Your data is yours. This policy explains what we collect, why, and how we keep it safe.
This Privacy Policy explains how Hospitality OS ("the Service"), provided by AIM Group Global ("we", "us", "our"), collects, uses, stores and protects your personal information when you visit our website, register an account, or use the Service. By using the Service you agree to the practices described in this policy.
We collect the following categories of information: (a) Account information — restaurant name, owner name, email, phone, address, city, username and a secured password hash; (b) Business data — menu items, tables, staff records, orders, customers, inventory, payroll and settings that you enter into the Service; (c) Payment information — handled directly by our payment processors (e.g. Stripe); we do not store full card numbers; (d) Usage data — pages visited, device type, browser and basic analytics to improve the Service; (e) Communications — messages you send to our support team.
We use your information to: (a) provide, operate and maintain the Service and your account; (b) send service, billing and account-related emails; (c) send onboarding and product updates that are essential to the Service; (d) improve features, fix bugs and monitor security; (e) respond to your support requests; (f) comply with legal obligations.
Where applicable, we process personal data on the basis of: (a) contract performance — to provide the Service you requested; (b) legitimate interest — to keep the Service secure and improve it; (c) consent — where you have given it, e.g. for marketing; (d) legal obligation. You may withdraw consent at any time without affecting the Service itself.
We do not sell your personal information. We share data only with: (a) service providers who help operate the Service — cloud hosting, email delivery (Brevo), payment processing (Stripe) — each bound by confidentiality and their own privacy policies; (b) authorities, where required by law, court order or to protect our legal rights; (c) a successor in case of merger, acquisition or sale of assets, with notice to you.
Data is stored on secure servers with encryption in transit (HTTPS/TLS) and encryption at rest where supported. Access to your data is restricted to authorised personnel on a need-to-know basis. We apply industry-standard measures including firewalls, access controls and regular monitoring. No method of transmission or storage is 100% secure, but we work hard to protect your data.
We keep your account and business data for as long as your account is active and for a reasonable period after cancellation to allow reactivation or export. When you permanently close your account, we delete or anonymise your personal data within a reasonable timeframe unless we are required to keep it by law (for example, tax records).
Depending on your jurisdiction, you may have the right to: access, correct or update your data; request deletion of your data; export your data in a portable format; restrict or object to processing; and withdraw consent. To exercise any right, email hospitalityos@aimgroupglobal.com and we will respond within 30 days.
The Service uses cookies and browser local storage to: keep you signed in, remember theme and language preferences, and support offline functionality of the POS. You can clear or block these in your browser settings, but some features may stop working.
The Service integrates with third-party providers: Brevo for transactional and marketing email, Stripe for card payments, and cloud infrastructure providers for hosting. Each provider has its own privacy policy and data processing terms. Please review them for details on how they handle data.
The Service is intended for businesses and individuals aged 18 and above. We do not knowingly collect personal information from children under 18. If you believe a child has provided us data, contact us and we will delete it.
Your data may be processed in countries other than your own, including Nepal and the hosting locations used by our providers. Where required, we ensure appropriate safeguards such as standard contractual clauses are in place.
We may update this Privacy Policy from time to time. Material changes will be announced by email or through the Service at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the latest revision.
For any privacy-related questions, complaints or requests, contact us at hospitalityos@aimgroupglobal.com or through our Support page. We will respond within 30 days.