Privacy Policy
What we collect, why, who we share it with, and what you can ask us to do. Written to be read, not skimmed past.
The short version
- We collect only what we need to run Foodnance: your name, work email, a password we store only as a one-way hash, and the business information you choose to put in.
- We do not sell personal information, and we use no advertising or cross-site tracking.
- Invoices and recipes you upload are sent to an AI provider (Anthropic, in the United States) so they can be read. Please do not upload anything you do not want processed that way.
- Your data is stored with Cloudflare and may be processed outside Canada, including in the United States and Japan.
- You can ask to see, correct or delete your information at any time: privacy@foodnance.com.
This summary helps you find your way. The full policy below is what applies.
Last updated: 4 October 2026
1. Who we are, and what this covers
Foodnance is operated by Simone Isonni, doing business as Foodnance (“Foodnance”, “we”, “us”). We handle personal information in line with applicable privacy law, including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA).
Foodnance is back-office software for food businesses. It reads supplier invoices and tracks products, recipes and stock, and reports costs and profit. It is sold to businesses, not to individuals.
This policy covers two different situations, and the difference matters:
- Your own information. When you visit foodnance.com, contact us, or have a Foodnance account (your name, work email, sign-in details). Here we decide why and how the information is used. See section 2.
- Information a business puts into Foodnance. Invoices, supplier and product records, recipes, sales, and records about the business’s own staff. Here the business decides what goes in and why, and we only process it for them. See section 3.
2. Your own information
2.1 What we collect
What you give us:
- Your name and work email address, when an account is created or you are invited to a team.
- A password, if you set one. We store only a salted, one-way hash, never the password itself.
- Your business name and type, when your organization is set up.
- What you tell us when you ask for access or write to us, including your business name, the plan you are interested in and any message you add.
- Billing details. When you subscribe, payment is handled by our reseller, Paddle.com, which is the Merchant of Record. Card numbers go to Paddle and never reach our servers.
What is created when you use the service:
- Your role in the organization and when you last signed in, for access control.
- A count of failed sign-in attempts, for security. Five wrong passwords in a row sends a password-reset email to the account holder.
- Password-reset and invitation records. We keep only a hash of each reset link, so a link works once and then expires.
- A log of how many invoices your organization has had read by AI, the size and cost of each request, and any request refused for being over your plan’s limit. It does not contain the documents.
Collected automatically: the app itself does not record your IP address or browser details. Our hosting provider, Cloudflare, processes IP addresses and request details to deliver the site and defend it against abuse, under its own policy. Your browser also contacts Google Fonts (Google) and jsDelivr, a code-delivery network, to load fonts and code libraries, which shows your IP address to those providers. Our public pages also use privacy-friendly analytics, described in section 2.4.
2.2 Why we use it
- To create and run your account, sign you in and keep it secure.
- To send service emails: invitations, password-reset links and notices about your account. We send these through Resend. They are not marketing.
- To answer questions, provide support, and fix and improve the service.
- To bill you, through Paddle.
- To meet legal obligations and to protect our rights.
Outreach. We may email businesses we think Foodnance could help, using a business address that is published publicly, about something relevant to that business. Each message says who we are and how to stop hearing from us, and we stop as soon as you ask. Anything beyond that, such as a newsletter, would be sent only with your express consent.
2.3 Your consent
By creating an account, accepting an invitation or using the service, you agree to the collection, use and disclosure described here. You can withdraw consent at any time by contacting us, though we may then be unable to provide the service. Where the law allows us to process information without consent, for example to comply with a legal demand, we may do so.
2.4 Cookies, local storage and analytics
We use one essential cookie, dm_session, which keeps you signed in. Scripts on the page cannot read it, it is sent only over a secure connection on the live site, and it lasts 14 days unless you sign out. Foodnance staff who are authorised to help a customer may also carry a second, internal support cookie that applies only to their own signed-in session.
The app also keeps four small items in your browser’s local storage: your chosen profit-and-loss cost basis; the list of features your plan includes, so menu tabs your plan does not have are hidden before the page is drawn; the name of your business (never your email address), so the account box in the menu bar appears straight away; and that box’s width, so the menu does not shift as the page loads. All but the first are removed when you sign out. None of them is sent to us.
Website analytics. On our public pages (the home page, pricing, the food cost calculator and our legal pages) we use Plausible Analytics. It does not use cookies, does not collect or store personal information about individual visitors, and does not build profiles or follow you across other sites. We see totals: how many people visited, which pages they viewed, which site sent them, their country and device type, and which buttons were clicked. Plausible is operated by a company in Estonia and keeps its data on servers in the European Union. We do not run analytics inside the signed-in app.
The food cost calculator. Anything you type into the calculator stays in your browser and is never saved or sent. Analytics may count that the calculator was used, but never what you enter.
We use no advertising or cross-site tracking cookies. Because nothing here tracks you across sites, there is nothing to switch off, and browser “Do Not Track” settings do not change what we do.
3. Information a business puts into Foodnance
3.1 What it is
Whatever a customer or its users upload or type: invoice images and PDFs; supplier, product and price records; recipes; inventory and stock counts; point-of-sale sales files; profit-and-loss inputs; and staff records, which can include names, roles, emails, phone numbers, hire dates and certificates (with uploaded copies).
Most of this is business information. Some of it is personal information, such as a supplier contact’s name on an invoice, a delivery driver’s signature, or a staff member’s phone number or food-safety certificate.
3.2 Who is responsible for it
The customer is responsible for its data and decides what goes in. We process it on the customer’s behalf, only to provide, secure and support the service, and to produce totals that do not identify any customer or individual. We do not sell it, use it for advertising, or use it to build profiles.
Customers are responsible for having the right to upload what they upload, including any notice or consent their own staff and suppliers are owed.
3.3 Access by us
Customer data is separated by organization throughout the application, and one customer cannot see another’s. We can access an organization’s data to provide support, investigate a problem or run the service.
3.4 If you are an employee or supplier contact of a customer
If your information is in Foodnance because your employer or a business you work with put it there, that business, not Foodnance, decides why it is held. Please make access, correction and deletion requests to them. If you write to us instead, we will pass your request to the business and tell you we have done so, unless the law requires us to answer directly.
4. Who we share information with
We do not sell personal information. We share it only with the service providers below, who may use it only to provide their service to us, and where the law requires or permits.
| Provider | What for | What they receive | Where |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, network delivery and security | All information in the service, including uploaded files | Global network; mainly the United States |
| Anthropic, PBC | Reading invoices and recipes, and suggesting categories for new products (section 5) | Invoice and recipe images and text; product names | United States |
| Resend | Delivering service emails | Recipient name and email, and the message (for example a reset link) | United States |
| Paddle.com | Payment, invoicing and sales tax, as Merchant of Record | Billing details you give it | United Kingdom and worldwide |
| Plausible Analytics | Counting visits to our public pages, without cookies | Anonymous page-view and click totals; no personal profile | European Union |
| Google Fonts, jsDelivr | Loading fonts and code libraries in your browser | Your IP address and browser details, directly from your browser | Various |
We may also disclose information: (a) to comply with a law, court order or lawful request; (b) to protect the rights, property or safety of Foodnance, our customers or others; (c) in a merger, acquisition, financing or sale of the business, subject to confidentiality; and (d) with your consent.
5. Artificial intelligence and your invoices
To turn an uploaded invoice or recipe into structured data, we send its image or text to Anthropic through its commercial API. To suggest a category for a newly created product, we send the product names (not the invoice). That is the only AI processing we do.
- Invoices can contain personal information, such as a contact’s name, a signature, an address or a phone number. It goes to Anthropic along with everything else on the page.
- Under Anthropic’s commercial terms, it may not train its models on customer content sent through its services. Its published policy is currently to delete API inputs and outputs automatically after a short period (currently 7 days). These terms are set by Anthropic and can change.
- We do not use your documents to train any model of our own.
- AI makes mistakes. What it reads is a suggestion for you to check, not a verified result. See our Terms of Service. No decision about a person is made by AI. It reads figures and text from business documents.
6. How long we keep information
- While your account is active, we keep your account information and your data so you can use the service.
- Invoices, products, stock and recipes are voided or archived, not erased, when you remove them, so your history and reports stay consistent. They stay in your account until it closes. This also means a deleted staff member or supplier contact can remain in historical records.
- When an account closes, we keep its data for 30 days so it can be exported, and then permanently delete it. Copies may remain for a short time afterwards in our provider’s backups, until they rotate out.
- Password-reset and invitation links are single-use and expire.
- Emails you send us are kept for as long as needed to answer you and for our records, and generally no longer than two years.
- We may keep information longer where the law requires, for example financial records, or to resolve a dispute.
7. Where information is stored
Our providers include companies in the United States and elsewhere. Cloudflare operates globally, and we do not currently choose a single country for storage. Your information may therefore be stored or processed outside Canada, including in the United States and Japan, and while there it may be accessible to courts, law enforcement and national-security authorities of that country under its laws. We rely on our providers’ contracts and security practices to protect it and to use it only for our purposes, but we cannot promise that foreign law will not apply to it.
8. Security
We protect information with measures appropriate to how sensitive it is. These include encryption of data in transit; one-way hashing of passwords with a unique salt; sign-in cookies that scripts cannot read; separation of each customer’s data; access controls by role; and single-use, expiring reset and invitation links.
No system is perfectly secure, and we cannot guarantee that information will never be accessed without authorisation. Please choose a strong, unique password and tell us straight away at privacy@foodnance.com if you think your account has been compromised.
If a breach of our security safeguards creates a real risk of significant harm to someone, we will report it to the regulator, notify the people affected, and notify affected customers, as the law requires. We keep a record of every breach.
9. Your rights
Under applicable privacy law you may ask us to:
- tell you what personal information we hold about you, how we use it and who we have shared it with;
- give you a copy of it;
- correct anything inaccurate;
- delete it or stop using it, where we no longer need it or the law does not require us to keep it; and
- withdraw your consent, subject to legal and contractual limits.
Write to privacy@foodnance.com. We may need to confirm who you are first. We respond within 30 days and will explain if we cannot do what you ask, for instance because it would reveal someone else’s information. Access is free unless the request is unreasonable, and we will tell you any cost beforehand.
Your organization’s owner can also correct team-member details and remove users from the account inside Foodnance. To ask for a copy of your organization’s data, email us.
If you are unhappy with our answer, you can complain to us first, and then to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
10. Children
Foodnance is business software and is not intended for anyone under 18. We do not knowingly collect information from minors. If you think we have, contact us and we will delete it.
11. Changes to this policy
We will post any change here and update the “last updated” date. For a material change, such as a new category of information, a new kind of sharing, or a new provider that handles customer data, we will notify account owners by email or in the app at least 30 days before it takes effect.
12. Contact
Privacy contact: Simone Isonni, privacy@foodnance.com. Foodnance is operated by Simone Isonni, doing business as Foodnance, Yokohama, Japan. For other questions: hello@foodnance.com. For questions about a charge: billing@foodnance.com.