Trust & Security

Trust, security & privacy at GovReady Restaurant

This page is maintained by the GovReady team to answer common security and privacy questions about GovReady Restaurant. It describes the controls we have in place today and is not an independent certification or audit.

Security is a shared responsibility: our hosting platform secures the underlying infrastructure, we operate the application and its data layer, and customers are responsible for managing user access and the content they upload.

Access & authentication

Sign-in is handled by our managed authentication provider. Passwords are never stored in plain text. Sessions use short-lived tokens that refresh automatically and can be revoked by signing out.

Role-based access is enforced server-side. Owners, managers, and employees only see the branches and restaurants they belong to. Super-admin actions are restricted to named platform operators.

Hosting & platform

The application runs on the Lovable Cloud platform, which provides managed compute, database, storage, and TLS in transit. The platform handles infrastructure patching, network isolation, and encrypted backups of the managed database.

Data we collect & how it is used

We collect the account, restaurant, and compliance data customers enter into the product (for example: branches, staff names, training records, temperature logs, inventory and incident reports). This data is used to operate the service and is only visible to the customer's own team based on their role.

Row-level security policies on every table restrict reads and writes to the owning restaurant or branch. Sensitive identifiers such as license keys are not exposed to the client.

Subprocessors & integrations

We rely on a small number of subprocessors to run the service, including our hosting and database provider, our payments processor (Stripe) for subscription billing, and our optional AI provider for in-product assistance. Customers can disable optional integrations from their account settings.

Cookies & analytics

We use strictly necessary cookies to keep users signed in. We do not sell personal data or use third-party advertising trackers inside the authenticated app.

Retention & deletion

Customer records are retained while the account is active so that compliance history remains available for inspections. Customers can request deletion of their account and associated data by contacting support; uploaded files are removed from storage as part of that process.

Security contact & vulnerability reporting

If you believe you have found a security issue, please email us so we can investigate. Include steps to reproduce and any relevant logs. We ask researchers to avoid accessing data that does not belong to them and to give us a reasonable window to respond before public disclosure.

General privacy and data requests can be sent through our contact form.

Last reviewed: July 2026. This page describes current practices and may be updated as the product evolves.