Privacy Policy
Effective September 5, 2026
This policy explains how Carlos Ubillus, doing business as RestoreCC ("Restore," "we," or "us"), collects, uses, discloses, retains, and protects information through restorecc.io and the Restore restaurant-compliance service.
Information We Collect
- Account and contact data: email address, hashed password, restaurant or provider name, contact name, telephone number, address, trade coverage, boroughs, licenses, and account preferences.
- Restaurant and public-record data: CAMIS, location, inspections, violations, hearings, penalties, complaints, permits, and related records obtained from NYC agencies and other public sources.
- Service and advisory data: watchlists, claimed leads, contact reveals, messages, job notes, invoices, compliance-review findings, recommendations, internal workflow status, and documents or photographs you upload as evidence.
- Payment data: Stripe customer, checkout, payment, and subscription identifiers, amount, status, and billing period. Restore does not receive full payment-card numbers.
- Technical and security data: IP address, user agent, request identifier, timestamps, authentication attempts, security events, error details, and product actions needed to operate and protect the service.
- Communications: support, privacy, billing, and other messages you send us.
Purposes and Legal Bases
We use information to provide accounts, public-record intelligence, alerts, compliance reviews, evidence delivery, provider matching, billing, support, fraud prevention, security, product improvement, and legal compliance. Where GDPR or similar law applies, our legal bases are performance of a contract or requested pre-contract steps, our legitimate interests in operating and securing Restore, compliance with law, and consent when a law requires consent. You may withdraw consent without affecting earlier lawful processing.
How We Disclose Information
We do not sell personal information and do not share it for cross-context behavioral advertising. We disclose only what is needed to service providers and participants in a requested workflow. Current categories include Vercel and Render for hosting, Supabase for database services, Stripe for payments, Resend for transactional email, Sentry when error monitoring is enabled, Anthropic for violation explanations using public violation text, and NYC Open Data as a public-record source. Restaurants and providers may receive each other's relevant business information when needed to fulfill a claim, quote, job, review, or advisory request. We may also disclose information when legally required or during a business transfer.
Cookies and Tracking
Restore currently uses strictly necessary signed, Secure, HttpOnly, SameSite cookies for authentication and security. We do not currently use advertising cookies, tracking pixels, or cross-site behavioral analytics. If that changes, we will update this notice and obtain consent or provide opt-out controls where required, including recognition of applicable browser-based opt-out signals.
Retention
- Active account, watchlist, review, and evidence data: while the service is active, then deleted or anonymized following a verified request unless an exception applies.
- Authentication and raw security logs: generally up to 12 months, unless needed to investigate an incident.
- Support communications and operational records: generally up to 24 months after resolution.
- Billing and transaction records: up to seven years where reasonably needed for tax, accounting, dispute, or legal obligations.
- Unsubscribe suppression: a minimal email suppression may be retained to honor your request not to receive alerts.
- Backups: removed through the ordinary backup-expiration cycle and protected from operational use except for disaster recovery.
Your Privacy Rights
Depending on your location, you may request access to and a portable copy of your data; correction; deletion; restriction; objection; withdrawal of consent; or information about categories, sources, purposes, recipients, sale, or sharing. California residents may also request correction, opt out of sale or sharing, limit certain uses of sensitive information where applicable, and receive equal service after exercising a right. We do not sell or share personal information for behavioral advertising.
Email privacy@restorecc.io. We will verify requests proportionately, respond within the legally required period (generally 30 days under GDPR or 45 days under California law), explain any lawful exception, and notify relevant processors when required. Authorized agents may submit requests with proof of authority. EEA/UK users may complain to their local supervisory authority.
International Processing, Children, and Security
Restore operates from the United States. Where required, international transfers are protected through contractual or other lawful safeguards. Restore is a business service not directed to children under 16. We use HTTPS, authenticated database connections, access controls, administrator MFA, revocable sessions, password hashing, CSRF protections, throttling, private document delivery, and restricted database permissions. No system is perfectly secure; report concerns to security@restorecc.io.
Changes and Contact
We will post revisions here and provide additional notice when legally required. Privacy requests: privacy@restorecc.io. Security reports: security@restorecc.io. Billing: billing@restorecc.io. Controller: Carlos Ubillus DBA RestoreCC, New York, New York, United States.