Restore

Privacy Policy

Effective September 5, 2026

This policy explains how Carlos Ubillus, doing business as RestoreCC ("Restore," "we," or "us"), collects, uses, discloses, retains, and protects information through restorecc.io and the Restore restaurant-compliance service.

Information We Collect

Purposes and Legal Bases

We use information to provide accounts, public-record intelligence, alerts, compliance reviews, evidence delivery, provider matching, billing, support, fraud prevention, security, product improvement, and legal compliance. Where GDPR or similar law applies, our legal bases are performance of a contract or requested pre-contract steps, our legitimate interests in operating and securing Restore, compliance with law, and consent when a law requires consent. You may withdraw consent without affecting earlier lawful processing.

How We Disclose Information

We do not sell personal information and do not share it for cross-context behavioral advertising. We disclose only what is needed to service providers and participants in a requested workflow. Current categories include Vercel and Render for hosting, Supabase for database services, Stripe for payments, Resend for transactional email, Sentry when error monitoring is enabled, Anthropic for violation explanations using public violation text, and NYC Open Data as a public-record source. Restaurants and providers may receive each other's relevant business information when needed to fulfill a claim, quote, job, review, or advisory request. We may also disclose information when legally required or during a business transfer.

Cookies and Tracking

Restore currently uses strictly necessary signed, Secure, HttpOnly, SameSite cookies for authentication and security. We do not currently use advertising cookies, tracking pixels, or cross-site behavioral analytics. If that changes, we will update this notice and obtain consent or provide opt-out controls where required, including recognition of applicable browser-based opt-out signals.

Retention

Your Privacy Rights

Depending on your location, you may request access to and a portable copy of your data; correction; deletion; restriction; objection; withdrawal of consent; or information about categories, sources, purposes, recipients, sale, or sharing. California residents may also request correction, opt out of sale or sharing, limit certain uses of sensitive information where applicable, and receive equal service after exercising a right. We do not sell or share personal information for behavioral advertising.

Email privacy@restorecc.io. We will verify requests proportionately, respond within the legally required period (generally 30 days under GDPR or 45 days under California law), explain any lawful exception, and notify relevant processors when required. Authorized agents may submit requests with proof of authority. EEA/UK users may complain to their local supervisory authority.

International Processing, Children, and Security

Restore operates from the United States. Where required, international transfers are protected through contractual or other lawful safeguards. Restore is a business service not directed to children under 16. We use HTTPS, authenticated database connections, access controls, administrator MFA, revocable sessions, password hashing, CSRF protections, throttling, private document delivery, and restricted database permissions. No system is perfectly secure; report concerns to security@restorecc.io.

Changes and Contact

We will post revisions here and provide additional notice when legally required. Privacy requests: privacy@restorecc.io. Security reports: security@restorecc.io. Billing: billing@restorecc.io. Controller: Carlos Ubillus DBA RestoreCC, New York, New York, United States.