Skip to main content

Security, privacy and data handling

Your money, your guests, your record.

How RestCall handles payments, guest data, staff authority and devices — described as mechanisms you can check, not badges you have to take our word for.

Charges run through your own merchant account.

A guest can ask to be forgotten, on the call.

Consequential actions carry a name, not a shared PIN.

Payments

We never hold your money.

Card data never reaches RestCall servers. Charges run through your restaurant’s own merchant account — Stripe or Stax — and settle directly to your bank on your own payout schedule. There is no platform balance in between, and no week where your revenue is sitting with us.

How payments work

What that means mechanically

Available
  • Your own merchant account, your own payout schedule
  • Direct settlement to your bank
  • Card data never reaches RestCall servers
  • In-person charges captured on certified reader hardware
  • Tap to Pay on a staff phone, on the same account

The rest of the surface

Guests, staff, devices and the record.

Each area below is handled by something that ships today. Where a capability is still in pilot, it says so.

Available

Guest data

The guest can leave, and take their record with them, without waiting on a support ticket.

  • A caller can ask to be forgotten, on the call
  • Guest data deletion honored on request
  • Guest phone numbers masked in every operator view
  • Order history attached to the guest, not scattered per channel
Pilot

Messaging consent

Every text a guest receives is one they agreed to, and one they can stop.

  • Consent recorded per guest
  • One-tap opt-out honored everywhere
  • Delivery receipts on every message
  • A platform sending number, so you register nothing
Available

Who did what

Authority is attached to a person. Refunds, voids and drawer opens are attributable after the shift ends.

  • An audit log across the group
  • Named manager codes for refunds, not a shared PIN
  • Attribution recorded on every refund
  • Per-staff sign-in codes and shift attribution
  • Lockout after repeated bad codes
Available

Devices

A tablet on an open counter is a risk. It is treated like one.

  • Kiosk mode locking a tablet to the app
  • Idle auto-lock on unattended tablets
  • Lock, restart or wipe a device that walks
  • Compliance state and last check-in per device
  • Pair a register with a code, revoke it remotely
Available

Call recordings

Recordings exist to fix the call, and they do not sit around after they have stopped being useful.

  • A retention policy with legal hold
  • Automatic purge when retention expires
  • Recording continues through a warm transfer
Available

Access

A group with several addresses should not hand every manager every location.

  • Per-location access control for multi-location groups
  • Role-based membership and invitations
  • Membership scoped to the locations a person actually works

What this page is not

Mechanisms, not badges.

Everything above describes how the software behaves, because that is what we can show you. We do not publish certification logos, audit seals or uptime numbers on a marketing page.

If your group runs a security review, send us the questionnaire. We will answer it against the product as it ships, and say plainly where something is roadmap rather than live.

Before you sign

Bring us your security review.

Send the questionnaire your group uses. We answer it against the product as it ships today — and tell you where something is still roadmap.