Privacy Policy
Last updated: 2026-05-13
This Privacy Policy explains how Nine Pound Hammer LLC ("we", "us", "our"), operating under the 1prairie brand, collects, uses, shares, and protects information in connection with the menu service (the "Service"). This policy applies to restaurant operators and collaborators who use the authoring side of menu. The diner experience on a published menu page is addressed separately in §3.
1. Information we collect
1.1 Account information
When you create an account we collect:
- Email address and a password hash (handled by Firebase Authentication; we do not see your plaintext password).
- When you sign in with a third-party provider (currently Google or Apple, with Facebook planned), we receive a limited identity token from that provider, including your email address and provider-assigned user ID. We do not receive your provider password.
1.2 Restaurant and menu content
We collect the content you provide to author your menu, including:
- The restaurant's name, location, contact details, branding, and operating hours;
- Menu items, sections, prices, descriptions, dietary tags, and any other structured fields you fill in;
- Uploaded source files (photos of printed menus, PDFs, dish photographs, logos).
Menu content and uploaded source files are stored in Google Firebase Storage and Cloud Firestore, both operated by Google Cloud Platform.
1.3 Billing information
When you subscribe to a paid plan, Stripe, Inc. acts as our payment processor and collects your payment method directly. We receive from Stripe a Stripe customer ID and your subscription state (active / trialing / past-due / canceled). We do not collect or store your full payment card number or other sensitive payment details.
1.4 Analytics and usage telemetry
We use Google Analytics 4 (GA4) on our marketing and authentication surfaces (/, /sign-in, /sign-up) to understand visitor flow. GA4 sets cookies and may collect IP address, device, and browser details, subject to its data-handling defaults.
Inside the authoring tools, we record limited usage counters in Firestore: for example, the number of AI ingestion attempts per restaurant. These counters help us monitor cost and abuse and are not associated with any third-party advertising.
1.5 Server logs and error reports
Our backend services generate server logs (request paths, response status, latency, error traces). Server logs are retained for a limited operational window.
2. AI processing of your content
Material you upload (menus, photos, descriptions) is sent to Google Vertex AI to be structured, transcribed, or rewritten on your behalf. Vertex AI is operated by Google Cloud Platform under its enterprise data terms, which do not permit your prompts or model outputs to be used to train Google's foundation models. If Google materially changes those terms, we will update this policy.
We do not use any other AI provider for processing your content. We do not use your content to train our own models.
3. Diner data on your published menu
Your published menu is a public webpage. We design it to collect as little as possible from the diners who view it:
- No login or PII collection. Diners do not sign in to view a menu and we do not ask them to identify themselves.
- No tracking cookies for advertising. The published menu does not set advertising cookies or share diner identifiers with marketing platforms.
- Aggregate impressions. We count how many times your published menu page is viewed per day, in aggregate, to give you basic page-view analytics. These counts are stored as integers in Firestore and are not tied to individual diners.
Your restaurant may have its own legal obligations to diners under consumer-privacy laws in your jurisdiction. We do not advise you on those obligations; you should consult your own counsel.
4. How we use information
We use the information we collect to:
- Provide and operate the Service (authenticate you, store and publish your menu);
- Bill and manage your subscription (through Stripe);
- Send transactional and Service-related email (account verification, billing notices, important policy changes), sent by Resend, Inc. as our transactional-email provider;
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms of Service;
- Improve the Service (operational analytics, debugging, capacity planning); and
- Comply with our legal obligations.
We do not sell your personal information, and we do not share it with advertising networks or data brokers.
5. Sub-processors
We rely on the following third-party services to operate menu. Each is bound by its own terms and privacy policy.
- Google Cloud Platform — Firebase Authentication, Cloud Firestore, Firebase Storage, Firebase Hosting.
- Google Vertex AI — AI parsing and content generation.
- Stripe, Inc. — payment processing.
- Resend, Inc. — transactional email.
- Formspree, Inc. — help/contact form on
/help. - Google — OAuth sign-in (account creation via Google).
- Apple Inc. — OAuth sign-in (account creation via Apple).
- Meta Platforms, Inc. — OAuth sign-in (account creation via Facebook), planned.
We may add or change sub-processors over time. Material changes will be reflected here.
We do not currently use Sentry for error tracking, but plan to. When it is added, this list will be updated.
6. International transfers
We currently operate the Service from the United States. Some sub-processors (including Google Cloud and Vertex AI) operate globally. If you access the Service from outside the United States, your information will be transferred to, and processed in, the United States and other countries where our sub-processors operate. We rely on the standard contractual and technical safeguards provided by our sub-processors for cross-border transfers.
We do not currently target the European Economic Area or the United Kingdom. Customers outside the United States should consider whether the Service is appropriate for their compliance needs before subscribing.
7. Your rights
Depending on where you live, you may have the following rights with respect to your personal information:
- Access — request a copy of the information we hold about you;
- Correction — ask us to correct inaccurate information;
- Deletion — ask us to delete your account and associated data;
- Export — receive a structured copy of your menu data; and
- Objection / restriction — limit how we use your information for certain purposes.
To exercise any of these rights, write to privacy@1prairie.com.
7.1 California residents (CCPA / CPRA)
California residents have specific rights, including the right to know what personal information we collect, to delete it, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as defined under the CCPA/CPRA. We will respond to verifiable consumer requests within the time period required by law.
8. Cookies
We use a small number of cookies and similar technologies:
- Authentication cookies set by Firebase Authentication to keep you signed in;
- GA4 analytics cookies on marketing and auth pages, used for visitor analytics as described in §1.4;
- Stripe Checkout cookies when you go through the billing flow; and
- Necessary CSRF / session cookies required for secure operation.
Most browsers let you block or delete cookies. Blocking authentication cookies will prevent you from staying signed in.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at privacy@1prairie.com and we will delete it.
10. Retention
We retain your account and menu data for as long as your account is active. After you cancel your subscription, your published menu remains available for a transitional period and your account data is deleted on the schedule described in §11 of the Terms of Service. Limited records (for example, financial records required for tax purposes) are retained for the period required by law.
When you delete your account, we remove your menu content, uploaded files, and account profile from our live systems. We keep a minimised forensic record of the deletion for up to twelve months so that we can answer billing questions, reconcile refunds, and respond to disputes. That record contains only:
- A one-way hash of your email address (so we can match a complaint to your deletion record without storing the address itself);
- The internal restaurant identifier and your Stripe customer / subscription identifiers;
- The deletion timestamp, the refund result (amount, refund ID, or skipped reason), and a count of any files that didn't purge cleanly so we can sweep them later.
After twelve months this record is automatically deleted from our systems. We do not retain your plaintext email address, your restaurant name, or any of your menu content past the deletion.
Backups containing your data may persist for a limited window beyond the deletion of the live record.
11. Security
We protect your information using the following measures:
- Tenant isolation in Firestore enforced by security rules (each restaurant tenant's data is accessible only to that tenant's signed-in members);
- Secrets management in Google Secret Manager (we do not store credentials in client-side code or source control);
- HTTPS everywhere for the authoring application, the API, and published menu pages;
- Limited human access to production data, granted only when necessary for support or investigation; and
- Authentication handled by Firebase Authentication, which provides salted-and-hashed password storage and OAuth integrations with Google and Apple.
No system is perfectly secure. If we become aware of a security incident affecting your information, we will notify you and any required regulators as the law requires.
12. Changes to this policy
We may update this policy from time to time. When we make a non-trivial change, we will notify you by email and through an in-app notice. The "Last updated" date at the top of this document reflects the most recent revision.
13. Contact
For privacy questions or to exercise the rights described in §7, write to:
privacy@1prairie.com
For general support, write to support@1prairie.com.
Nine Pound Hammer LLC (operating under the 1prairie brand)