(Legal)

Privacy Policy

Effective date: September 16, 2026

Delight AI Technologies, Inc. (“Delight AI”, “we”, “us”) builds Delight One, an operating assistant that restaurant companies use to run their restaurants. This policy explains what personal information we handle on our website at delightai.ai and in the Delight One application, why, who we share it with, how long we keep it, and what choices you have.

We are a business-to-business company. Most of the information we hold is work information about people who run restaurants, not information about consumers.

01 Scope, and the two roles we play

We handle personal information in two different situations, and it matters which one you are in.

Our website, where we decide

When you visit delightai.ai or submit the demo request form, we decide what is collected and why. Sections 2, 9, 10, 14 and 15 apply directly to you.

Delight One, where our customer decides

When a restaurant company subscribes to Delight One, it puts its own business records into the product: sales, labour, inventory, guest feedback and so on. Some relate to people, such as an employee’s hours or a guest’s survey comment. For that information our customer decides what is collected and why, and we act on its instructions under our agreement with it. In the language of US state privacy laws, the customer is the business or controller and we are the service provider or processor.

If you work for a customer and want to see, correct or delete information about you in Delight One, ask your employer first: they control it and can act on it in the product. If you contact us, we will pass the request to them and help them answer it, unless the law says otherwise.

This policy does not cover the practices of our customers, of the brands they operate under, or of any site we link to.

02 What we collect on this website

What you type into the demo request form

The form asks for your work email address, first name, last name and company, and offers an optional phone number. We also record whether you ticked the consent box, and the date and time.

The form includes one hidden field that a person never sees and never fills in. Bots tend to fill it in, so if it arrives filled we treat the submission as spam and discard it. It collects nothing about you.

Your submission goes to our own service at wen.delightai.net, is stored in our Google Cloud environment in the United States, and is emailed to our founders so someone can follow up.

What our servers record automatically

The website is served by Google’s Firebase Hosting, and the form submission is received by our own service on Google Cloud. Both keep ordinary server logs: the IP address a request came from, the date and time, the page or endpoint requested, the referring page and the browser user-agent. We use them to keep the site available, investigate errors and detect abuse. We keep our own platform logs for up to 30 days, and our hosting provider keeps standard server logs for a limited period under its own policies.

Fonts loaded from Google

This site uses web fonts hosted by Google, so your browser requests them from fonts.googleapis.com and fonts.gstatic.com. Google therefore receives that request, including your IP address and user-agent. We do not control what Google does with it, and Google’s privacy policy applies.

What we do not do here

The website sets no cookies and runs no analytics, no advertising pixels, no session recording and no third-party tracking. We do not buy contact lists or personal information from data brokers. If we add analytics or cookies, we will update this policy before turning them on.

03 What we collect in the Delight One application

Access is limited to our customers and the users they authorize. The information falls into four groups.

Account and identity. Name, work email, phone if provided, job role, the permissions on the account, and the restaurants, districts or markets it may see. To sign you in safely we hold a stored password verifier rather than the password itself, passkey credentials if you register one, sign-in timestamps and the IP addresses of sign-in attempts, plus an audit record of sensitive actions.

Customer operational data. The business records our customers bring in: sales and transaction totals, labour hours, schedules and time punches, inventory counts and food cost, guest survey responses and comments, drive-thru and service timing, facilities and maintenance records, and the tasks, notes and photographs managers create as they work. Some relate to identifiable people, such as an employee whose punches are shown.

Usage information. Which screens an account opens and when, which reports and alerts are run, browser and device type, and diagnostics when something fails.

What you send us. Support requests, email and other messages, with our replies.

We do not collect government identifiers such as Social Security numbers, financial account numbers, or health information.

04 Where the information comes from

  • From you, when you fill in the form, sign in or write to us.
  • From your employer, when a customer creates an account for you or sets your permissions.
  • From systems our customers connect, when a customer authorizes us to read the systems it already uses: point-of-sale and sales reporting, drive-thru timers, workforce and payroll systems, guest survey providers and vendor feeds.
  • From our own systems, as server logs, usage records and diagnostics.

05 How we use information

  • To respond to you. To reply to a demo request, arrange a demonstration and discuss whether the product fits your business.
  • To provide the product. To run accounts, authenticate users, and calculate and deliver the reports, scorecards and alerts our customers configure.
  • To support our customers. To investigate issues, restore data and help a customer roll the product out.
  • To keep things secure. To detect and prevent fraud, abuse and unauthorized access, and to keep audit records.
  • To improve what we build. To understand which features are used and where the product fails, using aggregated or de-identified information where practical, which we do not try to re-identify.
  • To market to business contacts who have consented, as described in Section 10.
  • To meet our obligations. To comply with law and to establish, exercise or defend legal claims.

We do not use customer operational data to advertise to restaurant guests, and we build advertising profiles of no one.

06 AI features

Delight One includes features that use artificial intelligence: you can ask a question about your own restaurants in ordinary language, and the product can write summaries and longer analyses of your numbers.

To produce an answer, the relevant slice of the customer’s own data and the question are sent to Anthropic, which provides the Claude models we use, under a contract with us. Anthropic is our AI model provider. The application itself runs on Google Cloud, as Section 7 describes.

That contract requires Anthropic to process the information only to return a result to us. It does not use the information to train its models. The information is retained only as long as needed to run the request and to meet limited abuse-monitoring obligations.

What an AI feature can see is limited to what the signed-in account may already see, so a manager scoped to a district gets answers about that district. AI output can be wrong: the product shows the underlying figures alongside the answer, and decisions stay with the operator.

07 How we share information

Service providers and subprocessors

Companies that run parts of our service for us, under contracts limiting them to our instructions and requiring them to protect the information:

Google Cloud
Hosting, compute, databases, storage and logging for the application and for form submissions. United States.
Firebase Hosting (Google)
Serving this website, and its server logs.
Google Workspace
Our business email and calendar, including the copy of your form submission that reaches our founders, and the product and marketing email we send.
Anthropic
The Claude models behind the AI features described in Section 6.

We will update this list when our providers change.

Everyone else

The customer organization. If you use Delight One for a customer, that customer can see your account, your activity and the operational data for its restaurants, as its agreement allows.

Legal and safety. Where the law requires it, in response to lawful process, to enforce our Terms of Service or a customer agreement, or to protect the rights, property or safety of Delight AI, our customers or the public. If a request covers customer data we will tell the customer so they can respond, unless we are legally prohibited.

Business transfers. In a merger, acquisition, financing or sale of assets, information may transfer. The recipient stays bound by this policy for what it receives, or you will be told before a materially different policy applies.

At your direction. With anyone else you or our customer asks us to share it with.

08 We do not sell or share your personal information

We do not sell personal information and have not sold any in the twelve months before the effective date of this policy. We do not share it for cross-context behavioural advertising, we do not run targeted advertising, and we do not disclose it to third parties for their own direct marketing. We do not use or disclose sensitive personal information for any purpose that would give you a right to limit it under California law.

09 Cookies and similar technologies

This website sets no cookies at all and stores nothing in your browser beyond what the browser caches on its own.

The Delight One application is different, because it has to know who is signed in. It stores what it needs for sign-in, session security and your saved preferences, such as the date range you last looked at. These are strictly necessary or functional; there is no advertising or cross-site tracking in the product.

Because we use no advertising cookies, there is nothing here for a Global Privacy Control signal to opt out of. If that changes, we will honour the signal and say so.

10 Marketing messages and your choices

Email. Ticking the consent box on the form means you agree to receive product and marketing information from us. Every marketing email carries an unsubscribe link, and you can write to hello@delightai.ai instead. We act within ten business days and keep a record of your unsubscribe so we do not contact you again by mistake. We will still send messages that are not marketing, such as a reply to your question or a notice about this policy.

Phone and text. The phone field is optional. If you give us a number, you agree that we may contact you at it about your request and our products, by phone call or text message, placed by a person on our team or sent by our systems. Text messages may incur charges from your mobile carrier. Reply STOP to any text to opt out of texts, or tell us by email or on a call. Giving us a phone number is never a condition of buying anything.

Product notifications. Alerts and reports inside Delight One are configured by our customer and by you, where you can change them or switch them off.

11 Security

We follow industry-standard practices to protect what we hold: encryption in transit using current TLS versions; encryption at rest; role-based access so each account sees only the restaurants it is scoped to; multi-factor and passkey sign-in; least-privilege administrative access with confidentiality obligations on our staff; audit logging of sensitive actions; separation of production from testing environments; and regular patching and backups.

No system is completely secure, and we do not hold a third-party security certification. If you think an account or system has been compromised, write to hello@delightai.ai straight away. Where we are required to notify a customer or an individual about a security incident, we will do so as the law and our customer agreements require.

12 How long we keep information

We keep personal information for as long as we need it for the purpose we collected it, then delete it or remove what identifies you. We keep it longer where the law requires it or a legal claim needs it.

Demo requests
Until you ask us to delete them, or 24 months after our last contact with you, whichever comes first.
Unsubscribe records
Kept indefinitely, so we do not contact you again.
Server logs
Our own platform logs, up to 30 days. Our hosting provider keeps standard server logs for a limited period under its own policies.
Account data and customer operational data
For the term of the customer’s agreement and up to 90 days after it ends, then deleted or anonymized unless the law requires us to keep it longer.
Support messages
As long as needed to resolve the matter and keep a service history.

13 Children

Our website and product are business tools. The Site is not directed to anyone under 18, and we do not knowingly collect personal information from children under 13. If we learn that we have collected a child’s information here, we will delete it. Tell us at hello@delightai.ai.

Delight One may hold workforce records that customers provide about their own employees, including employees under 18 where the law permits. We process those records only on the customer’s instructions, under our agreement with the customer and its own notices to its employees.

14 Your privacy rights in the United States

Residents of California and of other states with comprehensive privacy laws, such as Colorado, Connecticut, Texas and Virginia, have rights over their personal information. Depending on where you live, those rights include the right to:

  • Know what personal information we collected about you, where it came from, why, and who we disclosed it to, and to get a copy;
  • Delete what we hold, subject to the exceptions the law allows;
  • Correct personal information that is inaccurate;
  • Opt out of the sale or sharing of your personal information, and of targeted advertising and certain profiling. As Section 8 says, we do none of these, so there is nothing to opt out of;
  • Limit the use of sensitive personal information, which we do not use in a way that triggers this right; and
  • Not be discriminated against for exercising these rights. We will not deny you service, charge a different price or give lower quality because you made a request.

California’s “Shine the Light” law lets residents ask about personal information disclosed to third parties for their direct marketing. We make no such disclosures.

How to make a request

Email hello@delightai.ai with “Privacy request” in the subject. To protect you we will ask for enough information to be reasonably sure the request is yours, usually by writing to the address we already hold. We respond within 45 days, and may extend once by a further 45 days where that is reasonably necessary, in which case we will tell you within the first period. There is no charge unless a request is excessive or repetitive, and we will say so first. An authorized agent may act for you with written permission we can verify.

If we deny a request, we will explain why, and you may appeal by replying to our answer. We answer appeals within 45 days. If your request concerns information held in Delight One for your employer, see Section 1.

15 Categories of personal information we handle

Stated in the categories California law uses, and covering the twelve months before the effective date, we handle: identifiers (name, work email, optional phone, employer, account identifier, IP address); professional or employment information (job role, permissions, the restaurants an account covers, and workforce records such as hours, schedules and punches inside a customer’s account); commercial information (your interest in our product, our contact history with you, and a customer’s operational and transaction records); internet or network activity (pages and endpoints requested, browser and device type, referring page, sign-in attempts, and the screens and reports an account uses); guest feedback (survey responses and comments held for a customer, whose guests we never contact); visual information (photographs managers attach to maintenance and task records); and geolocation at the level of restaurant addresses and coordinates, which identify places of business rather than a person.

The only sensitive personal information we handle is your sign-in credentials, held to authenticate you. We do not collect government identifiers, financial account numbers, health data, precise device location, or information about race, religion, union membership or sexual orientation.

Sections 2 and 3 say what we collect, Section 4 where it comes from and Section 5 why. We disclose these categories to the service providers in Section 7, and to a customer organization where the information belongs to it. We sell none of it, share none of it for advertising, and do not knowingly collect personal information about children under 16.

16 Visitors and users outside the United States

Delight AI is based in the United States, and our systems and the people who run them are here. If you use our website or product from another country, the information you give us is transferred to the United States and processed here, where privacy laws may differ from those where you live and public authorities may be able to access information under US law.

Our website and product are directed to businesses in the United States, and this policy is written for United States law.

18 Changes to this policy

We will update this policy as our product and practices change. When we do, we post the updated effective date at the top of this page. For material changes we may also email people who have submitted the demo request form, and where the law requires it we will notify you directly.

19 Contact us

Questions, requests and complaints about privacy all go to the same place, and a person reads them.

Delight AI Technologies, Inc.
hello@delightai.ai

Notices sent to us by email are effective when sent. See also our Terms of Service.