Fortune OS privacy notice
This notice describes the data the Fortune OS application at app.fortuneos.ai stores and processes, why, where, and what you can do about it. It covers merchants and their staff, guests who order through a QR menu, and integrations that reach the API or the MCP server on a merchant's behalf.
Data an account provides
An account holds a name, an email address, a password hash or a linked Google or Fortis sign-in, an optional avatar, interface preferences such as locale and theme, and the memberships, roles and venues it belongs to. A merchant who enrols a device PIN stores that PIN as a hash bound to the device. Sign-in and sign-out events, sessions and API keys are recorded so that access can be reviewed and revoked.
Business data merchants store
Merchants store their catalog, orders, kitchen tickets, shifts, payments, receipts, invoices, tables, staff assignments and reports. Orders may carry a guest's table, a customer name or an invoice party the merchant enters. A guest who orders through a QR menu provides only what the merchant's menu asks for. This data belongs to the merchant; Fortune OS processes it to run the venue and does not sell it.
Cookies and local storage
- A session cookie keeps you signed in; it is HTTP-only and expires with the session.
- Preference cookies remember locale, theme, the active venue and shift so pages render correctly on the server.
- A feature-flag cookie keeps the variant of an experiment stable for your device.
- No advertising or cross-site tracking cookies are set.
Service providers
- Hosting and database: Amazon Web Services in the Frankfurt (eu-central-1) region, with production backups.
- Billing: Stripe processes the subscription and the card; Fortune OS stores the subscription state and never the card number.
- Email: transactional mail such as verification, welcome and billing messages is sent through Resend from the fortuneos.ai domain.
- Error and performance monitoring: Sentry, hosted in the European Union, receives error reports with personal data scrubbed before they leave the application.
- Bot protection: Cloudflare Turnstile verifies sign-up and sign-in forms where it is enabled.
- Sign-in providers: Google, when you choose it, and the Fortis platform for merchants migrating from it.
- Payment terminals and gateways a merchant connects, such as N-Genius or MyFatoorah, receive the payment data those services need.
AI agents and API access
An API key or an OAuth grant lets an AI agent or an integration read, and where explicitly delegated change, the business data the account is already authorized for. Keys expire, can be revoked at any time, and every call is authorized again against the live account, memberships and permissions. Business records exclude credentials, personal account state and internal execution data. What an external AI client does with the data it retrieves is governed by that client's own terms.
Retention and deletion
Operational records are kept for as long as the business is active, because orders, invoices and payments are financial history. Archiving a business, venue or item removes it from every ordinary listing while retaining the history that references it. Deleting an account removes the sign-in and its personal profile; business records the account created stay attributed to the business. Backups are retained on a rolling schedule and expire automatically.
Your choices
You can view and change your profile, preferences, sessions and API keys from the account settings, export the reports the business owns as CSV or PDF, and request access to, correction of, or deletion of personal data through the channels on the contact page. Requests are made from the account they concern. This notice changes when the product does; the date at the foot of the page is the date of the current version.