noosh Start free

Privacy Policy

Your data stays in your restaurant. On purpose.

Most restaurant software quietly ships your recipes, margins and guest list to someone else's cloud. Noosh doesn't. This page explains, in plain language, exactly what information we handle and how — and how little of it ever leaves your premises.

Last updated: 21 July 2026 · This policy is written to comply with South Africa's Protection of Personal Information Act (POPIA).

The short version

  • Your restaurant's operating data lives on-site. Sales, stock, staff, guests, invoices — that lives on the hardware in your restaurant, not on our servers. In most cases we cannot see it.
  • The AI runs on your premises, not in the cloud. Invoice and menu scanning, the nightly briefing, the benchmarking — the models run on your own equipment. Your documents are not sent to any third-party AI service, and are never used to train anyone's models.
  • We collect only what we need to run your account — enough to set you up, bill you, and support you.
  • We never sell your information. Not to advertisers, not to data brokers, not to anyone.

The rest of this page is the detail behind those four promises.

1. Who we are

Noosh is a restaurant software service operated as a sole proprietorship based in South Africa ("Noosh", "we", "us").

For the purposes of POPIA, our Information Officer can be reached at [email protected].

Two different relationships are worth separating up front:

  • For your Noosh account, subscription and this website, we are the responsible party (data controller).
  • For the personal information of your own customers and staff that Noosh processes inside your restaurant (for example a loyalty member's phone number, or an employee's payroll record), you are the responsible party and Noosh acts only as your operator (processor) — handling that data on your instruction, on your equipment.

2. What we collect, and why

Account & billing information

When you register, subscribe, or contact us, we collect the details you give us — your name, restaurant name and location, email address, phone number, and billing details. We use this to create and administer your account, take payment for your subscription, provide support, and send you service-related messages. This is the information we hold as responsible party.

Your restaurant's operating data

Sales, menu, stock, supplier invoices, staff and payroll records, loyalty members, and reports are generated and stored on the Noosh system running in your restaurant. In the normal course of things this data does not reach us. We may access a limited, specific slice of it only when you ask us to — for example, if you request hands-on support and grant us access to help troubleshoot.

Camera & photos

The app can use your device's camera or photo library so you can scan supplier invoices and menus. These images are read by the on-premises AI to pull out the text and figures; they are processed on your own equipment and are not uploaded to any third-party service. You are always the one who chooses which document to scan.

Website & enquiry information

If you fill in a form on this website, or message us on WhatsApp, we receive what you send us (such as your name, email and message) so we can reply. Our website uses only the cookies strictly necessary to function; we do not run third-party advertising or cross-site tracking.

Technical & device information

Like any online service, our systems automatically record basic technical data — such as IP address, device and browser type, and error logs — to keep the service secure and working. We keep this to the minimum needed for security and reliability.

The part most companies won't put in writing

On-premises AI, in plain terms.

Noosh's intelligent features — reading invoices, drafting the nightly briefing, spotting shrinkage, benchmarking — are powered by AI models that run on the hardware in your restaurant, not on a remote cloud API. In practical terms that means:

  • Your invoices, recipes, prices and guest information are not sent to OpenAI, Google, Anthropic or any other third-party AI provider.
  • Your data is never used to train any AI model — ours or anyone else's.
  • The intelligence keeps working even when your internet is down, which is the whole point of building it this way for South Africa.

3. How we share information

We do not sell your personal information, and we never will. We share it only in these limited situations:

  • Service providers who help us operate — for example a payment processor to collect your subscription, or infrastructure providers who host this website and our account systems. They may only use the information to perform that service for us, under contract.
  • Legal requirements — if we are required by law, court order, or a valid request from a competent authority to disclose information.
  • Business transfer — if Noosh is ever involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction, subject to this policy.

4. How we protect information

We use reasonable technical and organisational measures to protect personal information against loss and unauthorised access — including encryption of data in transit, access controls, and keeping the bulk of your operating data on your own premises rather than in a central store that could be breached at scale. No system is perfectly secure, but keeping your data on-site is a deliberate security decision, not just a privacy one.

5. How long we keep it

We keep account and billing information for as long as you have an account with us, and for a period afterwards where the law requires us to (for example, tax and accounting records). Data held on your on-premises system is retained and deleted under your control. When information is no longer needed, we delete or anonymise it.

6. Your rights

Under POPIA (and similar laws that may apply to you) you have the right to:

  • ask what personal information we hold about you and request a copy;
  • ask us to correct information that is wrong or out of date;
  • ask us to delete information we no longer have a lawful reason to keep;
  • object to certain processing, and withdraw any consent you have given;
  • lodge a complaint with the Information Regulator of South Africa.

To exercise any of these, email us at [email protected] and we will respond within a reasonable time. If your request concerns your own customers' or staff's data held inside your restaurant, you (as the responsible party) control that directly in the app; we will help where you need us to.

7. Children

Noosh is a business tool and is not directed at children. We do not knowingly collect personal information from children.

8. Where your data is processed

Your restaurant's operating data is processed on your premises in South Africa. The limited account, billing and website data we hold is processed in South Africa and/or with reputable providers who offer an adequate level of protection. We do not transfer your personal information internationally except as needed to provide the service, and always subject to appropriate safeguards.

9. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the date at the top and, where appropriate, let you know. Continuing to use Noosh after a change means you accept the updated policy.

10. Contact us

Questions about this policy, or about your information? We'd genuinely rather hear from you than not.

Noosh — Information Officer
Email: [email protected]

WhatsApp 072 645 7809