Effective date: June 19, 2026. Operator: FlowState QSR. Contact: grindstaffconnor@gmail.com.
FlowState QSR (“the App”) is a private team-management tool for the team and leadership of a restaurant. Accounts are created and managed by the restaurant’s operator. This policy explains what the App collects and how it is used.
Information we collect
- Account info: your name, username, and password (passwords are stored only as a secure one-way hash — never in plain text). Your role and store number.
- Profile & contact details you or your store add: a nickname, a profile photo, a phone number, an email address, and your birthday. If your store uses minor-labor protections, your full date of birth is stored to apply break and hours rules for employees under 18.
- Employment & pay data your store's leaders enter: schedules, station assignments, certifications, and — if your store uses the timeclock — clock-in/out punch records and an hourly wage used for payroll exports and waste costing.
- Location-verification signals (timeclock only): if your store turns on clock-in verification and you allow location access, your device sends its coordinates at clock-in; we store only your distance from the store and a near/far flag with the punch — not your coordinates, and never outside of clocking in. If your store doesn't use this or you decline, no location data is processed.
- Work records you and your team create: goals, feedback, shout-outs, messages and channel posts (with attachments), checklists, training interests, uniform & facilities requests, discipline records, safety checks (RSA/FSA), temperature logs, CEM scores, waste logs, car counts, events, and similar operational data.
- Push token (only if you enable notifications): a device identifier used solely to deliver notifications.
- Basic technical logs: session records include IP address and browser/app type for security.
We do not collect your contacts or browsing history, use advertising identifiers, or use any advertising or cross-site tracking tools.
How we use it
We use this information solely to operate the team-management tool for your store — schedules, the timeclock and payroll exports, recognition, food-safety and compliance logs, messaging, and the notifications you opt into. Some features use an AI assistant (see Service providers below); AI features only process store data when someone at your store uses them.
How it’s shared — service providers (subprocessors)
- Within your store: teammates see information according to their permission level (leaders and the operator see more than team members). The operator administers the system.
- Render (USA) — application hosting and data storage.
- Apple — push notifications (APNs) on iOS: device token and notification text; Sign in with Apple if you link it; App Store purchases.
- Google Firebase Cloud Messaging — push notifications on Android: device token and notification text.
- Anthropic (USA) — powers the optional AI features (the "Ask" assistant, checklist extraction from uploaded documents, schedule-photo import, and AI-drafted coaching/write-up text). When your store uses these, the relevant store data (for example, an uploaded schedule photo, or the names and records involved in the question) is sent to Anthropic's API to generate the response. Anthropic does not train on this API data.
- RevenueCat — subscription purchase processing for the store's plan (no employee data; purchase identifiers only).
- Sentry — error reporting (operational error context only; configured to exclude personal data and wages).
- Encrypted off-site backups may be stored with an S3-compatible storage provider.
- We do not sell your information and do not share it for advertising or cross-app/website tracking.
Tracking
The App does not track you across other companies’ apps or websites.
Data retention & deletion
Your information is kept while your account is active. Chat messages are deleted after one year. Timeclock records are retained for the period required by wage-and-hour law. You can export your personal data and delete your account from My Account in the app — deletion disables the account, removes your profile details, and signs out all devices; some operational records your store is required to keep (for example time records) are retained per the schedule above. You can also ask your store operator, or email us, to correct or delete your information.
Security
Passwords are hashed, data is encrypted in transit (HTTPS) and — where configured — at rest (AES-256), and access is limited to logged-in members of your store by role.
Permissions on your device
- Camera & Photos: requested only when you choose to add a photo (a profile photo, a chat attachment, or a document/schedule upload).
- Location: requested only if your store uses clock-in verification, and only at clock-in (see above).
- Notifications: requested so we can send you work notifications you opt into. You can turn these off anytime in Settings.
- Face ID / Touch ID: used to unlock the app and, if you turn it on, to sign you in. A revocable sign-in token (not your password) is kept in the device's encrypted Keychain and never leaves your device. The biometric check happens entirely on your device — we never receive your face or fingerprint data.
Employees under 18
The App is a workplace tool and is not directed to children under 13. Stores may employ workers aged 14–17; for them, the App stores date of birth so break and hours protections for minors can be applied automatically. Parents or guardians of an employed minor can contact the store operator, or email us, with questions about their teen's information.
Changes
We may update this policy; the effective date above reflects the latest version.
Contact
Questions? Email grindstaffconnor@gmail.com.