The Short Version
Zairo ingests a restaurant's daily operating reports, reads them with AI, and turns them into briefs, coaching, schedules, and HR records for that restaurant's own team. Everything below is the long form of five plain statements:
- We are a business tool, not a consumer app. Accounts are created for you by the restaurant business you work for, or by us on that business's instruction. There is no public sign-up inside the mobile app, and nothing is sold inside it.
- Your restaurant's data belongs to your restaurant. Zairo holds and processes it on that business's instructions. One operator can never see another operator's stores, staff, or numbers.
- We do not sell personal information, run ads, or track you across apps and websites. There are no advertising SDKs, no analytics trackers, and no third-party cookies anywhere in the product or on this website.
- AI providers process content on our behalf. Report text, uploaded documents, receipt photos, and chat messages are sent to Anthropic and OpenAI to be analyzed or read. They act as our service providers, not as independent users of the data.
- You can delete your account from inside the product — the Privacy button in the operator portal's top navigation bar, on the web and in the iOS app. A business owner can delete their entire operator account and everything under it. Section 11 walks through it step by step.
Who Does What With Your Data
Zairo is sold to a restaurant business — the "operator." The operator decides who gets an account, what stores they see, what employee records exist, and what happens to that data. In data-protection language the operator is the controller and Zairo is the processor (a "service provider"): we handle the information to run the service the operator bought, and we follow the operator's instructions about it.
That distinction matters most for employee data. If you are a general manager, shift manager, or crew member with a Zairo login, the records about you — your schedule, availability, pay rate, time-clock punches, corrective-action documents — exist because your employer put them there. Zairo does not decide what goes in your employee file.
If you are an employee and want to see, correct, or remove something about you, start with your employer — your manager, general manager, or HR contact. They can change it directly in Zairo. If they need help doing so, or if you cannot get a response, email us at zairoaiops@gmail.com and we will route the request to the right administrator at your company.
Zairo acts as the controller for a narrow slice: the account we hold for the operator itself, our billing records, our security and audit logs, and the emails you send us directly.
What We Collect
Account and contact information
- Name, work email address, work phone number
- Role (owner, area director, area leader, general manager, manager, employee) and which stores you are assigned to
- Your portal PIN or password. Every credential set or reset today is stored as a salted one-way hash, never in readable form. Accounts created before we moved to that scheme are being migrated onto it, and any reset moves an account over immediately. We never display a credential back to you, and we will never ask you for one.
- Security-question answers, stored only as one-way hashes
- Language preference and alert preferences (which SMS or push categories you want)
Employee and workforce records
- Position, sub-position, trained stations, pay rate, maximum weekly hours
- A yes/no minor flag used to enforce hour and shift rules for workers under 18. Zairo does not store dates of birth or Social Security numbers.
- Availability windows, time-off requests, published and draft schedules, shift swaps
- Time-clock punches and the timesheets built from them
- An optional employee photo, if your employer uploads one
HR records
- Performance and corrective-action documents, including the situation described, the manager's write-up, and signatures captured on-screen or photographed from a signed paper original
- Photographed paper documents kept as evidence of the original signed record
- HR chat conversations with the AI assistant, and any files attached to them
Store operating data
- Daily sales, transaction counts, average ticket, sales versus forecast and versus prior periods
- Speed-of-service percentages and drive-thru times, labor percentage and labor hours, food cost, waste, upsell rate, day-part breakdowns
- Profit-and-loss records, invoices and their line items, vendor names, and cost-of-goods data
- Rolling store history used to compute baselines, records, recurring issues, and wins
Content you upload or capture
- Daily report files (XLS, PDF, CSV) and payroll or sales exports you upload
- Photos of invoices, receipts, and paper documents taken with your device camera or picked from your photo library
- Documents you attach to an HR chat
Technical and security information
- The IP address a session is created from, and session records with their expiry
- An audit log of security-relevant actions — sign-ins, PIN changes, employee edits, schedule publishes, deletions — recorded with who did it, when, and from what IP
- On mobile, a push notification device token, if you allow notifications
Where the Information Comes From
- Directly from you — what you type into the portal or the app, and what you upload or photograph.
- From your employer or account administrator — the account they create for you and the employee record they maintain.
- From a reporting mailbox you configure. If your operator sets up email ingestion, Zairo connects to that mailbox over IMAP and reads the daily report emails and their attachments. It filters to the report subjects defined in the operator profile and marks what it processes as read. That mailbox is chosen and controlled by the operator.
- From Square, if you connect it. With the operator's authorization, Zairo calls Square's Payments, Locations, and Team APIs to pull daily sales totals and, optionally, the team roster.
- From public context sources. To explain why a day went the way it did, Zairo looks up local weather and public local events (for example, a stadium schedule near a store). These lookups send a store's location — never a person's. For events, that means the store's city and state, plus the store's street address sent once to a geocoding lookup that converts it into map coordinates; those coordinates are then reused to search for events within a radius of the store. For weather, it means the store's city and state, and the two backup weather sources are wired to a single fixed Kansas City coordinate rather than the store's own. No name, email address, phone number, employee record, or sales figure is ever sent to any of them, and what comes back is public information about a place, not about a person. The specific services, and exactly what each one receives, are listed in Section 7.
How We Use It
- To produce the product you bought — extract metrics from reports, analyze them, and write role-specific daily briefs, coaching, and forecasts.
- To deliver those results by email, SMS, Telegram, push notification, and the web portal.
- To run scheduling — build schedules against your labor target and forecast, honor availability, time-off, hour caps, and minor work rules, and notify staff whose shifts changed.
- To run the HR features your operator enables — corrective-action documents, records, meeting notes, and the HR assistant.
- To send operational alerts you or your employer configured, such as a speed-of-service alert or a labor spike.
- To bill the operator and manage the subscription.
- To keep the service secure — authenticate sessions, rate-limit sign-in attempts, detect abuse, and keep the audit trail.
- To support you when you email us, and to fix bugs you report.
We rely on these grounds, depending on the data and where you are: performing the contract with the operator (and, for employees, the operator's own legitimate interest in running its restaurants and meeting its employment obligations); our legitimate interest in keeping the service secure and working; and your consent where consent is what applies — for example, allowing camera access, turning on push notifications, or opting into SMS alerts. Where consent is the basis, you can withdraw it at any time without losing access to the rest of the product — camera, photo library, and notification permissions are revoked in iOS Settings, and SMS categories are changed by asking your administrator or us (see Section 11).
AI Processing
Zairo is built on large language models. This is the part of the policy most people want in plain terms, so here is exactly what goes where.
- Anthropic (Claude) receives store metrics, the store's recent history and baselines, the operator profile, your role, and the text of chat messages you send. It produces the analysis, the coaching language, the schedule optimization, and the answers in the chat and HR assistant. HR attachments — images and PDFs — are sent to Anthropic as native content blocks and read directly by the model.
- OpenAI (GPT-4o) receives the raw text of report files and the images of invoices, receipts, and documents you photograph. It turns them into structured data — sales figures, line items, vendors, totals. This is the extraction step, and it is why a photo of a receipt becomes an expense record.
Both providers act as our service providers and process this content to return a result to us. We use their business APIs; both publish that content submitted through those APIs is not used to train their models. We do not send them your PIN, password, or payment details, and there is no reason for them to receive a Social Security number or date of birth because Zairo does not hold those.
AI output is advice, not a decision. Zairo's briefs, coaching, schedules, and HR drafts are suggestions for a human to review. A manager reviews and edits a generated schedule before publishing it, and a manager writes, reviews, and signs a corrective-action document. Zairo does not make employment decisions automatically, and the AI never fabricates a signature — a photographed paper document is stored as evidence of the original.
What We Never Do
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not run advertising in the product or embed advertising SDKs.
- We do not track you across other apps or websites. The iOS app declares no tracking and no tracking domains.
- We do not use third-party analytics, session recording, or marketing pixels — not in the portals, not in the app, and not on this website.
- We do not collect device location for tracking. Zairo works from store assignments, not from where your phone is.
- We do not store payment card numbers. Stripe and Square handle those.
- We do not use one customer's data to serve another customer.
How Long We Keep It
- Store memory — the rolling detail history a store's analysis runs on is trimmed to the most recent 90 days. Derived baselines, records, and long-run sales history are kept longer so year-over-year comparisons work.
- Account records — kept for as long as the account is active, and then handled as described in Section 11.
- Employee and HR records — kept for as long as your employer needs them, because they are your employer's employment records. Your employer decides when they go.
- Sessions — every session has an expiry, and expired or revoked sessions are cleaned out after a short grace period.
- Audit logs — kept as a security record. When an account is deleted, its audit entries are anonymized rather than erased, so the security history stays intact without naming a person.
- Backups — encrypted database backups are taken on a nightly schedule and kept on a short rolling window of roughly two weeks, after which they age out and are deleted. A deletion you request is applied to the live system immediately; backups still holding the old data expire on that rolling schedule.
- Support email — kept as long as needed to resolve the issue and keep a record of it.
How We Protect It
- Encryption in transit. All portal and API traffic runs over HTTPS with TLS certificates. The mobile app talks to the same HTTPS endpoints.
- Credentials are hashed. Portal PINs, employee passwords, and security-question answers are hashed with PBKDF2-HMAC-SHA256 at 100,000 iterations with a unique random salt each, and compared in constant time. This is the scheme every credential set or reset today goes into; accounts that predate it are being migrated onto it, and a reset moves an account over at once.
- Session tokens are long random values with a server-side expiry, tied to a user type, and revocable. Changing or resetting a credential immediately kills every live session for that user across both portals.
- Access is scoped at the server. Every request is checked against the requester's operator, role, and store assignments — not hidden in the interface and trusted from the browser.
- Brute-force protection. Sign-in attempts are rate-limited per account and per network.
- Audit logging records security-relevant actions with actor, time, and source IP.
- Backups are encrypted and stored off-site in addition to the primary host.
No system is perfectly secure, and we do not claim certification under any security or privacy standard. What we do claim is the list above, which describes how the product is actually built. If you believe you have found a vulnerability, email zairoaiops@gmail.com with the details and we will respond.
Your Choices, and Deleting Your Account
Access, correction, and deletion
You can ask to see the information Zairo holds about you, have it corrected, or have it deleted. Depending on where you live, you may have these as formal legal rights, along with the right to object to certain processing, to ask for a portable copy, and to be free from discrimination for exercising them. We honor these requests regardless of where you live.
How to exercise them: if you are an employee or manager, ask your employer's Zairo administrator first — they can act on most of it immediately. If you are an operator, or you cannot get your employer to act, email zairoaiops@gmail.com from the address on your account. We will confirm who you are before acting, and we aim to respond within 30 days.
Deleting your own account, in the product
Sign in to the operator portal — on the web at dashboard.zairoai.com, or in the iOS app, which opens the same portal. The control is the button labelled Privacy in the top navigation bar, immediately to the right of Log Out. There is no separate settings menu; that button is the whole path. It opens a dialog titled Delete my account.
- If you are a general manager, area leader, or area director, the dialog asks you to type DELETE and re-enter your current PIN.
- If you are an owner, the same button opens the operator-wide version, because deleting an owner alone would strand their team. It asks for three things: your operator's name, the phrase I understand this is irreversible, and your current PIN.
When a general manager, area leader, or area director confirms:
- A confirmation email is sent to the address on the account, before anything is erased.
- Every live session for you is revoked immediately.
- Your profile record is overwritten with an anonymized stub — name, email, phone, stored credential, and security questions are cleared, and the account is marked inactive with a deletion date.
- Your entries in the audit log are anonymized, so the security record survives without identifying you.
- Operational records your store still needs to run — published schedules, invoices, sales history — stay in place, no longer linked to you by name.
When an owner confirms, the deletion cascades: every team member's user record, the store memory, the audit history, the Stripe subscription, and any Square connection. Every team member is signed out immediately. There is no undo.
One exception, stated plainly: internal Zairo staff accounts cannot be deleted through this button, because a second administrator has to authorize it. If that applies to you, the dialog says so and points you to email. Everyone else deletes from inside the product.
Communication choices
Push notifications can be turned off in your device's iOS settings at any time, and signing out of the app unregisters the device token. Which SMS categories you receive, and the language your SMS and push alerts are written in, are set on your profile when your account is created — there is no self-serve control for them yet, so ask your Zairo administrator or email us and we will change it. The schedule portal's Español button changes that portal's display language for you on that device; see Section 13. Report and schedule emails are part of the service your employer subscribes to; ask your administrator to change who receives them.
Minors and Children
Zairo is a workplace tool for restaurant businesses. It is not directed to children, it is not marketed to children, and we do not knowingly collect personal information from a child for their own use. Nobody signs themselves up for Zairo — accounts are created by an employer, or by us on an employer's instruction.
Restaurants employ workers under 18, so employee records in Zairo can relate to a minor. Those are employment records held on the employer's behalf and handled under the employer's obligations as an employer. Zairo stores only what the scheduling rules need: a yes/no minor flag, which the scheduler uses to keep those employees off overnight windows and inside shorter shift limits. We do not store a date of birth, an age, or a Social Security number.
If you believe a child's information has reached Zairo outside of that employment context, email zairoaiops@gmail.com and we will delete it.
Cookies, Local Storage, and the Mobile App
This website
zairoai.com is a set of static pages. It sets no cookies, runs no analytics, and loads no advertising or tracking scripts.
Web fonts — every surface, including the app
Zairo's typefaces are served by Google Fonts, and this is not limited to the marketing website. The same font request is made by this site, by all three web portals, and by all four screens bundled inside the iOS app — including the app's sign-in screen, which loads them before you have signed in. Practically, that means Google's servers receive your device's IP address and the standard headers any web request carries, each time a Zairo page opens.
What that request does not carry: no cookie set by us, no account identifier, no session token, and nothing about your restaurant, your team, or your numbers. We do not receive anything back from Google about you, and no font request is used for analytics or advertising. We are naming it here because it is a genuine third-party connection from inside the product; self-hosting the font files would remove it, and we intend to.
The web portals
The portals do not use tracking cookies. Your session token is kept in your browser's localStorage, along with a few preference and offline-convenience keys — the signed-in user, your language choice on the schedule portal, whether you dismissed the install prompt, and a cached copy of roster and schedule data so the app still shows something when the connection drops. Signing out clears the session token and the signed-in user; the small display preferences stay so the portal looks the same next time you sign in, and clearing site data in your browser removes everything. The portals are installable as progressive web apps, and their service worker caches static files and API responses on your device for offline use; uninstalling the app or clearing site data removes that cache.
Language
The schedule portal — the team-facing surface, in the browser and in the iOS app — has an Español toggle on its sign-in screen and its main screen. Your choice is stored on that device and changes only what that portal displays to you. SMS and push alerts are written in the language recorded on your profile. The operator dashboard, the HR admin area, and emailed reports are English only today.
Camera and photo library
The iOS app asks for camera access to capture invoices, receipts, and paper documents, and for photo library access so you can attach an existing photo. Both prompts appear only when you take that action, and both can be denied or revoked in iOS Settings — the rest of the app keeps working. Images you capture are uploaded so they can be read and turned into records, as described in Section 6.
Face ID
After a successful sign-in the app may offer to enable Face ID (or Touch ID) so you can unlock a saved sign-in instead of retyping it. The offer is only ever made after your credentials have been accepted — the app never asks for a biometric before you have signed in. Declining is fine and changes nothing else; the app asks at most a few times and then stops, and an Enable Face ID button appears on the sign-in screen if you skipped it and later change your mind.
Your biometric never reaches us. The check is performed entirely on your device by iOS. Your face or fingerprint data never leaves your iPhone, is never accessible to Zairo, and is never transmitted to our servers — iOS only tells the app whether the check passed.
What is stored, and what happens to it. If you enable the feature, your email address and your PIN or password are written to the iOS Keychain in an item that iOS will only unlock after a successful biometric check. On the next launch the app reads that item and signs you in with it, which means the saved credential itself is sent to our servers over HTTPS at that moment — exactly as it would be if you had typed it. It is the biometric, not the credential, that stays on the device.
Removing it. Signing out clears the saved credential from the Keychain — that is the off switch, and it is deliberate: on a shared phone, an enrolment that outlived a sign-out would let the next person Face-ID straight back into the previous person's account. Deleting your account clears it too, once the deletion is accepted. A session simply expiring does not clear it, because that is exactly the case Face ID is for — you unlock and carry on. The credential is also dropped automatically whenever it stops working: if your PIN or password is changed or reset, the saved copy is rejected on the next attempt and the app deletes it and asks you to sign in normally. Deleting the app removes it as well, along with everything else the app stored on your device.
Push notifications
If you allow notifications, the app registers a device token with Apple's Push Notification service and sends that token to Zairo so alerts can reach your phone. The token identifies a device installation, not you personally. Signing out unregisters it, and tokens Apple reports as dead are removed. Denying or revoking notification permission in iOS Settings stops the whole flow.
Tracking
The app's privacy manifest declares no tracking and no tracking domains, and the app never asks for permission to track you, because it does not. Nothing in the app is collected for advertising, analytics, or personalization.
What the App Store privacy labels say
Apple asks every app to declare the categories of data it collects. Zairo's declaration is the list below. Every entry is marked linked to your account, used for app functionality, and not used for tracking — there are no other purposes and no other categories:
- Contact Info — email address: your sign-in identity, and where reports and alerts are sent.
- Contact Info — name: your display name, and the names on employee records your managers create.
- Contact Info — phone number: SMS alerts, and the phone numbers on employee records so a manager can call a shift.
- User Content — photos or videos: the invoice, receipt, and document images you capture or attach.
- User Content — other content: assistant chat messages, store operating data, schedules, and HR and performance records.
- Identifiers — user ID: your account and session identity, used to route alerts to the right person.
- Identifiers — device ID: the Apple push notification token for this installation, if you allow notifications.
- Usage Data — product interaction: the security audit trail described in Section 3 — sign-ins, credential changes, record edits, deletions — kept with the actor, the time, and the source IP address, for security and fraud investigation only.
This list is deliberately the same list as the labels on the App Store product page and is meant to be read alongside Section 3, which describes the same information in more detail and in plain language. If the two ever disagree, Section 3 is the fuller description and this list is the Apple-category summary of it; tell us and we will correct whichever is wrong.
Changes, Transfers, and Contact
Where your data is processed
Zairo is operated from the United States, and the service providers listed in Section 7 process data in the United States. If you use Zairo from outside the United States, your information will be transferred to and processed there.
Changes to this policy
When this policy changes, we update the page and change the "Last updated" date at the top. If a change materially affects how we handle personal information, we will email the account administrators at each operator before it takes effect. Continuing to use Zairo after a change means the updated policy applies.
Contact us
Questions about this policy, or a request about your information:
- Email: zairoaiops@gmail.com — response within 24 hours
- Zairo LLC · Kansas City, KS
One address you may also see, and what it is for. Inside the product, and on parts of this website, you will find reports@zairoai.com. That is Zairo's report-intake mailbox: it is the address operators forward their daily and weekly store reports to, and it is polled automatically by the ingestion pipeline. A few screens in the product also point at it for help. For anything that needs a person — a privacy request, a deletion request, a support question, or a security report — write to zairoaiops@gmail.com, which is the address on this page and on the Support page and the one that is monitored for replies. Mail sent to the intake address is not lost, but it goes to the queue that reads reports first.
For help using the product, see the Support page.