name, and role, when you sign up, are invited to a team, or integrate with HR or business tools. We collect contact information, including your email address and phone number, through signup forms, onboarding, and customer support communications.

We also collect business information such as your restaurant or venue details, point-of-sale or HR integrations, and team data, which you or your organisation provide to us directly or through connected systems (like Xero, Deputy, or Employment Hero).

When you use our platform, we automatically collect usage data such as device information, log data, browser type, operating system, and how you interact with our Services. This helps us monitor performance, improve user experience, and maintain security.

We may also collect communications data, including messages, support requests, and related information exchanged with our team through email, chat, or our in-app tools.

We do not collect sensitive personal information such as health data, political opinions, religious beliefs, biometric identifiers, or similar categories.

3. How We Use Your Data

We use your personal data only for legitimate business purposes and in accordance with applicable privacy laws, including the EU GDPR, UK GDPR, and the Australian Privacy Act 1988.

We use your information to create and manage your account, including verifying your details, setting up your workspace, and managing subscriptions and billing. This processing is necessary to perform our contract with you.

We use your data to provide customer support, respond to enquiries, and resolve issues — based on our legitimate interest in maintaining high-quality service and customer satisfaction.

We use payment information to process transactions and manage billing through our trusted providers, such as Stripe and SaaSGrid, which act as data processors under strict confidentiality and security terms.

If you have given explicit consent, we may send you email marketing communications, such as newsletters, updates, or feature announcements. You can withdraw your consent or unsubscribe at any time using the link in our emails or by contacting privacy@restoke.ai.

We also process certain data under our legitimate interest in improving and securing our Services, including analysing how people use Restoke, fixing bugs, and developing new features. This helps us enhance performance and user experience while safeguarding your privacy.

Finally, we may process your data where required to meet legal obligations, such as complying with tax, regulatory, or data protection laws, and to respond to lawful requests from authorities.

We do not use your data for automated decision-making or profiling that produces legal or significant effects.

4. Cookies and Tracking

We use cookies and similar technologies to:

  • Understand how you use Restoke,
  • Improve performance and features, and
  • Personalise marketing (only if you’ve consented).

Non-essential cookies are disabled by default until you consent through our cookie banner or browser settings.
For full details, see our Cookie Policy.

5. Sharing Your Information

We only share your personal data where necessary to deliver our Services or comply with law.

Service providers

We use trusted third-party providers, including:

  • Hosting & Infrastructure: AWS (Sydney)
  • Payments: Stripe, SaaSGrid
  • CRM & Marketing: HubSpot, Smartlead, First Promoter, Rebrandly
  • Communication & Support: Intercom, Aircall, Sakari, Twilio, Slack, Zoom, Gmail/Superhuman
  • Analytics & Ads: Google Analytics, Meta (Facebook), LinkedIn, Twitter/X, Microsoft Ads, Google Tag Manager, Survicate, Dataslayer.io, Stape
  • Integrations & Automation: Zapier, Make/Integromat, Typeform, Webflow, Google Sheets
  • Internal Tools: Gong, ZoomInfo, ChatGPT

All vendors are bound by Data Processing Agreements (DPAs) and required to comply with the GDPR, UK GDPR, or equivalent frameworks.

We may also share data:

  • With integrations you connect, such as Xero, Deputy, or Employment Hero;
  • With law enforcement or regulators where legally required; or
  • As part of a business transaction, such as a merger or acquisition.

6. International Data Transfers

We primarily host data in AWS Sydney (Australia).
Where data is transferred outside Australia, the EU, or the UK (e.g. to the US or Singapore), we ensure appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission or UK ICO; or
  • Transfers to countries with an adequacy decision.

You can request a copy of these safeguards by contacting privacy@restoke.ai.

7. Data Retention

We retain personal data only as long as needed for the purposes described here:

  • Account and billing data: while your account is active and up to 24 months after closure.
  • Support and communications: up to 12 months.
  • Marketing consents: until withdrawn.
  • Backups: securely deleted or anonymised within 90 days after expiry.

When data is no longer needed, we delete or anonymise it.

8. Your Rights

Under the EU GDPR, UK GDPR, and Australian Privacy Act, you have the right to:

  • Access your personal data;
  • Correct inaccurate data;
  • Request deletion (“Right to be Forgotten”);
  • Withdraw consent (e.g. for marketing emails);
  • Object to or restrict processing in some cases;
  • Request a copy of your data (portability); and
  • Complain to a supervisory authority.

To exercise any of these rights, contact 📧 privacy@restoke.ai.
We’ll verify your identity and respond within 30 days.
Requests are free unless clearly excessive or unfounded.

You may request to delete your personal information using this form.

For EU/UK users, you may also contact your local data protection authority.
For Australian users, you can contact the Office of the Australian Information Commissioner (OAIC).

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what categories of data we collect and why;
  • Request deletion of your data;
  • Opt out of the sale or sharing of personal data (Restoke does not sell personal data); and
  • Not be discriminated against for exercising these rights.

Email privacy@restoke.ai to make a request.

10. Security

We protect your data using a mix of technical and organisational measures, including:

  • TLS encryption for data in transit;
  • Encryption at rest;
  • Multi-factor authentication for admin accounts;
  • Role-based access controls;
  • Regular audits and security reviews; and
  • Access limited to authorised Restoke staff only.

In the unlikely event of a data breach likely to risk your rights or freedoms, we will notify the relevant authority within 72 hours and contact you if required.

11. Children’s Privacy

Our Services are not directed to children under 16.
We do not knowingly collect data from minors.
If you believe a child has shared personal data with us, please contact privacy@restoke.ai for prompt removal.

12. Changes to This Policy

We may update this Privacy Policy from time to time.
If changes are material, we’ll notify users by email or in-app before they take effect.
The latest version will always be available at restoke.ai/privacy.

13. Contact Us

If you have any questions or privacy requests:
📧 privacy@restoke.ai
📍 Restoke Pty Ltd, 3/574 Plummer St, Port Melbourne, VIC, Australia

For EU/UK users, you may also contact your local data protection authority if you have concerns about how we handle your data.