Restaurant brands give us their guest relationships. We take that seriously. This page is the straight answer to "what exactly do you do with our data, and how do I know?" in plain English, without vendor jargon.
For the legal version, read the Privacy Policy →
No fabricated badges. Each tile is either a verifiable inheritance from our infra partners or a self-posture claim we can defend under review.
Inherited via Supabase + Vercel, our managed Postgres and application hosting. Their audits cover the infra your data lives on.
Built for the UAE Personal Data Protection Law, merchants are data controllers, we're the processor. DPA signed on request.
We never handle card data. All payments flow through your POS (Foodics, Square) which are PCI DSS Level 1 certified.
Data export, right-to-delete, and Data Processing Agreement available for merchants with EU-resident guests.
Merchant and guest data belongs to you, not us. You can export your data in standard formats at any time, including within 30 days of cancellation. We do not hold your data hostage.
Habitu has one revenue stream: the subscription you pay. We do not monetize your guest data in any other way. No advertising networks, no third-party data brokers, no cross-merchant sharing.
All traffic between your browser, your guests' app, and our infrastructure is protected with TLS 1.3. Data at rest is encrypted with AES-256 via our managed Postgres host. POS credentials are encrypted separately and never stored in plaintext.
Every merchant's data lives behind Row Level Security policies on Postgres. One merchant can never query or see another merchant's guests. Access is enforced at the database layer, not just the application layer.
If you cancel, we delete your data within 90 days unless law requires otherwise. Guests can request deletion through you at any time. We help you action the request on your dashboard.
The technical specifics under the commitments above. What we actually do, where we run, and what we never touch.
We don't pretend to have built every layer ourselves. We picked the strongest infra so the audit your buyer asks about already exists.
Managed Postgres, authentication, realtime subscriptions.
SOC 2 Type 2, HIPAA-eligible infrastructure.
Application hosting, edge network, DDoS protection.
SOC 2 Type 2, ISO 27001, PCI DSS Level 1.
POS integrations. Merchant initiates, scoped read-only tokens.
Both are PCI DSS certified; we never handle card data.
We don't claim what we haven't shipped. These are the things we're explicitly working toward, with rough timing.
Email hello@habitu.io with what you need. We'll route to the founding team and reply within one business day. We can also walk procurement through our security posture on a call under NDA.