Skip to main content

Privacy Policy

Last updated August 3, 2026

This Privacy Policy explains how Butter(“Butter,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our software for independent cafés — demand forecasting, purchasing and vendor ordering, inventory, invoice reconciliation, labor and scheduling, consignment, neighborhood insights, and social-media planning (the “Service”).

Butter is a business tool. Most of the information we handle is your café’s own operational data, plus data from the third-party accounts you choose to connect. Some of it, though, is about people — your staff (names, wages, hours and tips, if you connect a payroll-bearing system), your suppliers’ representatives, your consignment partners, and members of the public who review or comment on your business. Those are called out explicitly below, because they are the parts that most deserve your attention. We’ve tried to keep this policy thorough but plain. Questions? Email privacy@getbutter.app.

1. Who this applies to

Our direct users are café owners, managers, and staff (“you”). The Service is not directed to consumers or the general public, and it is not intended for anyone under 18. When you connect a third-party account or upload data, you confirm you’re authorized to do so and to share that data with us.

Some people whose data we process never sign up for Butter: your employees, your vendors’ contacts, consignment partners you invite, and people who review your business publicly or comment on your posts. You are responsible for having whatever notice or basis your local law requires before you put their data into Butter — particularly staff data. We tell you plainly below exactly what we hold about them.

2. Information we collect

Information you give us

  • Account & profile: your name and email address, and the password you set (passwords are handled by our authentication provider and are not visible to us).
  • Café & business details: café name, address, location (latitude/longitude), time zone, operating hours, and your settings and preferences.
  • Team members:the email addresses you invite, and each member’s role (owner, manager, member).
  • Vendors & purchasing:vendor names, and for each vendor the contact name, email, phone number, website, address, ordering schedule, and any consignment payout details you enter (payout details are stored as the free text you type, so avoid putting anything there you wouldn’t want stored in plain form).
  • Inventory & counts: items, units, par levels, on-hand counts, and the person who recorded a count.
  • Invoices you upload or forward by email: the invoice files and the information read from them (vendor, date, line items, amounts).
  • Voice recordings, when you count by voice:if you use voice counting, your device records audio and sends it to us to be transcribed into counts. See “AI processing” — the recording goes to our AI provider. We do not store the audio; only the resulting numbers are saved.
  • Photographs you take in the café: photos for photo-based counting (not stored), and photos of your display case for merchandising analysis (stored). These are pictures taken inside an operating café and can include staff or customers in the background. Don’t photograph people deliberately.
  • Feedback and screenshotsyou submit through the in-app feedback board, if your café is in that pilot. See “Sharing between cafés” below — this one is not private to your café.
  • Brand & content inputs: the brand voice/audience notes you provide for social briefs.
  • Billing details: when you subscribe, our payment processor collects your payment details directly. Butter never sees or stores your card number.We store your subscription status, plan, renewal date, and the processor’s customer and subscription identifiers; your email address and café name are sent to the processor to create your billing record.
  • Waitlist: if you join the waitlist before signing up, we store the name, email, and café name you give us.

Information about your staff

This is the most sensitive category Butter holds, and it only exists if you connect a system that carries it.

  • From Toast (labor): employee first, last and chosen names, an internal employee identifier, job titles and default wage rates, and per-shift time entries — clock-in and clock-out times, hours, overtime, hourly wage, and tips.
  • From 7shifts (scheduling), if you connect it: employee names, rostered shifts and roles, wage type and wage rate.
  • We deliberately do not read staff email addresses or phone numbers from these systems, even though they are available to us, because no feature needs them.
  • Per-person rows are restricted to owners and managers by database rules; a member role cannot read them.

Information about other people

  • Vendor representatives: the contact name, email and phone you record for a supplier. These reach our AI provider when we parse ordering details, and are readable through the assistant connection described in section 6.
  • Consignment partners: if you invite a shelf partner to their portal, we collect their email address, create an account for them with our authentication provider, and record when they last opened their portal. Your own email address is used as the reply-to on that invitation, so it is disclosed to them.
  • People who email your invoice inbox:we store the sender’s email address, the subject line, and — where there is no attachment — the body of the message.
  • Members of the public who review or comment: we read the author names and text of your public Google reviews, and the usernames and text of Instagram comments on your posts. Both are sent to our AI provider to summarize sentiment or draft replies, and short verbatim quotes from reviews may be stored alongside the item they mention.

Information from accounts you connect

  • Toast POS:we read your menu, inventory, stock levels, order history (including order totals, item-level sales, quantities, guest counts, and a trimmed subset of the raw order records — we deliberately exclude customer objects and identity- and payment-shaped fields, and keep a server’s identifier but never their name), and, if enabled, the labor data described above. We do write one thing back to Toast: when you count an item that Toast tracks stock for, we push the counted quantity (or in-stock / out-of-stock) into Toast so your POS matches your shelf. Nothing else is ever written back.
  • 7shifts (optional): schedules and the staff data described above.
  • Google Calendar (optional): your calendar list and the events on the calendars you select (titles, times, locations, descriptions), plus the Google email address of the connected account, to use events as demand signals.
  • Instagram / Facebook (Meta) (optional):your Instagram Business account’s username and follower count; account insights; recent media (captions, type, timestamps, permalinks) and their metrics; active stories and their metrics; and, where you use the comment tools, comments on your media including the commenter’s username. We store an access token to maintain the connection. We do not post or message on your behalf without an explicit action from you.
  • Slack / Google Chat (optional): if you connect either, we send notification content and social briefs to the channel or space you nominate.
  • Connection credentials: to keep these integrations working, we securely store the API keys and OAuth tokens for the accounts you connect.

Information we obtain about your business and its surroundings from public sources

  • Google Maps / Places:your café’s address, hours, public rating and reviews (including reviewer names), and nearby cafés (“competitors”) with their public details — place identifier, name, address, coordinates, rating, rating count, price level, website and ordering URL.
  • Competitor menus:we fetch a competitor’s published menu page (and, for pages that need a browser to render, have our AI provider fetch it) so we can compare their prices to yours.
  • Local events, news, school calendars and observances: discovered from public web sources and from any source URLs you provide. Local business news is about named nearby businesses — openings, closings, permits, licences — and is stored.
  • Weather:local forecasts and history based on your café’s coordinates.

Information we generate

  • Forecasts, trends and the factors behind them; reputation and sentiment summaries derived from your public reviews; consignment insights shared with the partner they concern; and AI-generated social briefs and brand-voice drafts.

Information collected automatically

  • Usage & device data: basic, privacy-friendly analytics about page views and performance, and server logs needed to operate and secure the Service.
  • Push notification subscriptions: if you enable push notifications, we store the push endpoint your browser gives us, its encryption keys, and your browser user-agent string.
  • AI usage records: for each AI call we record which café it was for, the kind of task, the model, token counts, cost and latency. We do not store the prompt or the response — only the metering.
  • Cookies & local storage:strictly necessary cookies to keep you signed in and a short-lived cookie to secure connection flows. We store small interface preferences in your browser’s local storage. We do not use advertising or cross-site tracking cookies.

3. How we use information

  • Provide, operate, and maintain the Service and your account.
  • Forecast demand, suggest and assemble vendor orders, reconcile invoices, track inventory and where it goes missing (waste, theft and over-ordering), analyze labor cost against sales, run consignment and pay partners, and generate insights, social briefs and brand-voice drafts.
  • Send vendor purchase orders, invitations and related emails at your direction.
  • Take payment and manage your subscription.
  • Provide support, respond to requests, and send service-related messages.
  • Keep the Service secure, prevent abuse, and debug problems.
  • Improve and develop features (using aggregated or de-identified data where practical).
  • Comply with law and enforce our Terms.

We do notsell your personal information, we do not use it for third-party advertising, and we do not use your data to train anyone’s AI models.

4. AI processing

Some features use Google’s Gemini API to generate results. Google is currently our only AI provider. To produce a result we send it the relevant inputs, which — depending on the feature — can include:

  • the contents of an invoice you upload or forward, to read its line items;
  • audio recordings of a staff member speaking, when counting by voice, along with your item names;
  • photographs taken inside your café — shelves for photo counting, display cases for merchandising analysis;
  • your sales, menu, items, events, weather, and review summaries, and connected Instagram metrics and captions, to write insights and social briefs;
  • the text of public reviews and the usernames and text of Instagram comments, to summarize sentiment or draft a reply;
  • your website text, and competitors’ published menus, to draft a brand voice or compare prices;
  • your café’s name and street address, in queries that use Google’s search grounding to find local events, news, and school calendars;
  • vendor contact and ordering details, when parsing ordering schedules;
  • consignment sales data, to write the insight shared with that partner.

Under the Gemini API terms that apply to this kind of usage, Google processes this data to return a result and does not use it to train its models. Some features additionally ask Google to fetch a public web page on our behalf. AI output can be wrong or incomplete — review it before relying on it or publishing it.

5. Instagram & Facebook (Meta) data

If you connect Instagram, our use of information received from the Meta Platforms follows the Meta Platform Terms and Developer Policies. Specifically:

  • What we access:your Instagram Business account profile, insights, recent media and their metrics, active stories, and — where you use the comment tools — comments on your media, including the commenter’s username.
  • Why:to analyze your account’s performance, generate your weekly social brief, and draft replies you choose whether to send. We never post, comment, or send messages without an explicit action from you, and we do not share this data with third parties except the AI processor described above and our infrastructure providers.
  • Disconnect & delete:you can disconnect Instagram at any time on the Social page. Disconnecting deletes the stored access token. To delete Instagram-derived data we’ve stored (e.g. metrics saved within past briefs), follow “Data deletion” below.

6. Connecting your own AI assistant

Butter can be connected to an AI assistant you choose, using an access token you create. This is off unless you set it up, and it is worth understanding before you do.

  • What the assistant can read: your café profile (including street address), sales summaries, inventory and low-stock lists, vendors — including your vendor contacts’ names, emails and phone numbers — purchase orders, stockouts, demand context, insights, and aggregate labor summaries. Per-person staff data is not exposed this way. It can also draft a purchase order, which you must confirm.
  • Where that data goes:to whichever assistant you connect, and therefore to that vendor’s model provider. That is a company Butter has no agreement with, and their handling of your data is governed by their terms, not ours. Only connect an assistant you trust.
  • What we store: a one-way hash of your token (never the token itself, which is shown once), its label, scopes, and when it was last used; and an audit log of which tools were called, when, and whether they succeeded, with arguments redacted.
  • Turning it off: revoke the token at any time in Settings. Revocation is immediate.

7. How we share information

We share information only as needed to run the Service. We use the following service providers (“sub-processors”), each of which receives only the data needed for its function:

  • Supabase — database, authentication, and file storage (hosts your account and café data, including uploaded invoices and case photos).
  • Vercel — application hosting and privacy-friendly analytics.
  • Google — Maps/Places, Calendar (if you connect it), Chat (if you connect it), and the Gemini AI API, including its search-grounding and page-fetching tools.
  • Stripe — payment processing and subscription management. Receives your email address and café name; collects your payment details directly.
  • Meta Platforms — Instagram Graph API (if you connect Instagram).
  • 7shifts — scheduling (if you connect it). Staff names, roles, shifts and wage data flow from them to us.
  • Resend — email delivery and receiving. Sends your vendor purchase orders, team and partner invitations, consignment remittances, and notification emails; receives invoices vendors email to your dedicated inbound address.
  • Slack — if you connect it, receives notification content and briefs.
  • Browser push services— if you enable push notifications, your browser vendor’s push service (Google, Apple, Microsoft or Mozilla, depending on your browser) relays the encrypted notification to your device.
  • Have I Been Pwned — when you set or change a password, your browser checks it against known-breached passwords using a method that sends only the first five characters of a hash. Your password, email and identity are never transmitted.
  • Open-Meteo — weather data (receives only coordinates, no personal data).

Sending to your vendors: when you send a purchase order, we transmit its contents (items, quantities, prices, dates, and your reply-to email) to the vendor and any recipients you add. You control the recipients and content.

Sending to your consignment partners: a partner you invite can see their own vendor record, their payout details, their sales and payment history with you, and an AI-written insight about their products. They cannot see anything else about your café.

We may also share information to comply with law, respond to lawful requests, protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).

8. Sharing between cafés

One feature deliberately crosses café boundaries, and we want it stated rather than buried. If your café is in the feedback pilot, the feedback items you submit — including any screenshots you attach and basic usage counts — are visible to other cafés in that pilot, so everyone can see and vote on what has already been asked for. Items can be marked so their details stay private. Nothing else about your café is shared with another café, ever. If you would rather not take part, tell us and we will remove your café from the pilot.

9. Data retention

We keep information for as long as your account is active and as needed to provide the Service. Specifically:

  • Connection tokens are kept until you disconnect that integration.
  • Uploaded and forwarded invoices, saved email bodies from your invoice inbox, display case photos, and feedback screenshots remain until you delete them or ask us to close your account. We do not currently expire these automatically.
  • If your subscription ends, your café becomes read-only rather than being deleted — your data stays and stays readable, so you can come back to it or export it. Cancelling is not the same as deleting. If you want your data removed, ask us; see below.
  • Billing records are kept for as long as tax and accounting law requires, even after deletion of other data.
  • Routine backups and logs are retained for a limited time and then expire.

When you ask us to delete your data or close your account, we delete or de-identify it within a reasonable period, except where we must retain it to comply with law, resolve disputes, or enforce our agreements.

10. Your choices & rights

  • Access & correction: you can view and edit most of your data in the app, or ask us for a copy.
  • Disconnect integrations: you can disconnect Toast, 7shifts, Google Calendar, Instagram, Slack or Google Chat at any time, which stops further data collection from that source and removes its stored credentials. You can revoke an assistant token at any time, and cancel your subscription through the billing portal.
  • Deletion: you can ask us to delete your data or close your account (see below).
  • Notifications: you can turn off push and email notifications in your preferences; disabling push removes the stored subscription.
  • Analytics: our analytics are aggregate and privacy-friendly; you can also use browser controls to limit cookies (strictly necessary cookies are required to sign in).

If you are in the EEA or UK,you have rights to access, correct, delete, restrict, or object to processing, and to data portability; our legal bases are performance of our contract with you, your consent (for optional integrations), and our legitimate interests in operating and improving the Service. Where we process your staff’s or your partners’ data, we generally act as a processor on your instructions and you are the controller. If you are a California resident,you have rights to know, access, delete, and correct your personal information and to not be discriminated against for exercising them; we do not “sell” or “share” personal information as those terms are defined under California law. To exercise any right, email privacy@getbutter.app; we may need to verify your identity.

11. Data deletion

To delete your data:

  • Disconnect a source (Toast, 7shifts, Google Calendar, Instagram, Slack, Google Chat) in the app to remove its stored credentials and stop further collection.
  • Revoke an assistant token in Settings to cut off that connection immediately.
  • Delete specific records (such as invoices) within the app.
  • Delete your account and associated data by emailing privacy@getbutter.app from your account email, or with enough detail for us to locate your account. Say so explicitly if you want deletion rather than simply cancelling — cancelling leaves your data in place and readable. We will confirm and complete deletion within a reasonable period, subject to legal retention requirements.

12. Security

We protect data with encryption in transit (TLS) and at rest, access controls and row-level security so each café’s data is isolated, role-based restrictions on the most sensitive tables (per-person labor data is owner and manager only), one-way hashing of API tokens, and least-privilege handling of credentials. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your information, we will notify you as required by law.

13. Where data is processed

Butter is operated from the United States, and our providers process data in the United States and other countries. If you access the Service from outside the U.S., you understand your information will be processed in the U.S. Where required, international transfers are made under appropriate safeguards.

14. Children

The Service is for businesses and is not intended for children. We do not knowingly collect personal information from anyone under 18 as a user. If you employ people under 18 and connect a system carrying their employment data, that data is handled as staff data described above. If you believe a minor has provided us information directly, contact us and we will delete it.

15. Third-party services & links

The Service integrates with and links to third-party services (such as Toast, 7shifts, Google, Meta, Stripe, Slack, and your vendors’ sites), and can be connected to an AI assistant of your choosing. Their handling of your information is governed by their own terms and privacy policies, which we encourage you to review. We are not responsible for third-party practices.

16. Changes to this policy

We may update this Privacy Policy from time to time. We’ll change the “Last updated” date above and, for material changes, provide additional notice. Your continued use of the Service after an update means you accept the revised policy.

17. Contact us

Butter — Privacy. Email privacy@getbutter.app.