Legal
Privacy Policy
Effective July 16, 2026
Our commitment
We do not sell your data, or your staff's data, to anyone, for any amount, ever. We do not share it with third parties for their own marketing or advertising purposes, and we do not use it to build advertising profiles. This applies for as long as Pali IQ operates.
1. Scope
This policy covers data submitted to Pali IQ by our customers (restaurant and QSR organizations) and their staff, operated by NMP. ("we", "us").
2. What we collect
- Account data: name, email, role, and a securely hashed password for each login.
- Workforce data your organization enters: staff names, roles, phone numbers, pay rates, availability, shift schedules, and coverage/call-out records.
- Operational data: location sales and labor-hour figures used to power forecasting and coverage recommendations.
- Usage data: login activity, questions sent to the chat copilot, and application logs, kept for security and debugging.
3. How we use it
We use your data only to operate the Service for the organization that submitted it: building schedules and forecasts, flagging compliance and coverage risks, and answering questions inside the copilot. Data from one customer is never used to answer questions for, or improve results for, another customer.
4. What we never do
- Sell your data or your staff's data to data brokers or advertisers.
- Share it with third parties for their own marketing purposes.
- Use it to target ads, on our platform or anyone else's.
5. Who processes data on our behalf
A small number of vetted providers process data strictly to help us deliver the Service. None of them are permitted to sell it or use it for their own purposes:
- Our AI/LLM provider (OpenAI): processes chat questions and the workforce context needed to answer them, in order to generate the copilot's responses.
- Cloud hosting/infrastructure: stores and runs the application and database.
6. Data retention
Data is retained for as long as your organization's account is active. On request or account closure, we delete or anonymize it, except where we're required to keep it longer by law.
7. Security
Passwords are stored as salted hashes, never in plaintext. Access to data is scoped by role (client admin, location admin, staff) and enforced on the server for every request. Data in transit is encrypted via HTTPS/TLS.
8. Your rights
You, or your organization's admin, can request a copy of, a correction to, or deletion of your data at any time using the contact below.
9. Changes to this policy
If this policy changes, we'll update the effective date above and, for material changes, notify account admins directly.
10. Contact
Questions or requests about your data: npatel121.py@gmail.com