Partner app privacy policy
Last updated: 11 October 2026
This policy covers Upelo Partners (for tablets) and Upelo Light (for phones), the apps restaurant owners and staff use to run their restaurant on Upelo. The orders and customer details shown in these apps belong to the restaurant and are governed by the customer app privacy policy.
Who this policy covers
Upelo Partners and Upelo Light are used by the owners and staff of restaurants that subscribe to the Upelo platform to manage orders, menu availability, receipt printers and outlet settings. Any restaurant can become a Upelo customer, and each restaurant is an independent business. This policy explains what Upelo processes about you when you use the apps as an owner or staff member. It does not cover the restaurant's own customers: the order and customer data you see in the apps is the restaurant's, and is handled under the customer app privacy policy linked above.
How accounts are created
You cannot sign up inside the apps. In most regions Upelo creates the restaurant and its owner account when a restaurant is onboarded. In regions with self-serve sign-up, the owner creates the restaurant themselves on upelo.io by confirming their email address (see the next section). Either way, owners invite staff by email through the Upelo web portal at partners.upelo.io, and the restaurant — your employer or the person who invited you — decides who gets an account and which role it has. If you have a question about why an account was created for you, ask the restaurant first.
Self-serve sign-up
When you claim a page on upelo.io we process the restaurant name and country, your name, email address and phone number (if given), the time you accepted the terms, your IP address and browser, and the tags on the link you arrived from (for example a campaign code). We send a confirmation link to the email address; the page is created only once it is clicked. Some claim links are prepared for a specific restaurant from information published on its existing ordering site or listings — its name, city and published phone number — so the form is filled in for you; that information is used only to set up the page you claim and is deleted if the claim is rejected. Visits to the claim form are measured with PostHog (see the website privacy policy); a rejected claim's personal data is removed after 30 days.
Billing
If your restaurant pays for Upelo online, Stripe collects and stores your card details; Upelo never sees the full card number and keeps only the card brand, the last four digits, your billing status and your invoices. Stripe also processes your name, email address and billing address as a payment processor under its own privacy policy. Order counts and order values are reported to Stripe to work out usage-based charges.
Information we process
To run your account we store your name, email address, role and outlet assignment, and a hashed password — the password itself is never stored. To sign you in and keep the platform secure we process your IP address and standard server logs, and on a new device we send a one-time code to your email address. To deliver new-order alerts we store a device identifier and a push-notification token issued by Firebase Cloud Messaging. We also record the actions you take in the apps, such as order status changes and menu edits, so the restaurant has an accurate history of who did what.
How your information is used
Your information is used solely to provide the service: to sign you in, to show you the orders and settings of the outlets you are assigned to, to send you new-order notifications, to keep an audit history for the restaurant, to keep the platform secure and to respond to support requests. Your name and email address are visible to the restaurant's owner, who manages staff accounts, and your name appears in the restaurant's order and audit history. Upelo does not sell your information and does not use it for advertising.
Device permissions
The apps ask for a permission only when a feature needs it. Camera and photo library access is used only when you add an image to a menu item or promotion. Bluetooth and local-network scanning are used only when you search for receipt printers, and the scan results stay on your device. Notifications are used for new-order alerts. The apps do not track your location and contain no advertising or tracking SDKs.
Who your information is shared with
Upelo relies on a small number of service providers to run the platform: Amazon Web Services (hosting and transactional email), Google Firebase (push notifications), Google Maps (selecting an outlet address), Stripe (subscription billing and restaurant payouts — the apps never store card details) and PostHog (usage measurement on the website's sign-up pages). Each provider receives only what it needs to perform its part of the service. Beyond that, your information is shared only with your restaurant, or where required by law.
How long we keep it
Your account data is kept for as long as your account is active. When your account is deleted, your profile is deactivated immediately and your name and email address are removed within 30 days. When a self-serve restaurant cancels its subscription, its store and data are kept for 30 days so it can be reactivated, then deleted. Server logs are kept only as long as needed for security and troubleshooting. The restaurant's business records — orders, menus and audit history — belong to the restaurant and are retained by it; they are not deleted with a staff account, although your name is no longer attached to them once it has been removed.
Your choices and rights
You can see your name, email address and role in the apps and ask your restaurant's owner to correct them. You can turn off notifications in your device settings, although you will then miss new-order alerts. You can delete your account from within the apps or by following the steps at upelo.io/partners/account-deletion. Depending on where you live you may have further rights, such as access to or portability of your data — email us and we will help.
Security
Data is sent over encrypted connections and stored on secured servers with access limited to what is needed to run the service. Passwords are stored as hashes, and signing in on a new device requires a one-time code sent to your email address. Keep your password confidential and tell the restaurant owner immediately if you think your account has been used by someone else.
Changes to this policy
If this policy changes in a meaningful way, the date on this page will be updated and significant changes will be highlighted in the apps.
Contact
For any question about your data — including requests to access, correct or delete it — email support@upelo.io.