Restaurant Operator Privacy Notice

Tade is operated by Taehyung Kim, a sole proprietorship operating as Tade, based in Vancouver, British Columbia, Canada. Tade has designated a Privacy Officer who can be reached at admin@thetade.com.

1. Scope and Roles

Tade is responsible for operator account, authentication, subscription, support, security, and product-use information handled for its own Service purposes. For guest information a restaurant enters, views, changes, or uses through the Operator Services, the restaurant determines the business purpose and is primarily responsible for providing notice, obtaining any required consent, limiting staff access, and responding to guest requests; Tade processes the information to supply and secure the Service.

This Notice covers the admin website on Tade's US and Canadian domains and the iOS and Android manager app. The domains identify a regional market experience but do not promise that information is stored only in that country.

The current iOS and Android manager builds are distributed internally through Expo/EAS and have not been submitted to the Apple App Store or Google Play. Before any public app-store distribution, Tade will complete and verify the applicable store privacy disclosures and policy URLs against the then-current app behavior.

2. Operator Account and Authentication Information

On a configured admin sign-in page, the browser loads both the Google Identity Services library and the Sign in with Apple JavaScript SDK before an operator chooses a provider. Merely opening that page can therefore let both providers process standard network and request data such as IP address, device or browser information, and referrer information under their own policies. The provider the operator selects additionally returns the identity information described below.

Google and Apple may use provider cookies or similar browser storage where permitted by the browser and their policies; Tade does not use that provider state for advertising. See the Google Privacy Policy and Apple Privacy Policy.

Account-deletion reauthentication is narrower: after that flow reaches identity verification, the admin page loads only the JavaScript library for the Google or Apple provider linked to that account. Merely opening the ordinary account page before that verification step does not load both sign-in libraries for deletion reauthentication.

Your Google or Apple account is independently governed by that provider's privacy terms. Different provider emails—including an Apple private relay address—can be treated as different Tade accounts unless support lawfully verifies and resolves the relationship.

The current Service does not create separate employee identities, provide granular staff role-based access control, or reliably attribute each action to an individual employee. Authorized staff may use an owner-authorized browser session or an admin-app session on a restaurant-controlled device, so account, session, consent, and operational records may identify the owner account or device session rather than the natural person who performed an action. The restaurant owner is responsible for granting and withdrawing staff access, controlling shared devices and sessions, and keeping any separate employee-level access or audit records the restaurant requires. Tade does not require or authorize disclosure of a Google, Apple, or legacy password to staff.

3. Restaurant and Operational Information

4. Device, Browser, App, and Diagnostic Information

Hosting and security systems may process IP address, request time, host, method, route, response status, browser or device details, and abuse signals. Tade's structured application logs are designed to use route templates and opaque identifiers and to exclude raw URLs and query strings, headers, cookies, bearer tokens, names, email addresses, phone numbers, street addresses, message bodies, IP addresses, user-agent strings, SQL values, and raw error stacks.

The manager app may send Tade's API a privacy-limited sign-in diagnostic event containing a random attempt identifier, provider, stage, outcome or safe error code, elapsed time, operating-system platform, app version, build version, runtime version, update identifier, release channel, and whether the app code was embedded. The endpoint validates those fields but the application diagnostic sink retains only the closed event stage; it does not persist the attempt identifier, provider, versions, elapsed time, release channel, or other correlation metadata. Hosting and network systems may still process the request transiently as described above. The event is designed not to include name, email, provider token, Tade token, phone number, URL, or restaurant content.

The current manager application code does not request device GPS or precise location, camera, photo-library or external-media access, notification permission, or biometric authentication; it does not register a push token, deliver push notifications, or use a system-overlay feature. Native libraries can nevertheless add unused capability declarations at build time. The last audited Android internal binary declared notification, legacy external-storage, system-overlay, and biometric capabilities, and the last audited iOS internal binary contained a Face ID usage-description key. Those declarations do not establish that the app invoked the capability. The source configuration for the next native binary removes the unused notifications package, blocks those unused Android permissions, removes the unused iOS Face ID description, and disables Android app backup. These native changes cannot take effect through an over-the-air update: an older installed binary keeps its original manifest until it is replaced and reverified. The app checks and receives application updates through Expo's update service. For EAS Update, Expo states that it may collect the device operating system and a randomized token used to determine whether an update was downloaded; it may also process standard request, error, performance, and delivery information under its own policy. Tade does not use Expo's push-notification service in the current app and does not register an Expo push token. Browser or platform providers may still process standard network and device information under their own policies.

5. Restaurant Address, Maps, and Images

The admin website offers Google Places address search. As an operator types, the search text and a temporary session token are sent through Tade's API to Google. When an address is selected or manually saved, Tade asks Google to verify the address and derive the most specific available neighborhood. If address components omit a neighborhood, Tade may temporarily process provider coordinates to request nearby neighborhood or sublocality results. Those coordinates are used only inside that server request, are not returned to the operator browser, and are not stored in the restaurant record. Tade retains the operator-confirmed business address and may retain the place identifier, which Google's Places policies permit to be stored indefinitely; it does not geocode the address to infer a time zone. New restaurant setup and current address or time-zone edits require the operator to explicitly select and confirm a valid IANA time zone. A time zone inferred before this control remains marked legacy_inferred until an operator reviews and confirms it and is not represented as operator-confirmed. This concerns the restaurant's business location, not the operator device's live GPS location.

Google handles its Maps and Places processing under the Google Privacy Policy. The applicable Google Maps end-user terms are linked from the Restaurant Operator Terms of Service.

The admin website can upload restaurant, gallery, menu, popular-dish, and promotion images. Tade validates supported image types and size boundaries in memory, creates a resized WebP service copy, and stores the generated service file. The current manager app does not offer camera or photo upload. Do not upload images unless the restaurant has permission to publish and process them.

6. SMS, Email, and Guest Communications

When a restaurant uses transactional messaging, Tade acts on the restaurant's instructions and also performs provider, security, opt-out, and compliance controls.

Current staff-assisted SMS workflows require the guest to personally read and check the complete electronic disclosure on the operator's screen. The ledger records the grant as written electronic consent with Twilio opt-in type WEB_FORM, together with the disclosure version, masked number, staff actor or account identifier, source, and time. Restaurant staff must not check the box for the guest or substitute an oral answer for the guest's action. When the guest cannot personally complete the current checkbox, staff must leave SMS off and use a non-SMS service method. More detail is in the Restaurant Operator Terms of Service and Guest Privacy Notice.

7. Why Tade Uses Operator Information

Tade does not use operator or guest information for third-party advertising, does not run behavioral advertising or cross-site tracking SDKs in the current Operator Services, and does not sell personal information or share it for cross-context behavioral advertising.

8. Service Providers and Disclosures

The table below describes the current production Operator Services. The separate non-production test environment uses Google Cloud Run and Cloud SQL with Vercel staging websites, may be powered down when not in use, and is reserved for authorized testing with synthetic information; operators must not enter real account, restaurant, staff, or guest information there.

Tade uses technical and organizational measures designed to provide a comparable level of protection, together with available provider configurations, while service providers perform the functions described above. Tade selects, configures, and oversees those providers for the Service. Each provider's handling is subject to any applicable agreement, product terms, privacy commitments, and law; information processed abroad may remain subject to lawful access under local law.

We may also disclose information to professional advisers, courts, regulators, law enforcement, or other parties where law requires or it is reasonably necessary to protect the Service, guests, operators, rights, or safety. Information may be reviewed or transferred during a financing, reorganization, sale, or similar business transaction subject to confidentiality and continued protection.

9. International Processing

Tade is based in Canada, but Google, Apple, Twilio, Resend, Google Workspace, Google Cloud, Vercel, Expo/EAS, and managed infrastructure may process information outside Canada, including in the United States. The tade.ca and thetade.com domains do not determine storage residency. Information processed elsewhere may be subject to local law and lawful access by courts, law enforcement, or authorities in that country.

10. Retention, Reset, and Account Deletion

11. Security

Tade uses safeguards designed for the sensitivity of the information, including encrypted transport, Google/Apple token validation, provider-specific nonce/state protections, secure device storage for persistent app sessions, fresh authentication for destructive web actions, access controls, image validation and isolation, encrypted pending email payloads, provider webhook validation, request limits, and privacy-restricted structured logs. No system is completely secure. Restaurants must also control staff and device access, protect provider accounts and sessions, and promptly report suspected incidents.

If Tade becomes aware of a suspected privacy or security incident, it will take reasonable steps to contain and assess it, preserve the incident record required by applicable law, and coordinate with affected restaurants and service providers. Tade will notify affected individuals and applicable privacy regulators when and in the manner required by law; not every security event legally requires individual notification. A restaurant remains responsible for incident duties arising from its own staff, devices, systems, or independent handling and must give Tade the information reasonably needed for a coordinated response.

12. Operator and Staff Rights

Depending on applicable law, an operator or staff user may request access to personal information, information about its use and disclosure, correction, withdrawal of consent, objection or restriction, portability where applicable, deletion, or review of compliance. Business records and guest data may be subject to the restaurant's authority, legal duties, and retention needs, so not every requested deletion can remove every record immediately.

Send a request to admin@thetade.com. The Privacy Officer may verify identity and business authority, identify the relevant restaurant or provider, investigate the concern, correct or explain the handling at issue, and provide a written response or available escalation route.

To make an access or correction request under British Columbia's Personal Information Protection Act (BC PIPA) for information under Tade's control, send a written request with enough detail for Tade to identify you and the information or correction sought. When BC PIPA applies, Tade will respond within 30 days unless the statutory period is lawfully suspended; an access-request period may also be extended as BC PIPA permits. If Tade extends an access-request period, it will state the reason, expected response date, and available complaint rights. If Tade refuses access to all or part of requested information, it will give the reasons and BC PIPA provision relied on, contact information for a person who can answer questions, and notice of the right to seek review by the Office of the Information and Privacy Commissioner for British Columbia within 30 days. Where BC PIPA permits an access fee, Tade will provide a written estimate before charging it; no access fee will be charged for employee personal information.

If Tade accepts a BC PIPA correction request, it will correct the information as soon as reasonably possible and send the corrected information to each organization to which Tade disclosed it during the previous year. If Tade does not make the correction, it will annotate the information under its control with the correction that was requested but not made, as BC PIPA requires. For other requests, Tade will respond within the period required by applicable law and explain any permitted refusal. You may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, the Office of the Information and Privacy Commissioner for British Columbia at oipc.bc.ca, or the regulator in your jurisdiction.

When Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies, make the access or correction request in writing. Tade will assist a person who says they need help preparing it and will respond with due diligence, no later than 30 days after receipt. If Tade uses a permitted extension, it will send notice by the original deadline stating the new deadline, the reason, and the right to complain to the Privacy Commissioner of Canada. A refusal will be provided in writing with the reasons and available recourse. Before charging any permitted response cost, Tade will disclose the approximate cost and confirm that the request is not withdrawn. Information that is the subject of the request will be retained as long as necessary for the individual to exhaust available PIPEDA recourse.

California residents

If the California Consumer Privacy Act applies, California residents may have rights to know, access, delete, and correct personal information, to opt out of sale or sharing, to limit certain uses of sensitive personal information, and not to receive discriminatory treatment for exercising a right. Tade does not sell personal information or share it for cross-context behavioral advertising. Use the contact above to submit a request.

13. Children

Operator accounts and the manager app are intended for adults authorized by a restaurant business, not children. Do not permit a child to create or operate an account. Guest information involving a child should be entered only by an authorized adult and limited to what is reasonably necessary for the visit.

14. Changes and Contact

We may update this Notice when products, providers, or law changes. We will revise the effective date above. Material changes will be announced through the affected account or app before or when they take effect and, where we have a suitable contact address and law requires, by email or another direct channel. For privacy questions, requests, or complaints, contact:

Tade — Privacy Officer
Email: admin@thetade.com
Location: Vancouver, British Columbia, Canada