Personal information at a glance
Read the Room Systems Inc., operating as RTR Systems and ReadTheRoom, collects account and contact details, organization access records, technical information, and the workforce or restaurant records needed for the features your organization uses. We receive information from you, your organization, connected systems, and your use of RTR.
We use it to provide accounts, operations and reports, support users, send requested communications, and protect the service. Your organization manages access to its records. Relevant information is also processed by our hosting, authentication, messaging and, where AI features are used or enabled, AI providers. Processing may occur outside Canada.
Optional Google sign-in uses basic identity information through WorkOS. It does not give RTR access to your Gmail, Drive files, or Google password.
Retention depends on the record's purpose, customer arrangements, and applicable obligations. Ending access does not automatically delete business history. You can ask about access, correction, deletion, or privacy concerns at [email protected].
1. Who we are and what this policy covers
Read the Room Systems Inc., operating as RTR Systems / ReadTheRoom ("RTR," "we," "us"), provides restaurant operations software. Personal information means information that identifies someone or can reasonably be linked to them, including information that identifies them when combined with other records.
This policy covers people who visit our website, request a demo or support, hold an RTR account, or have personal information included in a customer's records. Some people whose information is processed through RTR, including restaurant staff, may not have an RTR account themselves.
RTR helps restaurant organizations manage access, cashouts, tips, payments reconciliation, labour information, reporting, and related operations. An organization using RTR is our "customer." If you use RTR through your employer or another organization, that customer determines which business records it provides, the purposes for which it uses them, and who it authorizes to access them. We process those records to provide the customer's service. We also handle information for our own account administration, security, support, and business communications.
Your organization's employment and privacy policies may also apply. This policy does not replace its responsibilities or limit rights available under applicable law. Customers are responsible for providing the notices, permissions, and lawful instructions required for the employee and other personal information they provide to RTR. We remain responsible for our own handling of information and our obligations as their service provider.
2. Information we collect
The information depends on the features and integrations you or your organization use.
| Category | Examples and sources |
|---|---|
| Account and contact information | Name, email address, email-verification status, mobile number and account identifiers, provided by you, an inviting administrator, or an authentication provider. |
| Access and activity records | Organization and restaurant memberships, roles, invitations, access changes, the person who made an action, timestamps, and recorded reasons. |
| Workforce and operating records | Employee names and identifiers, work assignments, schedules, time punches, hours, wage rates, sales attribution, performance measures, cashouts, tips, payouts, adjustments, and related notes. These come from customer entry and connected systems. |
| Transaction records | Orders, items, amounts, payment status, transaction identifiers, payment method, card brand and last four digits, and other fields in transaction records supplied by connected systems. |
| Messages and requests | Demo enquiries, support correspondence, submitted content, operational messages and, when used, AI questions and conversation history. A demo request may include your name, work email, company, number of locations, and optional message details. |
| Technical information | IP address, browser and device information, session identifiers, request and sign-in times, errors, service usage, and security or diagnostic records. |
Connected restaurant systems may include Auphan, Clover, and 7shifts. These integrations supply restaurant and workforce information separately from Google sign-in. Please avoid entering personal information that is unnecessary for the task, including sensitive information in free-text notes or AI questions.
We collect information directly from you, from your organization and its authorized users, from connected providers, and automatically when you interact with our website or service. Reports and calculations can also create information about a person, such as attendance or sales-performance measures.
3. How we use information
We use personal information to:
- Create and maintain accounts, authenticate users, deliver invitations, and manage access.
- Provide the customer's selected operations, reconciliation, labour, tip, reporting, and communication features.
- Associate actions and records with the appropriate person and organization, and maintain business and access history.
- Answer questions, provide support, and respond to demo or business enquiries.
- Deliver requested operational reports and messages through configured channels.
- Diagnose problems, measure service performance, prevent abuse, and protect accounts and the service.
- Meet applicable legal obligations and address disputes or security incidents.
When a new use requires consent, we will explain that use and obtain the required consent before proceeding.
We generate summaries and aggregate reports for the customer's service. A total or score can still be personal information when it identifies an employee or a small group. Removing a name does not, by itself, make a record anonymous. Any separate use of genuinely anonymous statistics must respect customer agreements, applicable law, and the terms governing connected-platform data.
4. Google sign-in and WorkOS
If you choose Continue with Google, Google provides basic identity information to WorkOS, our authentication provider. This may include your Google account identifier, name, email address, verification status, and profile image. WorkOS provides RTR with the account information and authentication result needed to sign you in. RTR stores account identifiers and profile information needed to maintain your account, associate it with your organizations, and protect access.
The current Google sign-in connection requests basic identity permissions. It does not request access to Gmail messages, Google Drive files, calendars, or contacts. RTR does not receive your Google password.
We use Google sign-in information for account identity, authentication, profile presentation, and access security. Our handling of information received through Google sign-in is subject to the Google API Services User Data Policy.
You can manage or remove the connection through your Google Account; Google explains how. Removing that connection does not automatically delete your RTR account or previously stored records. To request deletion, see our data deletion request instructions.
5. AI features and connected tools
When you or your organization use or enable an AI feature, such as Ask your data or configured automated analysis, the question or instructions, relevant conversation history, and information retrieved for the task are sent to the AI services supporting it. This can include personal information from the customer's records, such as employee names, hours, sales attribution, or tip figures. An affected employee does not have to submit the question themselves for their records to be included. A user identifier and service-usage information may also be included.
RTR's in-app data assistant uses OpenRouter to access an xAI model. Other configured content-generation features may use Anthropic. We store conversation messages and usage records to support conversation history and operation of the service.
If you or your organization connect an external AI application or other tool to RTR, information requested through that connection is also handled by that application's provider under its own terms and privacy arrangements. Consider those arrangements before connecting a tool or submitting personal information.
Use of these features should follow your organization's policies. AI answers and automated performance summaries may be inaccurate; people responsible for employment, pay, or operational decisions should check the underlying records.
6. Who receives information
Your organization and its authorized users. Customer administrators and other authorized users can access information made available to their roles, such as employee or operating records, account email addresses, memberships, invitations, and access history. Your organization can also export or share reports through the service. Contact it for questions about its subsequent use or disclosure.
Service providers. We use third-party providers for hosting, data storage, authentication, communications and AI features. They receive information needed to perform these services on our behalf.
We require providers processing information on our behalf to protect it and limit their handling to the agreed service purposes and applicable legal requirements. Services that you or your organization connect independently also have their own privacy terms.
RTR does not sell personal information or share it for cross-context behavioural advertising.
Connections you or your organization use. Connected business systems and external tools receive information needed for the operations performed through those connections.
Other necessary disclosures. We may disclose information where required by law, to respond to a lawful request, or where legally permitted and reasonably necessary to investigate abuse, protect safety or security, or establish or defend legal claims.
Business transactions. If a financing, acquisition, reorganization, or sale of the business requires personal information to be reviewed or transferred, we will limit disclosure to what the transaction requires, subject to applicable law, confidentiality protections, and customer agreements. We will provide notice or obtain consent where required. A transaction does not automatically authorize an unrelated use of the information.
At your direction. We may make other disclosures that you specifically request or authorize, subject to applicable law and your organization's authority over its records.
8. Communications and marketing choices
We use your contact details to respond to your enquiry and deliver relevant service communications. If we send promotional messages, we will obtain consent where required and provide a way to stop them. You can request that RTR stop promotional communications at any time by emailing [email protected] or using the unsubscribe instructions in the message.
Where your organization uses RTR's operational messaging features, RTR processes the contact details, message content and service records needed for the enabled feature. Questions and replies handled by an AI feature may also involve the processing described in the AI section.
Stopping promotional messages does not stop necessary account, security, or requested service messages. Contact your organization about communications it sends or directs. Providing a mobile contact number for your account does not, by itself, subscribe you to operational reports or authorize promotional text messages.
9. Where information is processed and how it is protected
Our service providers may store or process information outside Canada. Information processed in another country is subject to that country's laws and may be accessible to its courts, law-enforcement, or other public authorities. Contact us for information about the providers and processing arrangements relevant to your account.
We use safeguards appropriate to the information and service, including encrypted connections, authentication, and access controls. No service can guarantee absolute security. If an incident requires notification under applicable law, we will provide the required notices.
10. Retention and deletion
We retain information according to its purpose, the customer's service arrangements, applicable record-keeping obligations, and legitimate security or dispute-resolution needs. Account and contact information supports the account; employment, payment, and audit records may need to remain available after a person's access ends.
When personal information is no longer needed for these purposes and no applicable preservation requirement remains, we will delete it or make it effectively anonymous. The appropriate period depends on the type of record and the reason it is retained.
Removing an organization membership, revoking an invitation, disconnecting Google, or deleting an authentication-provider account does not automatically erase all records associated with that person. For example, a customer may still need an accurate record of who received a tip payment or approved a cashout.
You may request deletion using our data deletion request instructions. We will assess which information can be deleted or de-identified, coordinate with the customer where appropriate, and explain any information that must be retained and the reason. Backup copies and records subject to legal retention may remain for their applicable retention periods.
11. Your choices, requests and concerns
Depending on applicable law, you may request access to personal information, correction of inaccurate information, deletion, or withdrawal of consent for processing that relies on your consent. Some requests are subject to legal, contractual, or third-party privacy limits. Withdrawing information needed for a feature may prevent us from providing it; we will explain the relevant consequences.
You can update available contact details in RTR. Ask your organization about access permissions, employment records, and reports it controls. You may also contact RTR directly; we will help identify the appropriate organization or handle the request where we are responsible. Removing access to one customer organization does not necessarily close an account used with another.
For access, correction, or deletion requests, we may ask for information reasonably necessary to verify your identity and locate the records. Use our data deletion request instructions for deletion requests. We will respond within the period required by applicable law and explain any permitted limitation or extension. If you remain concerned, you can contact the relevant privacy regulator, including the Office of the Privacy Commissioner of Canada.
12. Additional rights where California law applies
If you are a California resident and the California Consumer Privacy Act applies to our handling of your information, you may have rights to know the information collected, its sources, purposes, and recipients; obtain a copy; request deletion or correction; opt out of sale or sharing for cross-context behavioural advertising; and limit certain uses of sensitive personal information. Exercising applicable rights will not result in unlawful discrimination or retaliation.
Send requests to [email protected]. You may use an authorized representative; we may require proof of authority and any verification permitted for the request. Identity verification is not required for a sale/sharing opt-out. Where RTR acts as a service provider for your organization, we will help direct the request to that organization and assist as required. Applicable exceptions may affect the outcome, and we will explain a refusal. See the California Attorney General's rights guidance.
13. Young people in the workplace
RTR is a workplace service, not a service directed to young children. Customer records may concern staff who are minors. Organizations must take account of applicable employment and privacy laws and provide notices or obtain consent appropriate to the person's circumstances. Contact [email protected] if you believe information about a child has been provided improperly.
14. Changes to this policy
We will update this page and its effective date when our practices change. For a material change, we will provide notice appropriate to the change and obtain consent where required. A policy update alone does not authorize a new use that requires consent.
15. Contact us
For privacy questions, requests, or complaints, contact:
Privacy Officer, Read the Room Systems Inc. — RTR Systems / ReadTheRoomEmail: [email protected]
You can also use this address to request an accessible format of this policy or assistance submitting a privacy request. Please include enough information to identify your RTR account and organization. Do not send your password, verification codes, or unnecessary sensitive records.