Sharaly Logo

Privacy Policy

Sharaly Restaurant Management Platform & Staff Mobile Application

Effective & Last Updated: September 4, 2026URL: https://app.sharaly.com/privacy_policy
Zero Tracking

No third-party trackers, no advertising brokers, and no cross-app profiling.

Operational Only

Data is limited strictly to staff authentication and live kitchen order notifications.

Account Deletion

Full compliance with Apple 5.1.1(v). Instant staff deactivation and erasure upon request.

1

Overview & Scope

Sharaly (“Sharaly,” “we,” “us,” or “our”) provides an enterprise multi-tenant Software-as-a-Service (SaaS) platform for restaurant management, point of sale (POS), kitchen display operations, and customer dining.

This Privacy Policy explains how Sharaly collects, uses, protects, and discloses personal information through:

  • The Sharaly Staff Mobile Application for iOS and Android, utilized by restaurant employees, kitchen staff, waiters, cashiers, and branch supervisors.
  • The Sharaly Web Management Platform available at https://app.sharaly.com and associated restaurant storefront domains.

By downloading, accessing, or using the Sharaly Staff App or Web Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, please refrain from using our software.

2

Apple App Store Review Guidelines & Zero Tracking

Compliance with Apple App Store Review Guideline 5.1.1

The Sharaly Staff application is an internal enterprise operational tool provided specifically for authorized restaurant staff. It complies fully with Apple's data collection, privacy manifest, and account management requirements.

Zero Cross-App or Cross-Site Tracking

Under Apple's App Tracking Transparency (ATT) definitions, Sharaly does NOT track you. Specifically:

  • We do not link user data or device identifiers from our application with third-party data for targeted advertising purposes.
  • We do not share your personal data, email, or device identifiers with data brokers or advertising networks.
  • We do not include any third-party tracking or behavioral advertising SDKs (such as Facebook Pixel, Google AdMob, or AppsFlyer) within our mobile app.

Apple Privacy Manifest (PrivacyInfo.xcprivacy)

In compliance with Apple iOS SDK privacy manifest mandates:

  • NSPrivacyTracking is set to false.
  • NSPrivacyTrackingDomains contains an empty array.
  • API category usages (such as NSPrivacyAccessedAPICategoryUserDefaults) are strictly restricted to required operational reasons: storing user authentication sessions, selected restaurant branch IDs, and local interface preferences.
3

Information We Collect

We collect only the minimum information necessary to provide reliable restaurant ordering and staff workflow management:

Staff Account Credentials

Name, work email address, encrypted authentication password, assigned restaurant branch, and assigned staff role (Waiter, Kitchen, Cashier, or Admin). Provided when your restaurant creates your staff profile.

Device & Push Identifiers

OneSignal Player ID / Apple Push Notification service (APNs) device token, device model, operating system version, and application build number. Used solely for routing immediate order alerts to your device.

Operational Logs & Activities

Order status updates initiated by staff (e.g., accepting orders, marking food as preparing or ready), table assignments, and login timestamps to facilitate restaurant shift coordination.

Local Device Preferences

Secure authentication token stored locally in device Keychain / secure storage, audio notification preferences (e.g., sound alerts on incoming kitchen tickets), and selected branch ID.

What Sharaly Does NOT Collect in the Staff App:

We do not collect end-customer credit card numbers or banking credentials in the staff app, sensitive biometric data, health information, or background GPS location tracking.

4

How We Use Your Information

We process collected information exclusively for legitimate business purposes:

  • Authentication & Multi-Tenant Authorization: Verifying staff identity, ensuring staff can only access the branch and restaurant data authorized by their employer.
  • Real-Time Order Notifications: Sending critical operational alerts (e.g., new order arrived, kitchen order ready for pickup, table call button pressed).
  • Service Improvement & Bug Diagnosing: Investigating crashes, diagnosing communication errors with WebSocket services, and optimizing kitchen dispatch speed.
  • Security & Fraud Prevention: Preventing unauthorized access, protecting tenant isolation, and recording audit logs for inventory and cash drawer security.
5

Push Notifications & Device Permissions

To fulfill its primary role as a real-time kitchen and waitstaff tool, the Sharaly Staff App requests the following system permission:

Push Notifications (Apple APNs & OneSignal)

Required to alert kitchen staff of new tickets and waitstaff when orders are marked “Ready for Pickup.” We never send marketing or promotional notifications through the staff app. You can disable notifications at any time in iOS Settings > Sharaly Staff > Notifications.

* Note: The app does not request access to contacts, microphone, camera, photo library, or continuous background GPS location.

6

Data Sharing & Third-Party Service Providers

We do not sell, rent, or trade your personal data. We share technical information solely with vetted infrastructure sub-processors necessary to run the service:

ProviderPurposeData SharedPrivacy Safeguard
Apple Inc. (APNs)Delivering iOS push alertsAnonymized device tokenEncrypted by Apple APNs
OneSignalPush dispatch infrastructureDevice push token, App IDData Processing Addendum (DPA)
Cloud Infrastructure (VPS / AWS)Secure hosting & databaseEncrypted database recordsSOC 2 / ISO 27001 certified data center

We may also disclose information if required by valid legal process (such as a subpoena, court order, or regulatory mandate), or to protect the vital security of our users and services.

7

Data Storage, Security & Multi-Tenancy

Sharaly implements rigorous administrative, organizational, and technical safeguards:

End-to-End EncryptionAll data in transit is encrypted using TLS 1.3 / HTTPS. Sensitive credentials are hashed with Argon2 / bcrypt.
Multi-Tenant IsolationTenant scoping ensures each restaurant's data, staff credentials, and orders are isolated and impenetrable to other tenants.
8

Account Deletion & Data Retention (Apple Guideline 5.1.1(v))

In compliance with Apple App Store Review Guideline 5.1.1(v) and global privacy standards, we provide straightforward mechanisms to request and execute account deletion:

How to Delete or Deactivate a Staff Account

  1. Via Restaurant Administrator (Instant): Because staff accounts are managed under an enterprise organization, your restaurant owner or manager can immediately deactivate or delete your account directly inside the Sharaly Management Dashboard under Settings > Staff Members > Delete.
  2. Direct Deletion Request: If you are unable to contact your restaurant administrator, you may submit a direct account deletion request by emailing [email protected] with the subject line “Staff Account Deletion Request” and your registered work email.

Retention Period: Upon confirmation of deletion, authentication tokens, push tokens, and staff personal profiles are permanently purged or anonymized within 30 calendar days. Financial sales records (such as completed register audits) are preserved only as strictly required by tax and accounting legislation.

9

Your Privacy Rights (GDPR, CCPA & Global Laws)

Depending on your jurisdiction, you possess specific rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete information.
  • Right to Erasure (“Right to be Forgotten”): Request permanent deletion of your profile.
  • Right to Data Portability: Obtain your data in a structured, machine-readable format.
  • Right to Restrict Processing: Request suspension of certain processing activities.

To exercise any of these rights, contact our privacy team at [email protected].

10

Children's Privacy

The Sharaly Platform and Sharaly Staff App are exclusively enterprise business software intended for restaurant operational personnel. They are not intended for or directed toward children under 16 years of age. We do not knowingly collect personal information from children.

11

Contact Information & Inquiries

If you have questions, concerns, or requests regarding this Privacy Policy or our security practices, please contact us at:

Sharaly Technology & Privacy Team

Email: [email protected]

Web Platform: https://app.sharaly.com

Official Domain: https://sharaly.com