This Privacy Policy explains how CostIt LLC (“CostIt,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit costit.food, create or use a CostIt account, receive an invitation to a CostIt organization, communicate with us, or otherwise use the CostIt Service. This Privacy Policy applies to information CostIt processes for its own business purposes and explains how we handle information submitted through the Service.
1. Information We Collect
1.1 Account information. We may collect information such as your name, email address, organization, role, account identifiers, invitations, authentication information, and other information needed to create or administer your account.
1.2 Subscription and transaction information. We may collect information about your subscription plan, billing status, transaction identifiers, and limited billing information received from payment processors. Payment-card information may be collected directly by our payment processor rather than stored by CostIt.
1.3 Customer-submitted operational data. Customers may submit restaurant and hospitality information such as invoices, vendor information, inventory records, recipes, menus, pricing, purchasing data, sales information, schedules, banquet event orders (BEOs), event information, operational documents, notes, and other business records.
1.4 Usage and device information. We may collect IP address, browser or device information, timestamps, feature usage, login and security events, audit information, diagnostics, error information, and performance data.
1.5 Communications. We collect information you provide when you contact us for support, send feedback, communicate with CostIt, or otherwise correspond with us.
1.6 Integrations. When a customer chooses to connect or use a supported third-party integration, we may receive information necessary to provide that integration.
2. How We Use Information
We may use information to create and administer accounts; authenticate users; provide and operate the Service; process subscriptions; host and process Customer Data; provide customer support; communicate account, product, billing, or security information; troubleshoot and improve the Service; monitor performance; protect against fraud, misuse, and security threats; enforce our agreements; and comply with applicable law.
We may also process operational information to provide requested restaurant and hospitality functions, including invoice extraction, inventory workflows, recipe and menu costing, purchasing or price analysis, BEO and event processing, operational reporting, and related features.
3. OCR, Artificial Intelligence, and Automated Processing
Certain CostIt features may use optical character recognition (“OCR”), artificial intelligence, automated matching, formulas, analytics, or other computational methods to extract, classify, calculate, summarize, or analyze information submitted to the Service.
When CostIt uses a technology provider for this processing, we may transmit the information reasonably necessary to provide the requested feature and require the provider to process it for authorized service purposes. CostIt does not use Customer Data to train a general-purpose artificial-intelligence model unless the customer separately provides express consent. Customers and users must review material automated outputs before relying on them for business, financial, staffing, purchasing, pricing, accounting, food-safety, or other consequential decisions.
4. Customer-Controlled Data
CostIt provides software to businesses. A customer organization may submit personal information about its employees, vendors, guests, contacts, or other individuals. In those circumstances, the customer may determine why the information is collected and how it is used, while CostIt processes the information to provide the Service.
If your information was submitted to CostIt by a CostIt customer and you wish to exercise rights concerning that information, you may need to contact the customer organization directly. We may assist customers in responding to valid privacy requests where appropriate.
5. How We Disclose Information
We may disclose information to service providers and subprocessors that help us operate CostIt, such as cloud infrastructure and database providers, authentication providers, payment processors, communications providers, analytics and monitoring providers, security providers, customer-support tools, and OCR or AI technology providers.
We may also disclose information when required by law or valid legal process; when reasonably necessary to protect CostIt, our customers, users, or others; to investigate fraud, abuse, or security incidents; to professional advisers subject to appropriate duties; or in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of our business.
CostIt does not sell personal information for money. If our use of analytics, advertising, or similar technologies is considered a “sale,” “sharing,” or targeted advertising under an applicable privacy law, we will provide any notice and choices required by that law.
6. Payment Processing
CostIt may use a third-party payment processor to process subscription payments. The payment processor may collect payment-card, billing, and transaction information directly under its own privacy and security practices. CostIt may receive information such as transaction status, customer identifiers, subscription status, and limited billing information needed to administer your CostIt subscription.
7. Cookies and Similar Technologies
CostIt may use cookies, local storage, pixels, software development kits, and similar technologies for authentication, security, preferences, analytics, performance, and other Service functions. Where required by law, we will provide choices regarding non-essential cookies or similar technologies.
You may also be able to manage cookies through your browser settings. Disabling certain technologies may affect the operation of the Service.
8. Data Retention
We retain information for as long as reasonably necessary to provide and secure the Service, administer accounts, maintain legitimate business and audit records, comply with legal obligations, resolve disputes, prevent fraud, and enforce our agreements.
Where technically available, Customer Data may remain available to an organization owner for export for up to thirty (30) days after account termination. It may thereafter be deleted or de-identified, subject to backup cycles, security and audit records, legal holds, legal obligations, fraud prevention, dispute preservation, and legitimate recordkeeping. Backup copies may remain until overwritten through ordinary backup cycles. Customers are responsible for exporting records they are required to retain.
9. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, alteration, loss, or disclosure. No online service, transmission method, or storage system can be guaranteed completely secure.
Users are responsible for protecting their credentials and devices and should notify CostIt promptly if they suspect unauthorized access to an account.
10. Your Privacy Rights
Depending on where you live and which laws apply, you may have rights to request confirmation of processing, access to, correction of, deletion of, or a portable copy of certain personal information; to object to or restrict certain processing; or to opt out of certain sales, sharing, targeted advertising, or qualifying profiling.
To submit a privacy request, email support@costit.food with the subject “Privacy Request.” We may verify your identity, authority, account, and jurisdiction before responding. If the relevant information is controlled by a CostIt customer, we may direct the request to that customer or assist the customer with its response.
If we deny a request that is subject to an applicable appeal right, you may appeal by emailing support@costit.food with the subject “Privacy Appeal” within sixty (60) days after the denial. We will respond within the period required by applicable law and, when required, explain how to contact the appropriate regulator or attorney general.
11. Children’s Privacy
CostIt is intended for business and professional use and is not directed to children. We do not knowingly collect personal information directly from children through consumer-directed services. If we learn that personal information was collected in a manner prohibited by applicable law, we will take appropriate steps to address it.
12. International Processing
CostIt and our service providers may process information in the United States and other countries where they operate. When applicable law requires safeguards for international transfers of personal information, we will use appropriate transfer mechanisms.
13. Third-Party Services and Links
CostIt may contain links to or integrations with third-party services. Those third parties control their own privacy practices, and their terms and privacy policies apply to information they collect or process outside CostIt’s control.
14. Changes to This Privacy Policy
We may update this Privacy Policy as CostIt, our technology, our service providers, or applicable legal requirements change. We will post the updated Privacy Policy with a revised “Last updated” date and provide additional notice of material changes where appropriate or required.
15. Contact Us
For privacy questions, requests, or appeals, contact support@costit.food and use the subject line “Privacy Request” or “Privacy Appeal,” as applicable.
For general support, contact support@costit.food.
CostIt LLC
