Privacy Policy
Last updated: July 15, 2026
This Privacy Policy explains how Sofrito (“Sofrito,” “we,” “us”) collects, uses, and shares information when you use our website and services (the “Service”). By using the Service, you agree to this Policy.
1. Information we collect
- Account and contact details you provide, such as your name, email, phone, and business name.
- Business profile you provide during sign-up and onboarding, such as business type, role, number of locations, revenue range, goals, and the systems you use.
- Operational data you upload or enter, such as receipts, invoices, sales, and labor information, used to produce your cost leak check.
- Payment information is collected and processed directly by Stripe. We do not store your full card number; we receive limited billing details and subscription status from Stripe.
- Technical and usage data, such as device and log information and basic analytics needed to operate and secure the Service.
2. How we use information
- to provide, personalize, and improve the Service and your weekly cost leak check;
- to process subscriptions and payments and to communicate about your account;
- to send the reports and notifications you request, on the schedule you choose;
- to secure the Service, prevent abuse, and comply with legal obligations.
3. How we share information
We share information only as needed to run the Service, including with:
- Stripe — payment processing and subscription management;
- Supabase — database and file storage;
- Cloudflare — hosting, content delivery, and bot/security protection;
- Email delivery providers — to send your reports and account emails.
We do not sell your personal information. We may disclose information if required by law or to protect the rights, safety, and security of Sofrito and its users. If Sofrito is involved in a merger or acquisition, information may be transferred as part of that transaction.
4. Data retention
We keep your information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion as described below.
5. Security
We use reasonable technical and organizational measures to protect information, including encryption in transit and database access controls (row-level security) that restrict access to your data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Your choices and rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to opt out of marketing emails. To make a request, contact us at hello@sofrito.app. You can unsubscribe from marketing messages at any time; we will still send essential account and billing messages.
7. Cookies and local storage
We use browser local storage to remember preferences (such as your report-delivery choices) and may use cookies or similar technologies for essential functionality, security, and basic analytics. You can control these through your browser settings.
8. Children
The Service is intended for businesses and is not directed to children under 18.
9. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated through the Service or by email, and the “Last updated” date above will change.
10. Contact
Questions or requests? Contact us at hello@sofrito.app.
This document is a general starting point and not legal advice. Please have it reviewed by a qualified privacy professional or attorney, and update the contact email and any jurisdiction-specific disclosures (for example, GDPR/CCPA) that apply to your business.