Privacy Policy

Last updated: July 2026

1. Information We Collect

Ginger is a product of YSK Technologies LLC, an Indiana limited liability company ("YSK Technologies," "we," "us," or "our"). We collect different types of information depending on how you interact with Ginger:

Restaurant operators (merchants): When you sign up and use Ginger, we collect: restaurant name, address, and contact information; administrator and staff names and PIN codes (stored in bcrypt one-way encrypted form); menu data (item names, descriptions, prices, categories); transaction data (orders, payment amounts, tips); and device information and IP addresses.

Online ordering customers (end users): When customers place orders through your Ginger-powered ordering website, we collect: name and phone number; delivery address (if applicable); order contents; and payment information (processed by a third-party payment processor — see below).

AI phone ordering callers: When customers place orders through the AI phone ordering system, we collect: phone number (caller ID); name (verbally provided for pickup); and order contents. AI phone conversations are processed in real-time by a third-party AI service (Google Gemini). Ginger does not record or store call audio. However, the AI service provider may process conversation data according to its own data policies — see Google Gemini's Terms of Service for details.

2. How We Use Your Information

We use collected information to: provide and operate the POS system and related services; process orders and payment transactions; generate reports and analytics (available only to the restaurant operator); send service-related notifications (such as system updates or outages); provide customer support; improve our services and user experience; and comply with legal obligations. We do not use your information for advertising or marketing purposes unrelated to providing the Ginger service.

3. Information Sharing

We do not sell your personal information. We may share information with third parties in the following circumstances:

Payment processors: We share information necessary to complete payment transactions with Payroc or the restaurant's chosen payment processor. These processors have their own privacy policies, which we encourage you to review.

AI service providers: The AI phone ordering feature uses Google Gemini for real-time voice processing. Conversation data is transmitted to Google during processing. See Google's AI terms of service for their data handling practices.

Infrastructure providers: We use cloud infrastructure providers for database hosting, server-side functions, and website hosting. Your data is stored on servers located in the United States and protected by industry-standard security measures.

Legal requirements: We may disclose information if required by law or to protect our rights, safety, or property.

4. Data Security

We implement the following security measures: staff PIN codes are stored using bcrypt one-way encryption (we cannot view the original PINs); the database uses row-level security (RLS) policies to prevent cross-restaurant data access; all data in transit is encrypted via TLS; and payment information is processed by PCI-compliant third-party payment processors and is not stored on Ginger servers. While no system is 100% secure, we use industry-standard security practices to protect your data.

5. Customer Contact & SMS Privacy

When customers place orders through the AI phone system: the AI answers calls as an automated voice ordering system; Ginger does not record call audio; conversations are processed in real-time by Google Gemini to understand and respond to customer requests; we store the resulting order data (customer name, phone number, order contents) together with a redacted text transcript of the conversation, from which customer names and phone-number digit runs are removed before storage; transcripts are kept for up to 30 days and used only to diagnose ordering errors and improve menu comprehension; and caller phone numbers are used for order confirmation text messages, not for marketing. Restaurant operators are responsible for compliance with local laws and regulations regarding automated phone systems and caller handling in their jurisdiction.

Contact information customers provide: when a customer places an online or kiosk order, books a table, or joins a waitlist, we store the name, phone number, and (optionally) email address they provide, together with their order and booking history at that restaurant, so the restaurant can operate the transaction and recognize returning customers. This information is used for the transaction and its notifications, not for marketing.

SMS consent and opt-out: consent is collected where the number is given — verbally on AI phone-ordering calls (the AI reads a fixed disclosure and sends a text only if the caller answers yes; the answer is recorded with the order) and in writing at online checkout, reservation booking, the kiosk, and the host-stand waitlist, where a disclosure appears beside the phone field. Each consent record stores the timestamp, the channel, and the exact wording shown or read; web consent additionally records the IP address and browser details. These are transactional messages only — we do not send marketing or promotional text messages. Customers may opt out at any time by replying STOP to any message, or reply HELP for assistance. Standard message and data rates may apply. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Mobile phone numbers and SMS opt-in consent are never sold, rented, or shared with third parties or affiliates for their own marketing purposes.

6. Cookies and Local Storage

The Ginger POS application uses browser local storage to save language preferences and session data. The online ordering website uses cookies to maintain shopping cart state. Our marketing website (gingerserve.com) uses Google Analytics to measure traffic, and an advertising pixel from Reddit that tells us whether a visit or enquiry came from one of our ads. Both set third-party cookies and both are limited to the marketing website: neither runs in the POS application or on the online ordering pages, and no restaurant, staff, customer, or order data is shared with them.

7. Data Retention

Order and transaction data is retained for the duration of your active account to support reporting and analytics. If you cancel your account, we will delete your data within a reasonable timeframe (typically 90 days), unless we are legally required to retain it longer. Temporary session data from AI phone ordering expires automatically within 1 hour of order completion.

8. Your Rights

You have the right to: access the personal information we hold about you; correct inaccurate information; request deletion of your data (subject to legal retention requirements); and export your order and transaction data. To exercise these rights, contact us at info@gingerserve.com. We will respond within 30 days.

9. California Privacy Rights (CCPA)

If you are a California resident, under the California Consumer Privacy Act (CCPA), you have the right to: know what personal information we collect about you and how it is used; request deletion of your personal information; and opt out of the sale of your personal information.

We do not sell personal information. To exercise these rights, contact info@gingerserve.com. We will respond within 45 days of receiving your request. Exercising your privacy rights will not result in discriminatory treatment or denial of service.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be communicated via email to registered users, and the "Last updated" date on this page will be revised.

11. Contact Us

If you have any questions or concerns about this Privacy Policy, contact us at info@gingerserve.com.

Contact Us