Overview & Scope
Sharaly (“Sharaly,” “we,” “us,” or “our”) provides an enterprise multi-tenant Software-as-a-Service (SaaS) platform for restaurant management, point of sale (POS), kitchen display operations, and customer dining.
This Privacy Policy explains how Sharaly collects, uses, protects, and discloses personal information through:
- The Sharaly Staff Mobile Application for iOS and Android, utilized by restaurant employees, kitchen staff, waiters, cashiers, and branch supervisors.
- The Sharaly Web Management Platform available at
https://app.sharaly.comand associated restaurant storefront domains.
By downloading, accessing, or using the Sharaly Staff App or Web Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, please refrain from using our software.
Apple App Store Review Guidelines & Zero Tracking
The Sharaly Staff application is an internal enterprise operational tool provided specifically for authorized restaurant staff. It complies fully with Apple's data collection, privacy manifest, and account management requirements.
Zero Cross-App or Cross-Site Tracking
Under Apple's App Tracking Transparency (ATT) definitions, Sharaly does NOT track you. Specifically:
- We do not link user data or device identifiers from our application with third-party data for targeted advertising purposes.
- We do not share your personal data, email, or device identifiers with data brokers or advertising networks.
- We do not include any third-party tracking or behavioral advertising SDKs (such as Facebook Pixel, Google AdMob, or AppsFlyer) within our mobile app.
Apple Privacy Manifest (PrivacyInfo.xcprivacy)
In compliance with Apple iOS SDK privacy manifest mandates:
NSPrivacyTrackingis set tofalse.NSPrivacyTrackingDomainscontains an empty array.- API category usages (such as
NSPrivacyAccessedAPICategoryUserDefaults) are strictly restricted to required operational reasons: storing user authentication sessions, selected restaurant branch IDs, and local interface preferences.
Information We Collect
We collect only the minimum information necessary to provide reliable restaurant ordering and staff workflow management:
Name, work email address, encrypted authentication password, assigned restaurant branch, and assigned staff role (Waiter, Kitchen, Cashier, or Admin). Provided when your restaurant creates your staff profile.
OneSignal Player ID / Apple Push Notification service (APNs) device token, device model, operating system version, and application build number. Used solely for routing immediate order alerts to your device.
Order status updates initiated by staff (e.g., accepting orders, marking food as preparing or ready), table assignments, and login timestamps to facilitate restaurant shift coordination.
Secure authentication token stored locally in device Keychain / secure storage, audio notification preferences (e.g., sound alerts on incoming kitchen tickets), and selected branch ID.
What Sharaly Does NOT Collect in the Staff App:
We do not collect end-customer credit card numbers or banking credentials in the staff app, sensitive biometric data, health information, or background GPS location tracking.
How We Use Your Information
We process collected information exclusively for legitimate business purposes:
- Authentication & Multi-Tenant Authorization: Verifying staff identity, ensuring staff can only access the branch and restaurant data authorized by their employer.
- Real-Time Order Notifications: Sending critical operational alerts (e.g., new order arrived, kitchen order ready for pickup, table call button pressed).
- Service Improvement & Bug Diagnosing: Investigating crashes, diagnosing communication errors with WebSocket services, and optimizing kitchen dispatch speed.
- Security & Fraud Prevention: Preventing unauthorized access, protecting tenant isolation, and recording audit logs for inventory and cash drawer security.
Push Notifications & Device Permissions
To fulfill its primary role as a real-time kitchen and waitstaff tool, the Sharaly Staff App requests the following system permission:
Push Notifications (Apple APNs & OneSignal)
Required to alert kitchen staff of new tickets and waitstaff when orders are marked “Ready for Pickup.” We never send marketing or promotional notifications through the staff app. You can disable notifications at any time in iOS Settings > Sharaly Staff > Notifications.
* Note: The app does not request access to contacts, microphone, camera, photo library, or continuous background GPS location.
Data Sharing & Third-Party Service Providers
We do not sell, rent, or trade your personal data. We share technical information solely with vetted infrastructure sub-processors necessary to run the service:
| Provider | Purpose | Data Shared | Privacy Safeguard |
|---|---|---|---|
| Apple Inc. (APNs) | Delivering iOS push alerts | Anonymized device token | Encrypted by Apple APNs |
| OneSignal | Push dispatch infrastructure | Device push token, App ID | Data Processing Addendum (DPA) |
| Cloud Infrastructure (VPS / AWS) | Secure hosting & database | Encrypted database records | SOC 2 / ISO 27001 certified data center |
We may also disclose information if required by valid legal process (such as a subpoena, court order, or regulatory mandate), or to protect the vital security of our users and services.
Data Storage, Security & Multi-Tenancy
Sharaly implements rigorous administrative, organizational, and technical safeguards:
Account Deletion & Data Retention (Apple Guideline 5.1.1(v))
In compliance with Apple App Store Review Guideline 5.1.1(v) and global privacy standards, we provide straightforward mechanisms to request and execute account deletion:
How to Delete or Deactivate a Staff Account
- Via Restaurant Administrator (Instant): Because staff accounts are managed under an enterprise organization, your restaurant owner or manager can immediately deactivate or delete your account directly inside the Sharaly Management Dashboard under Settings > Staff Members > Delete.
- Direct Deletion Request: If you are unable to contact your restaurant administrator, you may submit a direct account deletion request by emailing [email protected] with the subject line “Staff Account Deletion Request” and your registered work email.
Retention Period: Upon confirmation of deletion, authentication tokens, push tokens, and staff personal profiles are permanently purged or anonymized within 30 calendar days. Financial sales records (such as completed register audits) are preserved only as strictly required by tax and accounting legislation.
Your Privacy Rights (GDPR, CCPA & Global Laws)
Depending on your jurisdiction, you possess specific rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure (“Right to be Forgotten”): Request permanent deletion of your profile.
- Right to Data Portability: Obtain your data in a structured, machine-readable format.
- Right to Restrict Processing: Request suspension of certain processing activities.
To exercise any of these rights, contact our privacy team at [email protected].
Children's Privacy
The Sharaly Platform and Sharaly Staff App are exclusively enterprise business software intended for restaurant operational personnel. They are not intended for or directed toward children under 16 years of age. We do not knowingly collect personal information from children.
Contact Information & Inquiries
If you have questions, concerns, or requests regarding this Privacy Policy or our security practices, please contact us at:
Sharaly Technology & Privacy Team
Email: [email protected]
Web Platform: https://app.sharaly.com
Official Domain: https://sharaly.com
