Privacy

What we hold, and why.

This is the whole of it, in plain words: what Syphor is given, why, who else ever sees it, how long it is kept, and how to have it removed. It covers this website and the Syphor product both.

Who this is

The companySyphor Inc, Toronto, Ontario, Canada. We are the people who hold the data described below.
Writing to us545 King Street West, Toronto, Ontario M5V 1M1, Canada. Visit by appointment. That is the address for a privacy request as well as for anything else.
Reaching a personprivacy@syphor.com1 888 593 3881 A person reads it and answers inside one working day.
When this was last changed12 September 2026. If we change it we date it again, and anything that materially affects a customer is emailed rather than quietly edited.

What this website collects

If you fill in a formYour name, your company, your telephone number, your email address, how many restaurants you run, which point of sale you use, and anything you type in a message box. Nothing else, except which page you were on when you filled it in, The only compulsory fields are your name, a way to reply to you, and — on the contact form, where there is nothing else to go on — a line saying what it is about.
WhyTo answer you, and to talk to you about Syphor. That is the only reason.
Where it goesInto our customer record system. It is not added to a mailing list, it does not start a sequence of emails, and it is not sold or shared for anybody else’s marketing. The one exception is booking a demo: that page is run by a scheduling service, and the name and email you type there go to them as well, so they can hold the slot and send the invitation.
Cookies and trackersThis website sets no cookies and carries no tracker, no advertising pixel and no session recorder. There is nothing to consent to, which is why you were not asked. The one page that is not ours is Book a demo, which is run by a scheduling service and sets its own.
Signing in is differentThe Syphor product itself sets one cookie when you sign in, to keep you signed in. It is not a tracker, it carries no advertising, and it ends when you close the browser. Nothing else is set.
What the web host recordsThe company that serves this site keeps ordinary request logs — the address asked for, the time, and the internet address it was asked from. That is standard for any website and we do not read them for anything but faults.
The typefaceThe fonts are fetched from a typeface service, so that service sees the internet address of the machine that loaded the page. Nothing else about you goes with it.

What Syphor is given about your restaurant

How it arrivesTwo ways, depending on where your point of sale runs. If it runs in your restaurant, it sends us read-only extracts on a schedule. If it runs in your supplier’s cloud, we read their interface with your authorisation, which you can withdraw. Either way nothing is installed in your restaurant, nothing of ours opens a connection into your own system, and nothing is ever written back. See Security, which says the same.
Your trading numbersChecks, items, revenue centers, dayparts, voids and discounts, kitchen ticket times, and supplier invoices you send us.
Your other connected systemsWhere you connect them, and only where you do: your accounting ledger (QuickBooks Online, Xero, Sage Intacct), your inventory and invoice system (MarginEdge, MarketMan, Restaurant365, Crunchtime), your scheduling and payroll (7shifts, Deputy, Toast Payroll, QuickBooks Time), your delivery apps (DoorDash, Uber Eats, Grubhub, ChowNow) and, for a hotel, the property system (Oracle OPERA, Mews, Cloudbeds, Stayntouch, Agilysys). Each one is read with your authorisation, read-only, and you can withdraw it. None of them is required to use Syphor and nothing is written back to any of them.
Your reservationsCovers, the time, and the size of the party. That is all. A reservation book is read for the count, never for the guest — no guest name, email or telephone number comes to us from OpenTable, Resy, SevenRooms or Tock, and there is nowhere in Syphor to put one.
Your staff, by nameWe hold named employees — employee number, first and last name, job, hours, and their pay rate, overtime, declared tips and credit card tips. This comes across in the timecard file. We say it plainly because it is the part a privacy notice usually hides.
What we are NOT given about staffNo social security or insurance number, no home address, no personal telephone number, no personal email, no date of birth. The export takes employee number, name, active flag, hire date and end date. Nothing else is available to it.
Your guestsWhere your point of sale records a guest name against a check, that name comes with it. No guest email, telephone number, address or card detail exists anywhere in Syphor, because no column for one exists.
Manager notesLogbook entries are stored as typed, with the name of whoever wrote them, and they are read into the morning brief. If a manager writes a name in a note, that name is in Syphor.
Card numbersNone. Syphor holds no card number, expiry, security code or payment token, anywhere, in any table. Trial and subscription cards are held by our payment processor and never reach us.
Who owns itYou do. It is your data and we hold it to do a job for you.
The one other useOnce your figures are stripped of anything identifying, we keep them in aggregate and may use them for benchmarking — the comparisons that tell an operator how their food cost sits against similar restaurants. Two hard rules go with it: no employee-level record is ever included, so labor as a percentage yes and never a person, and a benchmark is only ever built from five restaurants or more, so no figure can be traced back to one operator.

Who else ever sees it

The model that writes your answersThe answer engine. To answer a question we send the question, the map of your tables, and up to 200 rows of the result. To read an invoice we send the image. To write your morning brief we send the day’s figures and your logbook notes, with the author’s name.
A research serviceCompetitive research. Receives your restaurant’s name and address and your competitors’ names. It is never sent your sales, your checks, your labor, your staff or your guests.
An events serviceLocal events. Receives a latitude, a longitude, a radius and a date range. Nothing identifies you.
A weather serviceCoordinates and dates. No account, no name, no address.
A mapping serviceTurns your street address into coordinates. Receives your address.
Email and text deliveryDeliver the emails and text messages you asked for. They receive the recipient and the message, which contains your figures.
Our customer record systemHolds what a website form collected. No restaurant data ever goes into it.
A scheduling serviceRuns the Book a demo page. Receives the name and email you type to hold a slot, and anything you answer on that page. It is the only page on this website that is not ours, and it sets its own cookies when you use it.
A payment processorTakes the card. We see the last four digits and nothing more.
And nobody elseWe do not sell your data. Not to advertisers, not to data brokers, not to anyone. It is never shared for someone else’s marketing. If a court or a law compelled us to hand something over we would tell you, unless telling you were itself unlawful.
TrainingThat provider’s published terms for the interface we use say data sent through it is not used to train their models. We rely on that published term; we have not separately bought a zero-retention agreement, and we would rather say so than imply otherwise.
Which companies these areAsk us and we will tell you. They are not printed here because the list can change, and a page naming a company we have stopped using is worse than no page. Ask at any time and you get the list as it stands that day.

Where it is, and how long we keep it

Where it is heldOn hardware we run, in a hosting center in North America. It is not on a shared platform belonging to anybody else.
And the services aboveThose sit in the United States and Europe, so some of your data is processed outside Canada.
How longWhile your account is open, we keep it, and nothing expires on a timer — your history is the whole point. What happens when you leave is the next row but one.
Having it removedWrite to privacy@syphor.com and ask. A person removes it, and we do that inside 30 days. That applies while you are a customer and after you leave.
When you cancelYour data — sales, invoices, logbook, timecards and the raw files your point of sale sent us — stays available for you to export for 30 days. After that all of it is deleted. The de-identified aggregate described above is what remains, and it holds no employee record and no restaurant that can be picked out.
System logsThe logs that record activity hold questions asked and figures returned. They are kept 14 to 21 days and then overwritten.
Raw point-of-sale filesThe files your point of sale sends us are archived on our server while your account is open. They are not a separate case: they go with everything else, 30 days after you cancel, and sooner if you ask.

What you can ask for

To see itAsk and we will tell you what we hold about you and give you a copy.
To correct itIf something is wrong, tell us and we fix it.
To have it removedAs above — ask, and a person does it inside 30 days.
To take it with youAsk and we will export your data in a readable file.
To complainTell us first — privacy@syphor.com. If we do not put it right you can complain to the Office of the Privacy Commissioner of Canada. If you are in the United States you may also have rights under your own state’s law, including California’s; the same address reaches us.
If you are a member of staffYour employer decides what their point of sale sends us. Ask them first — but write to us at the address above and we will help, and we will tell your employer we heard from you.

Two last things

If there is a breachIf your data is exposed we tell you inside 72 hours of knowing about it, what was involved, and what we did. Not a week later and not in a footnote.
ChildrenSyphor is a tool for businesses. It is not for anyone under 16 and we do not knowingly collect anything about a child.
SecurityHow the data is protected is a separate page, written the same way: what protects your numbers.
Two things to be straight about

This is an honest account, written from the code rather than from a template, and it is the account we stand behind. It is not an attorney’s document and does not pretend to be one. If your legal team wants their own version, ask and we will work through it with them.

If any of it changes, the date at the top changes with it, and anything that materially affects a customer is emailed rather than quietly edited.

Questions about any of it — 1 888 593 3881.