1. Who we are
Yes Chefo ("Yes Chefo", "we", "us") is a service operated by [NE RESTAURANT LTD], registered in [Ireland]. We are the data controller for the personal data described in this policy. For any privacy question or to exercise your rights, contact us at [hello@yeschefo.com].
This policy covers the Yes Chefo website and the Yes Chefo product and its plans — Home Plus, Develop, Operate and Brigade (together, the "Services").
2. Data we collect
You give us
- Account & contact data — name, email address and password (stored hashed) when you create an account or enter your email at a prompt/paywall.
- Content you enter — the ideas, briefs, menus, dishes, costings and other text you submit to the Services.
- Billing data — when you subscribe, payment is processed by Stripe. We receive limited details (e.g. plan, status, last four digits, country) but we do not store full card numbers.
- Communications — messages you send us by email or support.
Collected automatically
- Usage & device data — pages viewed, features used, approximate location derived from IP, browser/device type, and similar diagnostic data.
- IP address — used transiently for security and rate-limiting of free previews.
3. How we use your data
- To provide, operate and improve the Services and generate the outputs you request.
- To create and manage your account and process subscriptions and payments.
- To send service and transactional emails (e.g. sign-in links, receipts, important notices).
- To protect the Services — preventing abuse, fraud and excessive use (rate limiting).
- To respond to your enquiries and provide support.
- To comply with legal obligations.
4. Legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Services & your account | Performance of a contract |
| Payments & billing | Performance of a contract; legal obligation |
| Security, anti-abuse, rate limiting | Legitimate interests |
| Product improvement & analytics | Legitimate interests |
| Marketing emails (if any) | Consent (you can withdraw at any time) |
5. Processors & sharing
We do not sell your personal data. We share it with trusted service providers ("processors") who act on our instructions:
| Processor | Purpose |
|---|---|
| Stripe | Payment processing & subscription billing |
| Supabase | Database & account storage |
| Cloudflare | Hosting, content delivery, security & rate limiting |
| Resend | Transactional email delivery |
| AI providers | Generating menus, dishes and briefs from the content you submit |
We may also disclose data where required by law, to enforce our terms, or in connection with a business transfer.
6. AI processing
Some features send the text you submit (for example a menu idea or dish brief) to third-party AI providers to generate a response. We instruct these providers to process the content only to return your result. You should avoid entering personal data or confidential third-party information into these prompts. We do not use your submitted content to train third-party AI models where that option is within our control.
7. Cookies & local storage
We use a small number of cookies and browser local storage that are strictly necessary to run the Services — for example to keep you signed in and to count free previews per device. We keep non-essential tracking to a minimum. Where required, we will ask for your consent for any non-essential cookies.
8. Data retention
We keep personal data only as long as needed for the purposes above: account data for the life of your account and a reasonable period afterwards; billing records for as long as required by law; and diagnostic/rate-limit data for a short period. You may ask us to delete your account and associated data (subject to legal retention duties).
9. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent. To exercise any right, email [hello@yeschefo.com]. You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie) or your local supervisory authority.
10. International transfers
Some processors may process data outside the European Economic Area. Where they do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
11. Security
We use technical and organisational measures appropriate to the risk — including encryption in transit, hashed passwords, access controls and reputable infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Children
The Services are intended for hospitality professionals and are not directed at children under 16. We do not knowingly collect data from children.
13. Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above and, for material changes, take reasonable steps to notify you.
14. Contact
[NE RESTAURANT LTD]
[Ireland]
Email: [hello@yeschefo.com]