Skip to content
Trust & security

Your guests' data, handled like it matters.

Restaurant brands give us their guest relationships. We take that seriously. This page is the straight answer to "what exactly do you do with our data, and how do I know?" in plain English, without vendor jargon.

For the legal version, read the Privacy Policy →

Recognized frameworks

The compliance posture, up front.

No fabricated badges. Each tile is either a verifiable inheritance from our infra partners or a self-posture claim we can defend under review.

SOC 2 Type 2

Inherited via Supabase + Vercel, our managed Postgres and application hosting. Their audits cover the infra your data lives on.

UAE PDPL aligned

Built for the UAE Personal Data Protection Law, merchants are data controllers, we're the processor. DPA signed on request.

PCI DSS (by design)

We never handle card data. All payments flow through your POS (Foodics, Square) which are PCI DSS Level 1 certified.

GDPR-ready

Data export, right-to-delete, and Data Processing Agreement available for merchants with EU-resident guests.

Our commitments

Five things we don't compromise on.

01 · Ownership

Your data is yours. Always.

Merchant and guest data belongs to you, not us. You can export your data in standard formats at any time, including within 30 days of cancellation. We do not hold your data hostage.

02 · Revenue model

We never sell, share, or resell.

Habitu has one revenue stream: the subscription you pay. We do not monetize your guest data in any other way. No advertising networks, no third-party data brokers, no cross-merchant sharing.

03 · Encryption

Encrypted end to end.

All traffic between your browser, your guests' app, and our infrastructure is protected with TLS 1.3. Data at rest is encrypted with AES-256 via our managed Postgres host. POS credentials are encrypted separately and never stored in plaintext.

04 · Tenant isolation

Tenant isolation by default.

Every merchant's data lives behind Row Level Security policies on Postgres. One merchant can never query or see another merchant's guests. Access is enforced at the database layer, not just the application layer.

05 · Right to delete

Right to delete, no questions.

If you cancel, we delete your data within 90 days unless law requires otherwise. Guests can request deletion through you at any time. We help you action the request on your dashboard.

How we operate

Concrete practices.

The technical specifics under the commitments above. What we actually do, where we run, and what we never touch.

Transport security
TLS 1.3 enforced at every edge. HSTS preload. No mixed content.
Encryption at rest
AES-256 via managed Postgres. Automatic daily backups retained for 30 days.
Access controls
Role-based access in the dashboard. Internal staff access is logged and scoped to support issues.
POS credentials
Foodics and Square tokens are encrypted at rest. Rotated on merchant request. Never sent to a browser.
Authentication
Managed auth provider with password hashing via bcrypt. Optional SSO and MFA on the roadmap.
No tracking pixels
The marketing site uses no third-party advertising or tracking cookies. Consumer apps ship no SDK we haven't vetted.
Who we run on

The pipes your data flows through.

We don't pretend to have built every layer ourselves. We picked the strongest infra so the audit your buyer asks about already exists.

Supabase

Managed Postgres, authentication, realtime subscriptions.

SOC 2 Type 2, HIPAA-eligible infrastructure.

Vercel

Application hosting, edge network, DDoS protection.

SOC 2 Type 2, ISO 27001, PCI DSS Level 1.

Foodics / Square

POS integrations. Merchant initiates, scoped read-only tokens.

Both are PCI DSS certified; we never handle card data.

What's not yet shipped

On the security roadmap.

We don't claim what we haven't shipped. These are the things we're explicitly working toward, with rough timing.

  • 01SOC 2 Type 1 assessment, targeting late 2026 as customer volume justifies the audit.
  • 02SAML SSO + mandatory MFA for enterprise-tier accounts.
  • 03Region pinning so UAE merchants can keep guest data in-region on request.
  • 04Public status page with real-time uptime history.
FAQ

Questions buyers ask before signing.

Need a DPA, NDA, or call?

Email hello@habitu.io with what you need. We'll route to the founding team and reply within one business day. We can also walk procurement through our security posture on a call under NDA.