Privacy Policy
Last updated: 31 August 2026
Who we are
We operate Reforno — an analytics and intelligence tool that helps independent pizza shop owners understand their business. The platform connects to your existing point-of-sale data via CSV import, lets you track sales by channel, analyse menu profitability, manage supplier invoices, and ask plain-English questions about your numbers using AI.
For privacy enquiries, contact us at: privacy@reforno.com.au
We are committed to handling all personal information in line with the Australian Privacy Act 1988 and its Australian Privacy Principles (APPs). Where our platform is accessed by anyone in the European Union, we also comply with the General Data Protection Regulation (GDPR).
What this policy covers — and what it does not
This policy covers information we collect and handle as the operator of this platform.
When you upload your sales data or customer transaction records, you are sharing information about your own customers — their names, phone numbers, and order details. In that situation:
- You (the shop owner) are responsible for your customers' data. You are their data controller.
- We store and process that data only on your instructions, to provide you with analytics.
- Your customers who want to access, correct, or delete their information should contact you directly.
We require all shop owners to have a lawful reason for uploading their customers' data and to have informed their customers that their information may be processed by business analytics tools.
What information we collect
Your account information
When you sign up, we collect your email address. We use this to create your account, send you important service updates, and let you log in securely.
Your shop profile
When you set up a shop in Reforno, you also provide your shop's name, the POS system you use, address, phone number, ABN, timezone, and currency. We use this to personalise your reports and communications.
Your shop's sales data
When you upload a CSV export from your POS system, we process:
- Transaction records: date, customer name, customer phone number, payment method, order amount, GST component, delivery channel, and collection type
- Item sales summaries: item name, size, quantities sold, revenue per item
- Channel summaries: revenue by sales channel
This data is uploaded by you and is used only to generate analytics and reports for your shop.
Staff and labour data
Named staff member records (name, default hourly rate, and active status), individual shift entries (staff member, date, start and end times, hourly rate, hours worked, total pay, and any notes you enter), and recurring shift templates — entered manually by you for wage-vs-revenue analysis.
Supplier and invoice data
Supplier names, contact details, invoice numbers, invoice and due dates, amounts (including GST, amount paid, and balance due), and line items. When you paste, upload, or photograph a supplier invoice, our AI extracts the line items on your behalf — and where you paste invoice text directly, we also store that original text alongside the extracted result.
Bank transaction data
Transaction dates, bank narration descriptions, amounts, and categories — uploaded as a CSV from your business bank account.
Menu data
Item names, categories, sizes, and prices. This is business information, not personal information about individuals.
Technical data
When you use the platform, we automatically collect standard technical information including your IP address, browser type, and usage logs. This includes audit records of significant account actions (such as imports, invoice changes, and billing events), and error and performance monitoring through Sentry. We use this information to keep the service secure and working correctly, to prevent abuse, to maintain records for troubleshooting and compliance, and to monitor performance — as described in more detail under 'How we use your information' and 'Who we share your information with', below. We do not use it for advertising or sell it to anyone.
AI chat queries
When you ask the AI assistant a question, we process your question and retrieve relevant data from your account to generate an answer. We do not store the content of your questions or Ask Reforno's answers after the request completes. We do keep a lightweight usage counter (how many questions you've asked in a given hour) to enforce fair-use rate limits — this counter contains no question or answer content.
Enquiries and contact requests
If you get in touch with us through our contact form, we collect your name, business name, email address, phone number, and the content of your message. We use this to respond to you and, where relevant, to follow up about Reforno.
How we use your information
We use your information only to:
- Provide, maintain, and improve the platform
- Generate reports and analytics that answer your business questions
- Process supplier invoice data you paste into the system
- Send you important account notices (password resets, security alerts) and onboarding emails to help you get set up during your trial period
- Respond to your support requests
- Set up and manage your payment method and subscription
- Prevent fraud and abuse (for example, rate-limiting sign-up attempts by IP address)
- Maintain audit and compliance records of account activity
- Monitor performance and diagnose errors
- Send operational alerts about your business (for example, food cost changes, margin alerts, or missed data imports)
We do not:
- Sell your data to anyone, ever
- Use your data to advertise to you or your customers
- Share your data with other pizza shops or competitors
- Use your customers' transaction data to build profiles on those individuals
- Train AI models on your personal data
Who we share your information with
We share your information only with the service providers who help us run the platform. We require all of them to protect your data and use it only to provide us with specific services.
Supabase
Your account and business data is primarily held in Supabase's secure database infrastructure, located in Singapore. Supabase provides our database, user authentication, and server-side processing. As described elsewhere in this section, some information is also necessarily shared with other service providers to deliver specific features.
Anthropic
Ask Reforno is powered by Anthropic's Claude API. It sends aggregated business summaries to Anthropic to answer your questions — including things like your shop's name, item names, and category-level totals, so it can give you an accurate, specific answer. These summaries do not include supplier names, invoice numbers, invoice line-item descriptions, customer names or phone numbers, or raw invoice text.
Invoice extraction works differently. When you ask Reforno to extract an invoice, the invoice text, PDF, or image content is sent to Anthropic so it can identify the supplier, date, line items, and amounts. Reforno returns the structured data for you to review.
Reforno also uses Anthropic's Claude to help you set up your menu: if you upload menu photos, those images are sent to Anthropic to extract menu items and prices, and if you use ingredient suggestions, menu item descriptions are sent to Anthropic to infer likely ingredients.
Vercel
Our platform is hosted on Vercel's infrastructure. Vercel processes web requests, serves the application, and collects performance and usage telemetry through Vercel Analytics and Speed Insights. Standard technical data may include IP address, browser, device, page URL, request logs, and timing data. We use this to keep the platform reliable and diagnose performance issues, not for advertising.
Sentry
We use Sentry to monitor application errors and performance. Sentry may receive technical information about errors that occur while using the platform, including request context. We do not intentionally send customer names, phone numbers, or payment card data to Sentry.
Stripe
Stripe is used both during your free trial, to securely collect and verify a payment method before your trial begins, and if you subscribe to a paid plan, to process your payment. We do not store your card details. Stripe's privacy policy governs how they handle your payment information.
Resend (email delivery)
We use Resend to send transactional and onboarding emails to shop owners, and to deliver messages you submit through our contact form. This necessarily includes the content of those emails — for example, account notices, invoice reminders (which may include supplier and invoice details), food-cost alerts, and the message content of any contact form submission. Resend is based in the United States. We have reviewed Resend's data processing terms and require them to handle your information in accordance with applicable privacy law.
We use Google Analytics 4 to measure traffic on our public marketing pages only — not inside your logged-in account. Google may process standard analytics data such as approximate location, browser type, device type, and pages visited. This is governed by Google's privacy policy. We have not enabled advertising features or ad personalisation in Google Analytics.
We do not sell data to advertisers, data brokers, or any third party for commercial purposes.
Data retention
- Account data: Held while your account is active. Cancelling your subscription only stops billing — it does not delete your account or data. If you choose to delete your account (available in Settings), your account, shop data, and Stripe payment-method records are deleted immediately and permanently. There is no grace period, so please make sure you have everything you need before deleting. Deleting your account permanently removes all of your associated data — including internal records such as activity and audit history. We do not retain any record, anonymised or otherwise, after your account is deleted.
- Business transaction and invoice data: Retained for as long as your account is active. If you delete your account, this data is deleted immediately and permanently along with everything else — we do not separately retain it afterward. Australian tax law requires you, as the business owner, to keep your own business records for the required period. We recommend exporting or downloading anything you need before deleting your account.
- AI chat conversations: Question and answer content is not retained after your request completes. We keep a lightweight usage counter (no content) to enforce rate limits.
- Email log records (which emails were sent to which address and when) are retained for 12 months after your trial ends or your account is closed, whichever comes first, then deleted.
- Technical logs: Retained for up to 90 days, then deleted.
If your account is inactive for 2 years, we will contact you before deleting it. If you'd like a copy of your data before closing your account, contact us at privacy@reforno.com.au and we'll help.
A small number of our service providers, such as our error-monitoring and hosting infrastructure tools, may retain their own technical logs for a limited period after account deletion, in line with their own retention settings — this is outside our direct control. These logs do not contain your business data.
How we protect your information
- Encryption in transit: All data between your browser and our servers uses TLS encryption (HTTPS)
- Encryption at rest: Your data is encrypted in the database
- Row-level security: Our database is configured so that each shop owner can only ever see their own data through the app — it is technically impossible for one shop owner to access another shop's data through their own account. (Our own internal systems — for example, the automated emails described above — necessarily process data across shops to deliver those features, under the same restricted access controls described below.)
- Restricted access: The platform uses only a restricted database key in all client code. Admin-level access is reserved for secured server-side functions only
- No passwords stored in plain text: Authentication is managed by Supabase Auth using industry-standard hashing
- No card data stored: We never store payment card numbers
If we become aware of a data breach that is likely to cause serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required under the Notifiable Data Breaches scheme — within 30 days of becoming aware.
Artificial intelligence and automated processing
The platform uses AI powered by Anthropic's Claude to answer plain-English questions about your business data. This AI:
- Does not make any decisions about you or your customers that have legal or significant practical effects
- Does not automatically take any action on your behalf — all outputs are for your information only
- Is not used to profile or score your end customers as individuals
- Ask Reforno answers questions using aggregated summaries, not individual-level customer records
You can always ask us to explain how the AI arrived at a particular answer. Contact us at privacy@reforno.com.au.
Your privacy rights
If you are the shop owner
You have the following rights in relation to the information we hold about you:
- Right to access: You can ask us what personal information we hold about you. We will respond within 30 days.
- Right to correction: If any information we hold is wrong, you can ask us to correct it within 30 days.
- Right to deletion: You can ask us to delete your personal information. We will do so unless we are legally required to keep it.
- Right to de-identification: Where full deletion is not practicable, you can ask us to de-identify your information.
- Right to complain: You can complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or call 1300 363 992.
To exercise any of these rights, email privacy@reforno.com.au with the subject line “Privacy Rights Request”. We will respond within 30 days and may need to verify your identity before actioning your request.
If you are a customer of a pizza shop that uses Reforno
Your personal information was collected by the pizza shop when you placed your order, not by us directly. To access, correct, or delete your information, please contact the pizza shop directly.
Cookies and tracking
We use two categories of cookies:
Essential cookies: required for you to log in, stay logged in securely, and remember which of your shops you're currently viewing if you manage more than one. These cannot be disabled if you want to use the platform.
Analytics cookies: We use Google Analytics 4 to understand how visitors use our public marketing pages (our homepage, pricing, product, and tool pages). Google Analytics collects information such as pages viewed, session duration, and general geographic location derived from IP address. Google does not store your full IP address. This data is not linked to your name, email, or Reforno account.
Google Analytics is not active anywhere inside your logged-in Reforno account — your dashboard, reports, invoices, menu, and settings pages are never tracked by Google Analytics. It runs based on which page you're viewing, not whether you happen to be logged in — so a signed-in user visiting a public page like our pricing page may still be measured the same way as any other visitor. Your dashboard and account pages themselves are never tracked, regardless of how you got there.
We do not use Google Analytics or any other tool for advertising, ad personalisation, or retargeting. We do not share your data with ad networks.
Children's privacy
This platform is designed for use by adult business owners and their staff. We do not knowingly collect personal information from anyone under 18 years of age. If you believe a minor has provided us with personal information, please contact us and we will delete it promptly.
Changes to this policy
If we make material changes to this policy, we will notify you by email at least 14 days before the change takes effect. The “last updated” date at the top of this page will always show when the policy was most recently revised. Continued use of the platform after notification constitutes acceptance of the updated policy.
Contact us
For any privacy questions, requests, or complaints:
Email: privacy@reforno.com.au
We aim to respond to all privacy enquiries within 10 business days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
← Back to Reforno