Privacy Policy

Last updated: July 10, 2026

This Privacy Policy explains how GomezTek (“we,” “us,” “our”) collects, uses, shares, and protects information when you use gomeztek.com, mesaos.com, MesaOS (our restaurant operating system), demos, and related services (together, the “Services”). By using the Services, you acknowledge this Policy. If you do not agree, do not use the Services.

1. Who we are

GomezTek is a software company. MesaOS is our restaurant product. For personal data we collect through our marketing sites and for operating MesaOS as a service provider to restaurants, GomezTek is typically the controller of account, billing, and site analytics data. For guest/customer data that a restaurant enters into MesaOS (orders, loyalty, etc.), the restaurant (Merchant) is generally the controller, and we process that data as a service provider / processor on the Merchant’s instructions.

2. Information we collect

2.1 Marketing websites (gomeztek.com, mesaos.com)

  • Technical data: IP address, browser/device type, pages viewed, referring URL, approximate location derived from IP, and timestamps.
  • Contact / demo forms: name, email, phone, city/state, business details, and message content you submit.
  • Cookies and similar tech: see Cookies.

2.2 MesaOS accounts and operations

  • Account & staff data: names, emails, phone numbers, roles, PINs/auth identifiers, login and security events.
  • Business data: menus, recipes, inventory, payroll/shift records, reports, settings, and other content you enter.
  • Guest / order data: order details, tickets, tips, and any guest contact info the Merchant chooses to store.
  • Payment metadata: payment status, amounts, last4/brand where provided by processors—not full card numbers (see Payments).
  • Support & logs: support tickets, audit logs, and diagnostic logs (we scrub secrets and card fields from logs where feasible).

2.3 Hardware lease

If we lease starter hardware (e.g. print box, card reader), we may collect shipping address, contact info, serial/asset IDs, and return/status records needed to manage the lease.

3. Artificial intelligence (AI) features

MesaOS may include optional AI features (for example Kitchen Setup, Product Coach, AI Rules, and the MesaOS Assistant). When you enable and use them:

  • We may send product/menu context you provide (names, descriptions, categories, options, photos you attach, and your AI Rules) to AI model providers or our AI gateway to generate suggestions.
  • AI output is propose-only until a human reviews and applies it. We do not intend AI to silently change prices, recipes, inventory, or guest-facing content.
  • AI providers may process prompts/outputs under their terms. Do not submit secrets, full payment card data, government IDs, or sensitive personal data into AI prompts unless necessary and lawful.
  • You (the Merchant) are responsible for reviewing AI suggestions before applying them and for the accuracy and legality of content you publish or use in operations.
  • We may log AI activity (e.g. that a suggestion was requested/applied) for security, billing, quality, and abuse prevention.

4. How we use information

  • Provide, secure, maintain, and improve the Services
  • Authenticate users, enforce roles, and prevent fraud/abuse
  • Process platform fees, invoices, and support requests
  • Operate optional AI features you enable
  • Analyze aggregated/de-identified usage to improve products
  • Send service/admin messages; marketing only where permitted
  • Comply with law and protect our rights and users’ safety

5. Cookies and similar technologies

We use cookies, local storage, and similar technologies:

  • Essential: session/login, security (e.g. CSRF), load balancing, and remembering basic preferences so the Services work.
  • Analytics: we may use privacy-minded analytics (e.g. Umami or similar) to understand page traffic. These tools may set cookies or use first-party storage; they are used to improve the sites, not to sell your data.
  • Third-party embeds: if we embed maps, video, payment widgets, or fonts from third parties, those parties may set their own cookies under their policies.

You can block or delete cookies in your browser. Blocking essential cookies may break login or checkout-related flows. Where required by law, we will present additional cookie choices.

6. Payments and card data

Card payments in MesaOS are typically processed by Stripe, Square, or another processor you connect. Those processors handle card data under their own terms and privacy policies. We do not store full primary account numbers (PANs), track data, or CVC. We may store payment intent/charge IDs, status, amounts, and receipt details such as card brand and last four digits. You authorize us and processors to process payment-related data to complete transactions and reconcile fees.

7. How we share information

We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are commonly defined under California law. We may share information with:

  • Service providers / subprocessors: hosting, databases, email, analytics, AI model providers, error monitoring, and similar vendors under contract.
  • Payment processors: Stripe, Square, or others you enable.
  • Professional advisors and authorities: when required by law, legal process, or to protect rights, safety, and security.
  • Business transfers: in a merger, acquisition, or asset sale, subject to appropriate protections.

Merchants may export or share their own Merchant Data with third parties they choose; that is outside our control once exported.

8. Retention and security

We retain information as needed to provide the Services, meet legal/accounting requirements, resolve disputes, and enforce agreements. We use reasonable technical and organizational safeguards (access controls, encryption in transit, selective encryption, backups, logging). No method of transmission or storage is 100% secure.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to / restrict certain processing. Merchants’ staff should contact their Merchant admin first for account data inside MesaOS. For GomezTek-controlled data, email [email protected]. We may need to verify your identity. Guests of a restaurant should contact that restaurant for requests about guest data the Merchant controls.

10. Children

The Services are for businesses and are not directed to children under 16 (or under 13 where that is the applicable standard). We do not knowingly collect children’s personal information for marketing. Merchants are responsible for any age-restricted sales compliance in their operations.

11. International transfers

We primarily operate in the United States. Information may be processed in the U.S. or other countries where our providers operate. By using the Services, you understand those transfers may occur. We take steps consistent with applicable law to protect transferred data.

12. Third-party links

Our sites may link to third-party sites or services. Their privacy practices are their own. Review their policies before providing information.

13. Changes

We may update this Policy by posting a new version and revising the “Last updated” date. Material changes may also be communicated by email or in-product notice where appropriate. Continued use after the update means you accept the revised Policy.

14. Contact

Privacy questions or requests: [email protected] · (562) 270-6101.

Addendum A — California (CCPA/CPRA)

If you are a California resident, you may have rights to know, delete, correct, and not be discriminated against for exercising privacy rights. Categories we may collect include identifiers, commercial information, internet activity, professional information (staff roles), and inferences. We collect them for the purposes in Section 4. We do not sell personal information or share it for cross-context behavioral advertising. To exercise rights: [email protected] or (562) 270-6101. You may use an authorized agent with proof of authorization.

Addendum B — Other U.S. states

Residents of states with consumer privacy laws (e.g. Virginia, Colorado, Connecticut, Utah, Texas, and others as enacted) may have additional rights to access, correct, delete, port data, or opt out of certain processing. Contact us as above. We will respond as required by applicable law.