Privacy Policy
Last revised: September 1, 2026
Cornshake is a product of Rolopad Inc. We build and run websites, ordering, loyalty, reviews, and marketing for independent restaurants and cafés.
That means we hold two very different kinds of information: information about the restaurants who pay us, and information about their customers. The second kind is not ours. It belongs to the restaurant. We hold it so we can do the work they hired us for, and for no other reason.
This policy explains what we collect, how we use it, and what we don't do with it.
1. The Information We Collect, and How We Use It
Everything in Cornshake falls into one of three buckets.
1.1 Account Information
Who's who. The restaurant owners and staff who use Cornshake.
At minimum: name, email address, phone number, business name, and a password. We store a hashed version of the password, not the password itself.
Optionally: business address, role, time zone, and a profile photo.
For billing: billing address and payment details. Card numbers are handled by Stripe and never stored by us. Depending on your setup, a tax ID and bank account details needed to route payouts.
1.2 How We Use Account Information
Only to run Cornshake and talk to you:
- Log you in and keep your account secure
- Show who did what inside the app
- Send you emails and texts: digests, notifications, support replies
- Bill you and process payments
- Identify you when you contact support
- Convert timestamps to your time zone
That's it.
1.3 Usage Data
Automatically collected log information, limited to:
- Login records: who logged in, when, from what browser and IP address
- In-app activity: what requests were made to our servers, when, and how long they took
- Basic web logs for visitors to cornshake.com: IP address, browser, pages requested
We infer general location from IP address. We do not collect precise device location.
1.4 How We Use Usage Data
Support, troubleshooting, debugging, and performance work. When someone reports a problem it helps not to have to ask which browser they were on.
We use analytics on cornshake.com to understand how the marketing site is used. We do not use advertising cookies and do not respond to Do Not Track signals, as there is no accepted standard for them.
1.5 Restaurant Data
This is the reason anyone uses Cornshake. It covers everything a restaurant sets up, uploads, or accumulates through us, and everything about their customers that flows through us:
- Menus, photos, site content, and business information
- Orders: items, totals, times, delivery addresses, allergy notes, delivery instructions
- Customer names, phone numbers, and email addresses
- Loyalty enrollments, visit history, and redemptions
- Form submissions: reservations, catering, events, jobs, contact
- Reviews and the replies we draft
- SMS and email opt-in records and consent status
- Campaign history: who was sent what, and what came back
- Data from connected third-party accounts (see Section 2)
1.6 How We Use Restaurant Data
We don't. It's the restaurant's business, not ours.
What we do technically do with it is what you'd expect: store it and make it available to the people who should have it.
- Show it to the restaurant in their dashboard and digest
- Fulfill orders, run loyalty, respond to forms
- Send messages the restaurant has authorized to customers who opted in
- Share it with the couriers, processors, and platforms needed to complete a transaction
- Produce reporting and recommendations for that restaurant
We do not use it for our own marketing. We do not sell it. We do not use one restaurant's data to serve another restaurant. We do not use it to train AI models that serve anyone else.
If you are a diner. The restaurant decides what is collected about you and how long it's kept. Their privacy policy governs, and it's on their website. Send requests to them. If you send one to us, we'll pass it along.
Retention. Restaurant data is kept until deleted, or until the account closes. Data from a connected third-party account is kept until that account is disconnected. When a restaurant leaves, we return their data on request and then delete it, as described in our Terms of Service.
2. Connected Accounts
When a restaurant connects a third-party account, we access it only to do the work they asked for. They can disconnect at any time from Settings → Integrations, or revoke our access directly with the platform.
Google Business Profile
We access the Google Business Profile APIs on the restaurant's behalf. That includes:
- Business listing information (name, address, hours, attributes, categories, and photos)
- Reviews and replies
- The account and location identifiers that tell us which listing is which
- The email address of the connecting Google account, for display in the dashboard
We use it to show reviews in the dashboard, draft reply suggestions for the owner to approve, and sync listing changes back to Google. We do not sell it, share it for advertising, or use it to train AI models that serve other customers.
Limited Use disclosure. Cornshake's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access. Disconnect from Settings → Integrations in the Cornshake dashboard, or revoke Cornshake's access from your Google Account permissions page.
Retention. Cached Google Business Profile content, such as reviews and listing data, is stored for no more than 30 calendar days and refreshed on demand. Connection settings are kept while the account is active and connected. On disconnection, OAuth refresh tokens are deleted immediately and cached content is deleted within 30 days of disconnection or account deletion, whichever comes first. Email team@cornshake.com to request earlier deletion.
Facebook and Instagram
We store the Page name, Page ID, Instagram username, and the access tokens needed to publish on the restaurant's behalf. We use them only to post content the restaurant authorized. On disconnection, we delete the tokens.
Square and Clover
We access transaction data, catalog data, and, where the restaurant uses the platform's loyalty program, loyalty member records. That can include customer names, phone numbers, emails, and visit history. This is restaurant data under Section 1.5 and is treated accordingly.
Stripe
We access transaction and payout data needed to process orders and reconcile payments. We never receive or store full card numbers.
Delivery providers
Where a restaurant uses delivery, we pass the courier what's needed to complete it: customer name, address, phone number, and delivery instructions.
3. Things We Don't Do
We charge money for a product. The product is the product. You are not.
- We don't sell your data.
- We don't rent or give your email or phone number to anyone for marketing.
- We don't use your data to serve ads, and we don't run ads.
- We don't use one restaurant's data to benefit another.
- We don't train AI models on your data for anyone else's benefit.
4. Sharing With Service Providers
A few companies handle parts of the data as a matter of running the service:
- Hosting and infrastructure
- Payment processing
- SMS and email delivery
- Error monitoring and analytics
- Delivery couriers, where delivery is in use
They are contractually limited to using the data only to provide those services to us, and for nothing else.
5. Disclosure Under Legal Necessity
We share information outside the cases above only when:
- We need to investigate or act on illegal activity, suspected fraud, threats to someone's safety, or violations of our Terms of Service, or the law requires it
- A government entity or legal process compels it, or we believe in good faith it's necessary to protect the rights, property, or safety of Cornshake, our customers, or others
- Cornshake is acquired by or merged with another company. In that case we'll notify you by email and on our website before your information transfers and becomes subject to a different policy.
6. SMS
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All categories described above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
To stop marketing texts from a restaurant using Cornshake, reply STOP to any message.
7. Your Rights
You have the right to be forgotten. A restaurant can delete customer data from their account at any time. We'll delete a restaurant's account on request from an authorized person, as long as it doesn't conflict with someone else's rights or a legal obligation we have.
You have the right to correct your data. Account information is editable in the app. Restaurant data is editable by the restaurant.
You have the right to know what we process about you. Reading this policy is you exercising that right. For specifics, email us.
You have the right to take your data with you. We export a restaurant's customer list, order history, loyalty members, and campaign history in a standard file format, at no charge, on request.
We extend these rights to everyone regardless of where they live. Email team@cornshake.com. We may need to verify who you are first.
We hold transaction records for 7 years for tax and accounting reasons, and may keep information longer where an open dispute or a legal obligation requires it. Otherwise we delete within 90 days of a deletion request.
8. Security
Data is stored on secure servers. Traffic between you and the application is encrypted with TLS. We follow generally accepted industry standards for protecting information in transit and at rest.
You are responsible for keeping your password confidential. If you share it with staff or a contractor, that's at your own risk.
No method of transmission or storage over the internet is completely secure, and we can't guarantee absolute security.
If a breach materially affects you or your customers, we'll notify you as soon as we can and follow up with what we did about it.
9. Children
Cornshake is not directed to children under 13 and we don't knowingly collect their information. If you believe a child has given us information, email team@cornshake.com and we'll delete it.
10. Where Your Data Lives
Our servers are in the United States. Cornshake is intended for use in the United States. Using it means your information is transferred to and stored there.
11. Changes
We may update this policy. If we make significant changes we'll notify you by email or in the product before they take effect.
12. Contact
Questions, concerns, or complaints about this policy, email us and we'll sort it out.
Rolopad Inc. dba Cornshake
team@cornshake.com
https://cornshake.com